AI agents can change plans, tools, and context while running. Static permissions aren't enough. Here's how continuous authorization can govern agent access.