Analysis · curated 21 Jul 2026
The Agent Security Stack: Transport, Identity, Policy, Runtime
First reported keycard.ai
Coverage timeline
Single-source analysis — first reported, latest, and curated coincide.
Why it matters
Defenders securing AI agents need a clear model of the separate control surfaces (transport auth, identity, policy, runtime guardrails) because each fails differently and no single check covers prompt injection, credential issuance, and access authorization together.
A Keycard explainer maps the "agent security stack" into distinct layers — transport (MCP/OAuth 2.1 authorization), identity, policy, and runtime guardrails that watch for prompt injection — arguing that agent security cannot be collapsed into a single control surface. The piece frames how multi-agent call chains multiply control surfaces (LLM tool invocation, transport, credential, authorization) and argues identity/authorization is the most under-served layer, citing recent CrowdStrike/SGNL and Palo Alto/CyberArk acquisitions.