Broadcom Releases AgentMinder to Check AI Agent Tool Calls at Runtime
The new control layer is designed to evaluate each requested agent action before it reaches company systems, shifting governance from static permissions toward live policy enforcement.
Listen to this story
The audio brief
Story brief
3 key pointsAgentMinder is now generally available as Broadcom’s runtime governance layer for enterprise AI agents, with release announced Aug. 31 at VMware Explore 2026. It evaluates identity, declared mission and intent, context, and risk at each tool or API request, then logs sessions for audit and anomaly detection. The product is designed to work across on-premises, private-cloud, and public-cloud LLM deployments and reuse...
- 01
Broadcom says AgentMinder’s own platform serves more than 20 million customer identities and 72,000 workforce identities.
- 02
The platform reportedly processes nearly 36 million customer-related and seven million workforce-related API calls daily.
- 03
A cloud-native gateway authenticates tokens, routes requests to authorized backends, and applies dynamic policies per tool call.
Broadcom has made AgentMinder generally available, offering enterprises a control layer that checks an AI agent’s requested actions before they reach company resources. The product was introduced Aug. 31 at VMware Explore 2026.
The system is aimed at agents that do more than produce text. Broadcom says AgentMinder verifies an agent’s identity and authorizes every action against its declared mission, intent, context and current risk before access to an enterprise resource. That puts the check at the point where an agent requests data, invokes a tool or seeks to change a system.
Broadcom’s design treats an agent as more than a software identity. It binds an agent’s authority to a declared mission, permitted intents, approved tools and authorized resources. The agent must declare what it is trying to do before it can touch enterprise systems, according to the company.
- Runtime enforcement: a cloud-native AI gateway authenticates tokens, directs traffic only to authorized backends and uses a dynamic policy engine to assess context for each tool call.
- Observability and audit: an OpenTelemetry-based layer records agent sessions and actions, with chain-of-custody and anomaly-detection capabilities.
- Deployment: AgentMinder can sit beside large language models running on premises, in virtual private clouds or across public clouds. Broadcom says AuthZEN integration lets organizations reuse existing authorization endpoints.
Broadcom is also using its own deployment to make the scale case. The company says its AgentMinder-powered platform supports more than 20 million customer identities and 72,000 workforce identities. It says the platform handles nearly 36 million customer-related API calls and seven million workforce-related API calls each day through a multi-region, active-active architecture.
Those are company-supplied operating figures for Broadcom’s own platform. The product’s practical promise is broader: Broadcom says its combination of intent governance, runtime enforcement and auditability can let enterprises use agents in finance, HR and IT without rewriting their existing identity or authorization stack.
Editorial analysis
Our Read
Our read: AgentMinder’s central bet is that agent governance must operate as a live authorization service, rather than as a set of model guardrails or permissions assigned once to a software account. Broadcom’s stated intent check is the consequential part of that proposition: companies would need policies that distinguish a permitted task from an impermissible action taken during it. The next evidence to watch is whether organizations can operationalize those policies across existing authorization endpoints while preserving the speed and availability agent workflows require.
Sources
- investors.broadcom.comBroadcom Unveils AgentMinder, An Enterprise Solution for AI Agent Governance and Runtime Control | Broadcom Inc.