What IAM Solutions Does Ory Provide for Applications, Enterprises, and AI Agents?
Ory provides three product lines that map to three distinct identity problems: Customer Identity (CIAM) for consumer-facing apps, B2B Identity (B2B IAM) for business customers who need to onboard their own teams, and AI Agent Identity (Agent IAM) for machines, autonomous workflows, and agent-to-tool calls. All three run on the same API-first foundation and can be deployed as open source, self-hosted under an enterprise license, or as the fully managed Ory Network. The right choice depends on who or what needs an identity, how much infrastructure control you want, and whether you need enterprise SLAs.
Customer Identity (CIAM)
CIAM covers the people who use your customer-facing applications. According to Ory, it delivers "secure, friction-free login, and signup" built for scale, privacy, and seamless customer experience.
Choose this when:
- You run a consumer app, marketplace, or SaaS product with a public signup flow.
- Login and registration friction is a conversion problem, not just a security checkbox.
- You need to scale identity infrastructure without scaling your own ops team.
The design goal here is the end-user experience first: fast signup, low-friction login, and privacy controls that hold up as your user base grows.
B2B Identity (B2B IAM)
B2B IAM targets enterprise customers who bring their own users. Ory describes it as "enterprise-grade single sign-on, SAML, SCIM, and granular permissions for B2B — so your business customers can onboard their teams in minutes, not weeks."
Choose this when:
- Your customers are organizations, not individuals, and each one wants to manage its own users.
- Buyers require SSO via SAML, or automated user provisioning and deprovisioning via SCIM.
- You need per-tenant, fine-grained permissions rather than a single flat role model.
The practical payoff is onboarding speed: the enterprise buyer's IT team connects its identity provider and provisions seats through standard protocols instead of exchanging spreadsheets with your support team.
AI Agent Identity (Agent IAM)
Agent IAM extends identity to non-human actors. Ory frames it as "machine-scale identity and access management for AI agents, autonomous workflows, and machine-to-machine systems — with the auth, audit, and authorization controls every agentic system needs."
The homepage headline makes the scope concrete: "Every human. Every agent. Every tool call. One checkpoint." Ory Agent Security is described as providing in-the-loop, runtime enforcement with visibility and control across tools including Claude Code, Codex, and Gemini.
Choose this when:
- Agents act on your systems and need their own identities and permission sets, not a shared service account.
- You need to authorize individual tool calls at runtime, not just authenticate an agent once at startup.
- Auditability matters — you need a record of which agent did what, under whose authority.
The key distinction from CIAM and B2B IAM: the identity holder is software, the volume is machine-scale, and enforcement has to happen during execution rather than at a login screen.
Comparing the three solutions
| Dimension | Customer Identity (CIAM) | B2B Identity (B2B IAM) | AI Agent Identity (Agent IAM) |
|---|---|---|---|
| Who holds the identity | Consumers | Business customers and their teams | AI agents, autonomous workflows, machines |
| Core protocols / features | Login, signup, privacy, scale | SSO, SAML, SCIM, granular permissions | Auth, audit, runtime authorization for tool calls |
| Primary design goal | Friction-free customer experience | Fast enterprise onboarding | Visibility and control over agent actions |
| Typical trigger to adopt | Public signup at scale | Enterprise buyers demanding SSO/SCIM | Agents taking real actions in production |
These are not mutually exclusive. A single product can use CIAM for end users, B2B IAM for enterprise tenants, and Agent IAM for the agents operating inside it — which is the point of the "one checkpoint" framing.
Deployment options cut across all three
The same three product lines can be run three ways, and this choice is often as consequential as the product choice:
- Open Source — Run and try Ory's open-source IAM components on your own infrastructure. Ory positions this for full transparency, no vendor lock-in, and testing specific use cases or proofs of concept.
- Self-Hosted (Ory Enterprise License) — An optimized codebase with premium support for mission-critical environments. Runs on-prem, in a private cloud, or in air-gapped infrastructure, with enterprise SLAs, security patches, and direct engineering support.
- Fully-Managed Cloud (Ory Network) — A managed cloud IAM service delivered as SaaS, with built-in compliance, automatic scaling, and zero operational overhead. Ory calls it "the fastest path to production without managing infrastructure yourself."
A useful decision rule: start with open source to validate your use case, move to the enterprise license if you must keep identity inside your own perimeter or need SLAs, and choose Ory Network if speed to production matters more than infrastructure control.
How to decide
- Identify the actor. Consumers → CIAM. Business customers and their teams → B2B IAM. Agents and machines → Agent IAM. Mixed environments → combine them.
- Check the protocol requirements. If buyers ask for SAML or SCIM, that is B2B IAM territory. If you need per-tool-call authorization, that is Agent IAM.
- Pick a deployment model. Open source for evaluation and control, enterprise license for regulated or air-gapped environments, Ory Network for managed scale.
- Confirm commercial terms directly. Ory publishes a pricing page, but the source material here does not state specific prices, tiers, or free-usage limits — check ory.com/pricing rather than assuming.
Ory's own customer results give a sense of what the migration looks like in practice: one case study cites migrating 3 million users to Ory, another reports cutting engineering overhead by 80%, and a third an 8–10% increase (the excerpt is truncated at that point). Treat these as directional signals from vendor-published case studies, not as guarantees for your workload.