Structural insight on digital identity & access infrastructure.
Long-form notes on programmable controls, coverage instances, and the architectural choices for modernizing capabilities.
-
Identity and Access Substrate
Every identity and access control resolves against the link between a subject and the identity representing it, and almost no enterprise measures how strong that link is. This report defines the substrate vocabulary and grades binding confidence across every identity constituency.
42 min read -
Identity and Access Observability Controls
An enterprise that cannot establish what happened cannot know whether its other controls worked. This report judges identity and access observability by what it returns — evidence to governance, signal to runtime — not by what it ingests, and makes attribution confidence the unit of control.
50 min read -
Identity and Access Runtime Controls
Every runtime capability family establishes authority well and sustains it poorly. This report treats verification, authentication, risk, session, federation, and authorization as one loop, and names what they produce: effective trusted authority, kept accurate for the life of the access.
59 min read -
Identity and Access Governance Controls
Identity and access governance is the oldest, least-defined part of IAM, and enterprises keep buying the product category while believing they have acquired the control. This report separates the two: the admin-time control that decides who or what gets access, on whose authority, before runtime.
44 min read -
Navigating IAM Market Evolution
Identity and access is an infrastructure market where infrastructure and the market logic diverge, leaving a permanent integration burden. This leadership brief describes how to map the market's supply-and-demand onto the coverage surface the enterprise must own and use architecture for navigation.
20 min read -
AI Agent Identity and Access
AI agents are workload identities with added agentic attributes: their identity layer is converging while authorization is not, and the consequential incidents are access failures. This report frames agent risk by type and argues for runtime authorization as the key control to manage risk.
Members 30 min read -
Identity and Access Management
Identity and access management is now the enterprise control plane, yet most programs are organized around tools, not the reality they govern. This report introduces the Control and Coverage Matrix as an organizing frame and argues for modernizing controls into programmable, runtime-adaptive policy.
26 min read