Permission Gap
Access control is necessary, but incomplete
IAM, OAuth, role-based access, policy engines, and agent identity answer important questions: who is acting, what tool can be called, and whether the request matches known policy. They do not always answer whether this specific action is recoverable under current conditions.
SMERC evaluates action metadata, evidence source, reversibility, containment, rollback latency, impact scope, anomaly pressure, and authorization confidence before execution.