Authorizing a given CA can still be too broad for your taste, which is why RFC8657 specifies the 'accounturi' and 'validationmethods' parameter extensions.
There's also a draft extension for Signed HTTP Exchanges ('cansignhttpexchanges') that appears to only be supported by DigiCert and pki.goog.
The usage of these parameters is quite limited:
In conclusion, after analyzing around 214 million domain names for CAA records, the following are worth noting:
1) CAA records are still not widely used.
Across all TLDs, only 1.4% of domains use CAA records; out of the Top 1M Domains, only 4.8%.
Considering that CAA records have been around since 2010 and honoring them has been mandatory for CAs since 2017, this seems like a pretty poor adoption rate.