Risks
Shared Credentials
Credentials shared across users through an agent break access boundaries and demand continuous auditing
In an agent PoC, it’s tempting to reuse the credentials at hand, whether a personal access token or a Machine User’s API key. Many implementers choose this path because it’s fast to build. But credentials shared by multiple users through an agent, that is, shared credentials, are also what breaks access boundaries.

