Identity and Access
Identity and Access Management (IAM and CIAM): from Active Directory to AI agents
Identity and access management decides who can sign in and what they can do. For twenty-five years that meant people: directories, SSO, MFA, passkeys. The shift now is to AI agents as identities in their own right, each needing its own credentials, narrow scopes, delegated authority from a human, and an audit trail that names both.
Autonomy level
2.0 of 5 · Copilot
launch score
Projected 3.3 by 2031
- Tasks automated
- 2.0
- Approval load
- 1.5
- Production maturity
- 2.5
Overall is the mean of the three sub-scores. How scores work
The same job, five eras
Drag across the eras to see who did the work, with what, and what broke.
What job does identity and access management software do?
Identity and access management answers two questions on every request: who is this, and what are they allowed to do? Workforce IAM answers them for employees and contractors. Customer IAM (CIAM) answers them for the millions of people who sign up for your product, where conversion and scale matter as much as control. The split is older than most buyers realise, and I walk through it in IAM vs CIAM.
The job has always included the boring middle: creating accounts, granting and removing access, proving to an auditor who had what, and catching stolen credentials. What changes now is the population. Software already holds far more identities than people do, and a fast-growing share of them are AI agents that act on a human's behalf.
Era 1 · Before SaaS · 1995-2009
How did identity and access management work before SaaS?
Identity lived in a directory inside the building. Microsoft shipped Active Directory with Windows 2000 Server, and it became the system of record for who worked at a company and which groups they sat in. Unix shops ran LDAP directories, and big enterprises bought identity suites from Sun, Oracle, IBM and CA to stitch provisioning and web access management together.
Customer identity barely existed as a category. Every web team built its own login table: a users table, a password column, a reset-by-email flow, and later a hash function someone hoped was strong enough. Single sign-on across companies needed SAML, which OASIS adopted as a standard in 2002 and revised as SAML 2.0 in 2005.
What broke was everything at the edges. Joiner, mover and leaver changes ran through help desk tickets, so ex-employees kept access for weeks. Passwords were the only factor, reused across sites and phished at scale. Every new application meant another integration project and another set of credentials to forget.
Era 2 · The Cloud Move · 2009-2020
What changed when identity and access management moved to the cloud?
Identity moved to the cloud because the applications did. Okta was founded in 2009 to put single sign-on and user lifecycle in a browser, and employees went from a dozen passwords to one portal. SCIM-based provisioning let HR changes flow into SaaS apps without a ticket. Microsoft followed with Azure Active Directory, later renamed Microsoft Entra ID.
The protocols settled. OAuth 2.0 was published as RFC 6749 in 2012 and became the way apps delegate access to APIs. OpenID Connect added an identity layer on top in 2014. SAML stayed for enterprise SSO, and OIDC took over for modern apps.
Customer identity became its own market in this era. I built LoginRadius as a CIAM platform and scaled it to over a billion users, alongside Auth0, Gigya, Janrain, ForgeRock and Ping. The lessons from that decade are in building customer identity at scale: conversion, social login, consent, and uptime matter more to a customer login page than to an employee one.
Pricing went per seat for workforce and per monthly active user for customers. MFA spread, but mostly as SMS codes and push approvals that attackers learned to phish and fatigue.
Era 3 · The Copilot Years · 2020-2024
What did AI copilots change in identity and access management?
Machine learning entered identity as a risk score. Adaptive authentication looked at device, location, velocity and behaviour, and stepped a login up to MFA only when something looked wrong. Bot detection on customer login pages blocked credential stuffing. Governance tools began suggesting which access to revoke in a review instead of listing everything.
Attackers moved to identity because it worked. Gartner named identity threat detection and response (ITDR) a top security trend for 2022, and vendors started watching the IdP itself for token theft, session hijacking and MFA bypass. Phishing-resistant authentication finally had a consumer path when Apple, Google and Microsoft committed to passkeys in May 2022.
The market consolidated around platforms. Okta closed its $6.5 billion purchase of Auth0 in 2021 and ran it as the developer-facing CIAM line. Microsoft renamed Azure AD to Entra ID in 2023. Copilot-style assistants appeared in admin consoles to answer policy questions, but a human still made every access decision.
Era 4 · The Agentic Shift · 2024-2026
The Agentic Shift: What do AI agents do in identity and access management today?
The new identity in the room is the AI agent. It calls APIs, reads files, books, buys and files tickets, and to do that it needs credentials. The first generation of agents borrowed them: a user's full-scope OAuth token pasted into a tool, or a static API key in an environment variable. That is the failure I describe in AI agents don't have passwords: consent, delegation, sessions, bot defence and audit all assume a human is on the other end.
The standards layer moved first. The Model Context Protocol added an authorization spec in March 2025 built on the OAuth 2.1 draft, and later revisions require resource indicators (RFC 8707) so a token is bound to the one MCP server it was issued for. OAuth token exchange (RFC 8693) gives a way to express an agent acting on behalf of a person. Keycloak now documents itself as an MCP authorization server.
Then the products shipped. Auth0 for AI Agents went GA in November 2025 with a Token Vault for third-party tokens and asynchronous human approval for critical actions. Ping made Identity for AI generally available in March 2026. Microsoft Entra Agent ID, announced in preview in May 2025, is now generally available with agent identity blueprints, sponsors and Conditional Access for agents. Okta announced Okta for AI Agents in March 2026 with GA set for April 30.
The money followed. Palo Alto Networks closed its CyberArk deal in February 2026 for $21.1 billion of consideration, and within ten weeks that summer Cisco, SailPoint, Okta and Cyera each bought a non-human identity startup. I cover the pattern in why the identity giants bought AI agent security. The real limit today: agents can register, receive scoped tokens and be revoked, but most access decisions about what an agent should hold are still made by a person.
Era 5 · The Next Five Years · 2026-2031
What will identity and access management look like by 2031?
My bet is that by 2031 an agent without its own identity will look the way a shared admin password looks today: a finding, not a practice. Every agent gets registered with an owner, receives short-lived tokens scoped to one task, and carries a delegation record that names the human who authorised it. Standing API keys for agents become the next thing the graveyard collects.
Identity governance flips direction. Today a person reviews what an agent holds. Next, agents will propose access, prepare reviews, and revoke unused entitlements on their own, with people approving only consequential grants such as production data, money movement and admin roles. Machine identities already outnumber humans by more than a hundred to one in Palo Alto Networks' 2026 survey, so human-only review cannot keep up.
On the customer side, passwordless becomes the default and CIAM learns to tell an authorised customer agent from a malicious bot. I made the longer case in the future of CIAM: the login page stops being the main event, and delegation becomes the product.
What has to be true: token exchange and agent-to-agent delegation must standardise across IdPs, agent registries must interoperate across vendors, and prompt injection must be contained well enough that a scoped agent can act on low-risk work without a human approving each step.
My prediction · by 2031 · medium confidence
By 2031, most enterprise and customer identity providers will issue AI agents their own identities by default, with short-lived, task-scoped tokens and a delegation record naming the human behind them, and standing API keys for agents will be treated as an audit finding.
What has to be true
- OAuth token exchange based delegation is supported consistently across major IdPs and the MCP ecosystem
- Agent registries from Microsoft, Okta, Ping and others interoperate rather than lock agents to one vendor
- Auditors and regulators start asking for agent-level audit trails, not only user-level ones
- Prompt injection is contained well enough that scoped agents can act on low-risk work without per-action approval
Projected autonomy 3.3 of 5
Then vs now: who does each step?
The job broken into its steps, and who or what does each one in each era.
| Job step | On-prem | SaaS and cloud | AI-assisted | Agentic | Next 5 years |
|---|---|---|---|---|---|
| Create the account | Help desk adds a user to Active Directory from a ticket | HR system triggers SCIM provisioning into SaaS apps | Provisioning rules suggest roles from peer groups | Agents are registered as their own identities with an owner and sponsor | Agents self-register against policy; a human sponsor is assigned automatically |
| Prove who is signing in | A password, checked by the directory | SSO plus SMS or push MFA | Risk scoring steps up MFA; passkeys arrive | Humans use passkeys; agents get short-lived tokens from an IdP | Passwordless by default for people; workload attestation for agents |
| Decide what they can access | Admins add users to groups by hand | Role-based access set in the IdP | ML flags excess access for an admin to remove | Scoped, delegated tokens per task; a person sets the scopes | Agents request just-in-time scopes; humans approve only high-risk grants |
| Review and remove access | Annual spreadsheet review signed by managers | Quarterly campaigns in a governance tool | AI recommends revoke or keep for each line | Sponsor workflows catch orphaned agents; humans still sign off | Continuous review by agents; humans audit samples and exceptions |
| Detect identity attacks | Failed-login logs read after an incident | SIEM rules on IdP logs | ITDR watches for token theft and MFA bypass | Risk-based Conditional Access and kill switches for agents | Automated containment that revokes a misbehaving agent in seconds |
| Give software its credentials | Service account passwords in config files | Static API keys and long-lived OAuth tokens | Secrets vaults with rotation | Token vaults and runtime-issued, short-lived credentials | No standing secrets; every credential is minted per task |
How does the identity and access management team change?
Identity teams were built around administering people: tickets to grant access, campaigns to review it, help desk calls to reset it. Passkeys and automated provisioning already shrank that work. Agents shrink it further, because the routine grant, review and reset steps are exactly what software does well.
The work that grows is design and accountability. Someone has to define what each agent may do, who sponsors it, how delegation is recorded, and when a human must approve. The market is consolidating around that job, which is why the 2026 identity market map now has a non-human identity branch that four acquirers bought into in one summer.
Roles that shrink
- Access request approvers for routine grants
- Help desk password reset staff
- Manual access review coordinators
- Directory administrators doing group changes by hand
Roles that appear
- Agent identity architect
- Agent sponsor and owner (a named human per agent)
- Delegation and authorization policy engineer
- Identity threat hunter for agent behaviour
- Non-human identity program lead
Skills to learn
- OAuth 2.1, token exchange and resource indicators
- Writing authorization policy as code
- Designing human approval points for agent actions
- Reading agent audit trails across multi-hop chains
- Passkey rollout and recovery design
- Threat modelling prompt injection against identity flows
What gets easier for the humans?
| Before | After |
|---|---|
| Users juggled passwords and SMS codes that attackers phished | Passkeys sign people in with nothing to phish or remember |
| An admin approved every routine access request by hand | Agents grant low-risk, time-boxed access against policy; admins handle exceptions |
| Managers rubber-stamped quarterly access review spreadsheets | Reviews arrive pre-sorted with unused access already proposed for removal |
| Agents ran on a user's full-scope token with no record of who approved what | Each agent holds its own scoped token and the log names both agent and human |
| Revoking a compromised integration meant hunting for keys in config files | One revoke in the IdP cuts an agent off everywhere it connects |
Decisions that stay human
- Approving access to production data, money movement and admin roles
- Deciding which agents may act on a customer's behalf, and with what limits
- Sponsoring an agent and answering for what it did
- Setting consent and privacy policy for customer identity data
- Responding to an identity breach and deciding what to tell customers
Where should agents not act alone?
Risks and failure modes, through a security and identity lens.
- 01
Agents running on borrowed, full-scope credentials
The most common pattern today is still an agent holding a user's whole OAuth token or a static API key. Every prompt injection then becomes a confused-deputy attack with that user's full access. Give each agent its own identity and tokens scoped to the task and the resource, with RFC 8707 audience binding so a token stolen from one tool cannot be replayed at another.
- 02
Delegation chains nobody can reconstruct
A human authorises an agent, which calls a sub-agent, which calls an API. If the log records only the human's user ID, incident response starts from a lie. Use token exchange so each hop carries who acted and on whose behalf, and keep audit records that name the human, agent, sub-agent, tool and scope.
- 03
Prompt injection turning identity into the attack path
An agent that reads email, tickets or web pages can be told by that content to request more access, approve a grant or exfiltrate a token. OWASP's Top 10 for Agentic Applications lists identity and privilege abuse as a core risk. Agents must not approve their own scope increases, and step-up to a human should be triggered by the action, not by the agent's judgement.
- 04
Orphaned and unreviewed agents
Agents get created by developers, business users and other agents, then outlive the project. Without a named sponsor and lifecycle rules they become the new stale service account. Require an owner at registration, expire agents that go unused, and move sponsorship when the owner leaves.
- 05
Consent that no longer means consent
A customer clicks allow once and an agent uses that grant thousands of times. Broad, standing consent fails privacy law and user trust alike. Prefer narrow, time-boxed grants and asynchronous approval for consequential actions such as payments or account changes.
- 06
Vendor consolidation changing your roadmap
Most well-known non-human identity startups were bought in 2025 and 2026. An acquired product's roadmap follows its parent's platform, and integrations with rival IdPs can lose priority. Write integration and data-export commitments into contracts before renewal.
Who is building agentic identity and access management?
Incumbents adding agents vs agent-native entrants. Capability lines are checked against each vendor's own site.
Incumbents
Okta for AI Agents discovers and registers known and unknown agents, standardises agent access and revokes it instantly; announced March 2026 with GA set for April 30, 2026.
Checked Oct 9, 2026Compare
Auth0 for AI Agents, GA since November 2025: user authentication for agents, Token Vault for third-party tokens, asynchronous human approval via CIBA, and fine-grained authorization for RAG. Auth for MCP was in early access at GA.
Checked Oct 9, 2026Compare
Generally available: agent identity blueprints, sponsors and owners, lifecycle workflows that prevent orphaned agents, and Conditional Access templates for autonomous and on-behalf-of agents.
Checked Oct 9, 2026Compare
Identity for AI, GA in March 2026: Agent IAM Core treats agents as their own identity type, Agent Gateway enforces and audits agent calls including MCP, and Agent Detection spots external agents.
Checked Oct 9, 2026Compare
Discovers, controls and governs agentic identities, and can grant an agent access only for the duration of a specific task.
Checked Oct 9, 2026Compare
Agentic IAM manages agent identities separately from users and apps, with credential issuance, rotation, revocation and action-level audit; Auth for MCP provides token-based authorization for MCP servers.
Checked Oct 9, 2026Compare
Agent-native
Enforces every agent access request through a verified identity and replaces long-lived credentials with short-lived, scoped credentials issued at runtime, with one policy engine and audit trail for agents and workloads.
Checked Oct 9, 2026Compare
Runtime authorization for AI agents: gives each agent its own identity, evaluates every credential request against Cedar policy, and issues short-lived scoped credentials; access is by request.
Checked Oct 9, 2026
Open source
Documents use as an authorization server for MCP servers; resource indicators and Client ID Metadata Documents are experimental features behind flags.
Checked Oct 9, 2026
Side-by-side comparisons: Top 10 Identity and Access Management (IAM) Solutions for 2026, Top 10 Customer Identity and Access Management (CIAM) Solutions for 2026, Top 10 Non-Human Identity (NHI) Security Tools of 2026.
Questions people ask
How is AI changing identity and access management?
In two ways. AI helps run IAM, through risk scoring, access review recommendations and identity threat detection. And AI agents have become identities themselves, needing their own credentials, scoped permissions, delegation from a human and audit trails. The second shift is the bigger one.
What is agent identity?
Agent identity means giving an AI agent its own account in your identity provider rather than letting it borrow a user's token or a static key. The agent gets short-lived tokens scoped to a task, a named human sponsor, and logs that record both the agent and the person it acted for.
How does MCP handle authorization?
The Model Context Protocol's authorization spec treats an MCP server as an OAuth 2.1 resource server. Clients discover the authorization server through protected resource metadata, use PKCE, and must send a resource indicator so tokens are bound to one MCP server. Authorization is optional for local STDIO servers.
Will AI agents replace IAM administrators?
They will replace much of the routine work: routine grants, resets, and first-pass access reviews. They will not replace the people who design policy, sponsor agents, approve high-risk access and answer to auditors. Expect smaller administration teams and larger identity architecture teams.
What is the difference between IAM and CIAM?
IAM manages employees and contractors: thousands of accounts, a central directory, compliance first. CIAM manages customers: millions of accounts, where signup conversion, scale and privacy consent matter most. They share protocols like OIDC and SAML but differ in almost every buying criterion.
Why did identity vendors buy AI agent security startups?
Agents run on non-human identities, and securing them became a hot category in 2024. In 2025 and 2026 Palo Alto Networks bought CyberArk, Okta bought Axiom and Permiso, Cisco bought Astrix, SailPoint bought Entro and Cyera bought Oasis, folding agent identity into existing platforms.
Are passkeys replacing passwords?
For people, yes, gradually. Apple, Google and Microsoft committed to passkeys in 2022, and major identity platforms support them. Enrollment still lags availability, so passwords remain as fallback. Agents never use passwords or passkeys; they need tokens.
Should an AI agent ever approve its own access?
No. An agent can request access and an automated policy can grant low-risk, time-boxed scopes, but an agent should never raise its own privileges or approve a grant. Consequential actions such as payments, production data and admin roles need a human approval point.
Sources
- Active Directory (Wikipedia), accessed Oct 9, 2026
- Security Assertion Markup Language (Wikipedia), accessed Oct 9, 2026
- Okta, Inc. (Wikipedia), accessed Oct 9, 2026
- RFC 6749: The OAuth 2.0 Authorization Framework, accessed Oct 9, 2026
- OpenID Connect Core 1.0, accessed Oct 9, 2026
- Okta Completes Acquisition of Auth0 (Business Wire), accessed Oct 9, 2026
- Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard, accessed Oct 9, 2026
- Microsoft Entra: Azure AD becomes Microsoft Entra ID, accessed Oct 9, 2026
- Model Context Protocol: Authorization (draft), accessed Oct 9, 2026
- RFC 8693: OAuth 2.0 Token Exchange, accessed Oct 9, 2026
- RFC 8707: Resource Indicators for OAuth 2.0, accessed Oct 9, 2026
- What's new in Microsoft Entra Agent ID, accessed Oct 9, 2026
- Auth0 for AI Agents is now generally available, accessed Oct 9, 2026
- Okta announces new blueprint for the secure agentic enterprise, accessed Oct 9, 2026
- Ping Identity Defines the Runtime Identity Standard for Autonomous AI, accessed Oct 9, 2026
- Palo Alto Networks Completes Acquisition of CyberArk to Secure the AI Era, accessed Oct 9, 2026
- Palo Alto Networks 10-K for fiscal year ended 31 July 2026, accessed Oct 9, 2026
- Okta with Axiom Security: privileged access for modern infrastructure in the AI era, accessed Oct 9, 2026
- Cisco announces intent to acquire Astrix Security, accessed Oct 9, 2026
- SailPoint closes Entro Security acquisition, accessed Oct 9, 2026
- Okta signs definitive agreement to acquire Permiso Security, accessed Oct 9, 2026
- Cyera completes acquisition of Oasis Security, accessed Oct 9, 2026
- Palo Alto Networks: when machine identities outnumber humans 109:1, accessed Oct 9, 2026
- OWASP Top 10 for Agentic Applications for 2026, accessed Oct 9, 2026
- Keycloak: Integrating with Model Context Protocol (MCP), accessed Oct 9, 2026
- Palo Alto Networks Idira, accessed Oct 9, 2026
- LoginRadius AI capabilities, accessed Oct 9, 2026
- Aembit, accessed Oct 9, 2026
- Keycard, accessed Oct 9, 2026
Published Oct 9, 2026. Last verified Oct 9, 2026. Eras 4 and 5, vendors, and scores are re-checked every six to eight weeks; see the changelog and methodology.
Keep reading
Essays and analysis
- The Future of CIAM: Why Legacy Identity Systems Are Dead (And What Replaces Them)
- AI Agents Don't Have Passwords. Your Auth Stack Assumes Everyone Does.
- Map Before You Buy: The 2026 Identity Market After the Consolidation Wave
- Every Identity Giant Just Bought an AI Agent Company. Here's What They Know That You Don't.
- Building Customer Identity at Scale: Lessons from 1 Billion Users
- The MCP Security Implementation Playbook: Enterprise Authorization Patterns That Actually Work