The proliferation of autonomous AI agents interacting with sensitive enterprise resources via protocols like the Model Context Protocol (MCP) introduces significant security challenges related to identity, access control, and auditing. Traditional Identity and Access Management (IAM) constructs: designed for users, applications, or workflows, fail to accurately model the hybrid, sometimes delegated, behaviors of agents. This article, based on insights from WSO2’s work on Agent Identity, details an architecture for establishing agents as first-class identities, allowing for robust governance, f