Why not just give the agent a short lived token with limited access rights?
We have reached the point where we need to control agent access the same way we control human access to systems.