Your AI agents don't need a new identity stack. They need a new enforcement point.
Blog post from Ory
Ory argues that AI agent security should extend existing identity, authorization, and audit systems rather than create a parallel security stack, with enforcement placed inside the agent runtime’s harness event loop where individual actions can be evaluated before execution. Its proposed architecture uses Kratos to establish human, agent, and sub-agent identities with delegation chains; Hydra for short-lived, revocable credentials; Keto for fine-grained relationship-based permissions; and supporting components for network traffic, enterprise endpoints, B2B access, developer workflows, and OpenTelemetry-based audit records. The approach is intended to govern local commands, file operations, API calls, and MCP tools that gateways, sandboxes, directories, and SIEMs may not directly control, while preserving a shared policy model for people and agents. Ory says its integrations support multiple coding harnesses and agent SDKs through common runtime hooks, draws scalability from its established identity products, and can be deployed either self-managed or through Ory Network. The system does not inspect prompts or retrieved content, focusing instead on actions, and it defaults to fail-open when authorization services are unavailable unless organizations deliberately choose stricter behavior. Ory recommends beginning in observation mode to inventory agent behavior, develop policies from recorded actions, and then introduce enforcement incrementally.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| MCP | 3 | 2,241 | 148 | 72 | -74% |
| AI Agents | 2 | 931 | 231 | 103 | -84% |
| Developer Experience | 2 | 131 | 58 | 24 | -72% |
| OpenTelemetry | 2 | 125 | 18 | 15 | -83% |
| Agent Plugins | 1 | 3 | 3 | 2 | -96% |
| Observability | 1 | 472 | 102 | 54 | -85% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.