Use a Service Principal
Run the agent as an application identity with its own credentials and permissions. This works for established workloads, but access is typically defined at the app, role, or resource level rather than around the task behind each tool call.