Skip to content

Identity & Access Leadership

Identity is usually the largest line in a security budget and the hardest one to explain upward. This desk covers the leadership decisions: sequencing IGA, PAM, and ITDR; owning non-human identity before it is a tooling problem; what identity debt costs at scale; and what an auditor will actually open when they test access control.

6 pieces

Decision BriefIdentityAugust 28, 2026

IGA, PAM, or ITDR First?

Three identity categories compete for the same budget line and vendors in each will tell you theirs comes first. The sequence is decided by which failure you can already evidence.

Field NoteIdentityAugust 28, 2026

The Cost of Identity Debt at Scale

Identity debt never arrives as a security incident. It arrives as onboarding that takes nine days, an audit finding that recurs, and a migration estimated at one quarter that takes three.

Field NoteIdentityAugust 28, 2026

What Auditors Actually Test in Identity

Auditors do not evaluate your identity architecture. They pick names off a list and ask you to prove what happened. Elegant design earns nothing if the record is missing.

Benchmarks on this desk

Common questions: identity

Should a security program buy IGA, PAM, or ITDR first?
Buy against the failure you can already evidence. If access reviews are manual and audit findings repeat, IGA first. If standing administrative credentials exist in production, PAM first. ITDR is third for most organizations, because detecting identity attacks is worth little while the underlying entitlements are still ungoverned.
Who owns non-human identity in an organization?
Usually nobody, which is the problem. Service accounts, API keys, and now AI agents are created by engineering, consumed by applications, and governed by no one. Non-human identity becomes tractable only when a named owner and a lifecycle are assigned, which is a governance decision that precedes any tooling purchase.
What do auditors actually test in identity?
Evidence of process, not architecture. An auditor samples joiners, movers, and leavers, then asks you to produce the approval and the deprovisioning record for each. Elegant single sign-on design earns nothing if you cannot show a dated record that a departing employee lost access within your stated window.