Runtime authorization is the enforcement layer that sits between an AI agent and the systems it acts on. Every prompt, tool call, and command is checked against policy before it runs.