According to Proofpoint CEO Sumit Dhawan, permissions confirm that a user or agent is authorized to access data, but they say nothing about whether a specific action is appropriate in context. AI runtime security must also evaluate intent, context, and outcome to determine whether behavior falls within expected business guardrails.