Identity Fabric POV
Five editorial pillars
The Tectonic Shift: Identity Moves from Access to Action
Standing access and session lifetime are no longer sufficient when AI agents act continuously. Enterprises must govern authority at the moment of effect.
Governed Execution: The Boundary Between Proposed and Real
Hyperscalers ship cognitive harnesses. Regulated enterprises need governance harnesses—policy before action, capability without custody, proof after outcome.
Continuous Authority: When Trust Changes, Effective Permission Must Change
An unexpired token is not proof of current authority. Signals-based recalculation keeps effective permission aligned with risk—before the next consequential action.
Purpose-Bound Autonomy: Why Architects Need More Than OAuth Scopes
OAuth scopes describe APIs. Regulated autonomy requires bounded work, approved purpose, and policy-at-mint authorization—what we implement as Continuous Dynamic Authorization (CDA).
Seven Laws of AIdentity: A Framework for Governed Agent Identity
Patrick Parker's Seven Laws build on KuppingerCole's AIdentity framing—an architect-facing summary with proper attribution.
More articles
Your AI Agent Audit Trail Is Probably Just a Log File. Here's Why That Won't Survive a Regulator.
The EU AI Act enforcement date is August 2, 2026. Structured logs do not satisfy transparency, oversight, or record-keeping requirements. Cryptographic receipts do.
Read article →MCP Is the Interface. Governance Is the Product.
Every major AI platform now speaks MCP. Interoperability is solved. Enforcement and trust are not — that is where governance lives.
Read article →Your Workforce IdP Wasn't Built for AI Agents (And That's Fine)
Don't rip out Okta, Entra, or Ping for AI agents. Federate them to an identity plane that composes policy-at-mint authorization, delegation, and fast revocation.
Read article →Runtime Control for AI Agents Fails the Moment Identity Disappears
OWASP LLM-08 is called "Excessive Agency." Read carefully: it is not a model safety problem. It is an identity and authorization problem.
Read article →Runtime Execution Control Has Two Layers. Most Vendors Only Sell You One.
In-process guardrails help agents try to behave well. Infrastructure-level enforcement proves they did. Production needs both — and it is critical to understand the difference before you buy.
Read article →SAP IdM 8.0 End-of-Life: What to Do Now
December 2027 sounds far away — until you realize migration takes 18–36 months. Here is the timeline, the options, and a realistic path that does not require big-bang.
Read article →