Dusting Off the Bastion Host: Why Yesterday’s Fortress Isn’t Enough for Agentic AI
Blog post from Ory
Security teams are increasingly applying familiar perimeter-security concepts such as bastion hosts, VPNs, segmentation, and centralized MCP servers to agentic workloads, reflecting a revival of older security terminology and architectures. While these controls remain useful for protecting network boundaries, the author argues that they are insufficient for agents that operate at machine speed and can perform local shell commands, file writes, API requests, and tool calls without crossing a traditional network chokepoint. The proposed alternative is to enforce identity, authorization, auditing, and policy decisions within the agent harness or SDK layer, where each specific action can be evaluated in context. Ory Agent Security is presented as a product pursuing this approach, expanding support from five to eleven coding-agent harnesses and adding thirteen SDK integrations for custom agent frameworks, all governed through a shared policy model. The author recommends retaining conventional network controls while first monitoring agent behavior, then introducing targeted enforcement at the points where agents actually act.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.