The service itself needs to control what the agent can access.
Relying on an intermediary to provide access controls, and that agents will never access the service directly, seems dangerous and naive.
Relying on an intermediary to provide access controls, and that agents will never access the service directly, seems dangerous and naive.