Enterprises spent years securing human identity.
Now the fastest-growing “employee” is an AI agent with API keys, tool access, memory, and zero clear owner.
When one agent asks another for help, the risky part is not the message.
It is the data that moves because of the message.
A Support Agent asking a Finance Agent about an account should not get the whole finance context.
It should get the minimum allowed answer, with restricted fields redacted and the decision recorded.
That is the enterprise A2A layer:
verify the caller
scope the reply by policy
record what happened
Agent-to-agent communication needs more than connectivity.
It needs boundaries.