The approval was real. The user authority was not.
That distinction is where a tool-using agent review becomes more than prompt testing. The evidence has to connect the attempted action to a trusted authorization record, not just to a plausible explanation from the model.
External context: the FBI IC3 Internet Crime Report and OWASP Agentic AI guidance both point to why action-level controls deserve attention as agents touch money, data, and operational systems.