We’re handing AI agents API keys, OAuth tokens, and tool execution rights - and hoping for the best. This talk examines how to claw back control using layered defenses: cross-app access scoping, strict input/output validation, and sandboxed execution environments.