The credential

What the agent gets handed at task start

Not a token with nine scopes and no expiry. A credential scoped to this task type, expiring when the task does, with the reasoning attached.

keyring issue --task process-refundpass
issued  cred_8f2a91  ttl=300s  task=process-refund

  granted:
    + orders:read
    + orders:refund
    + tickets:read

  withheld (6):
    - billing:read
    - billing:write
    - customers:delete
    - customers:read
    - customers:write
    - tickets:write

  basis: 620 observed tasks
  unseen-scope risk: 0.0%  (safe to tighten)
  blast radius: 13 of 52