How to secure create/update/delete Actions for trusted users?

Yes, OAuth is the way to go. Similar to Plugins: https://platform.openai.com/docs/actions/authentication.