# Ory Permissions Onboarding

> Agent-tool auth: observe → enforce, default-allow + deny

**Subcategory:** Ory  
**License:** Apache-2.0  
**Source:** https://github.com/ory/claude-plugins/blob/master/plugins/ory-agent-plugin/skills/ory-permissions-onboarding/SKILL.md

---

## When it is useful

Onboard native agent-tool authorization — connect plugin, review allowed/blocked tools, write blocks in Console, promote observe to enforce.

## The Catch

Loud: Network Developer Free $0 = PoC only (2 development envs, 0 prod/staging, 1 member). Production Network from ~$770/yr. Uncapped $0 = OSS self-host Apache-2.0 (incl. Keto). Skills Apache-2.0 LICENSE 200. Aligns with Ory gem Evaluation framing. Distinct from Descope BD Cloud Free MAU.
