From Agent Hype to Identity-Based Access Control
Identity-based access control for enterprise AI agents is an approach where every human, service, and agent is authenticated, authorized, and monitored before they can reach language models, data sources, or tools, so that LLM access management and actions are governed by centrally defined policies rather than by each application or vendor stack. After a chaotic first wave of AI adoption, with employees using personal accounts and disparate tools, enterprises are finding that orchestration alone is not enough. Agent platforms from major vendors promise unified experiences, but they often live inside a single ecosystem and risk recreating siloed control planes. The new priority is a consistent identity layer that decides which agent can talk to which model, call which API, or touch which dataset, regardless of where that asset or orchestration engine sits.
Tailscale Aperture Shows Why Boring Infrastructure Wins
Tailscale’s Aperture illustrates how identity-centric AI agent infrastructure is overtaking flashy orchestration as the real foundation of enterprise AI agent security. Aperture acts as a centralized AI gateway, using Tailscale’s identity layer to authenticate both humans and machines before routing LLM requests to providers such as OpenAI, Anthropic, or Google, without spraying API keys across tools. It now adds a chat interface, universal MCP and API connectors, and sandboxes so agents can run in contained environments before touching critical systems. Avery Pennarun, Tailscale’s CEO, argues that “agents need boring infrastructure around them – robust identity management, limited access controls, carefully tracked logs, and sandboxes – that boring outer shell is what lets them do useful work without making every developer’s laptop the place where all the risk lands.” In practice, that shell is where LLM access management becomes enforceable policy instead of hopeful guidelines.
OutSystems Bets on Neutral, Identity-Aware Agent Orchestration
While some vendors tie agent orchestration to their own systems of record, OutSystems is framing its platform as a neutral coordinator that connects many stacks without owning the data. CEO Woodson Martin describes the company as “the glue between commercial off-the-shelf solutions,” helping enterprises avoid becoming an “SAP enterprise or a Salesforce enterprise.” Its new Agent Experience exposes Model Context Protocol and Agent2Agent services so developers can use Claude Code, Codex, Cursor, or AWS’s Kiro across different application estates, including the older OutSystems 11 base. This neutrality matters for security: when the orchestration layer is not the primary data store, enterprises are freer to enforce identity-based access control across SAP, Salesforce, and custom systems alike. OutSystems’ role as an integration layer positions it to plug into identity and networking controls rather than replace them, aligning with the shift toward vendor-agnostic AI agent infrastructure.

Why Identity and Networking Now Trump Orchestration Features
The agent landscape is getting crowded, yet most platforms pitch similar narratives: centralized control planes, guardrails, and prebuilt agents. What is starting to separate them is not another orchestration trick, but how well they respect identity, networking boundaries, and data ownership. Tailscale Aperture aims to make AI “visible” again by centralizing LLM access management and logging, so organizations can see which agent called which model with which data, instead of losing activity in personal and free accounts. OutSystems, meanwhile, emphasizes that it does not create most of the data it touches, focusing instead on integrating existing systems. That stance aligns with enterprises that want to keep their data where it is and apply policy through an independent identity layer. In this environment, neutrality and control over where identities live, who holds keys, and how traffic is sandboxed are becoming competitive advantages in AI agent infrastructure.

The New Stack: AI Agents Need Guardrails at the Network Layer
A shared theme across emerging platforms is that security cannot rest on manual review of prompts or ad hoc guardrails baked into each agent. As Pennarun notes, if security depends on a developer approving a long stream of prompts, they will either slow down or hit approval fatigue and start approving by reflex. Identity-based access control and network-layer sandboxes address that by enforcing who can initiate an action and where that action runs, independent of any single vendor’s orchestration UI. Aperture’s model—holding API keys centrally, authenticating requests via its identity layer, and routing traffic across changing models and tools—shows how this can work without modifying each client. Combined with neutral coordination platforms like OutSystems, enterprises can build an AI stack where agents are portable, but permissions stay anchored to identity, networks, and logs that the organization owns and can audit over time.






