
Artificial intelligence is reshaping the enterprise. Organizations are moving beyond AI assistants to AI agents that can reason, make decisions, orchestrate workflows, invoke enterprise applications, collaborate with other agents, and autonomously execute business tasks. As enterprises accelerate adoption, they face a new identity challenge.
Traditional Identity and Access Management (IAM) was built for people, applications, and machine identities—not autonomous AI agents acting on behalf of users. As AI agents become part of the enterprise workforce, they require the same identity, governance, and accountability as employees.
That's why we're excited to announce the IBM Agent Identity Private Preview — an opportunity for our customers to help shape the future of AI agent security.
Why This Matters?
Enterprise AI is moving from experimentation to production. AI agents are retrieving enterprise data, invoking APIs, collaborating with other agents, and automating business workflows with increasing autonomy. As organizations scale agentic AI, identity becomes the foundation of trust.
To securely deploy AI agents at enterprise scale, organizations need answers to fundamental questions:
· Which AI agents exist?
· Who owns and manages them?
· What systems and data can they access?
· How is the AI agent authenticated?
· How are actions authorized and audited?
AI agents are a new enterprise identity type. Without managing AI Agents appropriately, as agents scale up they become a target for attackers and a risk to compliance. Organizations need to gain visibility, perform runtime access control and deliver governance to safely adopt agentic AI.
Introducing IBM Agent Identity
Today, IBM is introducing IBM Agent Identity — a new set of capabilities within the IBM Verify portfolio designed to secure AI agents as a recognized enterprise identities.
IBM has designed this technology in alignment with the Identity Fabric concept. As such, IBM Agent Identity delivers a coordinated Agent Identity Control Plane. Clients can adopt components of the Agent Identity solution based on their existing AI orchestration, identity provider (IdP), and secrets management technologies.
IBM engineered IBM Agent Identity to integrate with IBM watsonx Orchestrate and IBM (HashiCorp) Vault, enabling IBM clients to accelerate their adoption of agentic AI through proven integration patterns.
This integrated solution address three critical domains of AI agent security
- Agent Runtime – Securely establish and manage AI agent identities.
- Identity & Authorization – Enforce policy-based, least-privilege access and delegated authorization.
- Secrets & Credentials – Protect and manage the credentials AI agents need to securely access enterprise resources.
By extending enterprise identity beyond humans and traditional workloads, IBM Agent Identity helps organizations securely register, authenticate, authorize, govern, and monitor AI agents throughout their lifecycle.
With IBM Agent Identity, organizations can:
· Establish trusted identities for every AI agent.
· Remove standing privileges and grant permissions temporarily.
· Tie actions with intent.
· Enforce context-aware, least-privilege at every point of use of that credential.
· Govern AI agents with centralized ownership and lifecycle policies.
· Maintain end-to-end accountability and auditability.
· Accelerate enterprise AI adoption with identity and security built in from the start by implementing detection and remediation of agent identity risks.
AI agents must be managed alongside existing human identities, rather than service accounts or credentials. IBM Agent Identity provides the identity foundation that enables organizations to deploy trusted AI at scale.
How IBM Agent Identity Works?
IBM Agent Identity extends existing Identity and Access Management (IAM) to support both human and non-human identities, enabling organizations to securely manage AI agents alongside users, applications, entitlements, and workloads.
It provides an Agent Identity Control Plane that brings together identity, authorization, credential management, and governance to secure AI agents throughout their lifecycle.

- Discover & Onboard: Discover, register, and manage AI agents with centralized ownership — bringing AI agents under the same trusted identity model as human users.
- Secure & Delegate Access: Secure every AI interaction with delegated authorization, context-aware policies, and short-lived, task-specific access tokens, ensuring every action is traceable to an originating user or approved consent.
- Observe & Remediate Risks: Continuously evaluate and detect agentic risks internally as well as integrating with risk tools like Verify Identity Protection (VIP). And remediate the risks through automated workflows.
- Lifecycle & Govern: Manage agent’s lifecycle and maintain comprehensive audit trails that link human identities, AI agents, policy decisions, credential issuance, and downstream actions—providing the accountability and evidence needed for compliance.
Integration with HashiCorp Vault and watsonx Orchestrate
IBM Agent Identity is designed to integrate seamlessly with existing enterprise identity and security architectures, helping organizations extend trusted identity across their AI ecosystem.
Through integration with watsonx Orchestrate, organizations can securely onboard and manage AI agents created in orchestration-driven environments while centralizing identity, authorization, and governance within IBM Verify. End-to-end audit trails preserve the complete chain of trust—from the originating human identity to the delegated AI agent and every downstream action—providing the visibility and accountability required for enterprise AI.
Through integration with HashiCorp Vault, organizations can securely issue just-in-time, short-lived credentials for AI agents accessing enterprise systems that cannot consume delegated tokens directly. Credentials are issued within the approved delegation context, expire automatically, and are fully recorded in the audit trail—eliminating persistent secrets embedded in agent code, connectors, or shared infrastructure.
Who IBM Agent Identity Is Built For?
IBM Agent Identity is designed for four stakeholders who each need different answers from the same control plane:
|
Audience
|
Primary need
|
What IBM Agent Identity provides
|
|
AI developers & architects
|
Build agents that are secure by default without rebuilding the stack
|
On-behalf-of (OBO) token exchange, agent registry APIs, workload identity patterns
|
|
IAM administrators
|
Know which agents exist and who owns them
|
Centralized registry, lifecycle workflows, rapid disable path
|
|
Security teams
|
Enforce least privilege at every hop, not just the perimeter
|
Per-call risk-based access policy enforcement, Just-in-time (JIT) and Just-enough access (JEA) credentials
|
|
Auditors & compliance
|
Reconstruct who acted, under whose authority, with which credential
|
Correlated audit trail from user session through agent to tool call
|
Help Shape the Future of Agent Identity
We're inviting customers and partners to join the IBM Agent Identity Private Preview and help shape the future of enterprise AI security.
As an early participant, you'll have the opportunity to:
- Experience IBM Agent Identity before General Availability (GA)
- Collaborate directly with IBM product and engineering teams
- Influence the product roadmap through early feedback
- Help define best practices for securing AI agents at enterprise scale
Who Can Apply?
The Private Preview is open to a diverse group of participants, including:
- Existing IBM Verify and IBM Vault customers
- IBM customers using a variety of AI orchestration platforms (including watsonx)
- IBM Business Partners
- New prospects
Request Private Preview Access
Ready to be among the first organizations shaping the future of AI Agent Identity?
Send your request to agent.identity.eap@ibm.com with the subject: "IBM Agent Identity Private Preview Request"
Include:
- Organization name
- Participant name(s)
- Email address(es)
- Company role
- (Optional) A brief description of your AI initiative or use case including your existing IBM software estate.
Once approved, you'll receive access to the Private Preview portal, along with product downloads, documentation, and onboarding instructions.
Note: This Early Access Program and Private Preview artifacts are valid for limited duration.
Join the IBM Agent Identity Private Preview and help define the next generation of trusted AI. Applications are now open. Spaces are limited.
For questions, contact: