This paper presents an integrated security architecture that strengthens the agent web through a zero-trust IAM framework based on rich and verifiable agent identities using Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs). Security is achieved through a multi-layered trust structure that includes Trust Adaptive Runtime Environments (TAREs), causal chain auditing, and proof-of-action, along with discovery capabilities managed by a protocol-agnostic Agent Name Service (ANS). By explicitly linking LPCI threats to these enhanced architectural defense mechanisms within a formal security model, we propose a comprehensive and forward-looking blueprint for a secure, resilient, and trustworthy agent ecosystem. Formal analysis demonstrates that the proposed architecture provides provably secure protection against LPCI attacks with limited success rates.