問題文
Which practice correctly applies role-based access control to a multi-agent solution?
選択肢
- Grant each agent's identity the narrowest built-in or custom role that covers the operations its own tools perform
- Grant every agent the Contributor role on the resource group so no agent is ever blocked, and rely on the per-agent identities to keep the audit log attributable
- Grant roles to individual users only, never to agent identities
- Assign roles at the subscription scope so they do not need to be repeated per resource