An agent runs as you.
It reads every credential you can read and touches every repository you can touch, at a rate no review process was built to absorb. That is not an argument for stopping. It is an argument for moving the control.
We spent fifteen years running security inside organisations that could not afford to be wrong — Amazon, Cisco, Macquarie, NAB, and Australian government programs. The lesson repeated itself every time: the control that works is the one standing in the execution path, not the one written in the policy document. Everything else is a record of what you intended.
So we build in the path. Take the secret off the disk and put a broker where it used to be. Make the assessment emit its own evidence rather than a separate reporting exercise. Small, checkable mechanisms — the kind you can read the source of in an afternoon and decide for yourself.