Every security control ever built assumes a human or a program on the other side. An agent is neither: it decides what to do next by reading text, and text can be written by an attacker. So the question stops being “who is allowed in” and becomes “what is this thing allowed to do, who is it doing it on behalf of, what did it just read, and can anyone prove afterwards what happened”. Twelve sections, plain English first, and simulations for the controls that only make sense once you have watched one fail.