◇ agent
◇ provisioned accounts
◇ provision / log in
⚠ use a dedicated bot account, not a human's —
and a minimally-scoped personal access token (only
the repos/scopes the agent actually needs, e.g.
repo +
workflow). the container boundary is the enforcement:
anything within the token's scopes is reachable if the agent is
ever compromised. the token is injected into the agent's state dir
and is never displayed back on this page.