Agentic Enterprise: What Changes in Identity Architecture and Integration with AI Agents

Agentic Enterprise: What Changes in Identity Architecture and Integration with AI Agents

Created by: Arthur Monteiro

Published:10/07/2026

The digital identity of AI agents has become a critical issue for companies already using this technology to execute tasks, access systems, and support decisions. Even so, many corporate architectures are still not prepared to recognize these agents as real participants in the operation. They need their own permissions, responsibilities, and controls.

This question set the agenda for WSO2Con 2026. Under the theme “Agentic Enterprise,” AI agents are now treated as full-fledged corporate actors. As a result, identity and integration infrastructure needs to be rebuilt around them.

For those who make decisions about architecture and technology investment, the practical question is a single one: what here requires a decision now, and what is still roadmap?

From “Platformless” to “Agentic Enterprise”: What Actually Changed

In 2025, AI appeared as just another integration problem added to an existing platform. In 2026, the agent became a first-class workload, with infrastructure purpose-built for it.

The tone changed as well. Where 2025 presented a philosophy, 2026 opened with concrete infrastructure. The event featured agent lifecycle management, identity standards designed specifically for agents, and a new integration model.

Figure 1: Non-agentic enterprise architecture on WSO2.com

Figure 3: WSO2 agentic fabric on WSO2.com

AI Agent Manager: A New Product Category

The most significant announcement was the AI Agent Manager, a platform dedicated to managing the lifecycle of agents. The analogy is direct: it does for agents what an API Manager does for APIs.

  • Agent registry: a catalog of the agents in operation, with an owner, metadata, and a description of what each one does.
  • Agent identity: each agent receives its own cryptographic identity, integrated with ThunderID and Asgardeo.
  • Observability: tracking of everything the agent does — which tools it called, which AI models it used, and how its actions chained together.
  • Governance: rules defining which agent can invoke which tool, how often, and under what conditions.
  • Lifecycle: deploying, versioning, promoting, and retiring agents through a controlled flow.

If WSO2 turns the AI Agent Manager into the reference for agent governance, the way the API Manager became the reference for API lifecycle management in the 2010s, it secures a lasting position. The risk is timing. Microsoft, AWS, and Google are also embedding agent management directly into their clouds. WSO2’s trump card needs to be cloud neutrality, open governance, and integration with the middleware companies already have installed.

ThunderID: Identity Rebuilt for the Agent Era

The second launch, ThunderID, is a new identity core that extends, or replaces, the Identity Server for the agent era. Four pillars define it:

  • Agent-native identity, with “on-behalf-of” delegation built in from the start, not bolted on as an accessory.
  • Post-quantum cryptography, using algorithms already standardized by NIST, anticipating threats that quantum computers may bring in the future.
  • Decentralized identity, with support for verifiable credentials.
  • A lightweight core rewritten in Go, focused on performance and on edge scenarios, where processing happens close to where the data is generated.

There is also a governance signal that deserves attention: originally created at WSO2, the ThunderID project will be contributed into the OpenWallet Foundation (OWF) as an open-source project, positioning it as neutral, auditable infrastructure. It is a calculated move in the face of digital sovereignty requirements in Europe. In contrast with commercial platforms controlled in the US, this is a sensitive point for companies operating under stricter data protection rules.

“Who Are You, Agent?”

One question came up repeatedly across sessions: “who are you, agent?” When an agent makes a call to a system, that system needs to know whether it is authorized. It also needs to know on whose behalf the agent is acting, what it can access, and for how long.

The authentication standard we use today was designed for people and for system-to-system communication, and it fails on three fronts in the world of agents:

  • Delegation chains: a human authorizes an agent, which invokes another agent, which invokes a tool. Who is accountable for what?
  • Execution time: agent workflows can run for hours or days, well beyond what a traditional session anticipates.
  • Excess permissions: dozens of systems, each with its own access model.

WSO2’s answer is the so-called On-Behalf-Of token: the agent carries a token that records who the original human was, the entire delegation chain, and what it is allowed to do on each call. This is what makes it possible to answer, securely, “who are you, agent?”

Integration for Agents: 600+ Connectors and the MCP Standard

The integration platform reached a significant milestone: more than 600 connectors in version 5.0, up from 200 in 2025. The number matters less than the shift in logic. Integration is no longer just about connecting systems to one another; it is about exposing a company’s capabilities so that AI agents can use them.

The key piece is the adoption of MCP (Model Context Protocol), an open standard that works as a common language between agents and the systems they invoke. With it, a flow built on the platform can be published as a “tool” that the agent discovers and uses on its own. In practice, the catalog of 600+ connectors becomes an instant menu of actions available to agents, without having to develop a custom integration for each system. After all, agents are only as powerful as the knowledge they can access and the actions they can execute. Both come from integrations.

AI Governance: Traffic Control and LLM Cost

The WSO2 AI Gateway, presented as an idea in 2025, arrived in 2026 with more than 40 protection mechanisms (guardrails): masking of personal data, detection of attempts to manipulate the agent, content filtering, topic restriction, and response validation.

Alongside it came a model for measuring maturity in AI cost control, in five stages: from a total lack of visibility (stage 1) to knowing how much each interaction costs (stage 5). Most companies today are at stages 1 or 2. It is precisely the gateway that makes it possible to advance to the higher stages, attaching to each call the data that enables this cost attribution.

What This Means for You and How TreeID Can Help

The agentic enterprise is not a distant promise, but a set of architecture decisions that begin now.

For those already running API Manager, integration, or Identity Server, MCP support in version 5.0 is of immediate use to AI teams trying to connect agents to the company’s systems. For those evaluating new agent infrastructure, the AI Agent Manager + ThunderID pairing is the most differentiated offering WSO2 has.

Whatever platform you choose, three questions work as a diagnostic:

  • “Who are you, agent?” should be the first question in any project involving agents.
  • The AI Gateway’s catalog of 40+ guardrails serves as a reference for governing AI traffic, even if you use another gateway.
  • The five-stage cost model helps you measure your maturity, whatever the tool.

This is where TreeID comes in. With a focus on API design and management, gateway security, enterprise integration and middleware, iPaaS platforms, and agent-to-agent integration via MCP. We help technology teams turn the signals from WSO2Con 2026 into a predictable, open, agent-ready architecture. That way, there is no need to rewrite everything from scratch, it is enough to reposition what already exists for the agentic era.

Want to discuss how these topics apply to your environment? Talk to TreeID.

Share it

Built for critical decisions

More Insights

Agendar demonstração

Preencha o formulário abaixo e daremos o primeiro passo para a transformação digital da sua empresa.