When the panel says… the answer they are listening for
In plain English: each line is a question as a panel would phrase it, then the one-sentence answer that signals you built it, then the reason the usual answer loses.
“A demo agent and an enterprise agent: what is the difference?” → The same model in a different body: identity, isolation, egress control, resumability and audit are properties of the organs around the reasoning core, and each organ is an extension point where you attach a control. “A better prompt” misses that none of those lives in the model.
“How does state change in an event-sourced runtime?” → A tool's write becomes a delta on the event, committed only when the event is appended to the session log, which gives auditability, resumability and consistency for free. Writing to a global variable directly loses all three.
“Where do you keep an OAuth token fetched for one call?” → In the temp scope, which lives for the turn and is never persisted; the user scope is for this user across sessions and the app scope for everyone. A plain key would write the secret into the session store.
“The synthesiser ran before the slow specialists returned.” → The fan-in target was a plain node, which fires once per incoming branch; use a join node, a barrier that waits for every branch before the next node runs.
“A remote specialist's branch is empty at the join.” → A remote agent has no output key, so its reply never reaches shared state; add an after-agent callback that copies its final reply into state under a known key the synthesiser reads.
“Transfer, agent-as-tool, or a workflow?” → Transfer when a judgement call should route and the specialist then owns the conversation; agent-as-tool when the caller must stay in control and see only the result; a graph workflow when the flow must be the same every time and provable afterwards.
“MCP or A2A?” → MCP inside agents, for tools and data; A2A between agents that reason for themselves and are owned by someone else. Giving a capability is MCP; delegating a task is A2A.
“Where does identity go in an agent-to-agent call?” → In transport headers, never in the message body and never in the card; the card names the security scheme, the transport carries the token.
“The orchestrator cannot parse a specialist's agent card.” → The specialist runs the newer SDK and the orchestrator's client is pinned to 0.3, so the card must also advertise a 0.3-compatible interface; a version mismatch between caller and callee is the most common interop failure.
“The deployed root gets 403 from a specialist that worked in the playground.” → Locally it ran as you; deployed it runs as the runtime service account, which authenticates but has not been granted the role. 401 is no credential, 403 is a known identity with no permission.
“A public service versus a private one on Cloud Run.” → Public needs no token; private needs an identity token whose audience is the service URL plus the invoker role on the caller, and redeploying resets that IAM binding.
“Define the confused deputy.” → A privileged program tricked by a weaker party into misusing its authority; private data plus untrusted content plus a way out is the lethal trifecta, and agents are ideal deputies because they act on input an attacker can write.
“Delegation or impersonation?” → Delegation names both parties in the token, the user in sub and the agent in act, so the actor is visible and governable; impersonation names only the user and erases attribution. Prefer delegation.
“What makes a token safe?” → Short-lived, delegated with the actor visible, bound to its holder, one audience with a narrow scope; audience binding stops a token for one tool working on another, and no passthrough means every hop mints its own.
“Own authority or on behalf of a user?” → Own authority with a least-privilege workload identity for jobs that belong to the agent, such as a nightly reconciliation; a scoped short-lived delegation whenever the action belongs to a person. Never hand an own-authority agent a user's broad token.
“When is a discovery engine the right tool, not a coding assistant?” → When the problem is an optimisation with a scorer you can write, many parameters, and a search space too large for a person; the human sets the objective, the evaluator and the bounds, the engine evolves candidates and keeps the elites.