IBM Agent Identity preview ties agents to Verify and Entra
IBM Agent Identity is in private preview on watsonx Orchestrate with short-lived tokens and Verify/Entra ties, per the Oct 2 announcement.

- IBM's Oct 2, 2026 announcement says Agent Identity is in preview, separate from the builder and the end user, with short-lived tokens scoped to the task and an audit trail linking user, agent, and tool.
- The same post expands AI Gateway discovery to Microsoft Foundry and Google Gemini Enterprise Agent Platform agents alongside Amazon Bedrock.
- IBM Community's October technical touchpoint (posted around Oct 1) covers personalized Control Plane dashboards and related September release notes; it is a second IBM surface, not a contradiction.
in this block
IBM Agent Identity entered private preview as part of watsonx Orchestrate's October 2026 announcement cycle, giving each agent a verifiable identity tied to identity providers enterprises already run — IBM Verify and Microsoft Entra on the private preview path.
What actually happened
Gauri Mathur's IBM announcement dated 02 October 2026 lists four lanes: third-party agent management for Foundry and Gemini Enterprise Agent Platform (preview released 15 September 2026), custom LLM-as-a-Judge controls generally available 30 September 2026, Agent Identity preview also dated 15 September 2026 in the body, and personalized operational dashboards. For the identity feature specifically, the post says agents built in or registered with watsonx Orchestrate can be registered with the organization's identity provider; disabling the identity there can stop the agent from running; agents can receive short-lived tokens limited to the task instead of inheriting a user's full permissions; audit records keep the link between the requesting user, the acting agent, and the tool called.
That design is aimed at a real enterprise failure mode: shared service accounts, static API keys, or user credentials that make it hard to tell what a human did from what an agent did. The announcement does not claim every customer already enabled the preview. It points readers to a fuller Agent Identity announcement and an access request path.
The Community technical touchpoint by Femi Abiodun focuses on personalized Control Plane dashboards, inline file viewing in chat, September release recap items, ADK 2.18.0 notes, and October webinars. It reinforces the October governance theme without reprinting every identity bullet. Use it as corroborating IBM-channel context for the release window, not as a second set of identity-provider claims.
Why third-party gateway coverage matters next to identity
One inventory across Bedrock, Foundry, and Gemini Enterprise Agent Platform agents, with Gateway-level policies, is the visibility half of the story. Identity is the accountability half. IBM's narrative in the Oct 2 post is explicit: seeing every agent is step one; security teams still need to know who each agent is, what it may do, and what it did. Sampling rates for LLM-as-a-Judge evaluators — tenant default 3%, up to 20% per evaluator — are a separate cost-control feature in the same announcement and should not be confused with identity tokens. Custom LLM-as-a-Judge controls let admins enable or disable evaluators such as toxicity, helpfulness, hallucination, conciseness, context relevance, and answer relevance, with sampling as a direct cost lever.
Enterprise teams evaluating IBM Agent Identity should still map which agents are native versus imported through the AI Gateway, because identity registration and policy inheritance may differ by how the agent entered the control plane. The Oct 2 post is clear that Gateway-level controls can apply across connected clouds, while identity preview currently names Verify and Entra. If your IdP is neither, treat support as unconfirmed until IBM says otherwise. Personalized dashboards in the Community touchpoint let individuals rearrange widgets without changing teammates' views — useful for operators, orthogonal to token issuance for agents. ADK 2.18.0 notes on tool shortlisting and document processing are builder quality-of-life items in the same October newsletter, not part of the identity preview claims.
Primary sources: IBM's watsonx Orchestrate announcement and the Community October 2026 technical touchpoint. Adjacent memcool AI reading: Personal Agent Gateway and Decagon Voice 3. For model-release contrast see Gemini 4 Argon.
IBM’s October 2 announcement also lists Custom LLM-as-a-Judge production controls: six out-of-the-box evaluators, tenant-level enablement, and sampling defaults at 3% with per-evaluator overrides up to 20%. Those controls sit beside Agent Identity rather than replacing it.
What to do as a reader
If you only need the headline, IBM Agent Identity is in private preview on watsonx Orchestrate with Verify/Entra ties, short-lived task tokens, and clearer agent audit trails, announced in the Oct 2 package. Request access through IBM's linked path if you run agents in regulated environments. Nothing here is a suggestion to buy IBM stock. Not financial advice. DYOR, ser.
Not financial advice. DYOR, ser.