also OBO, token exchange, delegated access
A service swaps the user's token for a new one to call the next service as that user, so permissions and audit follow the real person instead of a shared service account.
You have done this if
Your agent called Graph with the signed-in user's delegated token, so it saw only that user's files.
Say it in a review
Tools are called on behalf of the user, so the agent can never see more than the person asking.
On the AI Application map Identity, Tools, Enterprise APIs