Start here. This is the direct spoken answer to practice first.
Overview
Runtime inference should not require a broad administrator key.
I give the deployed workload its own cloud identity and grant only the data-plane actions and model resources it needs. Human and automation identities that create deployments, change policy, or assign roles are separate from runtime callers. Static API keys are limited to cases where identity-based authentication is unavailable, then stored, rotated, and monitored as secrets.