Yeah. If we want fine grained "intelligent" authorization, there's a lot of work to be done. You can't simply slap a gateway on existing systems.
I wrote about this more on my employer's blog[0].
> The real long-term win is defining ground level permissions around common use cases, so that when composed they can alert as rarely as possible.
And this is an even larger effort to implement, especially as agent capabilities change over time (and they are changing rapidly).