Foundation Report
-
Identity and Access Substrate
Every identity and access control resolves against the link between a subject and the identity representing it, and almost no enterprise measures how strong that link is. This report defines the substrate vocabulary and grades binding confidence across every identity constituency.
42 min read -
Identity and Access Observability Controls
An enterprise that cannot establish what happened cannot know whether its other controls worked. This report judges identity and access observability by what it returns — evidence to governance, signal to runtime — not by what it ingests, and makes attribution confidence the unit of control.
50 min read -
Identity and Access Runtime Controls
Every runtime capability family establishes authority well and sustains it poorly. This report treats verification, authentication, risk, session, federation, and authorization as one loop, and names what they produce: effective trusted authority, kept accurate for the life of the access.
59 min read -
Identity and Access Governance Controls
Identity and access governance is the oldest, least-defined part of IAM, and enterprises keep buying the product category while believing they have acquired the control. This report separates the two: the admin-time control that decides who or what gets access, on whose authority, before runtime.
44 min read