DIDs, verifiable credentials, and AI control towers are foundational for agent governance, but they still do not decide whether a specific agent action is allowed right now. The article explains the runtime authorization model enterprises need for delegated AI execution.