SemAuth enforces Intent Integrity the authorization property every existing IAM system assumes but never verifies. It intercepts LLM agent tool calls,detects CVIC attacks that pass OAuth and Cedar, and gates RFC 8693 token issuance on verified reasoning.