IBM Verify

IBM Verify

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only

Every Agent Needs an Identity. Announcing IBM Agent Identity Public Preview.

By DINESH JAIN posted 7 days ago

  

IBM Agent Identity Public Preview brings identity, delegation, authorization, credential security and accountability to the agentic enterprise.

AI is crossing a critical threshold.

For the last several years, enterprises have focused on what AI can know and what AI can create. The next era is about what AI can do.

AI agents are retrieving sensitive data, calling APIs, invoking tools, orchestrating workflows, interacting with other agents and increasingly taking actions on behalf of people and businesses. Yet many enterprises still lack a fundamental security foundation: knowing which agents exist, who owns them, whose authority they are acting under, what they are permitted to do and how to stop them when risk changes.

That is an identity problem.
Earlier, IBM introduced the Private Preview of IBM Agent Identity, giving participating customers and partners an opportunity to explore its early capabilities and provide feedback.

Today, IBM is announcing the Public Preview of IBM Agent Identity, a new set of capabilities in the IBM Verify portfolio designed to help enterprises discover, register, authenticate, authorize and govern AI agents—and establish accountability across agentic workflows.

IBM Agent Identity is built around a simple principle:
Every agent should have an identity. Every actor and beneficiary of that action should be identified. Every credential should be controlled, minimally scoped and short lived. And every decision should be accountable.

The agentic enterprise requires a new identity control plane

Traditional IAM was designed primarily around people, applications and relatively predictable machine identities.

AI agents break those assumptions.

Agents can operate autonomously, inherit authority from people, invoke other agents, cross trust boundaries and interact with privileged enterprise systems at machine speed. IBM's strategy treats these agents as first-class non-human identities rather than simply another service account or application credential.

The security implications are significant.

Without the right controls, enterprises can face shadow agents outside governance, unclear ownership, broken delegation chains, persistent credentials, excessive privilege and limited ability to reconstruct who—or what—authorized an action.

Simply extending yesterday's workforce IAM model is not enough.

Enterprises need identity security capable of operating at agentic speed.

Introducing IBM Agent Identity
IBM Agent Identity extends enterprise IAM into a blended human and non-human identity control plane, adding the identity patterns required for agentic AI, delegated workflows and runtime security while preserving existing identity investments.
image
The Public Preview establishes the foundation across four critical areas:
  • Discover & Onboard: Discover, register, and manage AI agents with centralized ownership — bringing AI agents under the same trusted identity model as human users.
  • Secure & Delegate Access: Secure every AI interaction with delegated authorization, context-aware policies, and short-lived, task-specific access tokens, ensuring every action is traceable to an originating user or approved consent.
  • Observe & Remediate Risks: Continuously evaluate and detect agentic risks internally as well as integrating with risk tools like IBM Identity Protection. And remediate the risks through automated workflows.
  • Lifecycle & Govern: Manage agent’s lifecycle and maintain comprehensive audit trails that link human identities, AI agents, policy decisions, credential issuance, and downstream actions—providing the accountability and evidence needed for compliance.

The objective isn't simply visibility. It is provable accountability.

Identity becomes a runtime security control

Agentic AI changes where identity security must operate.

Authentication at the beginning of a session is no longer enough when an agent can execute dozens of actions, call multiple tools and delegate work to other agents after that authentication event.

Authorization must travel with the transaction.

IBM Agent Identity is designed around OAuth-based, least-privilege and short-lived access, including scoped tokens, human-in-the-loop and consent-aware flows, transaction constraints and risk-based authorization checks.

This creates the foundation for a different security model:
Verify the identity. Preserve the delegation. Limit the privilege. Enforce the policy. Protect the credential. Record the action.

Identity becomes more than the front door.

Identity becomes part of the runtime control plane for enterprise AI.

IBM Agent Identity + IBM Vault + watsonx Orchestrate

Securing an AI agent cannot stop at authentication.
Organizations need to understand where agents originate, who owns them, how authority is delegated, what resources they can access, where credentials are stored and what happens when risk changes.
That is why IBM is approaching agent identity as an end-to-end security problem.

IBM Agent Identity provides centralized agent registry, authorization, token exchange, governance and audit controls for agents.

IBM Vault (HashiCorp Vault) protects secrets and enables just-in-time access to enterprise systems where delegated tokens cannot be consumed directly.

watsonX Orchestrate provides an important ecosystem for building and operating agents that can be brought under centralized identity, access and governance controls.

Together, these capabilities are designed to connect the agentic runtime, identity and authorization layer, and secrets and credentials layer into a coordinated security architecture.

Inside the architecture: how the pieces connect?

At a high level, three platforms have to work together to secure an agent end to end: somewhere to build and run it, somewhere to give it a governed identity and policy, and somewhere to hold the secrets it needs at runtime. IBM Agent Identity is the piece in the middle that ties the other two together.

  • IBM watsonX Orchestrate (AI orchestration platform, or any agent builder of your choice) is where agents get built, deployed, and connected to the systems they need.
  • IBM Agent Identity holds the Agent Registry, the OAuth access model for agents, audit reporting, and risk and remediation workflows.
  • IBM Vault (HashiCorp Vault) holds the agent entity, its secrets and credentials, and an OAuth resource server so agents can pull scoped, short-lived credentials at runtime instead of holding standing secrets.
Personas and Use Cases

A lightweight connector — the Verify Antenna — links Agent Identity to both watsonx Orchestrate and Vault, so an agent registered in one place is automatically synced everywhere it needs to exist. Register an agent in watsonx Orchestrate, and it's onboarded into the Agent Registry and propagated into Vault as a governed agent entity, without a developer manually re-registering it in three different consoles. Verify Antenna can pull risk signals from IBM Identity Protection and external risk sources using Shared Signals Framework. Once the risk is detected, remediation can be further performed within IBM Agent Identity or against Vault or against wastsonX Orchestrate.

The result is one pane of glass — human users and AI agents side by side — instead of agent identity living as an afterthought bolted onto three disconnected tools.

Five personas, one control plane

The architecture above maps directly to how different people actually interact with an agent over its lifecycle:

Agent developer — Builds and deploys the agent using an agent builder (such as watsonx Orchestrate), then registers it in IBM Agent Identity to obtain a governed agent identity and configure the policies that secure it at runtime. Onboarding can happen through the UI, via API/SDK, or automatically through discovery — and once registered in IBM Agent Identity, the agent's identity and required secrets are propagated into Vault without extra manual steps.

IAM administrator — Owns the core policy work: assigning agent ownership and metadata, configuring access, sign-on, and human-in-the-loop policies, investigating incidents on the risk dashboard, and setting up automated remediation workflows.

Vault administrator — Configures the Vault-side policies that govern how an agent accesses certificates and secrets (static or dynamic), aligning those permissions with the least-privilege delegation set in IBM Agent Identity.

Agent owner/sponsor — Typically a business or AI leader who sponsors the agent in the organization. They own approvals and governance for their agents, and can monitor, manage, and remediate risk on the agents they're responsible for — the same lifecycle controls an admin has, scoped to their own portfolio.

End user — The employee or customer actually using the agent: enrolling it, prompting it, setting the guardrails it should operate within, and delegating specific actions to it through explicit consent.

Open by design. Because your AI environment won't come from one vendor.

The future of enterprise AI will be heterogeneous.

Organizations will use multiple AI models, agent frameworks, identity providers, orchestration platforms, clouds and enterprise applications.

Security cannot become the reason enterprises are forced into another closed ecosystem.

IBM Agent Identity is therefore being developed around IBM's broader Identity Fabric approach—supporting architectural choice and integration with existing tools rather than requiring enterprises to replace their identity environment.

Organizations can continue using identity providers such as Microsoft Entra ID or Okta for human authentication while extending IBM Agent Identity into the agentic tier for delegation, enforcement, credential brokering and audit.

The goal is not another identity silo.
The goal is an identity fabric capable of securing humans, non-human identities and AI agents across the hybrid enterprise.

Start with the workflow. Scale to the enterprise.

Organizations do not need to solve every agent identity challenge on day one.

IBM Agent Identity supports a phased approach.

Start with a known agentic workflow. Establish explicit delegation and contextual authorization. Prove that the security model works end to end.
Then expand discovery, registration, ownership, inventory and policy coverage as agent adoption grows.

Finally, extend toward just-in-time credentials, continuous risk evaluation, rapid revocation and evidence-grade governance across high-impact workflows.
This matters because security cannot become a brake on enterprise AI adoption.

The winning security architecture will be the one that allows enterprises to move faster because they can establish trust—not the one that simply adds more gates.

What's in Public Preview today?

Explore the available capabilities in the public preview today and start integrating. As with any preview, functionality, APIs, and UI are still evolving based on customer feedback ahead of General Availability (GA) — check the documentation for the current feature set and known limitations before relying on it in production.

Get Started

Try it now: 

Send your request to agent.identity.eap@ibm.com with the subject: "IBM Agent Identity Public Preview Request"
Include:

  • Organization name
  • Participant name(s)
  • Email address(es)
  • Company role
  • (Optional) A brief description of your AI initiative or use case including your existing IBM software estate.

Once approved, you'll receive access to the EAP portal, along with product documentation, and onboarding instructions.
Note: Participants already enrolled in the Private Preview do not need to request access to the Public Preview, as the capabilities are already enabled in their tenant.
IBM Agent Identity documentation: https://www.ibm.com/docs/en/agent-identity?topic=overview

Have questions on Agent Identity EAP? 
Contact the IBM Agent Identity Team:

AI agents are becoming part of your workforce. It's time they had an identity to match.

0 comments
72 views

Permalink