To secure AI agents and other workloads, use a workload IAM architecture that centralizes governance and policy management while leveraging multiple instances of access tools such as workload IdPs, PKIs, secrets management, and environment-specific workload identities.