This paper presents an integrated security architecture that strengthens the agent web through a zero-trust IAM framework. This architecture is based on rich, verifiable agent identities using Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs), with discovery managed by a protocol-agnostic Agent Name Service (ANS). Security is enabled by an innovative multi-layered trust structure that includes Trust Adaptive Runtime Environments (TAREs), causal chain auditing, and proof-of-action. By explicitly linking LPCI threats to these enhanced architectural defense mechanisms within a formal security model, we propose a comprehensive and forward-looking blueprint for a secure, resilient, and trustworthy agent ecosystem. Formal analysis demonstrates that the proposed architecture provides provably secure protection against LPCI attacks with limited success rates.