watsonx Orchestrate

watsonx Orchestrate

Connect with experts and peers to elevate technical expertise, solve problems and share insights.

 View Only

Who is my AI agent and what is it allowed to do?

By watsonx Orchestrate Blog Team posted 25 days ago

  

Enforcing identity and access management for enterprise agents - A brief introduction about security control center

The Security control center in watsonx Orchestrate serves as the foundation for managing how the platform integrates with external applications through a unified connection framework. This framework centralizes authentication, securely manages credentials, and provides a consistent way for tools to access external systems across draft and live environments. As a result, builders and admins gain greater oversight while ensuring secure access and a clear separation between development and production environments, allowing tools to operate with the appropriate permissions.

Admins in watsonx Orchestrate have visibility into all connections and their associated permissions, giving them the oversight needed to manage enterprise security. Similar to InfoSec leaders within a CISO organization, admins need transparency across the agentic stack to ensure access is properly governed, risks are controlled, and no unauthorized or "shadow" agents are operating within the enterprise.

 

Introducing Agent access overview

Today, administrators lack clear visibility into which agents are integrated with specific applications and the level of access granted to each. To build trust among managers, administrators, CISOs, and InfoSec leaders, organizations need transparent, centralized visibility into the permissions each agent holds within the enterprise tenant. Agent access overview addresses this need.

Security admins can now view a centralized list of all agents and their current permissions, helping them verify that there are no unauthorized or shadow agents operating within the organization.

Agent access overview table.

Figure 1. Agent access overview table.

What admins can achieve with this capability

  1. Oversight of agent types and identities

Admins can view both native and imported agents, along with their universally unique identifiers (UUIDs). They can also see when agents were created or last updated, who made those changes, and the cumulative list of collaborator agents that work alongside each agent during execution.

  1. Accessible resources

Admins can view which connections an agent and its collaborators can access, including whether those connections are prebuilt or custom, and how they are configured across draft and live environments.

  1. Agent permissions and auditing

Admins can view a cumulative list of all connection-level permissions available to an agent and its collaborators during tool execution. This view exposes the union of scopes associated with a connection, where applicable, making it easier to identify agents with excessive privileges and take appropriate action. Admins can also see all accessible tools that use each connection.

Permissions tearsheet.
Figure 2. Permissions tearsheet.

This view answers three simple questions:

  1. Who is the agent?
  2. What can the agent access?
  3. How much access does it have?

Additional features for troubleshooting connections

Enterprise agent deployments are often complex, with multiple dependencies and interconnected resources. The new View associations experience helps administrators understand where a specific connection and its associated credentials are being used. By navigating to View associations, admins can better evaluate the downstream impact of updating or modifying a connection.

View associations tearsheet.
Figure 3. View associations tearsheet.

Laying the groundwork for enterprise agent governance

Agent access overview is one of the most impactful enhancements to watsonx Orchestrate. This capability is designed to support a broad range of enterprise use cases while evolving to meet emerging security, governance, and integration requirements.

With users at the center of our design approach, we continue to enhance administrative visibility and security controls, enabling organizations to govern agent access with greater confidence and transparency. This capability represents the first step toward realizing our broader vision for agent identity, governance, and security.

The Security control center continues to evolve as a centralized hub for managing connections and integrations with external systems, securely storing credentials, and now governing agent access.

For more information, see the IBM documentation for Agent access overview and Security control center: Managing access using the security control center.

Written by @Samish Gundewar


Not using IBM watsonx Orchestrate yet? Start your free trial now.


#community-stories3
0 comments
15 views

Permalink