Picture your CI/CD pipeline humming along smoothly. Code gets merged, tested, and shipped while AI assistants review commits, write documentation, and suggest optimizations. Then an autonomous agent tries to push a config directly into production, skips your approval flow, and—if you’re unlucky—exposes an API key. That’