The agent controls are new, but the foundation underneath them is not. Identity for AI in software runs on the same hardened, standards-based platform enterprises already operate, which means these capabilities arrive as an integral part of a proven enterprise-grade identity platform rather than a new industry player to vet.
That distinction carries real weight for regulated buyers. Adopting a brand-new platform means fresh security reviews, new integration work, and new operational risk. Adopting a continuously evolving platform with sustained investment—and an established reputation as an industry leader—lets teams add agent controls while keeping the performance, compliance, and operability characteristics that have consistently been proven over time.
These updates run across the broader self-managed platform, from federation to identity lifecycle and directory services, so the following capabilities support these controls without asking teams to adopt a new platform.
Performance, scale, and operations
With distributed tracing now supported across most Ping Advanced Identity Software components, teams gain full end-to-end observability to trace and debug requests seamlessly. This capability is paramount for Identity for AI, where autonomous agents introduce high-volume, dynamic access patterns, requiring deep request-level visibility to maintain control, trace delegated identities, and resolve issues instantly.
Security hardening and compliance depth
Recent releases add support for AI agents alongside Federal Information Processing Standards (FIPS) 140-3 support. That combination matters for organizations that must meet strict cryptographic requirements while adopting automation.
The platform stays aligned with established standards, including FIDO, FAPI, and FIPS. For regulated customers, that alignment is what lets them extend to new actors without stepping outside their compliance obligations. It is the difference between a control that satisfies an auditor and one that creates a new finding.
Standards and interoperability
Token exchange and audience-aware token handling support agent flows, so a token issued for one purpose is not silently reused for another. This keeps delegation precise as agents move between services.
Recent releases add audience-based introspection for exchanged tokens, and OAuth enforcement remains standards-based for MCP protection. Building on open standards keeps these controls interoperable across a heterogeneous ecosystem, which matters because few enterprises will build all their automation on a single platform.
Ping Advanced Identity Software has also introduced support for ID-JAG and CIMD, extending these agent-security patterns across authorization domains. ID-JAG lets enterprises issue and consume identity assertions in token exchange flows, helping agents carry user-backed delegation across systems without repeatedly re-consenting or overextending a token beyond its intended audience. CIMD adds dynamic client metadata retrieval and validation at runtime, which is especially valuable for AI agents and other short-lived or externally originated clients that are impractical to preregister one by one. Together, these additions strengthen interoperable, standards-based trust for agent ecosystems while reducing brittle, manual client setup.
Administrative simplicity and modernization
File-based configuration is supported in production, which makes it easier to manage identity infrastructure as code and keep environments consistent. That fits the automation practices these teams already use.
These recent releases also bring DCR scripting improvements for managing agent identity attributes. Administrators get finer control over how agents are registered and shaped, without adding manual steps that slow deployment or invite error.
These updates also add OAuth client tagging with a clear Identity for AI purpose: it lets administrators distinguish AI agents, MCP servers, workforce apps, and other client types instead of treating every OAuth client as a generic application. That matters in agentic environments because secure AI operations depend on knowing what kind of actor is requesting access, relating that actor to the right trust model, and enforcing the right controls at runtime. With Tag Management, admins get a dedicated menu for managing default and custom tags, allows one or more tags to be assigned to OAuth clients, and exposes a Tag Authentication Selector so policies can branch differently for AI agents, MCP servers, or conventional apps. The result is a more governable agent ecosystem: teams can classify clients more cleanly, filter them more easily, and apply least-privilege, context-aware policy decisions that better fit Identity for AI use cases.