Agentic AI changes where identity security must operate.
Authentication at the beginning of a session is no longer enough when an agent can execute dozens of actions, call multiple tools and delegate work to other agents after that authentication event.
Authorization must travel with the transaction.
IBM Agent Identity is designed around OAuth-based, least-privilege and short-lived access, including scoped tokens, human-in-the-loop and consent-aware flows, transaction constraints and risk-based authorization checks.
This creates the foundation for a different security model:
Verify the identity. Preserve the delegation. Limit the privilege. Enforce the policy. Protect the credential. Record the action.
Identity becomes more than the front door.
Identity becomes part of the runtime control plane for enterprise AI.
IBM Agent Identity + IBM Vault + watsonx Orchestrate
Securing an AI agent cannot stop at authentication.
Organizations need to understand where agents originate, who owns them, how authority is delegated, what resources they can access, where credentials are stored and what happens when risk changes.
That is why IBM is approaching agent identity as an end-to-end security problem.
IBM Agent Identity provides centralized agent registry, authorization, token exchange, governance and audit controls for agents.
IBM Vault (HashiCorp Vault) protects secrets and enables just-in-time access to enterprise systems where delegated tokens cannot be consumed directly.
watsonX Orchestrate provides an important ecosystem for building and operating agents that can be brought under centralized identity, access and governance controls.
Together, these capabilities are designed to connect the agentic runtime, identity and authorization layer, and secrets and credentials layer into a coordinated security architecture.
Inside the architecture: how the pieces connect?
A lightweight connector — the Verify Antenna — links Agent Identity to both watsonx Orchestrate and Vault, so an agent registered in one place is automatically synced everywhere it needs to exist. Register an agent in watsonx Orchestrate, and it's onboarded into the Agent Registry and propagated into Vault as a governed agent entity, without a developer manually re-registering it in three different consoles. Verify Antenna can pull risk signals from IBM Identity Protection and external risk sources using Shared Signals Framework. Once the risk is detected, remediation can be further performed within IBM Agent Identity or against Vault or against wastsonX Orchestrate.
The result is one pane of glass — human users and AI agents side by side — instead of agent identity living as an afterthought bolted onto three disconnected tools.
Five personas, one control plane
The architecture above maps directly to how different people actually interact with an agent over its lifecycle:
Agent developer — Builds and deploys the agent using an agent builder (such as watsonx Orchestrate), then registers it in IBM Agent Identity to obtain a governed agent identity and configure the policies that secure it at runtime. Onboarding can happen through the UI, via API/SDK, or automatically through discovery — and once registered in IBM Agent Identity, the agent's identity and required secrets are propagated into Vault without extra manual steps.
IAM administrator — Owns the core policy work: assigning agent ownership and metadata, configuring access, sign-on, and human-in-the-loop policies, investigating incidents on the risk dashboard, and setting up automated remediation workflows.
Vault administrator — Configures the Vault-side policies that govern how an agent accesses certificates and secrets (static or dynamic), aligning those permissions with the least-privilege delegation set in IBM Agent Identity.
Agent owner/sponsor — Typically a business or AI leader who sponsors the agent in the organization. They own approvals and governance for their agents, and can monitor, manage, and remediate risk on the agents they're responsible for — the same lifecycle controls an admin has, scoped to their own portfolio.
End user — The employee or customer actually using the agent: enrolling it, prompting it, setting the guardrails it should operate within, and delegating specific actions to it through explicit consent.
Open by design. Because your AI environment won't come from one vendor.
The future of enterprise AI will be heterogeneous.
Organizations will use multiple AI models, agent frameworks, identity providers, orchestration platforms, clouds and enterprise applications.
Security cannot become the reason enterprises are forced into another closed ecosystem.
IBM Agent Identity is therefore being developed around IBM's broader Identity Fabric approach—supporting architectural choice and integration with existing tools rather than requiring enterprises to replace their identity environment.
Organizations can continue using identity providers such as Microsoft Entra ID or Okta for human authentication while extending IBM Agent Identity into the agentic tier for delegation, enforcement, credential brokering and audit.
The goal is not another identity silo.
The goal is an identity fabric capable of securing humans, non-human identities and AI agents across the hybrid enterprise.
Start with the workflow. Scale to the enterprise.
Organizations do not need to solve every agent identity challenge on day one.
IBM Agent Identity supports a phased approach.
Start with a known agentic workflow. Establish explicit delegation and contextual authorization. Prove that the security model works end to end.
Then expand discovery, registration, ownership, inventory and policy coverage as agent adoption grows.
Finally, extend toward just-in-time credentials, continuous risk evaluation, rapid revocation and evidence-grade governance across high-impact workflows.
This matters because security cannot become a brake on enterprise AI adoption.
The winning security architecture will be the one that allows enterprises to move faster because they can establish trust—not the one that simply adds more gates.
What's in Public Preview today?
Explore the available capabilities in the public preview today and start integrating. As with any preview, functionality, APIs, and UI are still evolving based on customer feedback ahead of General Availability (GA) — check the documentation for the current feature set and known limitations before relying on it in production.
Get Started
Try it now:
Send your request to agent.identity.eap@ibm.com with the subject: "IBM Agent Identity Public Preview Request"
Include:
- Organization name
- Participant name(s)
- Email address(es)
- Company role
- (Optional) A brief description of your AI initiative or use case including your existing IBM software estate.
Once approved, you'll receive access to the EAP portal, along with product documentation, and onboarding instructions.
Note: Participants already enrolled in the Private Preview do not need to request access to the Public Preview, as the capabilities are already enabled in their tenant.
IBM Agent Identity documentation: https://www.ibm.com/docs/en/agent-identity?topic=overview
Have questions on Agent Identity EAP?
Contact the IBM Agent Identity Team:
AI agents are becoming part of your workforce. It's time they had an identity to match.