Identity and Access
Workforce Identity and Access Management (IAM): from Active Directory to AI agents
Workforce IAM decides which employees, contractors and, now, AI agents can reach which company systems. It moved from Active Directory and SiteMinder to cloud SSO, SCIM and passkeys. The shift today is agents as workforce identities: registered with a human sponsor, given short-lived scoped tokens, reviewed and revoked like any employee.
Autonomy level
2.0 of 5 · Copilot
launch score
Projected 3.2 by 2031
- Tasks automated
- 2.0
- Approval load
- 1.5
- Production maturity
- 2.5
Overall is the mean of the three sub-scores. How scores work
Key numbers
109:1
Palo Alto Networks counts 109 machine identities per human in the enterprise in its 2026 Identity Security Landscape, up from 82 the year before (vendor-reported).
Palo Alto Networks: when machine identities outnumber humans 109:137%
In the same survey only 37% of organizations could revoke an AI agent's credentials, and 30% kept immutable audit logs of agent actions (vendor-reported).
Palo Alto Networks: when machine identities outnumber humans 109:122%
Credential abuse was the leading initial attack vector in Verizon's 2025 Data Breach Investigations Report at 22%, ahead of vulnerability exploitation at 20%, across 12,195 confirmed breaches.
Verizon 2025 Data Breach Investigations Report (news release)28%
In the FIDO Alliance's April 2026 survey of 1,400 enterprise decision-makers, 68% had deployed or were deploying passkeys for employee sign-in, but only 28% had reached fully passwordless workforce authentication.
FIDO Alliance: State of Passkeys 2026 on World Passkey DayNo MFA
Midnight Blizzard's 2024 intrusion at Microsoft began with a password spray against a legacy, non-production test account that did not have MFA enabled (vendor disclosure).
Microsoft: Midnight Blizzard, guidance for responders on nation-state attack134 customers
Okta's 2023 support system breach used a service account whose credentials were saved in an employee's personal Google profile; files for 134 customers were accessed and 5 customers' sessions hijacked (vendor disclosure).
Okta: root cause of unauthorized access to the support case management system20,000+
Okta made Agent SSO generally available on 24 August 2026 at no extra cost. Agent SSO ships inside Okta's core SSO, which Okta says more than 20,000 customers use (vendor-reported).
Okta brings first-class identity to AI agents with Agent SSO$1B
Cyera completed its $1 billion acquisition of non-human identity startup Oasis Security on 3 September 2026.
Cyera completes acquisition of Oasis Security
The same job, five eras
Drag across the eras to see who did the work, with what, and what broke.
What job does workforce identity and access management software do?
Workforce IAM answers three questions for everyone who works inside a company: who is this, what should they be able to reach, and when should that stop? The buyer is the CIO or CISO, the users are employees and contractors, and success is measured in audit findings, help desk tickets and breach reports, not signup conversion. That makes it a different market from customer identity, with different vendors and a different history.
The work runs on a lifecycle. A joiner gets accounts, a mover gets new access and should lose the old, a leaver loses everything on the last day. In between sit access requests, quarterly reviews for the auditor, and a constant stream of attacks on the one system that holds the keys to every other system.
The population is changing. Service accounts and API keys already outnumbered people, and AI agents are the newest members of the workforce directory. They act on an employee's behalf, inside the same apps, and they need the same lifecycle: a joiner date, an owner, scoped access, a review and a leaver date.
Era 1 · Before SaaS · 1993-2008
How did workforce identity and access management work before SaaS?
Identity lived in a directory in the server room. Novell shipped NDS with NetWare 4 in 1993, Microsoft released Active Directory with Windows 2000 Server, and Unix shops ran LDAP. The directory held users, groups and passwords, and group membership decided which file shares and apps a person could open.
Web applications needed something above the directory. Web access management products such as Netegrity SiteMinder and Oblix sat in front of intranet apps and gave employees one sign-on across them. The big vendors bought their way in: CA agreed to buy Netegrity for $430 million in 2004, and Oracle bought Oblix in 2005, the product line behind Oracle Access Manager.
Provisioning was a ticket. HR emailed IT, IT created accounts by hand in each system, and nobody reliably removed them. Identity suites promised automated joiner, mover and leaver flows, but each connector was a custom integration project, and most companies automated only the directory.
Era 2 · The Cloud Move · 2009-2019
What changed when workforce identity and access management moved to the cloud?
The apps left the building, so identity followed them. Okta was founded in 2009 to put single sign-on and user lifecycle in the browser, and employees went from a dozen SaaS passwords to one portal. Microsoft answered with Azure Active Directory, OneLogin and Ping competed for the same buyers, and JumpCloud sold a cloud directory to companies that never bought AD at all.
Provisioning finally got a standard. SCIM 2.0 was published as RFC 7644 in September 2015, so a change in the HR system could create, update and disable accounts across SaaS apps without a ticket. SAML stayed the workhorse for enterprise SSO, and OAuth carried API access between apps.
The weak spot moved to the second factor and to everything that was not a person. SMS codes and push approvals spread fast and were phished, SIM-swapped and fatigued just as fast. Service accounts, API keys and OAuth grants between apps sat outside the identity program entirely, with no owner and no review.
Era 3 · The Copilot Years · 2020-2024
What did AI copilots change in workforce identity and access management?
Machine learning entered workforce identity as a risk score. Conditional Access and adaptive MFA looked at device, location and behaviour, and challenged a sign-in only when something looked off. Governance tools began recommending which access to revoke instead of listing every line for a manager to rubber-stamp, the shift I describe in what identity governance and administration actually is.
Attackers went straight for the identity layer. Lapsus$ reached Okta through a support contractor's workstation in January 2022, a case I break down in how Lapsus$ breached Okta. Gartner named identity threat detection and response (ITDR) one of its top security trends for 2022, and products started watching the IdP itself for token theft, MFA bypass and rogue admin changes.
The help desk became the soft target. In August 2023 Okta warned that attackers were phoning IT service desks to reset MFA for super administrators. In January 2024 Microsoft disclosed that Midnight Blizzard got in through a password spray on a legacy test account with no MFA, then abused an old OAuth app. Passkeys gave a real answer to phishing after Apple, Google and Microsoft committed to them in May 2022, and Microsoft renamed Azure AD to Entra ID in 2023. Copilots appeared in admin consoles, but a person still made every access decision.
- Lapsus$ controls an Okta support contractor's workstation for 25 minutessource
- Gartner names ITDR a top security trendsource
- Apple, Google and Microsoft commit to passkeyssource
- Azure AD renamed Microsoft Entra IDsource
- Okta warns of help desk social engineering aimed at super adminssource
- Microsoft discloses Midnight Blizzard entry via a legacy test account without MFAsource
Era 4 · The Agentic Shift · 2025-2026
The Agentic Shift: What do AI agents do in workforce identity and access management today?
The newest member of the workforce directory is an AI agent. It reads mail, files tickets and calls internal APIs for an employee, and the first generation did it on borrowed credentials: the employee's full OAuth grant or a static key in a config file. I wrote about that gap in AI agents don't have passwords. Joiner, mover, leaver, review and audit all assumed a person.
The big IdPs now treat agents as identities. Microsoft announced Entra Agent ID in May 2025, and it is now generally available with agent blueprints, named sponsors, lifecycle workflows that hand sponsorship on when a person leaves, and Conditional Access templates for agents. Okta for AI Agents went GA in April 2026, and Ping made Identity for AI generally available on 31 March 2026.
Internal tools got an enterprise authorization model. Okta introduced Cross App Access in June 2025 so the IdP, not each employee, decides which app or agent may connect to which other app. It is now the Enterprise-Managed Authorization extension for MCP, built on the ID-JAG draft at the IETF, and Okta made Agent SSO generally available in August 2026. Governance vendors such as SailPoint and ConductorOne added agents to access reviews and use AI to run requests and certifications.
The buyers consolidated the market. Palo Alto Networks closed its CyberArk deal in February 2026, Cisco bought Astrix and Cyera bought Oasis, the pattern I cover in why the identity giants bought AI agent security. Agents can be registered, scoped and revoked today, but deciding what an agent should hold is still mostly a human call.
- MCP specification adds OAuth 2.1 based authorizationsource
- Microsoft announces Entra Agent ID at Buildsource
- Okta introduces Cross App Access for agent-to-app connectionssource
- Palo Alto Networks completes CyberArk acquisitionsource
- Ping Identity makes Identity for AI generally availablesource
- Okta for AI Agents reaches general availabilitysource
- Cross App Access becomes MCP's Enterprise-Managed Authorization extensionsource
- Okta makes Agent SSO generally available in core SSOsource
Era 5 · The Next Five Years · 2026-2031
What will workforce identity and access management look like by 2031?
My bet is that by 2031 the workforce directory is mostly software. Palo Alto Networks already counts 109 machine identities per human in its 2026 survey (vendor-reported), and agents are the fastest-growing slice. I expect an agent without its own registered identity and a named human sponsor to read as an audit finding, the way a shared admin password does today.
Standing access goes away. I expect agents and people alike to request just-in-time access for a task, receive a short-lived token scoped to one resource, and lose it when the task ends. My bet is that standing API keys go the way of standing admin rights.
I expect agents to draft access requests, prepare reviews, and revoke unused entitlements on their own, with people approving only consequential grants: production data, money movement and admin roles. Human-only quarterly reviews cannot keep pace with a directory that changes every minute.
What has to be true: delegation across agent hops must standardise (the IETF identity chaining and ID-JAG drafts are the leading candidates), registries from Microsoft, Okta and others must interoperate, and auditors must accept continuous, agent-prepared evidence in place of the quarterly spreadsheet.
My prediction · by 2031 · medium confidence
By 2031, most large enterprises will register AI agents in their workforce IdP with a named human sponsor and give them only just-in-time, task-scoped access, and standing credentials for agents will be treated as an audit finding.
What has to be true
- Delegation across agent hops is standardised and supported by the major IdPs
- Agent registries from Microsoft, Okta, Ping and others interoperate instead of locking agents to one vendor
- Auditors accept continuous, agent-prepared access evidence in place of quarterly campaigns
- Prompt injection is contained well enough that scoped agents can act on low-risk work without per-action approval
Projected autonomy 3.2 of 5
Then vs now: who does each step?
The job broken into its steps, and who or what does each one in each era.
| Job step | On-prem | SaaS and cloud | AI-assisted | Agentic | Next 5 years |
|---|---|---|---|---|---|
| Onboard a joiner | HR emails IT; an admin creates accounts in each system by hand | HR system triggers SCIM provisioning into SaaS apps | Birthright roles suggested from peer groups | Agents are registered as their own identities with an owner and sponsor | Expected: agents and people get task-scoped access on day one, nothing standing |
| Prove who is signing in | A directory password | SSO plus SMS or push MFA | Risk-based Conditional Access; passkeys arrive | Employees use passkeys; agents get short-lived tokens from the IdP | Expected: passwordless by default for people; workload attestation for agents |
| Handle an access request | A ticket, a manager email and an admin adding a group | Self-service request with manager approval in the IGA tool | Recommendations flag unusual requests for the approver | AI routes and pre-approves low-risk requests; the IdP decides which agent may reach which app | Expected: agents request just-in-time scopes; humans approve only high-risk grants |
| Review access for the auditor | Annual spreadsheet exported from each system | Quarterly certification campaigns | AI recommends keep or revoke for each line | Agents appear in review campaigns; sponsors certify them | Expected: continuous review prepared by agents; humans audit samples and exceptions |
| Offboard a leaver | Disable the AD account when someone remembers | HR termination disables accounts through SCIM | Session revocation and orphaned-account reports | Sponsorship of the leaver's agents moves to a new owner automatically | Expected: every credential dies with the task or the person, with no cleanup step |
| Detect identity attacks | Failed-login logs read after an incident | SIEM rules on IdP logs | ITDR watches for token theft, MFA bypass and admin changes | Risk-based policies and kill switches for agents | Expected: automated containment that revokes a misbehaving agent in seconds |
How does the workforce identity and access management team change?
Workforce identity teams were built around administering people: tickets to grant access, campaigns to review it, help desk calls to reset it. SCIM and passkeys already shrank that work. Agents shrink it further, because routine grants, first-pass reviews and resets are exactly the steps software handles well.
The work that grows is design and accountability. Someone has to decide what each agent may do, who sponsors it, how delegation is recorded and when a human must approve. Access reviews exist largely because auditors ask for them, and having built the SOC 2, PCI and ISO programs at Sageworks, I expect the audit side to change slowest. The vendor side is moving fast: the 2026 identity market map now has a non-human identity branch that the largest platforms bought into.
Roles that shrink
- Access request approvers for routine grants
- Help desk password and MFA reset staff
- Manual access review coordinators
- Directory administrators doing group changes by hand
Roles that appear
- Agent identity architect
- Agent sponsor (a named human per agent)
- Authorization policy engineer
- Identity threat detection engineer
- Non-human identity program lead
Skills to learn
- OAuth 2.1, token exchange and resource indicators
- Writing access policy as code
- Designing human approval points for agent actions
- Reading delegation chains in audit logs
- Passkey rollout and account recovery design
What gets easier for the humans?
| Before | After |
|---|---|
| Employees juggled passwords and SMS codes that attackers phished | Passkeys sign people in with nothing to phish or remember |
| New hires waited days for accounts while tickets moved between teams | HR-driven provisioning and agent-routed requests give access on day one |
| Managers rubber-stamped quarterly review spreadsheets | Reviews arrive pre-sorted, with unused access already proposed for removal |
| An agent ran on an employee's full token, with no record of who approved what | Each agent holds its own scoped token and the log names both agent and sponsor |
| When someone left, their scripts and integrations kept running on their access | Sponsorship transfers automatically and orphaned agents are flagged |
Decisions that stay human
- Approving access to production data, money movement and admin roles
- Sponsoring an agent and answering for what it did
- Deciding which tasks an agent may do without a person in the loop
- Verifying identity before a help desk MFA reset for a privileged user
- Signing the access attestation an auditor relies on
Where should agents not act alone?
Risks and failure modes, through a security and identity lens.
- 01
Agents running on an employee's borrowed credentials
The common pattern is still an agent holding an employee's whole OAuth grant or a static API key. A prompt injection then acts with that employee's full access. Give each agent its own identity in the IdP, tokens scoped to one task and one resource, and a named sponsor.
- 02
The help desk as the way in
In August 2023 Okta reported attackers calling IT service desks to reset MFA for super administrators, then using those accounts to weaken policies and add an impersonation identity provider. An AI help desk agent that can reset factors widens that hole. Keep privileged resets behind strong identity verification by a person.
- 03
Forgotten accounts and apps with old privileges
Midnight Blizzard got into Microsoft in 2024 through a password spray on a legacy test account without MFA, then used an old OAuth app with elevated access to reach corporate mailboxes. Agents created for a pilot and never retired are the same problem at higher volume. Expire unused identities and review app grants, not only users.
- 04
Service account credentials outside the program
Okta's 2023 support breach most likely started with a service account whose password was saved in an employee's personal Google profile; files for 134 customers were accessed. Agent credentials stored the same way are exposed the same way. Keep them in a vault, short-lived, and tied to an owner.
- 05
Delegation chains nobody can reconstruct
An employee authorises an agent, which calls a sub-agent, which calls an internal API. If the log records only the employee's ID, incident response starts from a lie. Use token exchange so each hop records who acted and on whose behalf.
- 06
Vendor consolidation changing your roadmap
CyberArk now sits inside Palo Alto Networks, and non-human identity startups Astrix and Oasis inside Cisco and Cyera. An acquired product follows its parent's roadmap, and support for rival IdPs can lose priority. Put integration and data-export commitments in the contract.
How should you evaluate an agentic workforce identity and access management vendor?
Questions to put to any vendor before you let its agents act.
- Does each agent get its own identity in your directory with a named human sponsor, or can it run on an employee's token or a shared key? Show me where that is enforced.
- When a sponsor leaves or changes roles, what happens to their agents, automatically and on what timeline?
- Which access can an agent or the AI request flow grant without a human, which grants trigger approval, and who sets that line: your default or my policy?
- Do agents appear in my access review campaigns alongside people, and can a reviewer see what each agent actually used?
- When an agent calls another agent or an internal MCP server, does the audit record name the employee, the agent, the tool and the scope, and can I export it to my SIEM?
- How fast can I revoke one agent everywhere it connects, and what happens to work in flight?
- Which of these agent features are generally available today, and which are announced or in early access?
Who is building agentic workforce identity and access management?
Incumbents adding agents vs agent-native entrants. Capability lines are checked against each vendor's own site.
Incumbents
Entra Agent ID is generally available: agent identity blueprints, owners and sponsors, access packages for agents, sponsor lifecycle workflows that prevent orphaned agents, and Conditional Access templates for autonomous and on-behalf-of agents.
Checked Oct 10, 2026Compare
Okta for AI Agents (GA April 2026) registers agents in Universal Directory with a human owner and issues short-lived tokens; Agent SSO (GA August 2026) brings Cross App Access into core SSO; Agent Gateway, which enforces policy at every tool call, became generally available on 8 October 2026.
Checked Oct 10, 2026Compare
Identity for AI, generally available since 31 March 2026: Agent IAM Core treats agents as their own identity type, Agent Gateway enforces and audits agent calls, and Agent Detection spots agents through PingOne Protect.
Checked Oct 10, 2026Compare
Agent Identity Security, now SailPoint Agentic Fabric, onboards AI agents as identities from AWS, Azure, GCP and Salesforce, assigns one or more human owners, and lets teams regularly review agents' access and revoke excessive permissions; the page publishes no availability status.
Checked Oct 10, 2026Compare
Idira Secure AI Agents discovers active agents with owner and permission context, can grant an agent access only for the duration of a task, and provides auditability of agent actions; the page gives no availability date.
Checked Oct 10, 2026Compare
Uses AI to manage lifecycle, access requests, reviews and compliance for people, non-human identities and agents, and gives agents policy-controlled access to models, tools and credentials at runtime.
Checked Oct 10, 2026Compare
Agent-native
Verifies each agent's identity, replaces long-lived secrets with short-lived scoped credentials issued at runtime, governs agent access to MCP servers, logs every action against one identity and can cut an agent off without disrupting the employee behind it.
Checked Oct 10, 2026Compare
Runtime authorization for AI agents: gives each agent its own identity, carries the user's identity when it acts on their behalf, checks each request against Cedar policy and issues short-lived task-scoped tokens that can be revoked.
Checked Oct 10, 2026
Open source
Documents full support for MCP specification 2025-03-26 as an authorization server; later versions including 2026-07-28 are experimental, as are resource indicators and Client ID Metadata Documents.
Checked Oct 10, 2026
Side-by-side comparisons: Top 10 Identity and Access Management (IAM) Solutions for 2026, Top 10 User Provisioning and Governance Tools for 2026, Top 10 PAM Solutions for 2026 (Privileged Access Management Compared), Top 10 Non-Human Identity (NHI) Security Tools of 2026.
Questions people ask
What is workforce identity and access management?
Workforce IAM controls which employees, contractors and now AI agents can reach company systems. It covers the directory, single sign-on, MFA, provisioning through joiner, mover and leaver changes, access requests, access reviews for auditors, and detection of attacks on the identity layer itself.
How is AI changing workforce IAM?
In two ways. AI helps run IAM through risk-based sign-in, review recommendations and identity threat detection. And AI agents have joined the workforce as identities, needing their own registration, a human sponsor, scoped tokens and reviews. The second change is bigger.
What is the difference between workforce IAM and CIAM?
Workforce IAM serves employees and contractors: thousands of accounts, a central directory, audit and security first. Customer IAM serves people who sign up for your product: millions of accounts, where conversion, scale and consent matter most. They share protocols but differ in buyers, vendors and success metrics.
What is Microsoft Entra Agent ID?
Entra Agent ID gives AI agents their own identities in Microsoft Entra. It is generally available, with agent identity blueprints, owners and sponsors, access packages for agents, lifecycle workflows that reassign sponsorship when a person leaves, and Conditional Access policies built for agents.
What is Okta Cross App Access?
Cross App Access is an OAuth extension Okta introduced in June 2025 that lets the company's identity provider, rather than each employee, decide which app or agent may connect to which other app. It is now MCP's Enterprise-Managed Authorization extension, built on the IETF ID-JAG draft.
Will AI agents replace IAM administrators?
I expect them to take much of the routine work: low-risk grants, resets, and first-pass access reviews. I do not expect them to replace the people who design policy, sponsor agents, approve high-risk access and answer to auditors. Expect smaller administration teams and larger identity architecture teams.
What is ITDR?
Identity threat detection and response is the practice and tooling for protecting identity systems themselves: spotting token theft, MFA bypass, rogue admin changes and attacks on the directory, then containing them. Gartner named it one of its top security trends for 2022.
Should AI agents be included in access reviews?
Yes. An agent with access to company data is an identity like any other, and it outlives projects just as service accounts do. Give it a named sponsor, include it in review campaigns, and expire it when it goes unused. SailPoint, Microsoft and others now support this.
How many machine identities are there per employee?
Palo Alto Networks reports 109 machine identities per human in the enterprise in its 2026 Identity Security Landscape, up from 82 the year before (vendor-reported). AI agents are the newest and fastest-growing part of that count.
Sources
- NetIQ eDirectory (Wikipedia), accessed Oct 10, 2026
- Active Directory (Wikipedia), accessed Oct 10, 2026
- CA to Acquire Netegrity for $430 Million (eWeek), accessed Oct 10, 2026
- Oracle snaps up security firm (The Register), accessed Oct 10, 2026
- Security Assertion Markup Language (Wikipedia), accessed Oct 10, 2026
- Okta, Inc. (Wikipedia), accessed Oct 10, 2026
- RFC 7644: System for Cross-domain Identity Management: Protocol, accessed Oct 10, 2026
- Okta Concludes its Investigation Into the January 2022 Compromise, accessed Oct 10, 2026
- Gartner identifies top security and risk management trends (Security MEA, 15 March 2022), accessed Oct 10, 2026
- Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard, accessed Oct 10, 2026
- Microsoft Entra expands into Security Service Edge and Azure AD becomes Microsoft Entra ID, accessed Oct 10, 2026
- Okta: Cross-Tenant Impersonation: Prevention and Detection, accessed Oct 10, 2026
- Microsoft: Midnight Blizzard, guidance for responders on nation-state attack, accessed Oct 10, 2026
- Okta: root cause of unauthorized access to the support case management system, accessed Oct 10, 2026
- Model Context Protocol: Authorization (2025-03-26), accessed Oct 10, 2026
- Model Context Protocol: Authorization (2026-07-28), accessed Oct 10, 2026
- Model Context Protocol: Enterprise-Managed Authorization extension, accessed Oct 10, 2026
- Microsoft extends Zero Trust to secure the agentic workforce, accessed Oct 10, 2026
- What's new in Microsoft Entra Agent ID, accessed Oct 10, 2026
- Okta introduces Cross App Access to help secure AI agents in the enterprise, accessed Oct 10, 2026
- Okta advances the industry standard for secure AI agent connections with expanding Cross App Access ecosystem, accessed Oct 10, 2026
- Okta brings first-class identity to AI agents with Agent SSO, accessed Oct 10, 2026
- New Okta for AI Agents innovations (Oktane 2026), accessed Oct 10, 2026
- Okta: the agent IdP identity stack (Okta for AI Agents is now generally available), accessed Oct 10, 2026
- Okta for AI Agents (product page), accessed Oct 10, 2026
- Ping Identity Defines the Runtime Identity Standard for Autonomous AI, accessed Oct 10, 2026
- Palo Alto Networks Completes Acquisition of CyberArk to Secure the AI Era, accessed Oct 10, 2026
- Palo Alto Networks Idira, accessed Oct 10, 2026
- SailPoint Agent Identity Security, accessed Oct 10, 2026
- C1 (ConductorOne), accessed Oct 10, 2026
- Aembit, accessed Oct 10, 2026
- Keycard, accessed Oct 10, 2026
- Keycloak: Integrating with Model Context Protocol (MCP), accessed Oct 10, 2026
- Cisco announces intent to acquire Astrix Security (updated 29 June 2026: acquisition completed), accessed Oct 10, 2026
- Cyera completes acquisition of Oasis Security, accessed Oct 10, 2026
- Palo Alto Networks: when machine identities outnumber humans 109:1, accessed Oct 10, 2026
- Verizon 2025 Data Breach Investigations Report (news release), accessed Oct 10, 2026
- FIDO Alliance: State of Passkeys 2026 on World Passkey Day, accessed Oct 10, 2026
- IETF datatracker: draft-ietf-oauth-identity-assertion-authz-grant, accessed Oct 10, 2026
- IETF datatracker: draft-ietf-oauth-identity-chaining, accessed Oct 10, 2026
- Okta for AI Agents is Now Generally Available, accessed Oct 10, 2026
- Securing AI agents at runtime: Okta's Agent Gateway explained (Agent Gateway generally available), accessed Oct 10, 2026
- Ping Identity for AI: What's new (release notes), accessed Oct 10, 2026
Published Oct 9, 2026. Last verified Oct 10, 2026. Eras 4 and 5, vendors, and scores are re-checked every six to eight weeks; see the changelog and methodology.
Keep reading
Essays and analysis
- AI Agents Don't Have Passwords. Your Auth Stack Assumes Everyone Does.
- Map Before You Buy: The 2026 Identity Market After the Consolidation Wave
- Every Identity Giant Just Bought an AI Agent Company. Here's What They Know That You Don't.
- What is Identity Governance & Administration?
- How Lapsus$ Breached Okta and What Organizations Should Learn