When AI agents are granted tool-execution privileges, they must be treated as autonomous enterprise identities. This deep-dive explains how to implement ephemeral OIDC credentials, least-privilege tool scopes, and cryptographic blast-radius containment.