Turn the Lights On Before You Start Blocking AI Agents
Security teams rolled out intrusion prevention and WAFs in monitor mode first. Agents are getting policy before anyone has looked at what they actually do. Ory's case for visibility before enforcement.
- AI agents have become production dependencies within months rather than years, outpacing the security visibility needed to govern them safely.
- Most security teams cannot answer basic questions about which systems their agents touch or whether observed agent actions are expected, representing a fundamental visibility gap.
- Ory Agent Security operates at the harness layer where agent actions execute, enabling both full observability and the ability to block actions before they run.
- Ory's recommended playbook mirrors IPS and WAF rollouts: observe first, run in monitor mode before enforcing, and let real behavioral data drive policy rather than generic templates.
- Because adoption timelines are compressed, teams have weeks or months rather than years to complete this process, but skipping the observation phase risks the same false-positive outages that plagued premature WAF deployments.
- IPS and WAF rollouts both started in monitor mode; teams learned what "normal" looked like before denying anything.
- Agents are the newest control plane, and many orgs are writing deny rules before they've observed agent behavior.
- The difference this time is speed: agents went from demo to production dependency in months, not years.
- Ory Agent Security sits at the harness layer, where agent actions execute, so it can both observe every action and stop one before it runs.
- Ory's playbook: watch first, monitor before enforcing, let observed data write policy, compress the timeline without skipping the phase, and keep the lights on permanently.
Security has run this playbook twice already
When intrusion prevention systems arrived, nobody switched them straight into blocking mode. Teams ran them in monitor mode, watched real traffic, and learned the difference between the network on the vendor's slide and the one crossing their wire. Only then did they start denying.
Web application firewalls followed the same path. Skip the observation step and a WAF with no context flags your own QA load tester as an attacker, production breaks, and the "security improvement" becomes the outage a CISO explains to the CEO on a Friday afternoon. As Ory's Chief Customer and Security Officer Justin Dolly puts it, that isn't caution for its own sake: "It's how you avoid a career limiting event."
Same three phases, much shorter clock: agents compress years of rollout into months.
Agents are a visibility problem, not a blocking problem
AI agents are now the newest control plane, and organizations are racing to put policy in front of them. What's different is the rate of adoption. IPS and WAFs took years to become standard; agentic workloads went from demo to production dependency in months, at companies already running dozens of agents against real systems.
Ask most security teams which systems their agents touch, which permissions they exercise, or whether the agent that hit the billing API this morning was expected or a forgotten workflow, and the honest answer is a shrug. Not from lack of interest, but because nobody built the sensor yet.
That's the gap Ory Agent Security targets. It sits at the harness layer, the point where an agent's actions actually execute, and records every action, call, and system touched. Because it lives at the point of execution rather than watching traffic go by like an IPS on a wire, the same position that provides visibility can also stop an action before it runs. Teams monitor first, learn what normal looks like for their agents, then decide deliberately what to allow and what to block.
What doing it right looks like
You can't write good policy for a system you can't see. Teams that jump straight to blocking will relearn the WAF lesson, except the false positive is now an agent that was supposed to process a refund, approve a deployment, or update a customer record, and suddenly can't. Ory's recommended sequence:
Ory's five-step playbook for rolling out agent policy
Watch first. Get full visibility into every action agents take and every system they touch before writing a single deny rule.
Monitor before you enforce. Run in observation mode long enough to see real agent behavior, not what the documentation claims.
Let the data write the policy. Deny and limit decisions should come from what was observed, not a generic template.
Move fast, but don't skip the step. With adoption outpacing every earlier control plane, teams have months or weeks, not years. Compress the timeline; don't cut the phase.
Treat it as a program, not a launch. Agent behavior keeps shifting as workflows evolve, so the lights stay on permanently. The industry has run this playbook with IPS and with WAFs. The advice for agents is the same: turn the lights on, then decide what to block.
Teams that want to start with visibility can set up agent observation on a free Ory account in about 10 minutes. Justin Dolly, Ory's Chief Customer and Security Officer, walks through the IPS and WAF parallels in his original post.