Tetrate & Ory secure AI agents with runtime controls
What happened
Tetrate and Ory launched a combined runtime control that enforces parameter-level policy on AI agent calls and can pause risky requests for authentication and approval. The integration operates at the gateway layer and grants short-lived elevated access while creating an audit trail, making it immediately relevant for production agent deployments. Watch whether suppliers adopt parameter-level enforcement as a baseline and how quickly buyers can require measurable audit SLAs in contracts
Buyer takeaway
Treat runtime authorization as a contractible deliverable because this offering operationalises agent identity and approval flows at the traffic layer
Cost / money
May shift costs into integration, gateway activation and ongoing support for distributed Envoy-based gateways
Supplier / commercial
Vendors offering both gateway enforcement and identity can bundle services; require unbundled pricing, activation caps and SLA credits for enforcement failures
Safety / operations
Runtime enforcement reduces the chance of unchecked agent actions when contracts mandate human approval gates and short-lived elevated access
What to watch
Require proofs-of-concept and measurable audit trails; avoid accepting parameter-level policy claims without test evidence
Key facts
- Policy enforcement at runtime on agent requests (parameter-level checks)
- Can pause requests and hand off for authentication/approval
- Available now as a combined gateway + identity enforcement option
Source excerpts
The joint offering is available now. The arrangement combines Ory's identity and authorisation software with Tetrate Agent Router Enterprise, which sits at the gateway layer where AI agents call models, tools and internal services
Runtime controls The companies are positioning the joint setup as a response to the changing risk profile of enterprise AI deployments. As businesses move AI agents beyond pilot projects into operational roles, they face questions around agent identity, broad permissions, unsafe access to tools, data exposure and the strength of runtime controls
"Together with Tetrate, Ory is helping enterprises secure AI agent deployments end to end, from identity and access decisions to runtime enforcement and policy control," he said
