
Principal Basil C. Puglisi reads the October agent-control releases the same way he reads any deployment claim: name who acts, name who decides, and write the measure before the tool expands. On October 2, 2026, IBM published New in IBM watsonx Orchestrate: Expanded third-party agent management and Agent Identities and said the AI Gateway now discovers and imports agents built on Microsoft Foundry and Google Gemini Enterprise Agent Platform, in addition to Amazon Bedrock. The same note says Agent Identity, now in preview, gives each agent a distinct identity managed through the identity provider the security team already uses, with private preview support for IBM Verify and Microsoft Entra. On September 29, 2026, the OpenClaw Foundation published OpenClaw Enterprise, an open-source control plane for persistent agents that organizations can self-host on Kubernetes, with early pilots described for internal workloads ahead of a planned 1.0 later in 2026.
Factics is the method he uses when a workflow claim has to become an action someone can measure: a verified fact, a tactic specific enough to assign, and a KPI written before the action so the result can fail. The fact here is the pair of releases that treat agent identity and a shared control plane as deployment requirements rather than optional extras. The tactic is one deployment brief that registers every production agent with a distinct identity, maps each agent to a named human owner, and requires a short-lived token scoped to the task before the agent may call a protected tool. The weekly KPI is the share of live agent runs that carry a recorded user-subject, agent-actor, and tool call in the audit trail. A second check counts how many agents still run on shared service accounts or static keys after the brief goes live.
The tactic follows an argument Puglisi already published. In the HAIA-RECCLIN Agent Architecture Specification, he writes that the agent is a pipe with a logbook: it dispatches, collects, routes, and records, while Checkpoint-Based Governance keeps a named human at the authority layer. Shared credentials erase that separation. When an audit line shows only that a user accessed Workday, the team cannot tell what the person did from what an agent did on their behalf. Agent Identity, as IBM describes it, keeps the subject and the actor apart so the record can show which agent acted for which user. That is the same accountability chain the HAIA-RECCLIN specification requires before an organization claims governance over multi-agent work.
One inventory across clouds changes how ops owns the estate
IBM’s October 2 note says agents from Amazon Bedrock, Microsoft Foundry, and Gemini Enterprise Agent Platform can appear next to native watsonx Orchestrate agents in a single view, and that Gateway-level controls apply to every connected agent. Most large enterprises already build on more than one cloud. Each platform’s native tooling governs the agents on that platform. A control plane that sits above them changes the operations job from chasing per-vendor consoles to maintaining one inventory and one policy set.
An operations lead should list every agent that can touch production data, name the cloud it runs on, and record whether it appears in the shared inventory. Agents that never appear in that inventory stay outside the brief until someone registers them or retires them. The inventory count is the first measure of whether the control plane is real for the estate the business actually runs.
Agent Identity turns shared keys into a deployment defect
IBM’s companion announcement, Announcing the private preview of Agent Identity in IBM watsonx Orchestrate (September 21, 2026), states the failure mode plainly: shared service accounts, static API keys, and borrowed user credentials make it hard to separate user action from agent action, and they tend to grant more access than the task requires. Agent Identity registers each agent with the identity provider, can stop an agent whose identity is disabled there, and can issue a short-lived token limited to the task. Audit records keep the link between the user who made the request, the agent that acted, and the tool it called.
Write the deployment brief so every production agent has a distinct identity before it receives standing access to HR, finance, or customer systems. The brief names the owner who can disable the identity, the tools the agent may call, and the reviewer who confirms the audit line shows subject, actor, and tool. When a run still authenticates with a shared key, treat that as a failed KPI for the week, not as a temporary exception that waits for a later cleanup sprint.
OpenClaw Enterprise adds a self-hosted control plane option
The OpenClaw Enterprise post says organizations ban agent platforms when they lack a common security and governance standard, and that OCE answers with multi-tenancy, hard security boundaries, sandboxing, fine-grained permissions, and lifecycle auditing while keeping the model, harness, and sandbox replaceable. The project started at OpenAI, moved to the OpenClaw Foundation, and continues with Red Hat and NVIDIA. Companies can run it on their own infrastructure with Docker Compose for local work and Kubernetes for internal deployments. The Foundation currently recommends it for internal pilot workloads ahead of a planned 1.0 later this year.
A platform team that needs agents inside its own cluster can pilot OCE against one non-customer workflow, then measure whether every agent revision, permission change, and model call lands in the control-plane record. That pilot KPI is the share of agent turns with a complete lifecycle entry. Until that share holds, the team keeps the agent off customer data.
Runtime evaluation and dashboards belong in the same brief
The October 2 IBM release also says six out-of-the-box LLM-as-a-Judge evaluators became generally available on September 30, 2026, covering toxicity, helpfulness, hallucination, conciseness, context relevance, and answer relevance. Admins can enable or disable evaluators at the tenant level and set sampling rates, with a 3% default and overrides up to 20%. Evaluation is a model call, so sampling is a cost lever tied to risk. Personalized control-plane dashboards let different teams arrange the views they need without changing everyone else’s layout.
Add the evaluation choices to the deployment brief. Name which evaluators run on customer-facing agents, at what sample rate, and who reviews a failing score. The measurable intent is the share of sampled runs that pass the named evaluators before the agent keeps its production slot. A dashboard without those thresholds is visibility without a decision rule.
What a deployment lead should lock before the next agent goes live
October 2 made multi-cloud agent inventory and Agent Identity the current story inside watsonx Orchestrate. September 29 put a free, self-hosted control plane on the table for teams that refuse to send every agent turn through a third-party SaaS service. Neither release removes the human checkpoint. Both make the missing identity and the missing inventory visible enough to fail a KPI.
A deployment lead can test the setup without waiting for every vendor feature to leave preview. Every production agent needs a distinct identity and a named owner. Every protected tool call needs a short-lived, task-scoped token when the platform supports it. Every live run needs an audit line that records the user, the agent, and the tool. If one of those checks fails, the agent waits while the brief is corrected. That is Checkpoint-Based Governance applied to workflow deployment, and it matches the non-cognitive agent plus human authority model already documented in the HAIA-RECCLIN Agent Architecture Specification.
Sources
- IBM. (2026, October 2). New in IBM watsonx Orchestrate: Expanded third-party agent management and Agent Identities. https://www.ibm.com/new/announcements/new-in-ibm-watsonx-orchestrate-expanded-third-party-agent-management-and-agent-identities
- IBM. (2026, September 21). Announcing the private preview of Agent Identity in IBM watsonx Orchestrate. https://www.ibm.com/new/announcements/announcing-the-private-preview-of-agent-identity-in-ibm-watsonx-orchestrate
- Lin, K. (2026, September 29). OpenClaw Enterprise – The Open Agent Platform. OpenClaw Blog. https://openclaw.ai/blog/openclaw-enterprise
Questions readers ask
What did IBM change for agent deployment on October 2, 2026?
IBM said the watsonx Orchestrate AI Gateway now discovers and imports agents built on Microsoft Foundry and Google Gemini Enterprise Agent Platform, in addition to Amazon Bedrock, so multi-cloud agents can sit in one inventory under shared Gateway policies. The same release highlights Agent Identity in preview, runtime LLM-as-a-Judge evaluators that became generally available on September 30, and personalized control-plane dashboards.
What is Agent Identity in watsonx Orchestrate?
IBM describes Agent Identity as a unique, verifiable identity for each agent, separate from the person who built it and the person using it. The identity connects to the organization’s existing identity provider. In the private preview, that includes IBM Verify and Microsoft Entra. Disabling the agent’s identity there can stop the agent from running, and short-lived tokens can limit access to the task at hand.
Why do shared service accounts fail a Factics deployment brief?
Shared service accounts and static keys blur user action with agent action and often grant more access than the task needs. A Factics brief requires a verified fact, an assignable tactic, and a KPI that can fail. When the audit trail cannot show subject, actor, and tool, the KPI fails and the agent stays out of production until identity and logging are fixed.
How does this connect to Basil Puglisi’s HAIA-RECCLIN work?
The HAIA-RECCLIN Agent Architecture Specification treats the orchestration agent as a non-cognitive dispatcher and logbook, with Checkpoint-Based Governance keeping a named human at final authority. Distinct agent identities and append-only audit records are the operational form of that model. Without them, an organization can claim oversight while the record still shows only a shared account.
What is OpenClaw Enterprise, and who should pilot it?
OpenClaw Enterprise is an open-source, vendor-neutral control plane for persistent agents, announced September 29, 2026. It adds multi-tenancy, security boundaries, sandboxing, permissions, and lifecycle auditing, and it can run on an organization’s own Kubernetes infrastructure. The Foundation currently recommends it for internal pilot workloads ahead of a planned 1.0 later in 2026.
What should a team put in the deployment brief before the next agent goes live?
The brief should register each production agent with a distinct identity, name a human owner who can disable that identity, list the tools the agent may call, require task-scoped tokens where the platform supports them, and set the weekly KPI as the share of runs that record user, agent, and tool. Evaluation sampling rates and failing-score owners belong in the same document.
#AIg
Leave a Reply