The URL is a temporary capability to fetch an object, not the durable identity of the report. Anyone who holds a valid bearer link may be able to use it under the conditions of its signature. Amazon S3's presigned URL guide explicitly describes these URLs as bearer tokens and explains that expiration can depend on the signing credential as well as the requested lifetime. Other storage systems differ in detail. The general mistake is making a transient access grant into both an object ID and a memory fact.

I would stop storing and displaying the raw URL. The agent's durable reference should be a stable report ID and revision, with tenant, source and purpose metadata. A file broker owns the mapping from that ID to storage and checks the user's current authority each time access is requested. It then fetches the bytes or grants a short, scoped URL for the immediate operation. The model may need the report content and citation handle. It does not need a reusable bearer secret in its long-term memory or a shared trace. If the tool output already went to logs, treat those logs as potentially containing a live access token until expiration or revocation is verified.

The retry failure is normal if the link expired. A year-long URL would make the old memory appear to work while extending exposure after the user's permissions, report revision or task purpose changes. A signed URL's validity is also not the same thing as current application authorization. At generation time we can check access, but a holder may use the URL later without asking the application again until the storage policy denies it. Design for the actual revocation requirements. Short expiry, narrow object and action scope, private network controls or a brokered fetch can reduce the window. If urgent revocation is needed, verify what the provider can invalidate and how quickly rather than assuming deleting a row in the app revokes an already issued link.

The trace should record a redacted access event: report ID, revision, requesting run, operation, decision, expiry and a non-secret correlation ID. Query strings containing signatures should not flow into model prompts, analytics URLs, exception messages, browser referrers or copied answer text. Redaction at one log sink is not enough if the model has already put the link into a summary that later gets replayed. Test retries, tool errors, shared dashboards, report deletion and permission loss while a link is still valid.

If the interviewer says the report is publicly shareable anyway, the risk changes. We may store a public canonical URL, but we should still distinguish that from an expiring signed request and know which revision it names. The design decision follows from the authority of the link, not from its familiar URL shape.