問題文
A downstream API must apply the calling user's own row-level permissions. The agent runs as a background service. Which flow is required, and why is the service's own identity insufficient?
選択肢
- The on-behalf-of flow is required, because the service's own identity carries the service's permissions and cannot express which user is asking
- The service's own identity is sufficient, since the agent can pass the user's identifier as a parameter that the downstream API resolves against its own permission table
- An API key is required, since keys can be issued per user
- A managed identity is required, since it can impersonate any user