Protect cluster · IAM, IT
Technology Rewired: Identity and Access
Identity moved from on-prem directories like Active Directory to cloud SSO, CIAM, and MFA, then to risk-based authentication. The agentic shift runs two ways: agents help IAM teams review access and run lifecycle work, and agents themselves become identities that need authentication, scoped permissions, delegation, and an audit trail.
The shift: Agents become identities that need auth, scopes, and audit.
Copilot today
3.3 in five years
How has the identity and access team changed across five eras?
Era 1 · On-prem
Before 2005
0.3Identity lived in the directory. A Windows or LDAP admin created accounts, reset passwords, and managed groups by hand, and customer logins were a users table each application built for itself. Access reviews were spreadsheets sent to managers once a year.
Era 2 · SaaS and cloud
2005 to 2020
0.8Cloud SSO, MFA, SCIM provisioning, and CIAM platforms made identity a service. I built LoginRadius in this era and scaled it to over a billion users; the lesson I wrote up in building customer identity at scale is that identity became product infrastructure, not an IT chore. IAM teams formed around SSO, IGA, and PAM, and developers owned customer login.
Era 3 · AI-assisted
2020 to 2024
1.5Risk-based authentication, bot detection, and ML-assisted access reviews flagged unusual logins and over-provisioned accounts. Humans still approved every grant and closed every review.
Era 4 · Agentic
2024 onward
2.0Two shifts are happening at once. Agents help IAM teams draft access reviews, clean up entitlements, and handle joiner-mover-leaver work. More important, agents are now principals that act on behalf of people and need their own credentials, scopes, and delegation, which is the gap in the AI agent identity crisis and why AI agents don't have passwords.
The large identity vendors have moved to own this layer, as I tracked in every identity giant bought an AI agent company.
Era 5 · Next 5 years
2026 to 2031
3.3My bet: within five years every serious identity platform treats agents as first-class identities with short-lived credentials, per-task scopes, delegation chains back to a human, and revocation that works in seconds. IAM teams grow in importance and shift from account administration to policy design and audit.
Which identity and access software is being rewired?
- Identity and Access Management (IAM and CIAM)
Identity and access management decides who can sign in and what they can do. For twenty-five years that meant people: directories, SSO, MFA, passkeys. The shift now is to AI agents as identities in their own right, each needing its own credentials, narrow scopes, delegated authority from a human, and an audit trail that names both.
Coming next
- Employee onboarding and provisioning
- MFA and passkeys
- Privileged access management (PAM)
- Identity governance (IGA)
- Identity threat detection and response
- Fraud and bot detection
- KYC and identity verification
- Agent and non-human identity
Also wired into this category: Email Security, Firewall and Network Security, Help Desk and Ticketing.
Keep reading
Essays and analysis
- The AI Agent Identity Crisis: Why Your IAM Strategy Needs a Machine-First Redesign
- AI Agents Don't Have Passwords. Your Auth Stack Assumes Everyone Does.
- Every Identity Giant Just Bought an AI Agent Company. Here's What They Know That You Don't.
- Building Customer Identity at Scale: Lessons from 1 Billion Users
- Map Before You Buy: The 2026 Identity Market After the Consolidation Wave
- Your AI Agent Has No Idea Who Authorized It
What died (Tech Graveyard)
What comes next (Future Tech)
Comparisons
- Top 10 Identity and Access Management (IAM) Solutions for 2026
- Top 10 Customer Identity and Access Management (CIAM) Solutions for 2026
- Top 10 Non-Human Identity (NHI) Security Tools of 2026
- Top 10 PAM Solutions for 2026 (Privileged Access Management Compared)
- Top 11 Identity Governance and Administration Solutions for 2026