Skip to Main Content
Shape the future of IBM watsonx Orchestrate

Start by searching and reviewing ideas others have posted, and add a comment (private if needed), vote, or subscribe to updates on them if they matter to you.

If you can't find what you are looking for, create a new idea:

  1. stick to one feature enhancement per idea

  2. add as much detail as possible, including use-case, examples & screenshots (put anything confidential in Hidden details field or a private comment)

  3. Explain business impact and timeline of project being affected

[For IBMers] Add customer/project name, details & timeline in Hidden details field or a private comment (only visible to you and the IBM product team).

This all helps to scope and prioritize your idea among many other good ones. Thank you for your feedback!

Specific links you will want to bookmark for future use
Learn more about IBM watsonx Orchestrate - Use this site to find out additional information and details about the product.
Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.
IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.
ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

Status Submitted
Created by Guest
Created on Sep 14, 2026

Enable tools to use member credentials through Microsoft Teams and the Orchestrate Agent API

Requested enhancement

Enable tools to use member credentials when an agent is accessed through external channels. IBM watsonx Orchestrate should identify the requesting user and run tool actions on behalf of that user, using the credentials and permissions associated with the user's account in the third-party application.

Target channels

  • Microsoft Teams channel

  • Custom applications that use the Orchestrate Agent API

Expected behavior

  • Securely map the authenticated user from the external channel to the corresponding watsonx Orchestrate user.

  • Use that user's member credentials, or generate a user-scoped access token and securely pass it to the downstream tool.

  • Ensure that User A and User B use their own credentials and permissions, even when using the same agent and tool.

  • Prompt the user to connect or reauthenticate if their credentials are missing or expired, and then resume the operation.

  • Do not automatically fall back to team credentials.

  • Record the user, channel, tool, target application, and result in audit logs without exposing credentials.

Value to users

This capability would preserve user-level permissions, least-privilege access, and auditability when agents are used outside the watsonx Orchestrate UI. It would also eliminate the need to share team credentials or build a separate credential-management mechanism, while allowing users to continue working through Microsoft Teams or an existing custom portal.

Idea priority High