Broadcom AgentMinder
by Broadcom
Authorize every AI agent action before it happens, not audit it afterwards
AgentMinder is Broadcom's AI agent governance and runtime control platform, generally available since August 2026. It treats each agent as an enterprise identity bound to a declared mission, permitted intents, approved tools and authorized resources, then authorizes every individual tool call through a policy gateway before it reaches a backend system. It is built for enterprises putting agents into production across private and hybrid infrastructure.
Broadcom announced AgentMinder on August 31, 2026 at VMware Explore 2026 and shipped it generally available the same day, built by the company's Identity Management Security Division. Its premise is that governance has to authorize an action before a tool call rather than document the agent afterwards. The product has three layers. Identity and intent treats every agent as an enterprise-grade identity whose authority is bound to a declared mission, permitted intents, approved tools and authorized resources — an agent must declare what it is trying to do, not only who it is, before touching enterprise systems. Runtime enforcement runs through a cloud-native AI gateway deployed alongside the customer's LLMs, which authenticates tokens, evaluates context including user identity, intent and current risk through a dynamic policy engine on every tool invocation, and routes traffic only to authorized backends. Observability is built on OpenTelemetry, producing a compliance-grade audit trail and chain of custody across agent sessions plus anomaly detection. Rather than replacing existing authorization infrastructure, AgentMinder integrates with it through AuthZEN, the OpenID Foundation standard, and runs on VMware vSphere Kubernetes Service, Google Cloud Platform and other standards-based Kubernetes platforms, on-premises, in VPCs or in public cloud. Broadcom cites its own internal deployment as the reference: nearly 36 million customer-related and 7 million workforce-related API calls daily across more than 20 million customer identities and 72,000 workforce identities on a multi-region active-active architecture. It is positioned alongside VMware vDefend for lateral security and MCP server discovery and VMware Avi Load Balancer for AI-aware load balancing and API protection, and addresses Model Context Protocol and agent-to-agent traffic explicitly.
An identity or platform security architect at an enterprise already running a centralized authorization service, moving agents into production on VMware private cloud or hybrid Kubernetes, who needs per-action control rather than another inventory dashboard.
Every individual agent tool call is authorized against declared mission, intent, resource and risk before it reaches a backend — so a compromised or drifting agent is stopped at the action, not discovered in the audit log.
At a Glance
- Category
- Governance & Security
- Pricing
- Contact for pricing, Subscription
- Target Market
- CISOs, CIOs, Identity Architects, Platform Engineering Teams
- Deployment
- Hybrid, Self-hosted, Multi-cloud
- Team Size
- 500+
Key Features
- ✓Identity and intent binding
Each agent gets an enterprise-grade identity whose authority is bound to a declared mission, permitted intents, approved tools and authorized resources.
- ✓Pre-action authorization
An agent must declare what it is trying to do before touching enterprise systems, and each action is authorized against that declaration, context and current risk.
- ✓Cloud-native AI gateway
Deployed alongside existing LLMs, it authenticates tokens on every tool call and routes traffic exclusively to authorized backend systems.
- ✓Dynamic policy engine
Evaluates user identity, agent intent and context per invocation, applying per-tool and per-backend policy rather than a static session-level grant.
- ✓OpenTelemetry observability and audit
Produces compliance-grade visibility, chain of custody and anomaly detection across every agent session and action for security, risk and platform teams.
- ✓AuthZEN standards integration
Plugs into existing authorization stacks via the OpenID Foundation's AuthZEN standard, so enterprises reuse current policy services instead of replacing them.
- ✓Multi-environment deployment
Runs on VMware vSphere Kubernetes Service, Google Cloud Platform and other standards-based Kubernetes, on-premises, in VPCs or in public cloud.
Capabilities
Use Cases
- •Constraining an agent to its mandate
A procurement agent authorized to read supplier records and raise purchase orders is blocked when it attempts an unrelated HR system call.
- •Securing MCP tool invocation
Every Model Context Protocol tool call passes through the gateway, which authenticates the token and routes only to backends the agent is approved for.
- •Regulated audit evidence
Risk and compliance teams reconstruct chain of custody for agent actions from OpenTelemetry data when an auditor asks what an agent touched and why.
- •Agent activity anomaly detection
Security teams spot an agent drifting from its declared mission or exhibiting unusual tool-call patterns across sessions before harm reaches production.
- •Private AI cloud defence in depth
AgentMinder governs agent actions while VMware vDefend handles lateral security and Avi Load Balancer handles AI-aware traffic and API protection.
Ideal For
Best For
- ✓Enforcing per-tool-call authorization for AI agents rather than session-level access grants
- ✓Enterprises standardised on VMware private cloud or vSphere Kubernetes Service moving agents into production
- ✓Organisations with an existing centralized authorization service they want to reuse through the AuthZEN standard rather than replace
- ✓Producing compliance-grade audit trails and chain of custody for regulated agent workloads via OpenTelemetry
- ✓Governing Model Context Protocol and agent-to-agent traffic where the attack surface is tool invocation rather than the model itself
Not Ideal For
- ✗Organisations without a mature identity provider and policy engine already in place — the integration design depends entirely on that existing infrastructure, which aicybr flags as the main implementation variable
- ✗Buyers who need pricing transparency or a trial before committing, since neither list pricing nor a self-serve trial is published
- ✗Teams whose primary problem is discovering unknown agents across heterogeneous clouds, where discovery-first tools are the better-matched category
- ✗Enterprises needing mature audit and compliance workflow tooling comparable to dedicated GRC platforms, which independent comparison identifies as a documented gap
Deployment
Market Analysis
Pros
- ✓Authorizes per call rather than per session, which independent comparison identifies as the real architectural shift — governance that intervenes instead of documenting
- ✓Standards-based integration via AuthZEN means enterprises reuse existing authorization services rather than running a parallel policy stack
- ✓Deploys across on-premises, VPC, public cloud and standards-based Kubernetes, covering private-AI estates that SaaS-only governance products cannot reach
- ✓Backed by a large-scale internal production deployment — nearly 36 million customer-related API calls daily across more than 20 million identities
Cons
- ✗Newly generally available with little independent customer evidence yet, as the governance-platform comparison that ranks it explicitly notes
- ✗No public pricing and no trial availability, which the same comparison scores as a maturity and transparency gap against competitors
- ✗Audit and compliance workflow documentation is thinner than dedicated GRC platforms such as OneTrust or IBM watsonx.governance
- ✗Integration design depends heavily on the customer's existing identity provider, policy engine, agent frameworks and tool architecture, so implementation effort varies widely by organisation
- ✗Behaviour during infrastructure failure — network, identity provider or authorization service outages — is unspecified in published material, a real question for a component that sits inline on every tool call
- ✗The 36 million API call figure is vendor-reported from Broadcom's own internal deployment, not an independently verified customer benchmark
Pricing
AgentMinder (Enterprise)
Contact for pricing
- ✓Agent identity and intent governance
- ✓Runtime AI gateway enforcement
- ✓OpenTelemetry audit and anomaly detection
- ✓AuthZEN integration
- ✓On-premises, VPC or public cloud deployment
Neither list pricing nor licensing terms were disclosed at general availability and no public trial is offered, which independent comparison flags as a maturity gap against competing governance platforms. Cost is negotiated through Broadcom's enterprise software licensing, and the practical spend includes integration work whose scope depends on the customer's existing identity provider, policy engine, agent frameworks and tool architecture. Buyers standardised on VMware infrastructure are the primary commercial target, so pricing is likely to be shaped by that broader relationship rather than quoted standalone.
Security & Compliance
Connect
Sources
This page was written from 7 sources, 6 on domains other than broadcom.com.
- 1.globenewswire.com — broadcom unveils agentminder an enterprise solution for ai a
- 2.globenewswire.com — broadcom delivers end to end security identity and observabi
- 3.aicybr.com — broadcom agentminder ai agent governance runtime control
- 4.omidsaffari.com — best ai agent governance platforms 2026
- 5.broadcom.com — agentmindervendor
- 6.storagenewsletter.com — vmware explore 2026 broadcom unveils agentminder an enterpri
- 7.cloudnews.tech — broadcom launches agentminder to control what ai agents can
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
CrowdStrike Falcon Guardian
AI detection and response that finds shadow AI agents on the endpoint and blocks the unapproved ones
Tenable CyberAgents Exchange
A free, vendor-neutral registry of security AI agents, skills, MCP servers and playbooks
Kosmoy
A self-hosted AI control plane: inventory, gateway, observability and agent sandboxing
SCALR AI
A licence-free multi-agent SOC workbench that runs in your own Azure tenant