Service accounts / IAM / WIF / proxies, which remove credentials from the environment all together, are more advanced options.
I'm working on a custom "tool calling policy" guardrail agent. There are a number of models which have been trained to accept a policy document and user content, returning a truthy value for the harness to use during approval.