Skip to content
Draft. This page is in editorial review and is not indexed yet.

Protect cluster · IAM, IT

Technology Rewired: Identity and Access

Identity moved from on-prem directories like Active Directory to cloud SSO, CIAM, and MFA, then to risk-based authentication. The agentic shift runs two ways: agents help IAM teams review access and run lifecycle work, and agents themselves become identities that need authentication, scoped permissions, delegation, and an audit trail.

The shift: Agents become identities that need auth, scopes, and audit.

Verified
2.0

Copilot today
3.3 in five years

How has the identity and access team changed across five eras?

  1. Era 1 · On-prem

    Before 2005

    0.3

    Identity lived in the directory. A Windows or LDAP admin created accounts, reset passwords, and managed groups by hand, and customer logins were a users table each application built for itself. Access reviews were spreadsheets sent to managers once a year.

  2. Era 2 · SaaS and cloud

    2005 to 2020

    0.8

    Cloud SSO, MFA, SCIM provisioning, and CIAM platforms made identity a service. I built LoginRadius in this era and scaled it to over a billion users; the lesson I wrote up in building customer identity at scale is that identity became product infrastructure, not an IT chore. IAM teams formed around SSO, IGA, and PAM, and developers owned customer login.

  3. Era 3 · AI-assisted

    2020 to 2024

    1.5

    Risk-based authentication, bot detection, and ML-assisted access reviews flagged unusual logins and over-provisioned accounts. Humans still approved every grant and closed every review.

  4. Era 4 · Agentic

    2024 onward

    2.0

    Two shifts are happening at once. Agents help IAM teams draft access reviews, clean up entitlements, and handle joiner-mover-leaver work. More important, agents are now principals that act on behalf of people and need their own credentials, scopes, and delegation, which is the gap in the AI agent identity crisis and why AI agents don't have passwords.

    The large identity vendors have moved to own this layer, as I tracked in every identity giant bought an AI agent company.

  5. Era 5 · Next 5 years

    2026 to 2031

    3.3

    My bet: within five years every serious identity platform treats agents as first-class identities with short-lived credentials, per-task scopes, delegation chains back to a human, and revocation that works in seconds. IAM teams grow in importance and shift from account administration to policy design and audit.

Which identity and access software is being rewired?

  • 2.0
    Identity and Access Management (IAM and CIAM)

    Identity and access management decides who can sign in and what they can do. For twenty-five years that meant people: directories, SSO, MFA, passkeys. The shift now is to AI agents as identities in their own right, each needing its own credentials, narrow scopes, delegated authority from a human, and an audit trail that names both.

Coming next

  • Employee onboarding and provisioning
  • MFA and passkeys
  • Privileged access management (PAM)
  • Identity governance (IGA)
  • Identity threat detection and response
  • Fraud and bot detection
  • KYC and identity verification
  • Agent and non-human identity

Also wired into this category: Email Security, Firewall and Network Security, Help Desk and Ticketing.