The three pillars make sense to me mostly.. but the gap I keep running into is authorization scope.
You can prove a human authorized an agent to "handle my inbox" but that agent might delete emails, reply to clients, forward stuff. Proving someone is at the root doesn't mean they signed off on every action the agent took.