Governing the AI Fleet: How CISOs Can Stop Rogue Agent Actions Without Slowing Down Developers

Your engineers are already running AI coding agents. Those agents run shell commands, edit files, call internal APIs, and spawn sub-agents — most of it inside developer environments that never cross a network boundary, where gateways cannot see and sandboxes are too coarse to help. Most organizations cannot produce a list of the agents running in their environment, let alone what those agents are permitted to do.

In this webinar session, Clint Hill, Product Technologist, shows and demos live a different approach: enforcement inside the agent harness itself, where every tool call is checked against policy before it executes rather than flagged after.

We will cover how to start in observe mode with nothing blocked, how to turn on enforcement without breaking your engineering org, where this approach still has gaps, and how it runs in self-managed and air-gapped environments.

Key takeaways

  • Why enforcement has to live inside the runtime loop. What gateways, sandboxes, directories, and SIEM each catch, what each structurally misses, and where in-harness enforcement fits alongside them rather than replacing them.
  • One policy set across every model and harnesses your team uses. Most organizations run more than one, and that is not reversing. Ory provides extensive coverage with 11 coding harnesses and 13 agent SDKs.
  • How to turn on enforcement without disrupting your engineers. Start in observe mode with every action evaluated and logged but nothing blocked, then write policy based on observed behavior via OpenTelemetry.
  • Prove what every agent did for auditing. Every action is recorded as allowed, denied, escalated, or approved, attributed to a named human owner, and exported to the SIEM you already run.

Who should attend

Security and platform leaders accountable for agent risk such as CISOs, heads of AI platform and enablement, non-human identity owners, GRC.

Engineering leaders and platform engineers deploying coding agents or shipping agent-powered products.

Enterprises are deploying autonomous AI agents and non-human identities (NHIs) at a pace that has outrun traditional security controls, and leadership isn't asking security teams to slow that down. They're asking CISOs to make it safe without making it stop. There are various challenges enterprises face today that tie into agent IAM and security. For example, static API keys leak into public repositories, agents execute on unauthorized commands – this goes to show that traditional defenses were never built for machine-to-machine trust at an agentic scale. Join Ory for an exclusive deep dive into the next generation of identity security. In this session, we will explore Ory’s newly launched, cutting-edge Agent IAM portfolio—including Ory Talos, Ory Agent Security, and Ory DX—alongside our strategic integration with Tetrate. Learn how to replace vulnerable, static credentials with programmable, short-lived tokens, and discover how to embed absolute governance right at the point where an AI agent decides to act. What You Will Learn: - Dynamic Credentialing with Ory Talos: Not every workload carries the same risk — and your credentialing strategy shouldn't treat them the same. Ory Talos gives you a range of token formats, from JWTs to Macaroon-based tokens, each scoped to least privilege and issued dynamically. Match your credential strategy to your risk posture without overhauling what's already working. - Securing the Action with Ory Agent Security: A look at our patent-pending architecture that embeds a security control plane directly into the agent harness, allowing you to intercept, evaluate, and audit commands before they execute. - Accelerating Secure Development with Ory DX: How free developer plugins bring Ory’s identity infrastructure directly into AI coding tools (like Claude Code and Gemini CLI), allowing developers to scaffold secure authentication natively using natural language. - Containing the Blast Radius with Ory + Tetrate: Agents need broad access to be useful. That's exactly what makes them dangerous. Ory locks down agent identity and least-privilege permissions at the application layer; Tetrate enforces them at the network gateway on every live call. High-risk actions are intercepted before they execute, require human approval, and elevated access expires after a single use — so you can say yes to AI deployment without handing agents unlimited access.