A company wants to use their existing corporate directory to manage user access to watsonx.governance, rather than maintaining a separate local user list. Which configuration approach should they select?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Think of it this way: in real-world AI governance, configure saml federation through ibm cloud iam, or connect an ldap directory for centralized authentication and access control is exactly what teams reach for when they need to handle this scenario. IBM Cloud IAM supports integration with enterprise identity providers via SAML 2. On the exam, remember that this falls squarely under the 3.0 Configure watsonx.governance domain.
Full explanation below image
Full Explanation
IBM Cloud IAM supports integration with enterprise identity providers via SAML 2.0 federation and LDAP, enabling centralized user management. This allows governance administrators to leverage existing directory groups and role assignments when granting access to watsonx.governance services, ensuring consistency with corporate access policies. The correct answer, "Configure SAML federation through IBM Cloud IAM, or connect an LDAP directory for centralized authentication and access control", directly addresses the scenario described because it aligns with the specific governance requirement in question. The incorrect options ("Manually create all governance users in the watsonx.governance local user registry and assign roles individually", "Distribute individual API keys to all governance users through a secure email distribution list", "Configure OAuth tokens within Watson OpenScale provider settings to map directory users to monitoring roles") may seem plausible but do not satisfy the core requirement. Understanding the distinction between these concepts is critical for IBM watsonx.governance implementations and is frequently tested in the 3.0 Configure watsonx.governance section of the certification exam.