Picture this. Your development team spins up an AI pipeline, mixing human inputs with generative agents from OpenAI and Anthropic. Models summarize specs, write test cases, approve pull requests. It’s fast, dazzling, and dangerous. Somewhere in that blur, a fine-grained permission went missing, a secret token slipped into a