most agents hold 10x more privileges than required

Extracted from: agent-access-control-zero-code-security.md