Task-scoped "warrants", attenuating with delegation, and enforced cryptographically at tool call.
Macaroons/Biscuits for agents basically.