Evidence Based Authorization
AI agents in production hold standing permissions. Identity confirms who the agent is — not whether any specific invocation, with these parameters and this context, is actually warranted. Evidence-bound authorization fills that gap: every tool call earns its token, or it does not execute.