Skip to Main Content
Digital Business Automation Ideas


This is an IBM Automation portal for Digital Business Automation products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Please use the following category to raise ideas for these offerings for all environments (traditional on premises, containers, on cloud):
  • Cloud Pak for Business Automation - including Business Automation Studio and App Designer, Business Automation Insights

  • Business Automation Workflow (BAW) - including BAW, Business Process Manager, Workstream Services, Business Performance Center, Advanced Case Management

  • Content Services - FileNet Content Manager

  • Content Services - Content Manager OnDemand

  • Content Services - Daeja Virtual Viewer

  • Content Services - Navigator

  • Content Services - Content Collector for Email, Sharepoint, Files

  • Content Services - Content Collector for SAP

  • Content Services - Enterprise Records

  • Content Services - Content Manager (CM8)

  • Datacap

  • Automation Document Processing

  • Automation Decision Services (ADS)

  • Operational Decision Manager

  • Robotic Process Automation

  • Robotic Process Automation with Automation Anywhere

  • Blueworks Live

  • Business Automation Manager Open Edition

  • IBM Process Mining


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.


Status Submitted
Created by Guest
Created on Nov 18, 2025

Allow the use of an Entra ID workload identity for Directory Server Accounts

The concept of non-human accounts doesn’t exist in Microsoft Entra ID typically applications where no human interaction is involved use OAuth client credential flow as explained here. The FileNet CPE makes use of some directory server accounts that don't accomodate this change that Microsoft is making with Entra ID, so this seems to limit the ability to fully make use of Microsoft Entra ID.

Idea priority High
  • Guest
    Nov 20, 2025

    This is about future security standards integrations with ALL IBM products.

    • Microsoft docs on this:

      https://learn.microsoft.com/en-us/entra/identity/managed-identities-azure-resources/overview

      Managed Identities and Service Principles

      Basically you get a token like an LTPA token. These will be expired on a timed basis so these will need to be refreshed constantly.

      GOAL: No more Non-Human Identities or Service Accounts - like the FileNet GCD user, Db2 Instance user, Linux root, etc...

    QUESTIONS:
    Is IBM planning to adopt the open source SPIFFE and SPIRE standards? However, to use the SPIFFE standard would require broad IBM software adoption and we are wondering if ENG is aware of the standard and has plans to support it... SPIFFE appears to be a framework to allow trust at an application level – Originally for Microservices/FaaS,( https://www.ibm.com/think/topics/faas ) serverless codelets that need to authenticate to each other.

    The issue here is all SERVICE ACCOUNTS. The “new” name for those is “Non-Human Accounts (NHAs). Microsoft wants these to all go away. Which would impact many IBM products. These are the permanent, problematic to change the passwords for identities. Those are the accounts that MS wants to elimiate. The IBM FCM/FileNet software have them, ICC, Db2, etc.

    QUESTION 2:
    Has ENG evaluated this newer open source security standard yet? Seems an IDP SEC standard like OAUTH, IAM to me. The biggest issue I'm seeing is how this impacts all IBM "Master" users and passwords and any other "Non Human User"/ Service Accounts.
    Thoughts?

    ABOUT SPIFFE:
    SPIFFE is an open standard and framework for workload identity, much the same way that OAuth is an open standard and framework for human identity.
    More details can be found at:

    https://spiffe.io

    So, even though this is a new standard, it is not widely adopted yet and since implementing this would cause code changes and a rethink of how we do security in many IBM products we just want it on the PM/Architects/Security planner radar.