The Agent Stack mascot
The Agent Stack _
Daily B2B AI automation brief · Friday, July 3, 2026 · Issue #26

Hey there 👋

Last week the news was that autonomy got cheaper. This week the news is where the brakes live.

Here is the reflex to catch yourself doing. You read that 88% of companies already had an agent-related security incident, you panic, and you go shopping for an “agent governance platform.” Reasonable. Also probably unnecessary.

Because the interesting move this week was not a new standalone control product. It was control showing up inside the tools you already run — your identity provider, your network path, your observability vendor, your ERP. The brake stopped being something you buy. It is becoming a setting you switch on.

Let’s walk the stack.


The Big Thing

Ory just put enterprise identity inside your coding agent

If your team builds with Claude Code, OpenAI Codex, or Gemini CLI, this one is deployable today. Ory launched Agent DX — free plugins that drop its identity stack straight into those coding agents. One command to install. No account, no API key.

Here is what it actually does. You describe an auth flow in plain language — login, registration, recovery, social login, permissions — and the agent scaffolds it against a real Ory environment running locally. You manage identities, OAuth2 clients, and permissions from inside the chat, through Ory’s MCP server. The auth is not a thing you add after the demo works. It is in the first commit.

The third-thought read matters here. This is easy to file under “another agent-security tool,” and that undersells it. The real shift is control moving left — into the moment the code gets written, not the review that happens later. Most teams prototype fast with a coding agent, ship the happy path, and bolt on identity when security asks. That gap is where shadow APIs, hardcoded secrets, and mis-scoped permissions are born. Agent DX closes the gap by making your central identity provider the default the agent reaches for.

Why it lands for this audience: the failure mode is not the model writing bad auth. It is the model writing no auth, or writing its own, inconsistently, across forty services. Pull identity into the dev loop and every agent-generated service inherits the same governed pattern — attributable, revocable, consistent.

The honest caveat. Agent DX is a developer-experience layer, not runtime enforcement — it helps agents build secure services; it does not stand between a live agent and your database. And every capability here is Ory’s own description, so treat the “production-equivalent” claim as a thing to verify on one service, not a promise.

Ship it? The plugin — try it now; it is free and installs in a command. The pattern — adopt it: mandate that any agent-generated service wires to your central IdP. The broader “shift-left governance” bet — watch it mature, but this is the most concrete version of it yet.

Read the launch.


Tour de Headlines

🛡️ Stop the write, don’t just log it

Vorlon debuted Guardian on June 30 — a real-time enforcement gateway that sits at the protocol layer between your agents and every system they touch: SaaS, cloud data stores, homegrown apps. The distinction that matters: it can block, mask data in transit, and force read-only before a transaction completes. Detection tools tell you an agent did something bad. Guardian is built to stop the bad write in flight, no matter what the model decided. Vorlon says it covers prompt injection, credential and OAuth abuse, MCP server attacks, and agent-to-agent manipulation, and auto-discovers shadow agents. The verb changed this week — from watch to enforce. Claims are Vorlon’s, so treat them as a pilot, not a purchase: route one slice of agent traffic through an enforcement proxy and measure false positives before you widen it. More at SiliconANGLE.

🔁 Your observability vendor wants the agent-improvement loop

Datadog announced it acquired Adaptive ML, a startup building an RLOps — reinforcement-learning operations — platform, and is folding the team into Datadog AI Research. The stated goal: turn Datadog’s observability and security data into first-party intelligence for agentic post-training. Read past the M&A. The loop that makes an agent better in production — reinforcement learning on your real outcomes — is becoming a platform feature, not a DIY research project. Whoever already holds your telemetry is about to offer to close that loop for you. Builder move: start capturing labeled outcome data now — what the agent did, and whether it worked — so you have the fuel when the loop shows up. Datadog’s release.

🏭 Agents moved into the system of record

Oracle added four new Fusion Agentic Applications for supply chain on June 29 — inventory and planning, supplier qualification, production readiness, and kanban admin — plus its AI Agent Studio to build and run reusable agents inside Fusion Cloud SCM. These are not assistant widgets bolted onto a screen. Oracle positions them to progress routine supply-chain work autonomously, inside the existing enterprise controls. Narrow relevance if you do not run Oracle SCM — but the pattern is universal, and it is the one every ERP, CRM, and ITSM incumbent is now running: the vendor that already holds your data ships agents that live where the work lives. If it is you, pilot inventory and supplier flows first, and watch exception and human-escalation rates before you widen scope. Oracle’s announcement.


Sponsor

You instrument your agents. Instrument your people too.

You can now bake identity into your agents, enforce their actions in-flight, and pipe every move to your SOC. Your humans have no such gateway — the misread on a discovery call still completes without a warning. RapportScore is the enforcement layer for human communication: it measures how your team actually connects on calls, in email, across every deal, so the misfires surface before they cost you the quarter.

See your team’s score →

Tool of the Day

🔭 Exabeam Observra

What it’s for: capturing and normalizing what your AI agents are actually doing — across frameworks — so your security team can see it in one place.

Exabeam open-sourced Observra on July 1. It captures agent activity across major frameworks, normalizes it into consumable events, enriches each one with cost, redaction, dedup, and risk signals, then routes it to any security-ops platform you already use. The same release doubled Exabeam’s AI- and agent-related behavioral detections to 90 and mapped its Outcomes Navigator to the new OWASP Top 10 for Agentic AI, adding Anthropic Claude alongside ChatGPT, Gemini, and Copilot. The reason to reach for the open-source piece first: it is the cheapest way to answer “what are our agents even doing?” before you commit to a paid platform. Instrument one agent workflow, see what the telemetry surfaces, then decide. The detection and OWASP-mapping claims are Exabeam’s own — Observra is the part you can run yourself today.

Grab Observra →


Worth a Click

  • The number that should set your Q3 priority. AvePoint’s 2026 State of AI — a survey of 750 enterprise IT and security leaders — reports 88.4% of organizations already had at least one AI-agent-related security incident, even as nearly half of employees use agents weekly. Adoption is outrunning control. That is AvePoint’s finding, and it is the backdrop for this whole issue. The report.
  • Compliance as an agent workload. The Pentagon is reportedly piloting agents to automate parts of its Authority-to-Operate process — approvals that can stretch two years — and stood up an “Agent Network” pairing commands with commercial AI firms. Borrow the pattern even if you will never touch defense: templated controls, supervised document generation, audit trails. Via AI Agent Store.
  • Agents that wire themselves. Berkeley RDI’s OpenSage is an agent-development kit that lets agents generate their own topology and synthesize their own tools at runtime, in sandboxes — a research-grade step past hand-wired agent graphs. Early, but it is the direction of travel. Via AI Agent Store.

Read “88% already had an incident” and the instinct is to go buy a governor. Resist it for one week. Because the control layer just came to you: identity moved into your coding agent (Ory), enforcement into your network path (Vorlon), the improvement loop into your observability vendor (Datadog), autonomous work into your system of record (Oracle). One move for the whole issue: before you evaluate a standalone agent-governance platform, turn on the agent controls arriving in the stack you already run — your IdP, your proxy, your SOC pipeline, your ERP. The brake is not a product you shop for. Increasingly, it is a setting you switch on.

See you tomorrow. — The Agent Stack
Built for people who ship AI, not people who tweet about it. Published weekday mornings by Pixiu Media Holdings LLC.

You’re receiving this because you subscribed to The Agent Stack. · Unsubscribe