Most enterprise deployments skip the authorization layer entirely.
Agents get API keys, not identity. When something goes wrong, there's nothing to trace. Just logs that say the agent acted, and no record of who said it could.
That's not a minor oversight. That's a liability.