How do you prevent unauthorized AI agent actions?

Unauthorized AI agent actions almost always result from one of four failures: the agent inherits a developer's blanket credentials, the scope is unbounded, no approval flow exists for destructive operations, and there is no audit that would survive an incident review.