A multi-cloud agent estate becomes easier to govern when every agent has a distinct identity, a task-scoped access path, and an audit trail separate from its builder or requester
Source: IBM
IBM says its watsonx Orchestrate AI Gateway can now discover and import agents built on Microsoft Foundry and Google Gemini Enterprise Agent Platform, alongside Amazon Agentcore agents, into one control plane. Its preview Agent Identity capability assigns an agent a distinct, verifiable identity through an existing identity provider; IBM says this can support task-scoped short-lived tokens and audit records that connect the requesting user, the acting agent, and the called tool. The private preview supports IBM Verify and Microsoft Entra.
Why this matters: Do not let a shared service account become the only explanation for an agent action. Inventory agents across platforms, register a distinct non-human identity where the platform supports it, bind permissions to a named task and expiry, and log the requester, agent, tool, and outcome together. Test revocation and incident investigation before approving a sensitive workflow. IBM's preview is one implementation, not proof that multi-cloud coverage or least privilege is automatic; validate the identity flow, connector permissions, and audit completeness in the architecture you operate.
Read IBM's watsonx Orchestrate announcement