{"slug":"mcp-i-becomes-kya-os-agent-identity-spec-moves-under-neutral-governance","citations":[{"url":"https://articles.idenhq.com/ai-agent-identity-management-2026","committed_hash":"sha256:58ac4b83adda607543a30574244044143450b9aa2aafcbf61cc71de9e8b4fccf","committed_hash_short":"sha256:58ac4b83…e8b4fccf","mime_type":"text/html","committed_at":"2026-07-26T11:00:18.146835+00:00","content_snapshot":"<!DOCTYPE html><html data-dpl-id=\"dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" lang=\"en\" class=\"inter_c15e96cb-module__0bjUvq__variable antialiased\"><head><meta charSet=\"utf-8\"/><meta name=\"viewport\" content=\"width=device-width, initial-scale=1\"/><link rel=\"stylesheet\" href=\"/_next/static/chunks/08_loej5.wuit.css?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" data-precedence=\"next\"/><link rel=\"stylesheet\" href=\"/_next/static/chunks/0-jf1u_rglope.css?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" data-precedence=\"next\"/><link rel=\"stylesheet\" href=\"/_next/static/chunks/0_kwzt0c~eysn.css?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" data-precedence=\"next\"/><link rel=\"preload\" as=\"script\" fetchPriority=\"low\" href=\"/_next/static/chunks/0oqqtf7q0fh8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\"/><script src=\"/_next/static/chunks/0waofks11mx~c.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" async=\"\"></script><script src=\"/_next/static/chunks/08elxagggt6cr.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" async=\"\"></script><script src=\"/_next/static/chunks/0gcjxa764g9a3.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" async=\"\"></script><script src=\"/_next/static/chunks/0ekb0u26wv.qk.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" async=\"\"></script><script src=\"/_next/static/chunks/turbopack-03zht_1ghj934.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" async=\"\"></script><script src=\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" async=\"\"></script><script src=\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" async=\"\"></script><script src=\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" async=\"\"></script><script src=\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" async=\"\"></script><script src=\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" async=\"\"></script><script src=\"/_next/static/chunks/15ozypjscxub5.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" async=\"\"></script><script src=\"/_next/static/chunks/08xg.0ckpl~2z.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" async=\"\"></script><meta name=\"next-size-adjust\" content=\"\"/><title>AI Agent Identity Management 2026: Standards &amp; Gaps | Iden Blog</title><meta name=\"description\" content=\"MCP OAuth 2.1, MCP-I at the DIF, Microsoft Entra Agent ID - the 2026 standards for AI agent identity are taking shape. Here&#x27;s what&#x27;s real, what&#x27;s missing, and how to evaluate governance today.\"/><meta name=\"application-name\" content=\"Iden\"/><link rel=\"author\" href=\"https://www.idenhq.com\"/><meta name=\"author\" content=\"Iden\"/><link rel=\"manifest\" href=\"/manifest.webmanifest\"/><meta name=\"creator\" content=\"Iden\"/><meta name=\"publisher\" content=\"Iden\"/><meta name=\"robots\" content=\"index, follow\"/><meta name=\"googlebot\" content=\"index, follow, max-video-preview:-1, max-image-preview:large, max-snippet:-1\"/><meta name=\"category\" content=\"technology\"/><link rel=\"canonical\" href=\"https://www.idenhq.com/en/blog/ai-agent-identity-management-2026\"/><link rel=\"alternate\" hrefLang=\"de\" href=\"https://www.idenhq.com/de/blog/ki-agenten-identity-management-2026\"/><link rel=\"alternate\" hrefLang=\"en\" href=\"https://www.idenhq.com/en/blog/ai-agent-identity-management-2026\"/><link rel=\"alternate\" hrefLang=\"x-default\" href=\"https://www.idenhq.com/en/blog/ai-agent-identity-management-2026\"/><meta property=\"og:title\" content=\"AI Agent Identity Management 2026: Standards &amp; Gaps\"/><meta property=\"og:description\" content=\"MCP OAuth 2.1, MCP-I at the DIF, Microsoft Entra Agent ID - the 2026 standards for AI agent identity are taking shape. Here&#x27;s what&#x27;s real, what&#x27;s missing, and how to evaluate governance today.\"/><meta property=\"og:locale\" content=\"en_US\"/><meta property=\"og:image\" content=\"https://aqynbjfkcfnrqkhzbzxl.supabase.co/storage/v1/object/public/cms-assets/5ed37a7f-297e-48c5-b007-40268093b3fa/74941670-e8c6-433e-8121-3ac624af2e95.jpg\"/><meta property=\"og:type\" content=\"article\"/><meta property=\"article:published_time\" content=\"2026-07-15T07:00:17.688+00:00\"/><meta name=\"twitter:card\" content=\"summary_large_image\"/><meta name=\"twitter:title\" content=\"AI Agent Identity Management 2026: Standards &amp; Gaps\"/><meta name=\"twitter:description\" content=\"MCP OAuth 2.1, MCP-I at the DIF, Microsoft Entra Agent ID - the 2026 standards for AI agent identity are taking shape. Here&#x27;s what&#x27;s real, what&#x27;s missing, and how to evaluate governance today.\"/><meta name=\"twitter:image\" content=\"https://aqynbjfkcfnrqkhzbzxl.supabase.co/storage/v1/object/public/cms-assets/5ed37a7f-297e-48c5-b007-40268093b3fa/74941670-e8c6-433e-8121-3ac624af2e95.jpg\"/><link rel=\"icon\" href=\"/favicon.ico?favicon.0i-q8a6zz7zw~.ico\" sizes=\"48x48\" type=\"image/x-icon\"/><link rel=\"apple-touch-icon\" href=\"/apple-icon.png?apple-icon.0v4oxdav-.ztw.png\" sizes=\"180x180\" type=\"image/png\"/><script src=\"/_next/static/chunks/03~yq9q893hmn.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" noModule=\"\"></script></head><body class=\"overscroll-y-none\"><div hidden=\"\"><!--$--><!--/$--></div><script type=\"application/ld+json\">[{\"@context\":\"https://schema.org\",\"@type\":\"Organization\",\"name\":\"Iden\",\"url\":\"https://www.idenhq.com\",\"logo\":\"https://www.idenhq.com/logo/iden-wordmark.svg\",\"description\":\"Iden is the complete identity governance (IGA) platform, purpose-built for growing companies of 50 to 2,000 employees. It automates the full user lifecycle from onboarding to offboarding, fine-grained access provisioning, and access reviews across every app your business runs on (SaaS, internal tools, and legacy systems), including the ones without SCIM or an API. It runs alongside your SSO and deploys in days, not months.\",\"sameAs\":[\"https://www.wikidata.org/wiki/Q140158373\",\"https://www.linkedin.com/company/idenhq\",\"https://github.com/IdenWorks\",\"https://twitter.com/idenhq\"],\"foundingDate\":\"2024-04\",\"founder\":[{\"@type\":\"Person\",\"name\":\"Pranay Yadav\",\"jobTitle\":\"CEO\",\"sameAs\":[\"https://www.wikidata.org/wiki/Q140158371\"]},{\"@type\":\"Person\",\"name\":\"Anchit Navelkar\",\"jobTitle\":\"CTO\",\"sameAs\":[\"https://www.wikidata.org/wiki/Q140158372\"]}],\"contactPoint\":[{\"@type\":\"ContactPoint\",\"contactType\":\"sales\",\"email\":\"hello@idenhq.com\",\"availableLanguage\":[\"en\",\"de\"]}]},{\"@context\":\"https://schema.org\",\"@type\":\"SoftwareApplication\",\"name\":\"Iden\",\"applicationCategory\":\"BusinessApplication\",\"applicationSubCategory\":\"Identity Governance and Administration (IGA)\",\"operatingSystem\":\"Web\",\"url\":\"https://www.idenhq.com\",\"description\":\"Iden is the complete identity governance (IGA) platform, purpose-built for growing companies of 50 to 2,000 employees. It automates the full user lifecycle from onboarding to offboarding, fine-grained access provisioning, and access reviews across every app your business runs on (SaaS, internal tools, and legacy systems), including the ones without SCIM or an API. It runs alongside your SSO and deploys in days, not months.\",\"offers\":{\"@type\":\"Offer\",\"price\":\"7.50\",\"priceCurrency\":\"USD\",\"priceSpecification\":{\"@type\":\"UnitPriceSpecification\",\"price\":\"7.50\",\"priceCurrency\":\"USD\",\"unitText\":\"user/month\"}},\"featureList\":[\"User lifecycle management (Joiner-Mover-Leaver) for employees and contractors\",\"Fine-grained access provisioning across SCIM and non-SCIM apps\",\"Clean, compliant offboarding with data backups and audit trail\",\"Access tickets automation\",\"JIT, time-bound access\",\"Automated user access reviews and access certifications for SOC 2, ISO 27001, GDPR, DPDP, CCPA, CMMC, and other frameworks\",\"Least privilege at scale\",\"Identity security posture management\",\"Human, non-human, and AI agentic identities in one platform\",\"AI agent identity governance\",\"Shadow IT and SaaS discovery\",\"SaaS management and cost optimization\",\"200+ non-SCIM app connectors\",\"Custom app connectors in 48 hours\"],\"publisher\":{\"@type\":\"Organization\",\"name\":\"Iden\",\"url\":\"https://www.idenhq.com\"}},{\"@context\":\"https://schema.org\",\"@type\":\"WebSite\",\"name\":\"Iden\",\"url\":\"https://www.idenhq.com\",\"inLanguage\":[\"en\",\"de\"],\"publisher\":{\"@type\":\"Organization\",\"name\":\"Iden\",\"url\":\"https://www.idenhq.com\"}}]</script><!--$--><!--/$--><div class=\"blog-root min-h-dvh\"><div class=\"max-w-[620px] px-6 sm:px-0 mx-auto pt-3 pb-3 w-full relative\"><div class=\"flex items-center justify-between\"><a aria-label=\"Iden\" class=\"flex items-center\" href=\"/\"><svg viewBox=\"0 0 101 30\" fill=\"none\" xmlns=\"http://www.w3.org/2000/svg\" class=\"h-4 w-auto block shrink-0\" style=\"fill:#a3a3a3\"><path fill-rule=\"evenodd\" clip-rule=\"evenodd\" d=\"M0.555176 29.1416H25.1243V18.9512H18.6608C18.0696 18.9512 17.5903 18.4719 17.5903 17.8807V15.8334C17.5903 15.2422 18.0696 14.763 18.6608 14.763H25.1243V0.927339H21.6923V4.5707H14.8833V0.927339H10.7962V4.5707H3.98717L3.98717 0.927339H0.555176L0.555176 14.763H7.01869C7.60988 14.763 8.08913 15.2422 8.08913 15.8334V17.8807C8.08913 18.4719 7.60988 18.9512 7.01869 18.9512H0.555176L0.555176 29.1416ZM3.98717 8.00269H21.6923V10.6758H19.3159C16.4674 10.6758 14.1583 12.9849 14.1583 15.8334V17.8807C14.1583 20.7292 16.4674 23.0383 19.3159 23.0383H21.6923V25.7096H3.98717L3.98717 23.0383H6.36355C9.212 23.0383 11.5211 20.7292 11.5211 17.8807V15.8334C11.5211 12.9849 9.212 10.6758 6.36355 10.6758H3.98717L3.98717 8.00269Z\"></path><path d=\"M33.0527 0.880305L36.984 0.880305V5.20874H33.0527V0.880305ZM33.0527 8.82239H36.984V29.0747H33.0527V8.82239ZM47.8585 29.5512C42.6564 29.5512 39.281 25.1434 39.281 18.9883C39.281 12.8729 42.6564 8.42529 47.8585 8.42529C50.8368 8.42529 53.0209 9.81515 54.2519 12.0786V0.880305H58.2229V29.0747H54.2519V25.8979C53.0209 28.1614 50.8368 29.5512 47.8585 29.5512ZM48.9307 26.4538C52.4252 26.4538 54.371 23.3564 54.371 18.9883C54.371 14.6201 52.4252 11.5227 48.9307 11.5227C45.4759 11.5227 43.4904 14.6201 43.4904 18.9883C43.4904 23.3564 45.4759 26.4538 48.9307 26.4538ZM60.4647 18.9485C60.4647 12.9126 64.396 8.42529 70.432 8.42529C76.7063 8.42529 80.4787 13.4288 80.2008 19.7825H64.5946C64.7534 23.8726 66.8978 26.5332 70.5909 26.5332C73.45 26.5332 75.0384 24.786 75.7929 22.6416H79.8037C78.6918 26.6524 75.4752 29.5512 70.5511 29.5512C64.4754 29.5512 60.4647 25.064 60.4647 18.9485ZM76.1106 17.0424C75.5547 13.6671 73.6088 11.4433 70.432 11.4433C67.2155 11.4433 65.2697 13.6274 64.7137 17.0424H76.1106ZM82.4131 8.82239H86.3047V12.1978C87.3769 10.252 89.3624 8.42529 92.9363 8.42529C97.3045 8.42529 99.6077 11.0065 99.6077 15.0569V29.0747H95.6764V15.8114C95.6764 13.1905 94.485 11.6021 91.4273 11.6021C88.5682 11.6021 86.3444 13.8259 86.3444 17.3998V29.0747H82.4131V8.82239Z\"></path></svg></a><div class=\"flex items-center gap-2 sm:gap-3\"><a href=\"https://cal.com/team/iden/demo\" class=\"sm:hidden inline-flex items-center gap-1.5 rounded-lg px-2 py-1 text-sm text-white font-medium transition-all hover:opacity-90 hover:scale-[1.03] active:scale-[0.98]\" style=\"background:linear-gradient(to top, #3b5bdb 0%, #4c6ef5 100%);border:1px solid #3b5bdb\">Book demo</a><button type=\"button\" aria-label=\"Open menu\" aria-expanded=\"false\" class=\"sm:hidden inline-flex items-center justify-center rounded-lg p-1.5 transition-colors text-neutral-400 hover:bg-neutral-800\"><svg viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"h-5 w-5\" aria-hidden=\"true\"><path d=\"M3.75 6.75h16.5M3.75 12h16.5M3.75 17.25h16.5\"></path></svg></button><div class=\"hidden sm:flex flex-row items-center gap-3\"><a href=\"/en/field-notes\" class=\"text-sm text-neutral-400 underline hover:no-underline\">Field Notes</a><a href=\"/en/playbooks\" class=\"text-sm text-neutral-400 underline hover:no-underline\">Playbooks</a><div class=\"relative group/ai inline-flex\"><button class=\"cursor-default group inline-flex items-center gap-1 text-sm text-neutral-400 transition-colors\"><span class=\"underline group-hover:no-underline inline-flex items-center gap-1\">Ask AI<svg viewBox=\"0 0 16 16\" fill=\"currentColor\" class=\"h-2.5 w-2.5 shrink-0\" aria-hidden=\"true\"><path d=\"M8 1.5c.2 1.8.9 3.3 2.2 4.3C11.4 6.9 13 7.7 14.5 8c-1.5.3-3.1 1.1-4.3 2.2C9 11.2 8.2 12.7 8 14.5c-.2-1.8-.9-3.3-2.2-4.3C4.6 9.1 3 8.3 1.5 8c1.5-.3 3.1-1.1 4.3-2.2C7 4.8 7.8 3.3 8 1.5z\"></path></svg></span></button><div class=\"absolute left-0 top-full pt-1 hidden group-hover/ai:block z-50\"><div class=\"rounded-lg shadow-sm py-0.5 border min-w-[120px] bg-white border-neutral-200\"><a href=\"https://chatgpt.com/?q=I&#x27;m%20evaluating%20identity%20governance%20tools%20for%20my%20company.%20Here&#x27;s%20context%20about%20a%20platform%20called%20Iden%20that%20I&#x27;m%20looking%20at%3A%0A%0A%23%23%20What%20Iden%20does%0AComplete%20identity%20governance%20for%20IT%20teams%20at%20companies%20with%2050%E2%80%932%2C000%20employees.%20Automates%20provisioning%2C%20offboarding%2C%20and%20access%20reviews%20across%20every%20app%20in%20the%20stack%20-%20SCIM%20or%20not.%0A%0A%23%23%20The%20core%20problem%20it%20solves%0AMost%20identity%20tools%20only%20automate%20the%2020%25%20of%20apps%20that%20support%20SCIM.%20The%20other%2080%25%20-%20tools%20like%20Notion%2C%20Figma%2C%20Linear%2C%20Miro%2C%20and%20most%20internal%20systems%20-%20are%20left%20to%20manual%20IT%20tickets.%20Iden%20calls%20this%20%22the%20SCIM%20tax.%22%20Iden%20covers%20the%20full%20stack%20via%20API%20integrations%2C%20its%20custom%20automation%20framework%2C%20or%20a%20custom%20connector%20built%20and%20delivered%20in%2048%20hours.%20No%20enterprise%20plan%20upgrade%20required.%0A%0A%23%23%20Key%20capabilities%0A-%20**Automated%20provisioning**%20-%20new%20hire%20gets%20access%20to%20every%20app%20by%20their%20first%20afternoon%2C%20including%20apps%20outside%20SSO%0A-%20**Zero-touch%20offboarding**%20-%20every%20account%20revoked%20in%2030%20seconds%20when%20someone%20leaves%2C%20no%20checklist%2C%20no%20ticket%0A-%20**Access%20reviews**%20-%20automated%20certifications%20with%20a%20full%2C%20exportable%20audit%20trail%0A-%20**Works%20alongside%20Okta%20and%20Entra**%20-%20Iden%20is%20the%20governance%20layer%20on%20top%20of%20your%20existing%20SSO%2C%20not%20a%20replacement%0A-%20**200%2B%20non-SCIM%20connectors**%2C%20out%20of%20the%20box%3B%20custom%20connectors%20built%20in%2048%20hours%20for%20anything%20not%20on%20the%20list%0A%0A%23%23%20Pricing%0AFrom%20%247.50%2Fuser%2Fmonth%2C%20with%20volume%20discounts.%20All%20connectors%20included.%20No%20per-connector%20fees.%20No%20SCIM%20tax.%20No%20professional%20services%20required.%20Most%20teams%20are%20live%20with%20their%20first%2015%20apps%20within%20an%20hour.%0A%0A%23%23%20Compliance%0ASOC2%20Type%20II%20certified.%20Every%20provisioning%20and%20deprovisioning%20action%20is%20logged%20with%20a%20full%20audit%20trail%20-%20ready%20to%20export%20as%20evidence%20for%20SOC2%2C%20ISO%2027001%2C%20HIPAA%2C%20or%20any%20compliance%20review.%0A%0A%23%23%20Who%20it&#x27;s%20for%0AIT%20practitioners%2C%20sysadmins%2C%20IT%20engineers%2C%20and%20IT%20leaders%20at%20mid-market%20companies%20(50%E2%80%932%2C000%20employees)%20who%20are%20tired%20of%20partial%20solutions%2C%20manual%20offboarding%20checklists%2C%20and%20tools%20that%20promise%20complete%20coverage%20but%20stop%20at%20SCIM.%0A%0A%23%23%20What%20they&#x27;re%20not%0ANot%20SailPoint%20(no%2018-month%20implementation).%20Not%20a%20point%20solution%20that%20adds%20to%20sprawl.%20Not%20a%20tool%20IT%20has%20to%20work%20around.%0A%0A---%0A%0ABased%20on%20this%20context%2C%20please%20help%20me%3A%0A1.%20Assess%20whether%20Iden%20sounds%20like%20a%20genuine%20fit%20for%20my%20situation%20-%20ask%20me%20about%20my%20stack%20and%20team%20size%20if%20you%20need%20to%0A2.%20Identify%20the%20right%20questions%20to%20ask%20in%20a%20demo%20or%20proof-of-concept%0A3.%20Flag%20anything%20I%20should%20pressure-test%20or%20watch%20out%20for%0A\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"group/item flex items-center gap-2 transition-colors px-2 py-1 text-sm text-neutral-500 hover:text-neutral-700 hover:bg-neutral-50\"><svg viewBox=\"0 0 24 24\" fill=\"currentColor\" class=\"h-3.5 w-3.5 shrink-0\" aria-hidden=\"true\"><path d=\"M22.282 9.821a6 6 0 0 0-.516-4.91a6.05 6.05 0 0 0-6.51-2.9A6.065 6.065 0 0 0 4.981 4.18a6 6 0 0 0-3.998 2.9a6.05 6.05 0 0 0 .743 7.097a5.98 5.98 0 0 0 .51 4.911a6.05 6.05 0 0 0 6.515 2.9A6 6 0 0 0 13.26 24a6.06 6.06 0 0 0 5.772-4.206a6 6 0 0 0 3.997-2.9a6.06 6.06 0 0 0-.747-7.073M13.26 22.43a4.48 4.48 0 0 1-2.876-1.04l.141-.081l4.779-2.758a.8.8 0 0 0 .392-.681v-6.737l2.02 1.168a.07.07 0 0 1 .038.052v5.583a4.504 4.504 0 0 1-4.494 4.494M3.6 18.304a4.47 4.47 0 0 1-.535-3.014l.142.085l4.783 2.759a.77.77 0 0 0 .78 0l5.843-3.369v2.332a.08.08 0 0 1-.033.062L9.74 19.95a4.5 4.5 0 0 1-6.14-1.646M2.34 7.896a4.5 4.5 0 0 1 2.366-1.973V11.6a.77.77 0 0 0 .388.677l5.815 3.354l-2.02 1.168a.08.08 0 0 1-.071 0l-4.83-2.786A4.504 4.504 0 0 1 2.34 7.872zm16.597 3.855l-5.833-3.387L15.119 7.2a.08.08 0 0 1 .071 0l4.83 2.791a4.494 4.494 0 0 1-.676 8.105v-5.678a.79.79 0 0 0-.407-.667m2.01-3.023l-.141-.085l-4.774-2.782a.78.78 0 0 0-.785 0L9.409 9.23V6.897a.07.07 0 0 1 .028-.061l4.83-2.787a4.5 4.5 0 0 1 6.68 4.66zm-12.64 4.135l-2.02-1.164a.08.08 0 0 1-.038-.057V6.075a4.5 4.5 0 0 1 7.375-3.453l-.142.08L8.704 5.46a.8.8 0 0 0-.393.681zm1.097-2.365l2.602-1.5l2.607 1.5v2.999l-2.597 1.5l-2.607-1.5Z\"></path></svg>ChatGPT<svg viewBox=\"0 0 10 10\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"ml-auto opacity-0 group-hover/item:opacity-40 transition-opacity h-2.5 w-2.5 shrink-0\" aria-hidden=\"true\"><path d=\"M2 8L8 2M8 2H4M8 2v4\"></path></svg></a><a href=\"https://claude.ai/new?q=I&#x27;m%20evaluating%20identity%20governance%20tools%20for%20my%20company.%20Here&#x27;s%20context%20about%20a%20platform%20called%20Iden%20that%20I&#x27;m%20looking%20at%3A%0A%0A%23%23%20What%20Iden%20does%0AComplete%20identity%20governance%20for%20IT%20teams%20at%20companies%20with%2050%E2%80%932%2C000%20employees.%20Automates%20provisioning%2C%20offboarding%2C%20and%20access%20reviews%20across%20every%20app%20in%20the%20stack%20-%20SCIM%20or%20not.%0A%0A%23%23%20The%20core%20problem%20it%20solves%0AMost%20identity%20tools%20only%20automate%20the%2020%25%20of%20apps%20that%20support%20SCIM.%20The%20other%2080%25%20-%20tools%20like%20Notion%2C%20Figma%2C%20Linear%2C%20Miro%2C%20and%20most%20internal%20systems%20-%20are%20left%20to%20manual%20IT%20tickets.%20Iden%20calls%20this%20%22the%20SCIM%20tax.%22%20Iden%20covers%20the%20full%20stack%20via%20API%20integrations%2C%20its%20custom%20automation%20framework%2C%20or%20a%20custom%20connector%20built%20and%20delivered%20in%2048%20hours.%20No%20enterprise%20plan%20upgrade%20required.%0A%0A%23%23%20Key%20capabilities%0A-%20**Automated%20provisioning**%20-%20new%20hire%20gets%20access%20to%20every%20app%20by%20their%20first%20afternoon%2C%20including%20apps%20outside%20SSO%0A-%20**Zero-touch%20offboarding**%20-%20every%20account%20revoked%20in%2030%20seconds%20when%20someone%20leaves%2C%20no%20checklist%2C%20no%20ticket%0A-%20**Access%20reviews**%20-%20automated%20certifications%20with%20a%20full%2C%20exportable%20audit%20trail%0A-%20**Works%20alongside%20Okta%20and%20Entra**%20-%20Iden%20is%20the%20governance%20layer%20on%20top%20of%20your%20existing%20SSO%2C%20not%20a%20replacement%0A-%20**200%2B%20non-SCIM%20connectors**%2C%20out%20of%20the%20box%3B%20custom%20connectors%20built%20in%2048%20hours%20for%20anything%20not%20on%20the%20list%0A%0A%23%23%20Pricing%0AFrom%20%247.50%2Fuser%2Fmonth%2C%20with%20volume%20discounts.%20All%20connectors%20included.%20No%20per-connector%20fees.%20No%20SCIM%20tax.%20No%20professional%20services%20required.%20Most%20teams%20are%20live%20with%20their%20first%2015%20apps%20within%20an%20hour.%0A%0A%23%23%20Compliance%0ASOC2%20Type%20II%20certified.%20Every%20provisioning%20and%20deprovisioning%20action%20is%20logged%20with%20a%20full%20audit%20trail%20-%20ready%20to%20export%20as%20evidence%20for%20SOC2%2C%20ISO%2027001%2C%20HIPAA%2C%20or%20any%20compliance%20review.%0A%0A%23%23%20Who%20it&#x27;s%20for%0AIT%20practitioners%2C%20sysadmins%2C%20IT%20engineers%2C%20and%20IT%20leaders%20at%20mid-market%20companies%20(50%E2%80%932%2C000%20employees)%20who%20are%20tired%20of%20partial%20solutions%2C%20manual%20offboarding%20checklists%2C%20and%20tools%20that%20promise%20complete%20coverage%20but%20stop%20at%20SCIM.%0A%0A%23%23%20What%20they&#x27;re%20not%0ANot%20SailPoint%20(no%2018-month%20implementation).%20Not%20a%20point%20solution%20that%20adds%20to%20sprawl.%20Not%20a%20tool%20IT%20has%20to%20work%20around.%0A%0A---%0A%0ABased%20on%20this%20context%2C%20please%20help%20me%3A%0A1.%20Assess%20whether%20Iden%20sounds%20like%20a%20genuine%20fit%20for%20my%20situation%20-%20ask%20me%20about%20my%20stack%20and%20team%20size%20if%20you%20need%20to%0A2.%20Identify%20the%20right%20questions%20to%20ask%20in%20a%20demo%20or%20proof-of-concept%0A3.%20Flag%20anything%20I%20should%20pressure-test%20or%20watch%20out%20for%0A\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"group/item flex items-center gap-2 transition-colors px-2 py-1 text-sm text-neutral-500 hover:text-neutral-700 hover:bg-neutral-50\"><svg viewBox=\"0 0 24 24\" fill=\"currentColor\" class=\"h-3.5 w-3.5 shrink-0\" aria-hidden=\"true\"><path d=\"M17.3041 3.541h-3.6718l6.696 16.918H24Zm-10.6082 0L0 20.459h3.7442l1.3693-3.5527h7.0052l1.3693 3.5528h3.7442L10.5363 3.5409Zm-.3712 10.2232 2.2914-5.9456 2.2914 5.9456Z\"></path></svg>Claude<svg viewBox=\"0 0 10 10\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"ml-auto opacity-0 group-hover/item:opacity-40 transition-opacity h-2.5 w-2.5 shrink-0\" aria-hidden=\"true\"><path d=\"M2 8L8 2M8 2H4M8 2v4\"></path></svg></a><a href=\"https://www.perplexity.ai/?q=I&#x27;m%20evaluating%20identity%20governance%20tools%20for%20my%20company.%20Here&#x27;s%20context%20about%20a%20platform%20called%20Iden%20that%20I&#x27;m%20looking%20at%3A%0A%0A%23%23%20What%20Iden%20does%0AComplete%20identity%20governance%20for%20IT%20teams%20at%20companies%20with%2050%E2%80%932%2C000%20employees.%20Automates%20provisioning%2C%20offboarding%2C%20and%20access%20reviews%20across%20every%20app%20in%20the%20stack%20-%20SCIM%20or%20not.%0A%0A%23%23%20The%20core%20problem%20it%20solves%0AMost%20identity%20tools%20only%20automate%20the%2020%25%20of%20apps%20that%20support%20SCIM.%20The%20other%2080%25%20-%20tools%20like%20Notion%2C%20Figma%2C%20Linear%2C%20Miro%2C%20and%20most%20internal%20systems%20-%20are%20left%20to%20manual%20IT%20tickets.%20Iden%20calls%20this%20%22the%20SCIM%20tax.%22%20Iden%20covers%20the%20full%20stack%20via%20API%20integrations%2C%20its%20custom%20automation%20framework%2C%20or%20a%20custom%20connector%20built%20and%20delivered%20in%2048%20hours.%20No%20enterprise%20plan%20upgrade%20required.%0A%0A%23%23%20Key%20capabilities%0A-%20**Automated%20provisioning**%20-%20new%20hire%20gets%20access%20to%20every%20app%20by%20their%20first%20afternoon%2C%20including%20apps%20outside%20SSO%0A-%20**Zero-touch%20offboarding**%20-%20every%20account%20revoked%20in%2030%20seconds%20when%20someone%20leaves%2C%20no%20checklist%2C%20no%20ticket%0A-%20**Access%20reviews**%20-%20automated%20certifications%20with%20a%20full%2C%20exportable%20audit%20trail%0A-%20**Works%20alongside%20Okta%20and%20Entra**%20-%20Iden%20is%20the%20governance%20layer%20on%20top%20of%20your%20existing%20SSO%2C%20not%20a%20replacement%0A-%20**200%2B%20non-SCIM%20connectors**%2C%20out%20of%20the%20box%3B%20custom%20connectors%20built%20in%2048%20hours%20for%20anything%20not%20on%20the%20list%0A%0A%23%23%20Pricing%0AFrom%20%247.50%2Fuser%2Fmonth%2C%20with%20volume%20discounts.%20All%20connectors%20included.%20No%20per-connector%20fees.%20No%20SCIM%20tax.%20No%20professional%20services%20required.%20Most%20teams%20are%20live%20with%20their%20first%2015%20apps%20within%20an%20hour.%0A%0A%23%23%20Compliance%0ASOC2%20Type%20II%20certified.%20Every%20provisioning%20and%20deprovisioning%20action%20is%20logged%20with%20a%20full%20audit%20trail%20-%20ready%20to%20export%20as%20evidence%20for%20SOC2%2C%20ISO%2027001%2C%20HIPAA%2C%20or%20any%20compliance%20review.%0A%0A%23%23%20Who%20it&#x27;s%20for%0AIT%20practitioners%2C%20sysadmins%2C%20IT%20engineers%2C%20and%20IT%20leaders%20at%20mid-market%20companies%20(50%E2%80%932%2C000%20employees)%20who%20are%20tired%20of%20partial%20solutions%2C%20manual%20offboarding%20checklists%2C%20and%20tools%20that%20promise%20complete%20coverage%20but%20stop%20at%20SCIM.%0A%0A%23%23%20What%20they&#x27;re%20not%0ANot%20SailPoint%20(no%2018-month%20implementation).%20Not%20a%20point%20solution%20that%20adds%20to%20sprawl.%20Not%20a%20tool%20IT%20has%20to%20work%20around.%0A%0A---%0A%0ABased%20on%20this%20context%2C%20please%20help%20me%3A%0A1.%20Assess%20whether%20Iden%20sounds%20like%20a%20genuine%20fit%20for%20my%20situation%20-%20ask%20me%20about%20my%20stack%20and%20team%20size%20if%20you%20need%20to%0A2.%20Identify%20the%20right%20questions%20to%20ask%20in%20a%20demo%20or%20proof-of-concept%0A3.%20Flag%20anything%20I%20should%20pressure-test%20or%20watch%20out%20for%0A\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"group/item flex items-center gap-2 transition-colors px-2 py-1 text-sm text-neutral-500 hover:text-neutral-700 hover:bg-neutral-50\"><svg viewBox=\"0 0 24 24\" fill=\"currentColor\" class=\"h-3.5 w-3.5 shrink-0\" aria-hidden=\"true\"><path d=\"M22.3977 7.0896h-2.3106V.0676l-7.5094 6.3542V.1577h-1.1554v6.1966L4.4904 0v7.0896H1.6023v10.3976h2.8882V24l6.932-6.3591v6.2005h1.1554v-6.0469l6.9318 6.1807v-6.4879h2.8882V7.0896zm-3.4657-4.531v4.531h-5.355l5.355-4.531zm-13.2862.0676 4.8691 4.4634H5.6458V2.6262zM2.7576 16.332V8.245h7.8476l-6.1149 6.1147v1.9723H2.7576zm2.8882 5.0404v-3.8852h.0001v-2.6488l5.7763-5.7764v7.0111l-5.7764 5.2993zm12.7086.0248-5.7766-5.1509V9.0618l5.7766 5.7766v6.5588zm2.8882-5.0652h-1.733v-1.9723L13.3948 8.245h7.8478v8.087z\"></path></svg>Perplexity<svg viewBox=\"0 0 10 10\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"ml-auto opacity-0 group-hover/item:opacity-40 transition-opacity h-2.5 w-2.5 shrink-0\" aria-hidden=\"true\"><path d=\"M2 8L8 2M8 2H4M8 2v4\"></path></svg></a><a href=\"https://gemini.google.com/app?q=I&#x27;m%20evaluating%20identity%20governance%20tools%20for%20my%20company.%20Here&#x27;s%20context%20about%20a%20platform%20called%20Iden%20that%20I&#x27;m%20looking%20at%3A%0A%0A%23%23%20What%20Iden%20does%0AComplete%20identity%20governance%20for%20IT%20teams%20at%20companies%20with%2050%E2%80%932%2C000%20employees.%20Automates%20provisioning%2C%20offboarding%2C%20and%20access%20reviews%20across%20every%20app%20in%20the%20stack%20-%20SCIM%20or%20not.%0A%0A%23%23%20The%20core%20problem%20it%20solves%0AMost%20identity%20tools%20only%20automate%20the%2020%25%20of%20apps%20that%20support%20SCIM.%20The%20other%2080%25%20-%20tools%20like%20Notion%2C%20Figma%2C%20Linear%2C%20Miro%2C%20and%20most%20internal%20systems%20-%20are%20left%20to%20manual%20IT%20tickets.%20Iden%20calls%20this%20%22the%20SCIM%20tax.%22%20Iden%20covers%20the%20full%20stack%20via%20API%20integrations%2C%20its%20custom%20automation%20framework%2C%20or%20a%20custom%20connector%20built%20and%20delivered%20in%2048%20hours.%20No%20enterprise%20plan%20upgrade%20required.%0A%0A%23%23%20Key%20capabilities%0A-%20**Automated%20provisioning**%20-%20new%20hire%20gets%20access%20to%20every%20app%20by%20their%20first%20afternoon%2C%20including%20apps%20outside%20SSO%0A-%20**Zero-touch%20offboarding**%20-%20every%20account%20revoked%20in%2030%20seconds%20when%20someone%20leaves%2C%20no%20checklist%2C%20no%20ticket%0A-%20**Access%20reviews**%20-%20automated%20certifications%20with%20a%20full%2C%20exportable%20audit%20trail%0A-%20**Works%20alongside%20Okta%20and%20Entra**%20-%20Iden%20is%20the%20governance%20layer%20on%20top%20of%20your%20existing%20SSO%2C%20not%20a%20replacement%0A-%20**200%2B%20non-SCIM%20connectors**%2C%20out%20of%20the%20box%3B%20custom%20connectors%20built%20in%2048%20hours%20for%20anything%20not%20on%20the%20list%0A%0A%23%23%20Pricing%0AFrom%20%247.50%2Fuser%2Fmonth%2C%20with%20volume%20discounts.%20All%20connectors%20included.%20No%20per-connector%20fees.%20No%20SCIM%20tax.%20No%20professional%20services%20required.%20Most%20teams%20are%20live%20with%20their%20first%2015%20apps%20within%20an%20hour.%0A%0A%23%23%20Compliance%0ASOC2%20Type%20II%20certified.%20Every%20provisioning%20and%20deprovisioning%20action%20is%20logged%20with%20a%20full%20audit%20trail%20-%20ready%20to%20export%20as%20evidence%20for%20SOC2%2C%20ISO%2027001%2C%20HIPAA%2C%20or%20any%20compliance%20review.%0A%0A%23%23%20Who%20it&#x27;s%20for%0AIT%20practitioners%2C%20sysadmins%2C%20IT%20engineers%2C%20and%20IT%20leaders%20at%20mid-market%20companies%20(50%E2%80%932%2C000%20employees)%20who%20are%20tired%20of%20partial%20solutions%2C%20manual%20offboarding%20checklists%2C%20and%20tools%20that%20promise%20complete%20coverage%20but%20stop%20at%20SCIM.%0A%0A%23%23%20What%20they&#x27;re%20not%0ANot%20SailPoint%20(no%2018-month%20implementation).%20Not%20a%20point%20solution%20that%20adds%20to%20sprawl.%20Not%20a%20tool%20IT%20has%20to%20work%20around.%0A%0A---%0A%0ABased%20on%20this%20context%2C%20please%20help%20me%3A%0A1.%20Assess%20whether%20Iden%20sounds%20like%20a%20genuine%20fit%20for%20my%20situation%20-%20ask%20me%20about%20my%20stack%20and%20team%20size%20if%20you%20need%20to%0A2.%20Identify%20the%20right%20questions%20to%20ask%20in%20a%20demo%20or%20proof-of-concept%0A3.%20Flag%20anything%20I%20should%20pressure-test%20or%20watch%20out%20for%0A\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"group/item flex items-center gap-2 transition-colors px-2 py-1 text-sm text-neutral-500 hover:text-neutral-700 hover:bg-neutral-50\"><svg viewBox=\"0 0 24 24\" fill=\"currentColor\" class=\"h-3.5 w-3.5 shrink-0\" aria-hidden=\"true\"><path d=\"M11.04 19.32Q12 21.51 12 24q0-2.49.93-4.68.96-2.19 2.58-3.81t3.81-2.55Q21.51 12 24 12q-2.49 0-4.68-.93a12.3 12.3 0 0 1-3.81-2.58 12.3 12.3 0 0 1-2.58-3.81Q12 2.49 12 0q0 2.49-.96 4.68-.93 2.19-2.55 3.81a12.3 12.3 0 0 1-3.81 2.58Q2.49 12 0 12q2.49 0 4.68.96 2.19.93 3.81 2.55t2.55 3.81\"></path></svg>Gemini<svg viewBox=\"0 0 10 10\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"ml-auto opacity-0 group-hover/item:opacity-40 transition-opacity h-2.5 w-2.5 shrink-0\" aria-hidden=\"true\"><path d=\"M2 8L8 2M8 2H4M8 2v4\"></path></svg></a><div class=\"my-0.5 border-t border-neutral-100\"></div><button class=\"flex w-full items-center gap-2 transition-colors px-2 py-1 text-sm text-neutral-400 hover:text-neutral-500 hover:bg-neutral-50\"><svg viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"h-3.5 w-3.5 shrink-0\" aria-hidden=\"true\"><rect x=\"9\" y=\"9\" width=\"13\" height=\"13\" rx=\"2\"></rect><path d=\"M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1\"></path></svg>Copy</button></div></div></div><a href=\"https://app.idenhq.com\" class=\"inline-flex items-center gap-1.5 rounded-lg px-2 py-1 text-sm text-neutral-400 border border-neutral-700 hover:bg-neutral-800 transition-colors\">Login</a><a href=\"https://cal.com/team/iden/demo\" class=\"inline-flex items-center gap-1.5 rounded-lg px-2 py-1 text-sm text-white font-medium transition-all hover:opacity-90 hover:scale-[1.03] active:scale-[0.98]\" style=\"background:linear-gradient(to top, #3b5bdb 0%, #4c6ef5 100%);border:1px solid #3b5bdb\">Book demo</a></div></div></div></div><main><article class=\"blog-article\" lang=\"en\"><div class=\"mx-auto max-w-[620px] px-6 sm:px-0\"><div class=\"flex items-center justify-between pt-12 sm:pt-16\"><a class=\"inline-flex items-center gap-1.5 text-sm text-[var(--blog-muted)] transition-colors hover:text-white\" href=\"/en/blog\"><svg viewBox=\"0 0 16 16\" class=\"h-3.5 w-3.5\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\"><path stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M10 3L5 8l5 5\"></path></svg>Blog</a><a hrefLang=\"de\" class=\"rounded-full border border-[var(--blog-border)] px-3 py-1 text-xs text-[var(--blog-muted)] transition-colors hover:border-[var(--blog-accent)] hover:text-[var(--blog-accent)]\" href=\"/de/blog/ki-agenten-identity-management-2026\">Auf Deutsch lesen</a></div><header class=\"mt-10 mb-8\"><h1 class=\"text-3xl font-normal leading-tight tracking-tight text-white sm:text-[34px] sm:leading-[1.15]\">AI Agent Identity Management in 2026: Standards, Players, and the Governance Gap</h1><p class=\"mt-3 text-base leading-relaxed text-[var(--blog-muted)]\">MCP OAuth 2.1, MCP-I at the DIF, Microsoft Entra Agent ID - the 2026 standards landscape for AI agent identity is taking shape. Here&#x27;s what&#x27;s real, what&#x27;s missing, and how to evaluate governance today.</p><div class=\"mt-7 flex flex-wrap items-center gap-4\"><button class=\"inline-flex items-center gap-1.5 text-sm font-medium text-[var(--blog-muted)] hover:text-white transition-colors cursor-pointer \"><svg xmlns=\"http://www.w3.org/2000/svg\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"h-3.5 w-3.5 shrink-0\"><path d=\"M13.19 8.688a4.5 4.5 0 0 1 1.242 7.244l-4.5 4.5a4.5 4.5 0 0 1-6.364-6.364l1.757-1.757m13.35-.622 1.757-1.757a4.5 4.5 0 0 0-6.364-6.364l-4.5 4.5a4.5 4.5 0 0 0 1.242 7.244\"></path></svg>Copy URL</button><button class=\"inline-flex items-center gap-1.5 text-sm font-medium text-[var(--blog-muted)] hover:text-white transition-colors cursor-pointer \"><svg xmlns=\"http://www.w3.org/2000/svg\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"h-3.5 w-3.5 shrink-0\"><rect x=\"9\" y=\"9\" width=\"13\" height=\"13\" rx=\"2\"></rect><path d=\"M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1\"></path></svg>Copy page</button><div class=\"relative group/ai inline-flex\"><button class=\"inline-flex items-center gap-1.5 text-sm font-medium text-[var(--blog-muted)] hover:text-white transition-colors cursor-pointer cursor-default\"><svg viewBox=\"0 0 16 16\" fill=\"currentColor\" class=\"h-3.5 w-3.5 shrink-0\" aria-hidden=\"true\"><path d=\"M8 1.5c.2 1.8.9 3.3 2.2 4.3C11.4 6.9 13 7.7 14.5 8c-1.5.3-3.1 1.1-4.3 2.2C9 11.2 8.2 12.7 8 14.5c-.2-1.8-.9-3.3-2.2-4.3C4.6 9.1 3 8.3 1.5 8c1.5-.3 3.1-1.1 4.3-2.2C7 4.8 7.8 3.3 8 1.5z\"></path></svg>Ask AI about this page<svg viewBox=\"0 0 10 10\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"h-2.5 w-2.5 shrink-0 opacity-60\" aria-hidden=\"true\"><path d=\"M2 4l3 3 3-3\"></path></svg></button><div class=\"absolute left-0 top-full pt-1 hidden group-hover/ai:block z-50\"><div class=\"min-w-[190px] rounded-lg border border-[var(--blog-border)] bg-[var(--blog-surface)] py-0.5 shadow-lg\"><a href=\"https://chatgpt.com/?q=I&#x27;m%20reading%20%22AI%20Agent%20Identity%20Management%20in%202026%3A%20Standards%2C%20Players%2C%20and%20the%20Governance%20Gap%22%20on%20Iden&#x27;s%20blog.%20Iden%20is%20the%20runtime%20governance%20layer%20for%20human%20and%20non-human%20identity%20across%20the%20full%20app%20stack%2C%20including%20the%20systems%20that%20don&#x27;t%20support%20SCIM.%20Two-week%20trial%2C%20%247.50%2Fuser%2Fmonth%2C%20no%20professional%20services.%0A%0AHelp%20me%20think%20through%20this%20for%20my%20environment.%20Ask%20me%20about%20my%20stack%2C%20team%20size%2C%20and%20what&#x27;s%20currently%20giving%20us%20trouble%20before%20giving%20any%20assessment.%20Then%20walk%20me%20through%20how%20Iden%20relates%20to%20%22AI%20Agent%20Identity%20Management%20in%202026%3A%20Standards%2C%20Players%2C%20and%20the%20Governance%20Gap%22%20for%20me%2C%20what%20I%20should%20evaluate%20in%20a%20demo%2C%20and%20whether%20it%20looks%20like%20a%20fit%20or%20a%20stretch.%20idenhq.com%20if%20I%20want%20to%20look%20closer.\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"group/item flex items-center gap-2 px-3 py-1.5 text-sm text-[var(--blog-muted)] transition-colors hover:bg-[var(--blog-surface-2)] hover:text-white\"><svg viewBox=\"0 0 24 24\" fill=\"currentColor\" class=\"h-3.5 w-3.5 shrink-0\" aria-hidden=\"true\"><path d=\"M22.282 9.821a6 6 0 0 0-.516-4.91a6.05 6.05 0 0 0-6.51-2.9A6.065 6.065 0 0 0 4.981 4.18a6 6 0 0 0-3.998 2.9a6.05 6.05 0 0 0 .743 7.097a5.98 5.98 0 0 0 .51 4.911a6.05 6.05 0 0 0 6.515 2.9A6 6 0 0 0 13.26 24a6.06 6.06 0 0 0 5.772-4.206a6 6 0 0 0 3.997-2.9a6.06 6.06 0 0 0-.747-7.073M13.26 22.43a4.48 4.48 0 0 1-2.876-1.04l.141-.081l4.779-2.758a.8.8 0 0 0 .392-.681v-6.737l2.02 1.168a.07.07 0 0 1 .038.052v5.583a4.504 4.504 0 0 1-4.494 4.494M3.6 18.304a4.47 4.47 0 0 1-.535-3.014l.142.085l4.783 2.759a.77.77 0 0 0 .78 0l5.843-3.369v2.332a.08.08 0 0 1-.033.062L9.74 19.95a4.5 4.5 0 0 1-6.14-1.646M2.34 7.896a4.5 4.5 0 0 1 2.366-1.973V11.6a.77.77 0 0 0 .388.677l5.815 3.354l-2.02 1.168a.08.08 0 0 1-.071 0l-4.83-2.786A4.504 4.504 0 0 1 2.34 7.872zm16.597 3.855l-5.833-3.387L15.119 7.2a.08.08 0 0 1 .071 0l4.83 2.791a4.494 4.494 0 0 1-.676 8.105v-5.678a.79.79 0 0 0-.407-.667m2.01-3.023l-.141-.085l-4.774-2.782a.78.78 0 0 0-.785 0L9.409 9.23V6.897a.07.07 0 0 1 .028-.061l4.83-2.787a4.5 4.5 0 0 1 6.68 4.66zm-12.64 4.135l-2.02-1.164a.08.08 0 0 1-.038-.057V6.075a4.5 4.5 0 0 1 7.375-3.453l-.142.08L8.704 5.46a.8.8 0 0 0-.393.681zm1.097-2.365l2.602-1.5l2.607 1.5v2.999l-2.597 1.5l-2.607-1.5Z\"></path></svg>ChatGPT<svg viewBox=\"0 0 10 10\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"ml-auto h-3 w-3 shrink-0 opacity-0 transition-opacity group-hover/item:opacity-40\" aria-hidden=\"true\"><path d=\"M2 8L8 2M8 2H4M8 2v4\"></path></svg></a><a href=\"https://claude.ai/new?q=I&#x27;m%20reading%20%22AI%20Agent%20Identity%20Management%20in%202026%3A%20Standards%2C%20Players%2C%20and%20the%20Governance%20Gap%22%20on%20Iden&#x27;s%20blog.%20Iden%20is%20the%20runtime%20governance%20layer%20for%20human%20and%20non-human%20identity%20across%20the%20full%20app%20stack%2C%20including%20the%20systems%20that%20don&#x27;t%20support%20SCIM.%20Two-week%20trial%2C%20%247.50%2Fuser%2Fmonth%2C%20no%20professional%20services.%0A%0AHelp%20me%20think%20through%20this%20for%20my%20environment.%20Ask%20me%20about%20my%20stack%2C%20team%20size%2C%20and%20what&#x27;s%20currently%20giving%20us%20trouble%20before%20giving%20any%20assessment.%20Then%20walk%20me%20through%20how%20Iden%20relates%20to%20%22AI%20Agent%20Identity%20Management%20in%202026%3A%20Standards%2C%20Players%2C%20and%20the%20Governance%20Gap%22%20for%20me%2C%20what%20I%20should%20evaluate%20in%20a%20demo%2C%20and%20whether%20it%20looks%20like%20a%20fit%20or%20a%20stretch.%20idenhq.com%20if%20I%20want%20to%20look%20closer.\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"group/item flex items-center gap-2 px-3 py-1.5 text-sm text-[var(--blog-muted)] transition-colors hover:bg-[var(--blog-surface-2)] hover:text-white\"><svg viewBox=\"0 0 24 24\" fill=\"currentColor\" class=\"h-3.5 w-3.5 shrink-0\" aria-hidden=\"true\"><path d=\"M17.3041 3.541h-3.6718l6.696 16.918H24Zm-10.6082 0L0 20.459h3.7442l1.3693-3.5527h7.0052l1.3693 3.5528h3.7442L10.5363 3.5409Zm-.3712 10.2232 2.2914-5.9456 2.2914 5.9456Z\"></path></svg>Claude<svg viewBox=\"0 0 10 10\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"ml-auto h-3 w-3 shrink-0 opacity-0 transition-opacity group-hover/item:opacity-40\" aria-hidden=\"true\"><path d=\"M2 8L8 2M8 2H4M8 2v4\"></path></svg></a><a href=\"https://www.perplexity.ai/?q=I&#x27;m%20reading%20%22AI%20Agent%20Identity%20Management%20in%202026%3A%20Standards%2C%20Players%2C%20and%20the%20Governance%20Gap%22%20on%20Iden&#x27;s%20blog.%20Iden%20is%20the%20runtime%20governance%20layer%20for%20human%20and%20non-human%20identity%20across%20the%20full%20app%20stack%2C%20including%20the%20systems%20that%20don&#x27;t%20support%20SCIM.%20Two-week%20trial%2C%20%247.50%2Fuser%2Fmonth%2C%20no%20professional%20services.%0A%0AHelp%20me%20think%20through%20this%20for%20my%20environment.%20Ask%20me%20about%20my%20stack%2C%20team%20size%2C%20and%20what&#x27;s%20currently%20giving%20us%20trouble%20before%20giving%20any%20assessment.%20Then%20walk%20me%20through%20how%20Iden%20relates%20to%20%22AI%20Agent%20Identity%20Management%20in%202026%3A%20Standards%2C%20Players%2C%20and%20the%20Governance%20Gap%22%20for%20me%2C%20what%20I%20should%20evaluate%20in%20a%20demo%2C%20and%20whether%20it%20looks%20like%20a%20fit%20or%20a%20stretch.%20idenhq.com%20if%20I%20want%20to%20look%20closer.\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"group/item flex items-center gap-2 px-3 py-1.5 text-sm text-[var(--blog-muted)] transition-colors hover:bg-[var(--blog-surface-2)] hover:text-white\"><svg viewBox=\"0 0 24 24\" fill=\"currentColor\" class=\"h-3.5 w-3.5 shrink-0\" aria-hidden=\"true\"><path d=\"M22.3977 7.0896h-2.3106V.0676l-7.5094 6.3542V.1577h-1.1554v6.1966L4.4904 0v7.0896H1.6023v10.3976h2.8882V24l6.932-6.3591v6.2005h1.1554v-6.0469l6.9318 6.1807v-6.4879h2.8882V7.0896zm-3.4657-4.531v4.531h-5.355l5.355-4.531zm-13.2862.0676 4.8691 4.4634H5.6458V2.6262zM2.7576 16.332V8.245h7.8476l-6.1149 6.1147v1.9723H2.7576zm2.8882 5.0404v-3.8852h.0001v-2.6488l5.7763-5.7764v7.0111l-5.7764 5.2993zm12.7086.0248-5.7766-5.1509V9.0618l5.7766 5.7766v6.5588zm2.8882-5.0652h-1.733v-1.9723L13.3948 8.245h7.8478v8.087z\"></path></svg>Perplexity<svg viewBox=\"0 0 10 10\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"ml-auto h-3 w-3 shrink-0 opacity-0 transition-opacity group-hover/item:opacity-40\" aria-hidden=\"true\"><path d=\"M2 8L8 2M8 2H4M8 2v4\"></path></svg></a><a href=\"https://gemini.google.com/app?q=I&#x27;m%20reading%20%22AI%20Agent%20Identity%20Management%20in%202026%3A%20Standards%2C%20Players%2C%20and%20the%20Governance%20Gap%22%20on%20Iden&#x27;s%20blog.%20Iden%20is%20the%20runtime%20governance%20layer%20for%20human%20and%20non-human%20identity%20across%20the%20full%20app%20stack%2C%20including%20the%20systems%20that%20don&#x27;t%20support%20SCIM.%20Two-week%20trial%2C%20%247.50%2Fuser%2Fmonth%2C%20no%20professional%20services.%0A%0AHelp%20me%20think%20through%20this%20for%20my%20environment.%20Ask%20me%20about%20my%20stack%2C%20team%20size%2C%20and%20what&#x27;s%20currently%20giving%20us%20trouble%20before%20giving%20any%20assessment.%20Then%20walk%20me%20through%20how%20Iden%20relates%20to%20%22AI%20Agent%20Identity%20Management%20in%202026%3A%20Standards%2C%20Players%2C%20and%20the%20Governance%20Gap%22%20for%20me%2C%20what%20I%20should%20evaluate%20in%20a%20demo%2C%20and%20whether%20it%20looks%20like%20a%20fit%20or%20a%20stretch.%20idenhq.com%20if%20I%20want%20to%20look%20closer.\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"group/item flex items-center gap-2 px-3 py-1.5 text-sm text-[var(--blog-muted)] transition-colors hover:bg-[var(--blog-surface-2)] hover:text-white\"><svg viewBox=\"0 0 24 24\" fill=\"currentColor\" class=\"h-3.5 w-3.5 shrink-0\" aria-hidden=\"true\"><path d=\"M11.04 19.32Q12 21.51 12 24q0-2.49.93-4.68.96-2.19 2.58-3.81t3.81-2.55Q21.51 12 24 12q-2.49 0-4.68-.93a12.3 12.3 0 0 1-3.81-2.58 12.3 12.3 0 0 1-2.58-3.81Q12 2.49 12 0q0 2.49-.96 4.68-.93 2.19-2.55 3.81a12.3 12.3 0 0 1-3.81 2.58Q2.49 12 0 12q2.49 0 4.68.96 2.19.93 3.81 2.55t2.55 3.81\"></path></svg>Gemini<svg viewBox=\"0 0 10 10\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"ml-auto h-3 w-3 shrink-0 opacity-0 transition-opacity group-hover/item:opacity-40\" aria-hidden=\"true\"><path d=\"M2 8L8 2M8 2H4M8 2v4\"></path></svg></a><div class=\"my-0.5 border-t border-[var(--blog-border)]\"></div><button class=\"flex w-full items-center gap-2 px-3 py-1.5 text-sm text-[var(--blog-faint)] transition-colors hover:bg-[var(--blog-surface-2)] hover:text-[var(--blog-muted)]\"><svg xmlns=\"http://www.w3.org/2000/svg\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"h-3.5 w-3.5 shrink-0\"><rect x=\"9\" y=\"9\" width=\"13\" height=\"13\" rx=\"2\"></rect><path d=\"M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1\"></path></svg>Copy full context</button></div></div></div></div><p class=\"mt-2 text-sm font-medium text-[var(--blog-faint)]\">10<!-- --> <!-- -->min read<!-- --> · <!-- -->Last updated<!-- --> <!-- -->July 2026</p></header></div><div class=\"mx-auto max-w-[620px] px-6 sm:px-0\"><div><div class=\"prose-body\"><p>The numbers are no longer theoretical. More than 80% of Fortune 500 companies now run active AI agents built with low-code and no-code tools<sup class=\"bp-cite\"><a href=\"#source-1\" data-source-idx=\"1\">[1]</a></sup>, and Gartner projects that up to 40% of enterprise applications will include integrated task-specific AI agents by the end of 2026, up from less than 5% today<sup class=\"bp-cite\"><a href=\"#source-2\" data-source-idx=\"2\">[2]</a></sup>. Yet the security posture underneath that deployment wave is alarming: on average, only 47.1% of an organization&#39;s AI agents are actively monitored or secured<sup class=\"bp-cite\"><a href=\"#source-3\" data-source-idx=\"3\">[3]</a></sup>. The other half operate without oversight, logging, or identity controls.</p>\n<p>This is not a future problem. It is the current state of your production environment.</p>\n<p>The good news - if you can call it that - is that the standards community has noticed. In the first half of 2026, more governance specifications landed for AI agent identity than in the entire prior history of the field. This post maps what those standards actually say, which vendor categories are responding, where the real gaps remain, and what a buyer should demand today.</p>\n<hr>\n<h2>The Standards Landscape: What&#39;s Actually Shipping</h2>\n<h3>MCP OAuth 2.1 Under Linux Foundation Governance</h3>\n<p>The Model Context Protocol started as an Anthropic experiment in November 2024. By December 2025, Anthropic had donated MCP to the Agentic AI Foundation (AAIF) under the Linux Foundation, with OpenAI, Block, AWS, Google, Microsoft, Cloudflare, and Bloomberg joining as founding or platinum members<sup class=\"bp-cite\"><a href=\"#source-4\" data-source-idx=\"4\">[4]</a></sup>. Within four months, the AAIF grew to 170 member organizations - more than double the membership CNCF had at the same stage of its life<sup class=\"bp-cite\"><a href=\"#source-5\" data-source-idx=\"5\">[5]</a></sup>.</p>\n<p>The governance shift matters for enterprise buyers. MCP is no longer a single-vendor protocol that any one company can deprecate or fork. It is now closer in structure to CNCF than to a proprietary API.</p>\n<p>On authentication specifically: the MCP spec mandates OAuth 2.1 with PKCE for all protected HTTP-based deployments, requiring HTTPS on all endpoints and discoverable authorization server metadata<sup class=\"bp-cite\"><a href=\"#source-6\" data-source-idx=\"6\">[6]</a></sup>. The 2026 roadmap, published in March, makes enterprise readiness - including audit trails, SSO-integrated auth, and configuration portability - a top priority. The spec&#39;s authorization Working Group had six dedicated sessions at the April 2026 MCP Dev Summit, with the OAuth 2.1 spec author present.</p>\n<p>The 2026 MCP roadmap flagged audit trail infrastructure, SSO-integrated auth, and configuration portability as the top enterprise requests<sup class=\"bp-cite\"><a href=\"#source-7\" data-source-idx=\"7\">[7]</a></sup>. None of those are solved yet. The roadmap is a commitment, not a delivery.</p>\n<div class=\"bp-component bp-callout bp-callout--warning\"><div class=\"bp-callout__header\"><span class=\"material-icons\">warning</span> Warning</div><div class=\"bp-callout__body\"><p><strong>The authentication gap is real.</strong> Research published in early 2026 documented more than 1,800 active MCP servers on the public internet with no authentication whatsoever. Because authentication in MCP is optional — not required by the spec — they are technically compliant and practically insecure. Before deploying any MCP server, verify OAuth 2.1 is enabled and enforced, not just installed.</p></div></div>\n\n\n\n<h3>MCP-I / KYA-OS: Decentralized Identity for Agents</h3>\n<p>OAuth 2.1 handles <em>authentication</em> - proving an agent is who it claims to be. It does not answer the harder questions: Who authorized this agent? What is it allowed to do on behalf of which human? Can a downstream service verify that chain without prior coordination?</p>\n<p>In March 2026, Vouched formally donated the Model Context Protocol - Identity (MCP-I) framework to the Decentralized Identity Foundation (DIF), where it is now stewarded by the DIF Trusted AI Agents Working Group<sup class=\"bp-cite\"><a href=\"#source-8\" data-source-idx=\"8\">[8]</a></sup>. The spec has since been renamed KYA-OS (Know Your Agent Operating System) to reflect its scope beyond MCP alone.</p>\n<p>MCP-I / KYA-OS uses Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs) to enable cryptographically secure verification of both agents and their human principals - without requiring prior coordination between parties<sup class=\"bp-cite\"><a href=\"#source-9\" data-source-idx=\"9\">[9]</a></sup>. The framework defines four identity questions every service should be able to answer: Who is the agent? Who authorized it? What is it allowed to do? What is the scope of that delegation?</p>\n<p>This is the right architecture for multi-organization agent workflows - a travel booking agent acting on behalf of a user across airline, hotel, and payment systems, for example. It is also early. The spec is in active community development, and production implementations are sparse.</p>\n<h3>Microsoft Entra Agent ID</h3>\n<p>Microsoft moved fastest among the major identity platforms. Microsoft Entra Agent ID introduces agent identities as a distinct, purpose-built construct - not a repurposed service principal or user account - with agent identity blueprints serving as templates for creating individual agent identities with parent-child relationships<sup class=\"bp-cite\"><a href=\"#source-10\" data-source-idx=\"10\">[10]</a></sup>.</p>\n<p>Agent identities in Entra do not have credentials of their own; they rely on the agent identity blueprint to acquire tokens on their behalf, and they only authenticate using federated identity credentials<sup class=\"bp-cite\"><a href=\"#source-11\" data-source-idx=\"11\">[11]</a></sup>. This is the right model: credentials live in the blueprint, not on the agent, so a compromised agent cannot exfiltrate its own keys.</p>\n<p>Microsoft Agent 365, generally available from May 1, 2026, gives each AI agent its own Entra Agent ID for identity, lifecycle, and access management, and integrates with Conditional Access, identity protection, and Microsoft Purview<sup class=\"bp-cite\"><a href=\"#source-12\" data-source-idx=\"12\">[12]</a></sup>. Third-party agents from AWS Bedrock, n8n, and other frameworks can be onboarded via workload identity federation - no platform-specific credential management required.</p>\n<p>The honest limitation: Entra Agent ID is a strong solution if your agent estate lives inside the Microsoft ecosystem. For organizations running heterogeneous stacks - Anthropic, AWS, open-source frameworks, and custom-built agents - the governance surface extends well beyond what any single IdP can cover.</p>\n<h3>CSA Agentic Trust Framework and CSAI Foundation</h3>\n<p>The Cloud Security Alliance has been the most prolific standards producer in this space. The CSA published the Agentic Trust Framework (ATF) on February 2, 2026 - the first governance specification applying Zero Trust principles to autonomous AI agents with a structured maturity model<sup class=\"bp-cite\"><a href=\"#source-13\" data-source-idx=\"13\">[13]</a></sup>. The ATF was co-authored by John Kindervag, the original creator of Zero Trust.</p>\n<p>A companion survey of 285 IT and security professionals makes the urgency concrete: 84% of organizations cannot pass a compliance audit focused on agent behavior or access controls, and only 23% have a formal agent identity strategy<sup class=\"bp-cite\"><a href=\"#source-14\" data-source-idx=\"14\">[14]</a></sup>.</p>\n<p>The CSA&#39;s MAESTRO threat modeling framework explicitly names <strong>agent impersonation</strong> as a distinct threat class - malicious actors deceiving users or other agents by impersonating legitimate AI agents. The prescribed mitigations are trusted agent registries, cryptographic agent identities, and short-lived OAuth/OIDC tokens scoped to the intersection of what the agent is allowed to do AND what the delegating user is allowed to do. An AND gate, not an OR gate.</p>\n<p>In March 2026, the CSA launched the CSAI Foundation at RSAC 2026, a new 501(c)3 dedicated exclusively to AI security, with a 2026 mission of &quot;Securing the Agentic Control Plane&quot; - governing identity, authorization, orchestration, runtime behavior, and trust assurance for autonomous AI agent ecosystems<sup class=\"bp-cite\"><a href=\"#source-15\" data-source-idx=\"15\">[15]</a></sup>.</p>\n<hr>\n<h2>The Player Map: Four Categories, Different Strengths</h2>\n<p>The vendor landscape has fragmented into four distinct categories. Understanding what each does - and doesn&#39;t do - is essential before buying.</p>\n<div class=\"bp-component bp-data-table\"><div class=\"bp-data-table__title\">AI Agent Identity: Vendor Category Comparison</div><table><thead><tr><th>Category</th><th>Examples</th><th>Core Strength</th><th>Key Gap</th></tr></thead><tbody><tr><td>Identity Providers extending to agents</td><td>Microsoft Entra Agent ID, Okta (MCP server + Auth for MCP), Auth0</td><td>Standards-based auth (OAuth 2.1/OIDC), existing enterprise trust, lifecycle hooks</td><td>Ecosystem lock-in; heterogeneous agent stacks require federation workarounds</td></tr><tr><td>NHI Security Specialists</td><td>Oasis Security, Entro, Teleport</td><td>Discovery, secrets rotation, posture management for service accounts and API keys</td><td>Agent governance is identity-discovery-led, not runtime-enforcement-led; agents treated as NHI subset, not first-class</td></tr><tr><td>MCP Gateways</td><td>Arcade, TrueFoundry, Cloudflare Agents SDK</td><td>Runtime authorization at the tool-call level; per-session ephemeral credentials; low-latency enforcement</td><td>Closed ecosystems; governance doesn&#39;t extend to human identities or non-MCP agents</td></tr><tr><td>IGA Platforms governing agents + humans</td><td>Iden, SailPoint (Agent Identity Security add-on), ServiceNow/Veza</td><td>Unified lifecycle governance across human and non-human identities; policy-driven provisioning and deprovisioning; access reviews</td><td>Legacy IGA platforms bolt on agent support; depth and automation vary significantly</td></tr></tbody></table></div>\n\n\n\n<p>A few notes on the landscape:</p>\n<p><strong>Identity providers</strong> are moving fast. Auth0&#39;s &quot;Auth for MCP&quot; became generally available on May 6, 2026, and Okta released its own MCP server as a secure protocol abstraction layer enabling AI agents to interact with Okta&#39;s scoped management APIs with least-privilege access control enforced at each tool call<sup class=\"bp-cite\"><a href=\"#source-2\" data-source-idx=\"2\">[2]</a></sup>. These are authentication solutions. They do not govern the full identity lifecycle.</p>\n<p><strong>NHI specialists</strong> have the discovery story right. Veza&#39;s 2026 State of Identity and Access report found that a mere 0.01% of non-human identities control 80% of cloud resources, while the average worker holds 96,000 entitlements<sup class=\"bp-cite\"><a href=\"#source-16\" data-source-idx=\"16\">[16]</a></sup>. Knowing that is valuable. Governing it requires more than a posture dashboard.</p>\n<p><strong>MCP gateways</strong> solve the runtime enforcement problem elegantly for agents you build inside their ecosystem. The problem is coverage: only 23.7% of organizations use their existing IAM/IdP as an authorization server for their agentic MCP infrastructure<sup class=\"bp-cite\"><a href=\"#source-3\" data-source-idx=\"3\">[3]</a></sup>. The rest are running disconnected auth stacks.</p>\n<p><strong>IGA platforms</strong> are the natural home for agent governance - if they&#39;ve actually built it. SailPoint expanded Agent Identity Security connectors in 2026 to include SaaS versions of Salesforce, ServiceNow, and Snowflake, but governance of agent identities requires a separate Agent Identity Security license<sup class=\"bp-cite\"><a href=\"#source-17\" data-source-idx=\"17\">[17]</a></sup>. Legacy IGA vendors are adding agent support as a module. That&#39;s not the same as designing for it from the start.</p>\n<hr>\n<h2>The Honest Gaps</h2>\n<p>Standards are immature. The MCP OAuth 2.1 profile is solid for authentication but has no standardized audit trail format. MCP-I / KYA-OS is in active community development with sparse production implementations. The CSA ATF is a governance framework, not an enforcement tool.</p>\n<p>The monitoring gap is severe. Only 14.4% of organizations have achieved full IT and security approval for their entire agent fleet, and 88% of organizations reported confirmed or suspected AI agent security incidents in the past year<sup class=\"bp-cite\"><a href=\"#source-18\" data-source-idx=\"18\">[18]</a></sup>. Only 21.9% of organizations currently treat AI agents as independent, identity-bearing entities within their security model<sup class=\"bp-cite\"><a href=\"#source-3\" data-source-idx=\"3\">[3]</a></sup>. Most still treat agents as extensions of human users or generic service accounts.</p>\n<p>The over-permissioning problem is structural. 70% of security leaders say AI systems have more access than a human in the same role, and 67% of organizations rely on static credentials for AI systems<sup class=\"bp-cite\"><a href=\"#source-19\" data-source-idx=\"19\">[19]</a></sup>. Static, long-lived credentials are the opposite of what every framework recommends. They persist after an agent&#39;s task is complete, survive offboarding, and create the same orphaned-account problem that has plagued human identity governance for decades - just at machine speed.</p>\n<p>The CSA-Oasis State of NHI and AI Security 2026 found that 51% of organizations cite over-permissioned access as a top NHI pain point, and 78% have no documented policy for creating or removing AI identities<sup class=\"bp-cite\"><a href=\"#source-20\" data-source-idx=\"20\">[20]</a></sup>.</p>\n<figure class=\"bp-component bp-image\" data-component-id=\"3a13a849-8155-45c7-8c5c-27430a712e8c\"><img src=\"https://aqynbjfkcfnrqkhzbzxl.supabase.co/storage/v1/object/public/cms-assets/5ed37a7f-297e-48c5-b007-40268093b3fa/6c51af9e-cfc7-42f5-958f-0a84c680cb69.jpg\" alt=\"Isometric diagram showing two parallel governance tracks: on the left, a structured lifecycle flow for human employees (hire, provision, review, offboard) with clear checkpoints; on the right, a chaotic tangle of AI agents with no lifecycle, overlapping permissions, and missing audit trails - visually contrasting governed vs. ungoverned identity\" loading=\"lazy\" /></figure>\n\n\n\n<hr>\n<h2>What IGA Looks Like When It&#39;s Built for This</h2>\n<p>The governance problem for AI agents is structurally identical to the governance problem for human identities - and for the same reason that IGA exists: access sprawl, orphaned accounts, over-permissioning, and the inability to answer &quot;who has access to what, and should they?&quot; at any given moment.</p>\n<p>The difference is velocity and scale. NHIs outnumber human identities 17 to 1 in the average enterprise, and the NHI population grew 44% year-over-year between 2024 and 2025<sup class=\"bp-cite\"><a href=\"#source-21\" data-source-idx=\"21\">[21]</a></sup>. AI agents are the fastest-growing segment within that already-exploding category. Quarterly access reviews cannot keep pace. Neither can spreadsheets.</p>\n<p>What&#39;s needed is a single governance plane that treats human and non-human identities with the same policy engine, the same lifecycle automation, and the same access review workflows - without requiring a separate module, a separate license, or a separate team.</p>\n<p>That&#39;s the design principle behind Iden. Rather than bolting agent governance onto a human-centric IGA platform, or treating agents as a subset of NHI discovery, Iden governs all identity types - employees, contractors, service accounts, bots, and AI agents - through the same policy-driven lifecycle engine. Fine-grained control at the channel, repository, and project level means an agent gets exactly the access its task requires, and that access is revoked when the task is done. No standing permissions. No orphaned agent accounts.</p>\n<p>For organizations evaluating where AI agent governance fits in their stack, the <a href=\"/blog/12-best-iga-vendors-2026\">12 Best IGA Vendors in 2026</a> post maps the full landscape, and our <a href=\"/blog/nhi-explosion-non-human-identity\">NHI explosion piece</a> covers the scale of the underlying problem in detail.</p>\n<hr>\n<h2>How to Evaluate Agent Identity Capabilities Today</h2>\n<p>The standards are immature, the vendor claims are ahead of the implementations, and the threat is real. Here is a practical evaluation framework for buyers.</p>\n<div class=\"bp-component bp-steps\"><div class=\"bp-step\"><div class=\"bp-step__marker\"><span class=\"bp-step__num\">1</span><span class=\"bp-step__line\"></span></div><div class=\"bp-step__content\"><strong>Inventory your agent estate before you buy anything</strong><p>You cannot govern what you cannot see. Start with a full discovery pass: which agents are running, who deployed them, what credentials they hold, and what systems they can reach. Shadow agents — those with no registry entry, no assigned owner, and no managed identity — are your highest-risk population. Treat them as Critical findings.</p></div></div><div class=\"bp-step\"><div class=\"bp-step__marker\"><span class=\"bp-step__num\">2</span><span class=\"bp-step__line\"></span></div><div class=\"bp-step__content\"><strong>Demand short-lived, scoped credentials — not API keys</strong><p>Any platform that relies on shared API keys or long-lived static credentials for agent authentication is not a governance solution. Require per-session ephemeral tokens scoped to the specific task, with automatic teardown at end of session. This is the single highest-leverage control against prompt injection and credential theft.</p></div></div><div class=\"bp-step\"><div class=\"bp-step__marker\"><span class=\"bp-step__num\">3</span><span class=\"bp-step__line\"></span></div><div class=\"bp-step__content\"><strong>Verify the AND gate, not the OR gate</strong><p>An agent should only be able to do what the agent is authorized to do AND what the delegating user is authorized to do — not the union of both. Service accounts that inherit broad employee credentials create authorization bypass vulnerabilities. Confirm that your chosen platform enforces the intersection, not the superset.</p></div></div><div class=\"bp-step\"><div class=\"bp-step__marker\"><span class=\"bp-step__num\">4</span><span class=\"bp-step__line\"></span></div><div class=\"bp-step__content\"><strong>Require a full audit trail at the tool-call level</strong><p>Logging that an agent &#39;ran&#39; is not an audit trail. You need: which agent, which user delegated, which tool was called, with what arguments, what data was accessed, and what the result was. The EU AI Act&#39;s transparency provisions take effect August 2, 2026. If your platform cannot produce this log on demand, it cannot support compliance.</p></div></div><div class=\"bp-step\"><div class=\"bp-step__marker\"><span class=\"bp-step__num\">5</span><span class=\"bp-step__line\"></span></div><div class=\"bp-step__content\"><strong>Evaluate lifecycle governance, not just runtime enforcement</strong><p>Runtime authorization at the tool-call level is necessary but not sufficient. You also need: agent registration and approval workflows before deployment, access reviews on the same cadence as human identities, and automated deprovisioning when an agent is retired. Ask vendors specifically how they handle agent offboarding — most have no answer.</p></div></div><div class=\"bp-step bp-step--last\"><div class=\"bp-step__marker\"><span class=\"bp-step__num\">6</span></div><div class=\"bp-step__content\"><strong>Insist on unified governance across human and non-human identities</strong><p>Separate tools for human IGA and agent governance create blind spots at the seams. An agent acting on behalf of a human should be governed in the same plane as that human — same policy engine, same access review, same audit log. If your IGA platform treats agents as a bolt-on module, you have a coverage gap.</p></div></div></div>\n\n\n\n<hr>\n<h2>The Bottom Line</h2>\n<p>The 2026 standards landscape for AI agent identity is real and moving fast - MCP OAuth 2.1 under Linux Foundation governance, MCP-I / KYA-OS at the DIF, Microsoft Entra Agent ID in GA, and the CSA Agentic Trust Framework providing the governance vocabulary. These are genuine milestones.</p>\n<p>But standards are not implementations. Only 3% of organizations have automated, machine-speed controls governing AI behavior<sup class=\"bp-cite\"><a href=\"#source-19\" data-source-idx=\"19\">[19]</a></sup>. The gap between what the frameworks prescribe and what organizations have actually deployed is enormous.</p>\n<p>The organizations that close that gap fastest will be the ones that stop treating agent governance as a separate problem from identity governance. Agents are identities. They need the same lifecycle controls, the same access reviews, the same deprovisioning workflows, and the same audit trails as every other identity in your environment - just with shorter-lived credentials and faster policy enforcement.</p>\n<p>That&#39;s not a new category of tooling. It&#39;s IGA, built for the full population of identities your enterprise actually runs.</p>\n<div class=\"bp-component bp-widget\"><div class=\"inline-widget-container\" data-island=\"widget\" data-widget-id=\"e5afe1d7-cb52-4acd-8a56-b6970002b90b\" data-widget-lang=\"en\"></div></div>\n\n\n</div></div><div class=\"prose-body mt-12 border-t border-[var(--blog-border)] pt-8\"><ol class=\"bp-sources\"><li id=\"source-1\"><a href=\"https://www.microsoft.com/en-us/security/blog/2026/02/10/80-of-fortune-500-use-active-ai-agents-observability-governance-and-security-shape-the-new-frontier/\" target=\"_blank\" rel=\"noopener nofollow\">microsoft.com — 80 of fortune 500 use active ai agents observability governance and security shape the new frontier</a></li><li id=\"source-2\"><a href=\"https://www.marktechpost.com/2026/05/25/best-authentication-platforms-for-ai-agents-and-mcp-servers-in-2026/\" target=\"_blank\" rel=\"noopener nofollow\">marktechpost.com — Best authentication platforms for ai agents and mcp servers in 2026</a></li><li id=\"source-3\"><a href=\"https://www.gravitee.io/state-of-ai-agent-security\" target=\"_blank\" rel=\"noopener nofollow\">gravitee.io — State of ai agent security</a></li><li id=\"source-4\"><a href=\"https://workos.com/blog/everything-your-team-needs-to-know-about-mcp-in-2026/\" target=\"_blank\" rel=\"noopener nofollow\">workos.com — Everything your team needs to know about mcp in 2026</a></li><li id=\"source-5\"><a href=\"https://aaif.io/blog/mcp-is-now-enterprise-infrastructure-everything-that-happened-at-mcp-dev-summit-north-america-2026/\" target=\"_blank\" rel=\"noopener nofollow\">aaif.io — Mcp is now enterprise infrastructure everything that happened at mcp dev summit north america 2026</a></li><li id=\"source-6\"><a href=\"https://www.prefect.io/resources/mcp-oauth\" target=\"_blank\" rel=\"noopener nofollow\">prefect.io — Mcp oauth</a></li><li id=\"source-7\"><a href=\"https://epinium.com/en/blog/model-context-protocol-enterprise-guide/\" target=\"_blank\" rel=\"noopener nofollow\">epinium.com — Model context protocol enterprise guide</a></li><li id=\"source-8\"><a href=\"https://www.vouched.id/learn/vouched-donates-mcp-i-identity-framework-to-the-decentralized-identity-foundation-to-advance-trust-and-security-for-ai-agents\" target=\"_blank\" rel=\"noopener nofollow\">vouched.id — Vouched donates mcp i identity framework to the decentralized identity foundation to advance trust and security for ai agents</a></li><li id=\"source-9\"><a href=\"https://blog.identity.foundation/why-dif-said-yes-to-mcp-i/\" target=\"_blank\" rel=\"noopener nofollow\">blog.identity.foundation — Why dif said yes to mcp i</a></li><li id=\"source-10\"><a href=\"https://learn.microsoft.com/en-us/entra/agent-id/what-is-microsoft-entra-agent-id\" target=\"_blank\" rel=\"noopener nofollow\">learn.microsoft.com — What is microsoft entra agent id</a></li><li id=\"source-11\"><a href=\"https://learn.microsoft.com/en-us/entra/agent-id/agent-identities\" target=\"_blank\" rel=\"noopener nofollow\">learn.microsoft.com — Agent identities</a></li><li id=\"source-12\"><a href=\"https://www.microsoft.com/en-us/security/blog/2026/03/20/secure-agentic-ai-end-to-end/\" target=\"_blank\" rel=\"noopener nofollow\">microsoft.com — Secure agentic ai end to end</a></li><li id=\"source-13\"><a href=\"https://cloudsecurityalliance.org/blog/2026/02/02/the-agentic-trust-framework-zero-trust-governance-for-ai-agents\" target=\"_blank\" rel=\"noopener nofollow\">cloudsecurityalliance.org — The agentic trust framework zero trust governance for ai agents</a></li><li id=\"source-14\"><a href=\"https://www.oktsec.com/blog/csa-agentic-trust-framework-zero-trust-agents/\" target=\"_blank\" rel=\"noopener nofollow\">oktsec.com — Csa agentic trust framework zero trust agents</a></li><li id=\"source-15\"><a href=\"https://cloudsecurityalliance.org/press-releases/2026/03/23/csa-securing-the-agentic-control-plane\" target=\"_blank\" rel=\"noopener nofollow\">cloudsecurityalliance.org — Csa securing the agentic control plane</a></li><li id=\"source-16\"><a href=\"https://veza.com/blog/forrester-recognizes-veza-for-iga-ispm-and-nhi-ai-identity-management/\" target=\"_blank\" rel=\"noopener nofollow\">veza.com — Forrester recognizes veza for iga ispm and nhi ai identity management</a></li><li id=\"source-17\"><a href=\"https://aimultiple.com/iga-solutions\" target=\"_blank\" rel=\"noopener nofollow\">aimultiple.com — Iga solutions</a></li><li id=\"source-18\"><a href=\"https://www.gravitee.io/blog/state-of-ai-agent-security-2026-report-when-adoption-outpaces-control\" target=\"_blank\" rel=\"noopener nofollow\">gravitee.io — State of ai agent security 2026 report when adoption outpaces control</a></li><li id=\"source-19\"><a href=\"https://www.cybersecstats.com/ai-cybersecurity-statistics-2026-q1-q2/\" target=\"_blank\" rel=\"noopener nofollow\">cybersecstats.com — Ai cybersecurity statistics 2026 q1 q2</a></li><li id=\"source-20\"><a href=\"https://secureflo.net/ai-agent-identity-management-a-2026-ciso-playbook/\" target=\"_blank\" rel=\"noopener nofollow\">secureflo.net — Ai agent identity management a 2026 ciso playbook</a></li><li id=\"source-21\"><a href=\"https://labs.cloudsecurityalliance.org/research/csa-whitepaper-nonhuman-identity-agentic-ai-governance-v1-cs/\" target=\"_blank\" rel=\"noopener nofollow\">labs.cloudsecurityalliance.org — Csa whitepaper nonhuman identity agentic ai governance v1 cs</a></li></ol></div></div><section class=\"mx-auto mt-20 max-w-[620px] border-t border-[var(--blog-border)] px-6 pt-12 sm:px-0\"><h2 class=\"mb-6 font-mono text-[11px] uppercase tracking-[0.22em] text-[var(--blog-faint)]\">Related reading</h2><div class=\"grid gap-6 sm:grid-cols-2\"><a class=\"group flex flex-col overflow-hidden rounded-xl border border-[var(--blog-border)] bg-[var(--blog-surface)] transition-colors hover:border-[color-mix(in_srgb,var(--blog-accent)_50%,var(--blog-border))]\" href=\"/en/blog/segregation-of-duties-guide-entitlement-level\"><div class=\"relative aspect-[16/9] overflow-hidden\"><div class=\"relative h-full w-full overflow-hidden transition-transform duration-500 group-hover:scale-[1.04]\"><svg class=\"absolute inset-0 h-full w-full\" viewBox=\"0 0 320 200\" preserveAspectRatio=\"xMidYMid slice\" aria-hidden=\"true\"><defs><linearGradient id=\"blog-grad-segregation-of-duties-guide-entitlement-level\" x1=\"50%\" y1=\"0%\" x2=\"50%\" y2=\"100%\"><stop offset=\"0%\" stop-color=\"#D4DCDA\"></stop><stop offset=\"100%\" stop-color=\"#47585C\"></stop></linearGradient><filter id=\"blog-grain-segregation-of-duties-guide-entitlement-level\" x=\"0\" y=\"0\" width=\"100%\" height=\"100%\"><feTurbulence type=\"fractalNoise\" baseFrequency=\"0.9\" numOctaves=\"2\" seed=\"6543\" result=\"noise\"></feTurbulence><feColorMatrix in=\"noise\" type=\"matrix\" values=\"0 0 0 0 1 0 0 0 0 1 0 0 0 0 1 0 0 0 0.45 0\"></feColorMatrix></filter><pattern id=\"blog-dither-segregation-of-duties-guide-entitlement-level\" patternUnits=\"userSpaceOnUse\" width=\"4\" height=\"4\"><circle cx=\"1.5\" cy=\"1.5\" r=\"0.3\" fill=\"#000\" fill-opacity=\"0.06\"></circle></pattern></defs><rect width=\"320\" height=\"200\" fill=\"url(#blog-grad-segregation-of-duties-guide-entitlement-level)\"></rect><rect width=\"320\" height=\"220\" filter=\"url(#blog-grain-segregation-of-duties-guide-entitlement-level)\" style=\"mix-blend-mode:overlay\"></rect><rect width=\"320\" height=\"200\" fill=\"url(#blog-dither-segregation-of-duties-guide-entitlement-level)\"></rect></svg><svg viewBox=\"0 0 256 256\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"6\" class=\"absolute left-5 top-5 h-9 w-9 pointer-events-none\" style=\"color:#1c1c1c;opacity:0.78\" aria-hidden=\"true\"><path d=\"M10 128H246M71 69L10 128L71 187M186 187L246 128L186 69\"></path></svg></div><div class=\"absolute right-3 top-3\"><span class=\"inline-flex items-center rounded-full border border-[var(--blog-border)] bg-[color-mix(in_srgb,var(--blog-bg)_60%,transparent)] px-2.5 py-0.5 font-mono text-[10px] uppercase tracking-[0.18em] text-[var(--blog-muted)]\">Segregation of duties</span></div></div><div class=\"flex flex-1 flex-col gap-2.5 p-5\"><h3 class=\"text-[17px] font-normal leading-snug tracking-tight text-white\"><span class=\"blog-underline\">The Definitive Guide to Segregation of Duties (SoD): From Policy to Entitlement-Level Enforcement</span></h3><p class=\"line-clamp-2 text-sm leading-relaxed text-[var(--blog-muted)]\">A complete SoD guide: definition, toxic combinations, framework mapping (SOC 2, ISO 27001, SOX, PCI DSS), the conflict matrix, and why role-level SoD misses the real violations hiding inside broad entitlements.</p><div class=\"mt-auto flex items-center gap-2 pt-2 text-xs text-[var(--blog-faint)]\"><span class=\"tabular-nums\">Jul 24, 2026</span></div></div></a><a class=\"group flex flex-col overflow-hidden rounded-xl border border-[var(--blog-border)] bg-[var(--blog-surface)] transition-colors hover:border-[color-mix(in_srgb,var(--blog-accent)_50%,var(--blog-border))]\" href=\"/en/blog/third-party-contractor-access-audit-evidence\"><div class=\"relative aspect-[16/9] overflow-hidden\"><div class=\"relative h-full w-full overflow-hidden transition-transform duration-500 group-hover:scale-[1.04]\"><svg class=\"absolute inset-0 h-full w-full\" viewBox=\"0 0 320 200\" preserveAspectRatio=\"xMidYMid slice\" aria-hidden=\"true\"><defs><linearGradient id=\"blog-grad-third-party-contractor-access-audit-evidence\" x1=\"50%\" y1=\"0%\" x2=\"50%\" y2=\"100%\"><stop offset=\"0%\" stop-color=\"#E5E4E6\"></stop><stop offset=\"100%\" stop-color=\"#4D80E6\"></stop></linearGradient><filter id=\"blog-grain-third-party-contractor-access-audit-evidence\" x=\"0\" y=\"0\" width=\"100%\" height=\"100%\"><feTurbulence type=\"fractalNoise\" baseFrequency=\"0.9\" numOctaves=\"2\" seed=\"4201\" result=\"noise\"></feTurbulence><feColorMatrix in=\"noise\" type=\"matrix\" values=\"0 0 0 0 1 0 0 0 0 1 0 0 0 0 1 0 0 0 0.45 0\"></feColorMatrix></filter><pattern id=\"blog-dither-third-party-contractor-access-audit-evidence\" patternUnits=\"userSpaceOnUse\" width=\"4\" height=\"4\"><circle cx=\"1.5\" cy=\"1.5\" r=\"0.3\" fill=\"#000\" fill-opacity=\"0.06\"></circle></pattern></defs><rect width=\"320\" height=\"200\" fill=\"url(#blog-grad-third-party-contractor-access-audit-evidence)\"></rect><rect width=\"320\" height=\"220\" filter=\"url(#blog-grain-third-party-contractor-access-audit-evidence)\" style=\"mix-blend-mode:overlay\"></rect><rect width=\"320\" height=\"200\" fill=\"url(#blog-dither-third-party-contractor-access-audit-evidence)\"></rect></svg><svg viewBox=\"0 0 256 256\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"6\" class=\"absolute left-5 top-5 h-9 w-9 pointer-events-none\" style=\"color:#1c1c1c;opacity:0.78\" aria-hidden=\"true\"><path d=\"M128 8V88M246.5 9.5L156.697 99.3026M168 128H248M246.5 246.5L156.697 156.697M128 168V248M9.5 246.5L99.3026 156.697M8 128H88M9.5 9.5L99.3026 99.3026\"></path></svg></div><div class=\"absolute right-3 top-3\"><span class=\"inline-flex items-center rounded-full border border-[var(--blog-border)] bg-[color-mix(in_srgb,var(--blog-bg)_60%,transparent)] px-2.5 py-0.5 font-mono text-[10px] uppercase tracking-[0.18em] text-[var(--blog-muted)]\">Third-party access audit trail</span></div></div><div class=\"flex flex-1 flex-col gap-2.5 p-5\"><h3 class=\"text-[17px] font-normal leading-snug tracking-tight text-white\"><span class=\"blog-underline\">Third-Party Access Is Your Audit&#x27;s Weakest Link - Here&#x27;s How to Fix It</span></h3><p class=\"line-clamp-2 text-sm leading-relaxed text-[var(--blog-muted)]\">Contractors and partners don&#x27;t live in your HRIS - so they fall outside JML automation and become orphaned-access hotspots. Here&#x27;s the evidence every auditor demands and how to produce it.</p><div class=\"mt-auto flex items-center gap-2 pt-2 text-xs text-[var(--blog-faint)]\"><span class=\"tabular-nums\">Jul 17, 2026</span></div></div></a><a class=\"group flex flex-col overflow-hidden rounded-xl border border-[var(--blog-border)] bg-[var(--blog-surface)] transition-colors hover:border-[color-mix(in_srgb,var(--blog-accent)_50%,var(--blog-border))]\" href=\"/en/blog/legacy-iga-migration-guide-checklist\"><div class=\"relative aspect-[16/9] overflow-hidden\"><div class=\"relative h-full w-full overflow-hidden transition-transform duration-500 group-hover:scale-[1.04]\"><svg class=\"absolute inset-0 h-full w-full\" viewBox=\"0 0 320 200\" preserveAspectRatio=\"xMidYMid slice\" aria-hidden=\"true\"><defs><linearGradient id=\"blog-grad-legacy-iga-migration-guide-checklist\" x1=\"50%\" y1=\"0%\" x2=\"50%\" y2=\"100%\"><stop offset=\"0%\" stop-color=\"#D4DCDA\"></stop><stop offset=\"100%\" stop-color=\"#949495\"></stop></linearGradient><filter id=\"blog-grain-legacy-iga-migration-guide-checklist\" x=\"0\" y=\"0\" width=\"100%\" height=\"100%\"><feTurbulence type=\"fractalNoise\" baseFrequency=\"0.9\" numOctaves=\"2\" seed=\"349\" result=\"noise\"></feTurbulence><feColorMatrix in=\"noise\" type=\"matrix\" values=\"0 0 0 0 1 0 0 0 0 1 0 0 0 0 1 0 0 0 0.45 0\"></feColorMatrix></filter><pattern id=\"blog-dither-legacy-iga-migration-guide-checklist\" patternUnits=\"userSpaceOnUse\" width=\"4\" height=\"4\"><circle cx=\"1.5\" cy=\"1.5\" r=\"0.3\" fill=\"#000\" fill-opacity=\"0.06\"></circle></pattern></defs><rect width=\"320\" height=\"200\" fill=\"url(#blog-grad-legacy-iga-migration-guide-checklist)\"></rect><rect width=\"320\" height=\"220\" filter=\"url(#blog-grain-legacy-iga-migration-guide-checklist)\" style=\"mix-blend-mode:overlay\"></rect><rect width=\"320\" height=\"200\" fill=\"url(#blog-dither-legacy-iga-migration-guide-checklist)\"></rect></svg><svg viewBox=\"0 0 256 256\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"6\" class=\"absolute left-5 top-5 h-9 w-9 pointer-events-none\" style=\"color:#1c1c1c;opacity:0.78\" aria-hidden=\"true\"><path d=\"M10 128C10 193.17 62.8304 246 128 246C193.17 246 246 193.17 246 128C246 62.8304 193.17 10 128 10C62.8304 10 10 62.8304 10 128ZM10 128L246 128.123M39.4543 50H216.546M39.4543 206H216.546\"></path></svg></div><div class=\"absolute right-3 top-3\"><span class=\"inline-flex items-center rounded-full border border-[var(--blog-border)] bg-[color-mix(in_srgb,var(--blog-bg)_60%,transparent)] px-2.5 py-0.5 font-mono text-[10px] uppercase tracking-[0.18em] text-[var(--blog-muted)]\">Legacy IGA migration</span></div></div><div class=\"flex flex-1 flex-col gap-2.5 p-5\"><h3 class=\"text-[17px] font-normal leading-snug tracking-tight text-white\"><span class=\"blog-underline\">The Legacy IGA Migration Guide: Real Costs, Realistic Timelines, and a Step-by-Step Checklist</span></h3><p class=\"line-clamp-2 text-sm leading-relaxed text-[var(--blog-muted)]\">Replacing SailPoint IIQ, Oracle, IBM, or One Identity feels terrifying. This guide breaks down the real migration costs, honest timelines, and a step-by-step checklist to de-risk the switch.</p><div class=\"mt-auto flex items-center gap-2 pt-2 text-xs text-[var(--blog-faint)]\"><span class=\"tabular-nums\">Jul 13, 2026</span></div></div></a></div></section></article><!--$--><!--/$--></main><div class=\"border-t border-neutral-800\"><footer class=\"w-full bg-neutral-900 overflow-hidden\"><div class=\"px-4 pt-32 pb-3 flex items-center justify-between gap-4\"><span class=\"text-base text-neutral-500 shrink-0 uppercase tracking-tight\">© 2026 IDENHQ, INC.</span><div class=\"hidden sm:flex flex-wrap items-center justify-center gap-x-3 gap-y-1\"><span class=\"flex items-center gap-3\"><a href=\"/charter\" class=\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\">Charter</a></span><span class=\"flex items-center gap-3\"><span class=\"text-xl select-none text-neutral-700\">·</span><a href=\"/field-notes\" class=\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\">Field Notes</a></span><span class=\"flex items-center gap-3\"><span class=\"text-xl select-none text-neutral-700\">·</span><a href=\"/vs\" class=\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\">Versus</a></span><span class=\"flex items-center gap-3\"><span class=\"text-xl select-none text-neutral-700\">·</span><a href=\"/faq\" class=\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\">FAQ</a></span><span class=\"flex items-center gap-3\"><span class=\"text-xl select-none text-neutral-700\">·</span><a href=\"https://trust.idenhq.com\" class=\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\">Trust</a></span><span class=\"flex items-center gap-3\"><span class=\"text-xl select-none text-neutral-700\">·</span><a class=\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\" href=\"/en/privacy-policy\">Privacy</a></span><span class=\"flex items-center gap-3\"><span class=\"text-xl select-none text-neutral-700\">·</span><a class=\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\" href=\"/en/terms-of-service\">Terms</a></span><span class=\"flex items-center gap-3\"><span class=\"text-xl select-none text-neutral-700\">·</span><a class=\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\" href=\"/en/legal-notice\">Legal Notice</a></span><span class=\"flex items-center gap-3\"><span class=\"text-xl select-none text-neutral-700\">·</span><button class=\"text-base text-neutral-500 transition-colors hover:text-neutral-300\">Cookies</button></span></div><span class=\"text-base text-neutral-500 shrink-0 uppercase tracking-tight\">Backed by<!-- --> <a href=\"https://www.accel.com\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"hover:text-neutral-300 transition-colors\">Accel</a></span></div><div class=\"pt-1 pb-0 select-none overflow-hidden\"><svg viewBox=\"0.55 0 99.06 29.07\" preserveAspectRatio=\"xMinYMin meet\" fill=\"none\" xmlns=\"http://www.w3.org/2000/svg\" class=\"w-full h-auto block\" style=\"fill:#262626\"><path fill-rule=\"evenodd\" clip-rule=\"evenodd\" d=\"M0.555176 29.1416H25.1243V18.9512H18.6608C18.0696 18.9512 17.5903 18.4719 17.5903 17.8807V15.8334C17.5903 15.2422 18.0696 14.763 18.6608 14.763H25.1243V0.927339H21.6923V4.5707H14.8833V0.927339H10.7962V4.5707H3.98717L3.98717 0.927339H0.555176L0.555176 14.763H7.01869C7.60988 14.763 8.08913 15.2422 8.08913 15.8334V17.8807C8.08913 18.4719 7.60988 18.9512 7.01869 18.9512H0.555176L0.555176 29.1416ZM3.98717 8.00269H21.6923V10.6758H19.3159C16.4674 10.6758 14.1583 12.9849 14.1583 15.8334V17.8807C14.1583 20.7292 16.4674 23.0383 19.3159 23.0383H21.6923V25.7096H3.98717L3.98717 23.0383H6.36355C9.212 23.0383 11.5211 20.7292 11.5211 17.8807V15.8334C11.5211 12.9849 9.212 10.6758 6.36355 10.6758H3.98717L3.98717 8.00269Z\"></path><path d=\"M33.0527 0.880305L36.984 0.880305V5.20874H33.0527V0.880305ZM33.0527 8.82239H36.984V29.0747H33.0527V8.82239ZM47.8585 29.5512C42.6564 29.5512 39.281 25.1434 39.281 18.9883C39.281 12.8729 42.6564 8.42529 47.8585 8.42529C50.8368 8.42529 53.0209 9.81515 54.2519 12.0786V0.880305H58.2229V29.0747H54.2519V25.8979C53.0209 28.1614 50.8368 29.5512 47.8585 29.5512ZM48.9307 26.4538C52.4252 26.4538 54.371 23.3564 54.371 18.9883C54.371 14.6201 52.4252 11.5227 48.9307 11.5227C45.4759 11.5227 43.4904 14.6201 43.4904 18.9883C43.4904 23.3564 45.4759 26.4538 48.9307 26.4538ZM60.4647 18.9485C60.4647 12.9126 64.396 8.42529 70.432 8.42529C76.7063 8.42529 80.4787 13.4288 80.2008 19.7825H64.5946C64.7534 23.8726 66.8978 26.5332 70.5909 26.5332C73.45 26.5332 75.0384 24.786 75.7929 22.6416H79.8037C78.6918 26.6524 75.4752 29.5512 70.5511 29.5512C64.4754 29.5512 60.4647 25.064 60.4647 18.9485ZM76.1106 17.0424C75.5547 13.6671 73.6088 11.4433 70.432 11.4433C67.2155 11.4433 65.2697 13.6274 64.7137 17.0424H76.1106ZM82.4131 8.82239H86.3047V12.1978C87.3769 10.252 89.3624 8.42529 92.9363 8.42529C97.3045 8.42529 99.6077 11.0065 99.6077 15.0569V29.0747H95.6764V15.8114C95.6764 13.1905 94.485 11.6021 91.4273 11.6021C88.5682 11.6021 86.3444 13.8259 86.3444 17.3998V29.0747H82.4131V8.82239Z\"></path></svg></div></footer></div></div><script src=\"/_next/static/chunks/0oqqtf7q0fh8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\" id=\"_R_\" async=\"\"></script><script>(self.__next_f=self.__next_f||[]).push([0])</script><script>self.__next_f.push([1,\"1:\\\"$Sreact.fragment\\\"\\n2:I[65453,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"default\\\"]\\n3:I[92263,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"default\\\"]\\n8:I[58096,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"OutletBoundary\\\"]\\n9:\\\"$Sreact.suspense\\\"\\nc:I[58096,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"ViewportBoundary\\\"]\\ne:I[58096,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"MetadataBoundary\\\"]\\n10:I[17506,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"default\\\",1]\\n15:I[10085,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/15ozypjscxub5.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"default\\\"]\\n19:I[4534,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/15ozypjscxub5.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/08xg.0ckpl~2z.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"\\\"]\\n1b:I[8051,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/15ozypjscxub5.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"default\\\"]\\n1c:I[12924,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/15ozypjscxub5.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"default\\\"]\\n1d:I[23133,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"default\\\"]\\n21:I[63369,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"PostHogProvider\\\"]\\n22:I[99132,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.j\"])</script><script>self.__next_f.push([1,\"s?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"default\\\"]\\n23:I[48504,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"default\\\"]\\n24:I[29950,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"FloatingLangSwitch\\\"]\\n25:I[40244,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"default\\\"]\\n26:I[59255,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"VisitTracker\\\"]\\n27:I[64242,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"Analytics\\\"]\\n:HL[\\\"/_next/static/chunks/08_loej5.wuit.css?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"style\\\"]\\n:HL[\\\"/_next/static/chunks/0-jf1u_rglope.css?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"style\\\"]\\n:HL[\\\"/_next/static/chunks/0_kwzt0c~eysn.css?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"style\\\"]\\n:HL[\\\"/_next/static/media/83afe278b6a6bb3c-s.p.0q-301v4kxxnr.woff2?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"font\\\",{\\\"crossOrigin\\\":\\\"\\\",\\\"type\\\":\\\"font/woff2\\\"}]\\n\"])</script><script>self.__next_f.push([1,\"0:{\\\"P\\\":null,\\\"c\\\":[\\\"\\\",\\\"en\\\",\\\"blog\\\",\\\"ai-agent-identity-management-2026\\\"],\\\"q\\\":\\\"\\\",\\\"i\\\":false,\\\"f\\\":[[[\\\"\\\",{\\\"children\\\":[[\\\"locale\\\",\\\"en\\\",\\\"d\\\",null],{\\\"children\\\":[\\\"blog\\\",{\\\"children\\\":[[\\\"slug\\\",\\\"ai-agent-identity-management-2026\\\",\\\"d\\\",null],{\\\"children\\\":[\\\"__PAGE__\\\",{}]}]}]}]},\\\"$undefined\\\",\\\"$undefined\\\",16],[[\\\"$\\\",\\\"$1\\\",\\\"c\\\",{\\\"children\\\":[[[\\\"$\\\",\\\"script\\\",\\\"script-0\\\",{\\\"src\\\":\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"async\\\":true,\\\"nonce\\\":\\\"$undefined\\\"}],[\\\"$\\\",\\\"script\\\",\\\"script-1\\\",{\\\"src\\\":\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"async\\\":true,\\\"nonce\\\":\\\"$undefined\\\"}]],[\\\"$\\\",\\\"$L2\\\",null,{\\\"parallelRouterKey\\\":\\\"children\\\",\\\"error\\\":\\\"$undefined\\\",\\\"errorStyles\\\":\\\"$undefined\\\",\\\"errorScripts\\\":\\\"$undefined\\\",\\\"template\\\":[\\\"$\\\",\\\"$L3\\\",null,{}],\\\"templateStyles\\\":\\\"$undefined\\\",\\\"templateScripts\\\":\\\"$undefined\\\",\\\"notFound\\\":[[[\\\"$\\\",\\\"title\\\",null,{\\\"children\\\":\\\"404: This page could not be found.\\\"}],[\\\"$\\\",\\\"div\\\",null,{\\\"style\\\":{\\\"fontFamily\\\":\\\"system-ui,\\\\\\\"Segoe UI\\\\\\\",Roboto,Helvetica,Arial,sans-serif,\\\\\\\"Apple Color Emoji\\\\\\\",\\\\\\\"Segoe UI Emoji\\\\\\\"\\\",\\\"height\\\":\\\"100vh\\\",\\\"textAlign\\\":\\\"center\\\",\\\"display\\\":\\\"flex\\\",\\\"flexDirection\\\":\\\"column\\\",\\\"alignItems\\\":\\\"center\\\",\\\"justifyContent\\\":\\\"center\\\"},\\\"children\\\":[\\\"$\\\",\\\"div\\\",null,{\\\"children\\\":[[\\\"$\\\",\\\"style\\\",null,{\\\"dangerouslySetInnerHTML\\\":{\\\"__html\\\":\\\"body{color:#000;background:#fff;margin:0}.next-error-h1{border-right:1px solid rgba(0,0,0,.3)}@media (prefers-color-scheme:dark){body{color:#fff;background:#000}.next-error-h1{border-right:1px solid rgba(255,255,255,.3)}}\\\"}}],[\\\"$\\\",\\\"h1\\\",null,{\\\"className\\\":\\\"next-error-h1\\\",\\\"style\\\":{\\\"display\\\":\\\"inline-block\\\",\\\"margin\\\":\\\"0 20px 0 0\\\",\\\"padding\\\":\\\"0 23px 0 0\\\",\\\"fontSize\\\":24,\\\"fontWeight\\\":500,\\\"verticalAlign\\\":\\\"top\\\",\\\"lineHeight\\\":\\\"49px\\\"},\\\"children\\\":404}],[\\\"$\\\",\\\"div\\\",null,{\\\"style\\\":{\\\"display\\\":\\\"inline-block\\\"},\\\"children\\\":[\\\"$\\\",\\\"h2\\\",null,{\\\"style\\\":{\\\"fontSize\\\":14,\\\"fontWeight\\\":400,\\\"lineHeight\\\":\\\"49px\\\",\\\"margin\\\":0},\\\"children\\\":\\\"This page could not be found.\\\"}]}]]}]}]],[]],\\\"forbidden\\\":\\\"$undefined\\\",\\\"unauthorized\\\":\\\"$undefined\\\"}]]}],{\\\"children\\\":[[\\\"$\\\",\\\"$1\\\",\\\"c\\\",{\\\"children\\\":[[[\\\"$\\\",\\\"link\\\",\\\"0\\\",{\\\"rel\\\":\\\"stylesheet\\\",\\\"href\\\":\\\"/_next/static/chunks/08_loej5.wuit.css?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"precedence\\\":\\\"next\\\",\\\"crossOrigin\\\":\\\"$undefined\\\",\\\"nonce\\\":\\\"$undefined\\\"}],[\\\"$\\\",\\\"link\\\",\\\"1\\\",{\\\"rel\\\":\\\"stylesheet\\\",\\\"href\\\":\\\"/_next/static/chunks/0-jf1u_rglope.css?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"precedence\\\":\\\"next\\\",\\\"crossOrigin\\\":\\\"$undefined\\\",\\\"nonce\\\":\\\"$undefined\\\"}],[\\\"$\\\",\\\"script\\\",\\\"script-0\\\",{\\\"src\\\":\\\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"async\\\":true,\\\"nonce\\\":\\\"$undefined\\\"}],[\\\"$\\\",\\\"script\\\",\\\"script-1\\\",{\\\"src\\\":\\\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"async\\\":true,\\\"nonce\\\":\\\"$undefined\\\"}],[\\\"$\\\",\\\"script\\\",\\\"script-2\\\",{\\\"src\\\":\\\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"async\\\":true,\\\"nonce\\\":\\\"$undefined\\\"}]],\\\"$L4\\\"]}],{\\\"children\\\":[[\\\"$\\\",\\\"$1\\\",\\\"c\\\",{\\\"children\\\":[[[\\\"$\\\",\\\"link\\\",\\\"0\\\",{\\\"rel\\\":\\\"stylesheet\\\",\\\"href\\\":\\\"/_next/static/chunks/0_kwzt0c~eysn.css?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"precedence\\\":\\\"next\\\",\\\"crossOrigin\\\":\\\"$undefined\\\",\\\"nonce\\\":\\\"$undefined\\\"}],[\\\"$\\\",\\\"script\\\",\\\"script-0\\\",{\\\"src\\\":\\\"/_next/static/chunks/15ozypjscxub5.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"async\\\":true,\\\"nonce\\\":\\\"$undefined\\\"}]],[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"blog-root min-h-dvh\\\",\\\"children\\\":[\\\"$L5\\\",[\\\"$\\\",\\\"main\\\",null,{\\\"children\\\":[\\\"$\\\",\\\"$L2\\\",null,{\\\"parallelRouterKey\\\":\\\"children\\\",\\\"error\\\":\\\"$undefined\\\",\\\"errorStyles\\\":\\\"$undefined\\\",\\\"errorScripts\\\":\\\"$undefined\\\",\\\"template\\\":[\\\"$\\\",\\\"$L3\\\",null,{}],\\\"templateStyles\\\":\\\"$undefined\\\",\\\"templateScripts\\\":\\\"$undefined\\\",\\\"notFound\\\":\\\"$undefined\\\",\\\"forbidden\\\":\\\"$undefined\\\",\\\"unauthorized\\\":\\\"$undefined\\\"}]}],[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"border-t border-neutral-800\\\",\\\"children\\\":\\\"$L6\\\"}]]}]]}],{\\\"children\\\":[[\\\"$\\\",\\\"$1\\\",\\\"c\\\",{\\\"children\\\":[null,[\\\"$\\\",\\\"$L2\\\",null,{\\\"parallelRouterKey\\\":\\\"children\\\",\\\"error\\\":\\\"$undefined\\\",\\\"errorStyles\\\":\\\"$undefined\\\",\\\"errorScripts\\\":\\\"$undefined\\\",\\\"template\\\":[\\\"$\\\",\\\"$L3\\\",null,{}],\\\"templateStyles\\\":\\\"$undefined\\\",\\\"templateScripts\\\":\\\"$undefined\\\",\\\"notFound\\\":\\\"$undefined\\\",\\\"forbidden\\\":\\\"$undefined\\\",\\\"unauthorized\\\":\\\"$undefined\\\"}]]}],{\\\"children\\\":[[\\\"$\\\",\\\"$1\\\",\\\"c\\\",{\\\"children\\\":[\\\"$L7\\\",[[\\\"$\\\",\\\"script\\\",\\\"script-0\\\",{\\\"src\\\":\\\"/_next/static/chunks/08xg.0ckpl~2z.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"async\\\":true,\\\"nonce\\\":\\\"$undefined\\\"}]],[\\\"$\\\",\\\"$L8\\\",null,{\\\"children\\\":[\\\"$\\\",\\\"$9\\\",null,{\\\"name\\\":\\\"Next.MetadataOutlet\\\",\\\"children\\\":\\\"$@a\\\"}]}]]}],{},null,false,null]},null,false,\\\"$@b\\\"]},null,false,null]},null,false,null]},null,false,null],[\\\"$\\\",\\\"$1\\\",\\\"h\\\",{\\\"children\\\":[null,[\\\"$\\\",\\\"$Lc\\\",null,{\\\"children\\\":\\\"$Ld\\\"}],[\\\"$\\\",\\\"div\\\",null,{\\\"hidden\\\":true,\\\"children\\\":[\\\"$\\\",\\\"$Le\\\",null,{\\\"children\\\":[\\\"$\\\",\\\"$9\\\",null,{\\\"name\\\":\\\"Next.Metadata\\\",\\\"children\\\":\\\"$Lf\\\"}]}]}],[\\\"$\\\",\\\"meta\\\",null,{\\\"name\\\":\\\"next-size-adjust\\\",\\\"content\\\":\\\"\\\"}]]}],false]],\\\"m\\\":\\\"$undefined\\\",\\\"G\\\":[\\\"$10\\\",[]],\\\"S\\\":false,\\\"h\\\":null,\\\"s\\\":\\\"$undefined\\\",\\\"l\\\":\\\"$undefined\\\",\\\"p\\\":\\\"$undefined\\\",\\\"d\\\":\\\"$undefined\\\"}\\n\"])</script><script>self.__next_f.push([1,\"11:[]\\nb:\\\"$W11\\\"\\n16:T4f2,M33.0527 0.880305L36.984 0.880305V5.20874H33.0527V0.880305ZM33.0527 8.82239H36.984V29.0747H33.0527V8.82239ZM47.8585 29.5512C42.6564 29.5512 39.281 25.1434 39.281 18.9883C39.281 12.8729 42.6564 8.42529 47.8585 8.42529C50.8368 8.42529 53.0209 9.81515 54.2519 12.0786V0.880305H58.2229V29.0747H54.2519V25.8979C53.0209 28.1614 50.8368 29.5512 47.8585 29.5512ZM48.9307 26.4538C52.4252 26.4538 54.371 23.3564 54.371 18.9883C54.371 14.6201 52.4252 11.5227 48.9307 11.5227C45.4759 11.5227 43.4904 14.6201 43.4904 18.9883C43.4904 23.3564 45.4759 26.4538 48.9307 26.4538ZM60.4647 18.9485C60.4647 12.9126 64.396 8.42529 70.432 8.42529C76.7063 8.42529 80.4787 13.4288 80.2008 19.7825H64.5946C64.7534 23.8726 66.8978 26.5332 70.5909 26.5332C73.45 26.5332 75.0384 24.786 75.7929 22.6416H79.8037C78.6918 26.6524 75.4752 29.5512 70.5511 29.5512C64.4754 29.5512 60.4647 25.064 60.4647 18.9485ZM76.1106 17.0424C75.5547 13.6671 73.6088 11.4433 70.432 11.4433C67.2155 11.4433 65.2697 13.6274 64.7137 17.0424H76.1106ZM82.4131 8.82239H86.3047V12.1978C87.3769 10.252 89.3624 8.42529 92.9363 8.42529C97.3045 8.42529 99.6077 11.0065 99.6077 15.0569V29.0747H95.6764V15.8114C95.6764 13.1905 94.485 11.6021 91.4273 11.6021C88.5682 11.6021 86.3444 13.8259 86.3444 17.3998V29.0747H82.4131V8.82239Z\"])</script><script>self.__next_f.push([1,\"6:[\\\"$\\\",\\\"footer\\\",null,{\\\"className\\\":\\\"w-full bg-neutral-900 overflow-hidden\\\",\\\"children\\\":[[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"px-4 pt-32 pb-3 flex items-center justify-between gap-4\\\",\\\"children\\\":[[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"text-base text-neutral-500 shrink-0 uppercase tracking-tight\\\",\\\"children\\\":\\\"© 2026 IDENHQ, INC.\\\"}],[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"hidden sm:flex flex-wrap items-center justify-center gap-x-3 gap-y-1\\\",\\\"children\\\":[[[\\\"$\\\",\\\"span\\\",\\\"Charter\\\",{\\\"className\\\":\\\"flex items-center gap-3\\\",\\\"children\\\":[false,[\\\"$\\\",\\\"a\\\",null,{\\\"href\\\":\\\"/charter\\\",\\\"className\\\":\\\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\\\",\\\"children\\\":\\\"Charter\\\"}]]}],[\\\"$\\\",\\\"span\\\",\\\"Field Notes\\\",{\\\"className\\\":\\\"flex items-center gap-3\\\",\\\"children\\\":[[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"text-xl select-none text-neutral-700\\\",\\\"children\\\":\\\"·\\\"}],[\\\"$\\\",\\\"a\\\",null,{\\\"href\\\":\\\"/field-notes\\\",\\\"className\\\":\\\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\\\",\\\"children\\\":\\\"Field Notes\\\"}]]}],[\\\"$\\\",\\\"span\\\",\\\"Versus\\\",{\\\"className\\\":\\\"flex items-center gap-3\\\",\\\"children\\\":[[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"text-xl select-none text-neutral-700\\\",\\\"children\\\":\\\"·\\\"}],[\\\"$\\\",\\\"a\\\",null,{\\\"href\\\":\\\"/vs\\\",\\\"className\\\":\\\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\\\",\\\"children\\\":\\\"Versus\\\"}]]}],[\\\"$\\\",\\\"span\\\",\\\"FAQ\\\",{\\\"className\\\":\\\"flex items-center gap-3\\\",\\\"children\\\":[[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"text-xl select-none text-neutral-700\\\",\\\"children\\\":\\\"·\\\"}],[\\\"$\\\",\\\"a\\\",null,{\\\"href\\\":\\\"/faq\\\",\\\"className\\\":\\\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\\\",\\\"children\\\":\\\"FAQ\\\"}]]}],[\\\"$\\\",\\\"span\\\",\\\"Trust\\\",{\\\"className\\\":\\\"flex items-center gap-3\\\",\\\"children\\\":[[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"text-xl select-none text-neutral-700\\\",\\\"children\\\":\\\"·\\\"}],[\\\"$\\\",\\\"a\\\",null,{\\\"href\\\":\\\"https://trust.idenhq.com\\\",\\\"className\\\":\\\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\\\",\\\"children\\\":\\\"Trust\\\"}]]}]],[[\\\"$\\\",\\\"span\\\",\\\"Privacy\\\",{\\\"className\\\":\\\"flex items-center gap-3\\\",\\\"children\\\":[[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"text-xl select-none text-neutral-700\\\",\\\"children\\\":\\\"·\\\"}],\\\"$L12\\\"]}],[\\\"$\\\",\\\"span\\\",\\\"Terms\\\",{\\\"className\\\":\\\"flex items-center gap-3\\\",\\\"children\\\":[[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"text-xl select-none text-neutral-700\\\",\\\"children\\\":\\\"·\\\"}],\\\"$L13\\\"]}],[\\\"$\\\",\\\"span\\\",\\\"Legal Notice\\\",{\\\"className\\\":\\\"flex items-center gap-3\\\",\\\"children\\\":[[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"text-xl select-none text-neutral-700\\\",\\\"children\\\":\\\"·\\\"}],\\\"$L14\\\"]}]],[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"flex items-center gap-3\\\",\\\"children\\\":[[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"text-xl select-none text-neutral-700\\\",\\\"children\\\":\\\"·\\\"}],[\\\"$\\\",\\\"$L15\\\",null,{\\\"light\\\":false}]]}]]}],[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"text-base text-neutral-500 shrink-0 uppercase tracking-tight\\\",\\\"children\\\":[\\\"Backed by\\\",\\\" \\\",[\\\"$\\\",\\\"a\\\",null,{\\\"href\\\":\\\"https://www.accel.com\\\",\\\"target\\\":\\\"_blank\\\",\\\"rel\\\":\\\"noopener noreferrer\\\",\\\"className\\\":\\\"hover:text-neutral-300 transition-colors\\\",\\\"children\\\":\\\"Accel\\\"}]]}]]}],[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"pt-1 pb-0 select-none overflow-hidden\\\",\\\"children\\\":[\\\"$\\\",\\\"svg\\\",null,{\\\"viewBox\\\":\\\"0.55 0 99.06 29.07\\\",\\\"preserveAspectRatio\\\":\\\"xMinYMin meet\\\",\\\"fill\\\":\\\"none\\\",\\\"xmlns\\\":\\\"http://www.w3.org/2000/svg\\\",\\\"className\\\":\\\"w-full h-auto block\\\",\\\"style\\\":{\\\"fill\\\":\\\"#262626\\\"},\\\"children\\\":[[\\\"$\\\",\\\"path\\\",null,{\\\"fillRule\\\":\\\"evenodd\\\",\\\"clipRule\\\":\\\"evenodd\\\",\\\"d\\\":\\\"M0.555176 29.1416H25.1243V18.9512H18.6608C18.0696 18.9512 17.5903 18.4719 17.5903 17.8807V15.8334C17.5903 15.2422 18.0696 14.763 18.6608 14.763H25.1243V0.927339H21.6923V4.5707H14.8833V0.927339H10.7962V4.5707H3.98717L3.98717 0.927339H0.555176L0.555176 14.763H7.01869C7.60988 14.763 8.08913 15.2422 8.08913 15.8334V17.8807C8.08913 18.4719 7.60988 18.9512 7.01869 18.9512H0.555176L0.555176 29.1416ZM3.98717 8.00269H21.6923V10.6758H19.3159C16.4674 10.6758 14.1583 12.9849 14.1583 15.8334V17.8807C14.1583 20.7292 16.4674 23.0383 19.3159 23.0383H21.6923V25.7096H3.98717L3.98717 23.0383H6.36355C9.212 23.0383 11.5211 20.7292 11.5211 17.8807V15.8334C11.5211 12.9849 9.212 10.6758 6.36355 10.6758H3.98717L3.98717 8.00269Z\\\"}],[\\\"$\\\",\\\"path\\\",null,{\\\"d\\\":\\\"$16\\\"}]]}]}]]}]\\n\"])</script><script>self.__next_f.push([1,\"17:Tbbc,\"])</script><script>self.__next_f.push([1,\"[{\\\"@context\\\":\\\"https://schema.org\\\",\\\"@type\\\":\\\"Organization\\\",\\\"name\\\":\\\"Iden\\\",\\\"url\\\":\\\"https://www.idenhq.com\\\",\\\"logo\\\":\\\"https://www.idenhq.com/logo/iden-wordmark.svg\\\",\\\"description\\\":\\\"Iden is the complete identity governance (IGA) platform, purpose-built for growing companies of 50 to 2,000 employees. It automates the full user lifecycle from onboarding to offboarding, fine-grained access provisioning, and access reviews across every app your business runs on (SaaS, internal tools, and legacy systems), including the ones without SCIM or an API. It runs alongside your SSO and deploys in days, not months.\\\",\\\"sameAs\\\":[\\\"https://www.wikidata.org/wiki/Q140158373\\\",\\\"https://www.linkedin.com/company/idenhq\\\",\\\"https://github.com/IdenWorks\\\",\\\"https://twitter.com/idenhq\\\"],\\\"foundingDate\\\":\\\"2024-04\\\",\\\"founder\\\":[{\\\"@type\\\":\\\"Person\\\",\\\"name\\\":\\\"Pranay Yadav\\\",\\\"jobTitle\\\":\\\"CEO\\\",\\\"sameAs\\\":[\\\"https://www.wikidata.org/wiki/Q140158371\\\"]},{\\\"@type\\\":\\\"Person\\\",\\\"name\\\":\\\"Anchit Navelkar\\\",\\\"jobTitle\\\":\\\"CTO\\\",\\\"sameAs\\\":[\\\"https://www.wikidata.org/wiki/Q140158372\\\"]}],\\\"contactPoint\\\":[{\\\"@type\\\":\\\"ContactPoint\\\",\\\"contactType\\\":\\\"sales\\\",\\\"email\\\":\\\"hello@idenhq.com\\\",\\\"availableLanguage\\\":[\\\"en\\\",\\\"de\\\"]}]},{\\\"@context\\\":\\\"https://schema.org\\\",\\\"@type\\\":\\\"SoftwareApplication\\\",\\\"name\\\":\\\"Iden\\\",\\\"applicationCategory\\\":\\\"BusinessApplication\\\",\\\"applicationSubCategory\\\":\\\"Identity Governance and Administration (IGA)\\\",\\\"operatingSystem\\\":\\\"Web\\\",\\\"url\\\":\\\"https://www.idenhq.com\\\",\\\"description\\\":\\\"Iden is the complete identity governance (IGA) platform, purpose-built for growing companies of 50 to 2,000 employees. It automates the full user lifecycle from onboarding to offboarding, fine-grained access provisioning, and access reviews across every app your business runs on (SaaS, internal tools, and legacy systems), including the ones without SCIM or an API. It runs alongside your SSO and deploys in days, not months.\\\",\\\"offers\\\":{\\\"@type\\\":\\\"Offer\\\",\\\"price\\\":\\\"7.50\\\",\\\"priceCurrency\\\":\\\"USD\\\",\\\"priceSpecification\\\":{\\\"@type\\\":\\\"UnitPriceSpecification\\\",\\\"price\\\":\\\"7.50\\\",\\\"priceCurrency\\\":\\\"USD\\\",\\\"unitText\\\":\\\"user/month\\\"}},\\\"featureList\\\":[\\\"User lifecycle management (Joiner-Mover-Leaver) for employees and contractors\\\",\\\"Fine-grained access provisioning across SCIM and non-SCIM apps\\\",\\\"Clean, compliant offboarding with data backups and audit trail\\\",\\\"Access tickets automation\\\",\\\"JIT, time-bound access\\\",\\\"Automated user access reviews and access certifications for SOC 2, ISO 27001, GDPR, DPDP, CCPA, CMMC, and other frameworks\\\",\\\"Least privilege at scale\\\",\\\"Identity security posture management\\\",\\\"Human, non-human, and AI agentic identities in one platform\\\",\\\"AI agent identity governance\\\",\\\"Shadow IT and SaaS discovery\\\",\\\"SaaS management and cost optimization\\\",\\\"200+ non-SCIM app connectors\\\",\\\"Custom app connectors in 48 hours\\\"],\\\"publisher\\\":{\\\"@type\\\":\\\"Organization\\\",\\\"name\\\":\\\"Iden\\\",\\\"url\\\":\\\"https://www.idenhq.com\\\"}},{\\\"@context\\\":\\\"https://schema.org\\\",\\\"@type\\\":\\\"WebSite\\\",\\\"name\\\":\\\"Iden\\\",\\\"url\\\":\\\"https://www.idenhq.com\\\",\\\"inLanguage\\\":[\\\"en\\\",\\\"de\\\"],\\\"publisher\\\":{\\\"@type\\\":\\\"Organization\\\",\\\"name\\\":\\\"Iden\\\",\\\"url\\\":\\\"https://www.idenhq.com\\\"}}]\"])</script><script>self.__next_f.push([1,\"4:[\\\"$\\\",\\\"html\\\",null,{\\\"lang\\\":\\\"en\\\",\\\"className\\\":\\\"inter_c15e96cb-module__0bjUvq__variable antialiased\\\",\\\"suppressHydrationWarning\\\":true,\\\"children\\\":[\\\"$\\\",\\\"body\\\",null,{\\\"className\\\":\\\"overscroll-y-none\\\",\\\"children\\\":[[\\\"$\\\",\\\"script\\\",null,{\\\"type\\\":\\\"application/ld+json\\\",\\\"dangerouslySetInnerHTML\\\":{\\\"__html\\\":\\\"$17\\\"}}],\\\"$L18\\\"]}]}]\\n1a:T4f2,M33.0527 0.880305L36.984 0.880305V5.20874H33.0527V0.880305ZM33.0527 8.82239H36.984V29.0747H33.0527V8.82239ZM47.8585 29.5512C42.6564 29.5512 39.281 25.1434 39.281 18.9883C39.281 12.8729 42.6564 8.42529 47.8585 8.42529C50.8368 8.42529 53.0209 9.81515 54.2519 12.0786V0.880305H58.2229V29.0747H54.2519V25.8979C53.0209 28.1614 50.8368 29.5512 47.8585 29.5512ZM48.9307 26.4538C52.4252 26.4538 54.371 23.3564 54.371 18.9883C54.371 14.6201 52.4252 11.5227 48.9307 11.5227C45.4759 11.5227 43.4904 14.6201 43.4904 18.9883C43.4904 23.3564 45.4759 26.4538 48.9307 26.4538ZM60.4647 18.9485C60.4647 12.9126 64.396 8.42529 70.432 8.42529C76.7063 8.42529 80.4787 13.4288 80.2008 19.7825H64.5946C64.7534 23.8726 66.8978 26.5332 70.5909 26.5332C73.45 26.5332 75.0384 24.786 75.7929 22.6416H79.8037C78.6918 26.6524 75.4752 29.5512 70.5511 29.5512C64.4754 29.5512 60.4647 25.064 60.4647 18.9485ZM76.1106 17.0424C75.5547 13.6671 73.6088 11.4433 70.432 11.4433C67.2155 11.4433 65.2697 13.6274 64.7137 17.0424H76.1106ZM82.4131 8.82239H86.3047V12.1978C87.3769 10.252 89.3624 8.42529 92.9363 8.42529C97.3045 8.42529 99.6077 11.0065 99.6077 15.0569V29.0747H95.6764V15.8114C95.6764 13.1905 94.485 11.6021 91.4273 11.6021C88.5682 11.6021 86.3444 13.8259 86.3444 17.3998V29.0747H82.4131V8.82239Z\"])</script><script>self.__next_f.push([1,\"5:[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"max-w-[620px] px-6 sm:px-0 mx-auto pt-3 pb-3 w-full relative\\\",\\\"children\\\":[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"flex items-center justify-between\\\",\\\"children\\\":[[\\\"$\\\",\\\"$L19\\\",null,{\\\"href\\\":\\\"/\\\",\\\"aria-label\\\":\\\"Iden\\\",\\\"className\\\":\\\"flex items-center\\\",\\\"children\\\":[\\\"$\\\",\\\"svg\\\",null,{\\\"viewBox\\\":\\\"0 0 101 30\\\",\\\"fill\\\":\\\"none\\\",\\\"xmlns\\\":\\\"http://www.w3.org/2000/svg\\\",\\\"className\\\":\\\"h-4 w-auto block shrink-0\\\",\\\"style\\\":{\\\"fill\\\":\\\"#a3a3a3\\\"},\\\"children\\\":[[\\\"$\\\",\\\"path\\\",null,{\\\"fillRule\\\":\\\"evenodd\\\",\\\"clipRule\\\":\\\"evenodd\\\",\\\"d\\\":\\\"M0.555176 29.1416H25.1243V18.9512H18.6608C18.0696 18.9512 17.5903 18.4719 17.5903 17.8807V15.8334C17.5903 15.2422 18.0696 14.763 18.6608 14.763H25.1243V0.927339H21.6923V4.5707H14.8833V0.927339H10.7962V4.5707H3.98717L3.98717 0.927339H0.555176L0.555176 14.763H7.01869C7.60988 14.763 8.08913 15.2422 8.08913 15.8334V17.8807C8.08913 18.4719 7.60988 18.9512 7.01869 18.9512H0.555176L0.555176 29.1416ZM3.98717 8.00269H21.6923V10.6758H19.3159C16.4674 10.6758 14.1583 12.9849 14.1583 15.8334V17.8807C14.1583 20.7292 16.4674 23.0383 19.3159 23.0383H21.6923V25.7096H3.98717L3.98717 23.0383H6.36355C9.212 23.0383 11.5211 20.7292 11.5211 17.8807V15.8334C11.5211 12.9849 9.212 10.6758 6.36355 10.6758H3.98717L3.98717 8.00269Z\\\"}],[\\\"$\\\",\\\"path\\\",null,{\\\"d\\\":\\\"$1a\\\"}]]}]}],[\\\"$\\\",\\\"$L1b\\\",null,{\\\"dark\\\":true,\\\"bookDemo\\\":true,\\\"fieldNotes\\\":true,\\\"playbooks\\\":true,\\\"demoUrl\\\":\\\"https://cal.com/team/iden/demo\\\",\\\"askAILabel\\\":\\\"Ask AI\\\",\\\"loginLabel\\\":\\\"Login\\\",\\\"demoCtaLabel\\\":\\\"Book demo\\\",\\\"showLanguageSwitcher\\\":false}]]}]}]\\n\"])</script><script>self.__next_f.push([1,\"12:[\\\"$\\\",\\\"$L1c\\\",null,{\\\"ref\\\":\\\"$undefined\\\",\\\"href\\\":\\\"/en/privacy-policy\\\",\\\"locale\\\":\\\"$undefined\\\",\\\"localeCookie\\\":{\\\"name\\\":\\\"NEXT_LOCALE\\\",\\\"sameSite\\\":\\\"lax\\\"},\\\"className\\\":\\\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\\\",\\\"children\\\":\\\"Privacy\\\"}]\\n13:[\\\"$\\\",\\\"$L1c\\\",null,{\\\"ref\\\":\\\"$undefined\\\",\\\"href\\\":\\\"/en/terms-of-service\\\",\\\"locale\\\":\\\"$undefined\\\",\\\"localeCookie\\\":\\\"$12:props:localeCookie\\\",\\\"className\\\":\\\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\\\",\\\"children\\\":\\\"Terms\\\"}]\\n14:[\\\"$\\\",\\\"$L1c\\\",null,{\\\"ref\\\":\\\"$undefined\\\",\\\"href\\\":\\\"/en/legal-notice\\\",\\\"locale\\\":\\\"$undefined\\\",\\\"localeCookie\\\":\\\"$12:props:localeCookie\\\",\\\"className\\\":\\\"text-base text-neutral-500 hover:text-neutral-300 transition-colors\\\",\\\"children\\\":\\\"Legal Notice\\\"}]\\n\"])</script><script>self.__next_f.push([1,\"18:[\\\"$\\\",\\\"$L1d\\\",null,{\\\"formats\\\":\\\"$undefined\\\",\\\"locale\\\":\\\"en\\\",\\\"messages\\\":{\\\"nav\\\":{\\\"docs\\\":\\\"Docs\\\",\\\"trust\\\":\\\"Trust\\\",\\\"contact\\\":\\\"Contact\\\",\\\"askAI\\\":\\\"Ask AI\\\",\\\"login\\\":\\\"Login\\\",\\\"demoCta\\\":\\\"Book demo\\\"},\\\"hero\\\":{\\\"headlineLine1\\\":\\\"Identity governance for your entire stack.\\\",\\\"headlineLine2\\\":\\\"SCIM or not.\\\",\\\"body\\\":\\\"Iden automates the full identity lifecycle across all your apps – SaaS, internal or legacy. Purpose-built for IT teams who have outgrown spreadsheets but don't want the enterprise bloat.\\\",\\\"cta\\\":\\\"Try Iden for your stack\\\",\\\"watchDemo\\\":\\\"Watch 2-min demo\\\",\\\"statsConnectors\\\":\\\"180+ connectors\\\",\\\"statsRevoke\\\":\\\"30s to grant/revoke access\\\",\\\"statsLive\\\":\\\"go live in \\u003c1h\\\",\\\"statsTrial\\\":\\\"2-week trial\\\"},\\\"productFeatures\\\":{\\\"heading\\\":\\\"Why Iden?\\\",\\\"engineerCta\\\":\\\"Talk to our engineer\\\",\\\"noUpgrade\\\":\\\"Iden works even on standard plans. No upgrade required.\\\",\\\"scimTaxHeading\\\":\\\"\\u003cu\\u003eSCIM Tax\\u003c/u\\u003e: why your current tools stop at 20%\\\",\\\"scimTaxBody\\\":\\\"~70% of your stack locks SCIM behind enterprise plans, forcing an expensive upgrade just to automate provisioning.\\\",\\\"scimTaxRead\\\":\\\"Read: What is the SCIM Tax? -\\u003e\\\",\\\"scimTaxSource\\\":\\\"Source: SCIM Tax Index -\\u003e\\\",\\\"scimTable\\\":{\\\"appCol\\\":\\\"App\\\",\\\"standardCol\\\":\\\"Standard plan\\\",\\\"enterpriseCol\\\":\\\"Enterprise (for SCIM)\\\",\\\"multCol\\\":\\\"×\\\"},\\\"pillars\\\":{\\\"coverage\\\":{\\\"stat\\\":\\\"Coverage\\\",\\\"heading\\\":\\\"Every app. SCIM or not.\\\",\\\"body\\\":\\\"Other IGA tools stop at SCIM or require custom dev. Iden covers every app out of the box: SCIM, API or neither.\\\"},\\\"controls\\\":{\\\"stat\\\":\\\"Controls\\\",\\\"heading\\\":\\\"Fine-grained. Fully automated.\\\",\\\"body\\\":\\\"You need more than groups. Iden offers fine-grained access controls and workflows across your stack.\\\"},\\\"cost\\\":{\\\"stat\\\":\\\"Cost\\\",\\\"heading\\\":\\\"IGA that pays for itself.\\\",\\\"body\\\":\\\"No SCIM tax. No wasted SaaS licenses. No manual tickets. No hidden costs. Starts at $7.50/user/mo.\\\"}}},\\\"howItWorks\\\":{\\\"heading\\\":\\\"How it works\\\",\\\"demoCta\\\":\\\"Book a demo\\\",\\\"steps\\\":[{\\\"number\\\":\\\"01\\\",\\\"title\\\":\\\"Connect every app\\\",\\\"body\\\":\\\"180+ connectors out of the box. Connect your HRIS, SSO and every app in your stack: SCIM, API or neither. Custom connectors in 48h.\\\"},{\\\"number\\\":\\\"02\\\",\\\"title\\\":\\\"Define your policies once\\\",\\\"body\\\":\\\"Who gets what, when, and for how long. Set once, enforced across your apps. Birthright by role, time-bound JIT for everything else.\\\"},{\\\"number\\\":\\\"03\\\",\\\"title\\\":\\\"Everything runs itself\\\",\\\"body\\\":\\\"New hires get access by 8am. Clean, compliant offboarding with data backups. Auto-provisioned access tickets. Your entire stack governed.\\\"}]},\\\"comparison\\\":{\\\"heading\\\":\\\"Not SailPoint. Not a spreadsheet.\\\",\\\"tagline\\\":\\\"Coverage they didn't. Controls they won't. Cost they can't.\\\",\\\"table\\\":{\\\"featureCol\\\":\\\"Feature\\\",\\\"othersCol\\\":\\\"Others\\\",\\\"idenCol\\\":\\\"Iden\\\"},\\\"groups\\\":{\\\"Coverage\\\":\\\"Coverage\\\",\\\"Controls\\\":\\\"Controls\\\",\\\"Cost\\\":\\\"Cost\\\"},\\\"rows\\\":{\\\"Apps without SCIM/API\\\":\\\"Apps without SCIM/API\\\",\\\"Human + Non-human\\\":\\\"Human + Non-human\\\",\\\"Custom connectors in 48h\\\":\\\"Custom connectors in 48h\\\",\\\"Fine-grained permissions (SCIM++)\\\":\\\"Fine-grained permissions (SCIM++)\\\",\\\"Granular policies + workflows\\\":\\\"Granular policies + workflows\\\",\\\"Data backups/migrations\\\":\\\"Data backups/migrations\\\",\\\"No SCIM tax\\\":\\\"No SCIM tax\\\",\\\"Flat pricing\\\":\\\"Flat pricing\\\",\\\"SaaS spend optimization\\\":\\\"SaaS spend optimization\\\"},\\\"vsLumos\\\":\\\"Iden vs Lumos\\\",\\\"vsConductorOne\\\":\\\"Iden vs ConductorOne\\\",\\\"sailPointAlt\\\":\\\"SailPoint alternative\\\",\\\"soon\\\":\\\"soon\\\"},\\\"trustTestimonials\\\":{\\\"heading\\\":\\\"Built for teams like yours.\\\",\\\"tagline\\\":\\\"Used by teams where IT is a person and a department. Loved by all.\\\",\\\"quotes\\\":{\\\"kat\\\":\\\"Found \\u003cb\\u003e47 orphaned accounts\\u003c/b\\u003e we didn't know existed. We're only 120 people.\\\",\\\"ajeesh\\\":\\\"Finally, \\u003cb\\u003ehuman and machine identities in one dashboard\\u003c/b\\u003e, not three.\\\",\\\"shiv\\\":\\\"Access reviews with teeth that \\u003cb\\u003eemployees don't dread\\u003c/b\\u003e. Security, GRC, auditors – all happy.\\\",\\\"evan\\\":\\\"Without the SCIM tax, \\u003cb\\u003eIden pays for itself multiple times over\\u003c/b\\u003e.\\\"}},\\\"featureShowcase\\\":{\\\"heading\\\":\\\"Capabilities.\\\",\\\"features\\\":{\\\"onboarding\\\":{\\\"title\\\":\\\"Onboarding\\\",\\\"body\\\":\\\"Every app provisioned on day 1. Role-based, automated, zero tickets.\\\"},\\\"offboarding\\\":{\\\"title\\\":\\\"Offboarding\\\",\\\"body\\\":\\\"Every access revoked in 30s. No checklist. No gaps.\\\"},\\\"jit\\\":{\\\"title\\\":\\\"Time-based Access\\\",\\\"body\\\":\\\"JIT permissions that expire automatically. Right access, right window.\\\"},\\\"tickets\\\":{\\\"title\\\":\\\"Access Tickets\\\",\\\"body\\\":\\\"Self-serve tickets with automatic provisioning. Your ITSM or ours.\\\"},\\\"governance\\\":{\\\"title\\\":\\\"Real-time Governance\\\",\\\"body\\\":\\\"Detect and fix overprovisioned or unauthorized access across your stack.\\\"},\\\"reviews\\\":{\\\"title\\\":\\\"User Access Reviews\\\",\\\"body\\\":\\\"Multi-stage, automated access certifications with full audit trail.\\\"},\\\"shadow\\\":{\\\"title\\\":\\\"Shadow IT \\u0026 Risk\\\",\\\"body\\\":\\\"Monitor usage and access risks from apps outside your scope today.\\\"},\\\"finance\\\":{\\\"title\\\":\\\"Finance\\\",\\\"body\\\":\\\"Reclaim unused licenses. SaaS spend tied to actual access.\\\"},\\\"nhi\\\":{\\\"title\\\":\\\"NHI Management\\\",\\\"body\\\":\\\"Service accounts, OAuth grants, API keys, MCP/AI agents, all in one place.\\\"}},\\\"mockupUI\\\":{\\\"apps\\\":\\\"apps\\\",\\\"users\\\":\\\"users\\\",\\\"more\\\":\\\"more\\\",\\\"riskCol\\\":\\\"Risk\\\",\\\"riskCritical\\\":\\\"critical\\\",\\\"riskHigh\\\":\\\"high\\\",\\\"riskMedium\\\":\\\"medium\\\",\\\"riskLow\\\":\\\"low\\\",\\\"policyMatched\\\":\\\"policy matched\\\",\\\"onbScheduled\\\":\\\"onboarding scheduled\\\",\\\"offbScheduled\\\":\\\"offboarding scheduled\\\",\\\"onboarding\\\":\\\"Onboarding\\\",\\\"offboarding\\\":\\\"Offboarding\\\",\\\"onboardedIn\\\":\\\"Onboarded in\\\",\\\"offboardedIn\\\":\\\"Offboarded in\\\",\\\"removed\\\":\\\"removed\\\",\\\"deactivated\\\":\\\"deactivated\\\",\\\"migrated\\\":\\\"migrated\\\",\\\"revoked\\\":\\\"revoked\\\",\\\"provisioning\\\":\\\"Provisioning\\\",\\\"deprovisioning\\\":\\\"Deprovisioning\\\",\\\"fulfilledIn\\\":\\\"Fulfilled in\\\",\\\"approve\\\":\\\"Approve\\\",\\\"approved\\\":\\\"Approved\\\",\\\"deny\\\":\\\"Deny\\\",\\\"routedTo\\\":\\\"routed to\\\",\\\"govMinAgo\\\":\\\"1 min ago\\\",\\\"govAlerts\\\":\\\"alerts\\\",\\\"govScanning\\\":\\\"scanning...\\\",\\\"govOrphaned\\\":\\\"Orphaned accounts\\\",\\\"govSoD\\\":\\\"SoD violations\\\",\\\"govNewPrivileged\\\":\\\"New privileged accounts\\\",\\\"govZombie\\\":\\\"Zombie accounts\\\",\\\"govOverprovisioned\\\":\\\"Overprovisioned\\\",\\\"govNewExternal\\\":\\\"New external accounts\\\",\\\"reviewItems\\\":\\\"items\\\",\\\"reviewReviewers\\\":\\\"reviewers\\\",\\\"reviewStage1\\\":\\\"Stage 1 · Reporting Managers\\\",\\\"reviewStage2\\\":\\\"Stage 2 · App Owners\\\",\\\"reviewFlagged\\\":\\\"flagged\\\",\\\"reviewFlaggedLabel\\\":\\\"Flagged:\\\",\\\"reviewRemediated\\\":\\\"Remediated:\\\",\\\"reviewRetained\\\":\\\"Retained:\\\",\\\"reviewAuditReady\\\":\\\"Audit evidence for SOC2 JFM 2026 UAR ready\\\",\\\"shadowUserCol\\\":\\\"User\\\",\\\"shadowLastSignup\\\":\\\"last signup\\\",\\\"shadowWatchlist\\\":\\\"Watchlist\\\",\\\"shadowBlock\\\":\\\"Block\\\",\\\"shadowManage\\\":\\\"Manage via Iden\\\",\\\"finAppBilling\\\":\\\"App Billing\\\",\\\"finPotentialSavings\\\":\\\"Potential Savings\\\",\\\"finTotalSpend\\\":\\\"Total Spend:\\\",\\\"finSavingsLabel\\\":\\\"Potential savings:\\\",\\\"finMonthly\\\":\\\"Monthly\\\",\\\"finAnnual\\\":\\\"Annual\\\",\\\"finActive\\\":\\\"active\\\",\\\"nhiNonHuman\\\":\\\"Non-human identities\\\",\\\"nhiOverdue\\\":\\\"overdue\\\",\\\"nhiName\\\":\\\"Name\\\",\\\"nhiOwner\\\":\\\"Owner\\\",\\\"nhiAge\\\":\\\"Age\\\"}},\\\"security\\\":{\\\"heading\\\":\\\"Security\\\",\\\"viewTrustCta\\\":\\\"View trust center\\\",\\\"body\\\":\\\"Iden is designed to meet rigorous security and compliance requirements. AES-256 at rest. TLS 1.3 in transit. Our connectors do not ask or store login credentials and are built security-first with bank-grade encryption. On-prem deployment available for full data sovereignty. Every action logged with a full audit trail, export-ready for any compliance review.\\\"},\\\"faq\\\":{\\\"heading\\\":\\\"Good questions.\\\",\\\"askCta\\\":\\\"Ask a question\\\",\\\"items\\\":[{\\\"question\\\":\\\"We already have Okta/Entra ID. Why do we need Iden?\\\",\\\"answer\\\":\\\"Okta and Entra handle auth and basic IGA for apps that support SCIM. Iden handles the rest of your stack. Nothing gets replaced.\\\"},{\\\"question\\\":\\\"What about apps not in our SSO on standard plans?\\\",\\\"answer\\\":\\\"That's the whole point. Iden supports standard plans too via our custom connectors. If we don't have one for your app yet, we'll ship it in 48h.\\\"},{\\\"question\\\":\\\"How long does this actually take?\\\",\\\"answer\\\":\\\"First 15 apps in under 1 hour. Most of your stack in a week or two.\\\"},{\\\"question\\\":\\\"What does it cost, really?\\\",\\\"answer\\\":\\\"Starts at $7.50/user/mo – volume discounts apply. All connectors included. No enterprise upgrades for your SaaS apps.\\\"},{\\\"question\\\":\\\"How do I know offboarding is actually complete?\\\",\\\"answer\\\":\\\"Every workflow and action is audit logged. Because Iden connects with all of your apps, our offboarding is clean, complete and compliant.\\\"},{\\\"question\\\":\\\"Can I try it before I commit?\\\",\\\"answer\\\":\\\"Yes. Two-week trial. Connect your stack, run a real offboarding. You'll know if it works before you commit anything.\\\"}]},\\\"about\\\":{\\\"heading\\\":\\\"Who are we?\\\",\\\"charterCta\\\":\\\"Read our charter\\\",\\\"body1\\\":\\\"We're second-time founders, investors and operators who've watched dozens of companies scale, their stacks outgrowing the tools meant to govern them. Iden is what we wish had existed.\\\",\\\"body2\\\":\\\"Quietly building what IGA should have always been from SF, BCN and BLR.\\\",\\\"body3\\\":\\\"Backed by \\u003clink\\u003eAccel\\u003c/link\\u003e.\\\"},\\\"closingCta\\\":{\\\"headline1\\\":\\\"You've been patching gaps for years.\\\",\\\"headline2\\\":\\\"You don't have to anymore.\\\",\\\"body\\\":\\\"Pick the apps you use. See how Iden handles them, including the ones not on the list yet.\\\",\\\"primaryCta\\\":\\\"Try Iden for your stack\\\",\\\"askAILabel\\\":\\\"Ask your AI\\\",\\\"emailLink\\\":\\\"Or email us -\\u003e\\\"},\\\"footer\\\":{\\\"copyright\\\":\\\"© 2026 IDENHQ, INC.\\\",\\\"backedBy\\\":\\\"Backed by\\\",\\\"links\\\":{\\\"charter\\\":\\\"Charter\\\",\\\"fieldNotes\\\":\\\"Field Notes\\\",\\\"versus\\\":\\\"Versus\\\",\\\"faq\\\":\\\"FAQ\\\",\\\"docs\\\":\\\"Docs\\\",\\\"trustCenter\\\":\\\"Trust\\\",\\\"privacy\\\":\\\"Privacy\\\",\\\"terms\\\":\\\"Terms\\\",\\\"impressum\\\":\\\"Legal Notice\\\"}},\\\"impressum\\\":{\\\"meta\\\":{\\\"title\\\":\\\"Legal Notice | Iden\\\",\\\"description\\\":\\\"Legal notice for IdenHQ Inc. — service provider information pursuant to Section 5 of the German Digital Services Act (DDG).\\\"},\\\"pageTitle\\\":\\\"Legal Notice\\\",\\\"legalCitation\\\":\\\"Information pursuant to Section 5 DDG\\\",\\\"lastUpdated\\\":\\\"Last updated: April 27, 2026\\\",\\\"sections\\\":{\\\"entity\\\":{\\\"heading\\\":\\\"Service Provider\\\",\\\"name\\\":\\\"IdenHQ Inc.\\\",\\\"type\\\":\\\"Corporation incorporated under the laws of the State of Delaware, USA\\\"},\\\"rep\\\":{\\\"heading\\\":\\\"Authorized Representative\\\",\\\"name\\\":\\\"Pranay Yadav\\\",\\\"role\\\":\\\"Chief Executive Officer\\\"},\\\"address\\\":{\\\"heading\\\":\\\"Registered Address\\\",\\\"street\\\":\\\"108 W 13th Street, Suite 100\\\",\\\"city\\\":\\\"Wilmington, Delaware 19801\\\",\\\"country\\\":\\\"United States of America\\\"},\\\"contact\\\":{\\\"heading\\\":\\\"Contact\\\",\\\"emailLabel\\\":\\\"E-mail\\\",\\\"email\\\":\\\"legal@idenhq.com\\\",\\\"phoneLabel\\\":\\\"Telephone\\\",\\\"phone\\\":\\\"+1 (650) 509-7775\\\"},\\\"registry\\\":{\\\"heading\\\":\\\"Company Registry\\\",\\\"authorityLabel\\\":\\\"Registry Authority\\\",\\\"authority\\\":\\\"Delaware Division of Corporations, State of Delaware, USA\\\",\\\"numberLabel\\\":\\\"Registration Number\\\",\\\"number\\\":\\\"File No. 3369197\\\"},\\\"vat\\\":{\\\"heading\\\":\\\"VAT Identification Number\\\",\\\"content\\\":\\\"No VAT identification number pursuant to § 27a of the German Value Added Tax Act (UStG) has been issued.\\\"},\\\"liability\\\":{\\\"heading\\\":\\\"Liability Disclaimer\\\",\\\"contentHeading\\\":\\\"Content\\\",\\\"contentText\\\":\\\"The contents of this website have been prepared with due care and diligence. However, IdenHQ Inc. makes no representations or warranties of any kind, express or implied, as to the accuracy, completeness, currency, or fitness for any particular purpose of the information contained herein. The information provided on this website is subject to change without notice and does not constitute legal, financial, or professional advice of any kind. IdenHQ Inc. expressly disclaims all liability for any loss or damage of any nature — whether direct, indirect, incidental, or consequential — arising from reliance on the content of this website. Liability claims arising from material or immaterial damage caused by the use or non-use of the information provided, or by the use of erroneous or incomplete information, are excluded to the extent that IdenHQ Inc. has not acted with willful intent or gross negligence.\\\",\\\"linksHeading\\\":\\\"External Links\\\",\\\"linksText\\\":\\\"This website contains hyperlinks to external third-party websites over which IdenHQ Inc. exercises no editorial control and for which IdenHQ Inc. assumes no responsibility. The respective provider or operator of each linked website is solely responsible for that website's content. The linked pages were reviewed by IdenHQ Inc. for potential legal violations at the time each link was established; no unlawful content was apparent at that time. Ongoing monitoring of all linked websites is neither feasible nor reasonable in the absence of specific evidence of a legal violation. Should IdenHQ Inc. become aware of any legal infringement on a linked website, the relevant link will be removed without undue delay. If you identify a potential infringement on any linked page, please contact us at the address set out in the Contact section above.\\\",\\\"copyrightHeading\\\":\\\"Copyright\\\",\\\"copyrightText\\\":\\\"The content, works, and materials published on this website — including but not limited to text, graphics, logos, images, and software — are the property of IdenHQ Inc. or its respective content suppliers and are protected by applicable United States and international copyright law. Any reproduction, adaptation, translation, distribution, transmission, display, or other commercial exploitation of such materials beyond the scope expressly permitted by applicable copyright law is strictly prohibited without the prior written consent of IdenHQ Inc. Permitted private, non-commercial use does not extend to systematic reproduction, redistribution, or the creation of derivative works. Where content on this website has not been created by IdenHQ Inc., the intellectual property rights of the respective third party apply and are respected accordingly.\\\"},\\\"dispute\\\":{\\\"heading\\\":\\\"Dispute Resolution\\\",\\\"intro\\\":\\\"IdenHQ Inc. is neither obligated nor willing to participate in dispute resolution proceedings before a consumer arbitration board.\\\",\\\"odrText\\\":\\\"The European Commission provides a platform for online dispute resolution (ODR) at\\\",\\\"odrUrl\\\":\\\"https://ec.europa.eu/consumers/odr/\\\",\\\"emailText\\\":\\\"Our designated contact address for matters relating to online dispute resolution is: legal@idenhq.com.\\\"}}},\\\"cookieLink\\\":\\\"Cookies\\\",\\\"cookieBanner\\\":{\\\"body1\\\":\\\"We use cookies for analytics\\\",\\\"body2\\\":\\\"and to improve your experience.\\\",\\\"acceptAll\\\":\\\"Accept all\\\",\\\"decline\\\":\\\"Decline\\\",\\\"manage\\\":\\\"Manage\\\",\\\"prefsTitle\\\":\\\"Cookie preferences\\\",\\\"save\\\":\\\"Save\\\",\\\"declineAll\\\":\\\"Decline all\\\",\\\"essential\\\":\\\"Essential\\\",\\\"essentialDesc\\\":\\\"Required for the site to function.\\\",\\\"analytics\\\":\\\"Analytics\\\",\\\"analyticsDesc\\\":\\\"Help us understand how visitors use the site.\\\",\\\"marketing\\\":\\\"Marketing\\\",\\\"marketingDesc\\\":\\\"Deliver relevant ads and measure campaigns.\\\",\\\"privacyLabel\\\":\\\"Privacy Policy\\\",\\\"impressumLabel\\\":\\\"Legal Notice\\\"},\\\"askAI\\\":{\\\"label\\\":\\\"Ask your AI\\\",\\\"copied\\\":\\\"Copied - paste into Claude, ChatGPT or any AI\\\"},\\\"meta\\\":{\\\"title\\\":\\\"Iden | Identity Governance for IT Teams\\\",\\\"description\\\":\\\"Automates provisioning, offboarding, and access reviews across every app, SCIM or not. For IT teams of 50 to 2,000. $7.50/user/month.\\\"},\\\"roiCalculator\\\":{\\\"meta\\\":{\\\"title\\\":\\\"Identity Governance ROI Calculator | Iden\\\",\\\"description\\\":\\\"Calculate savings from replacing manual IGA tools with Iden. Factors in licensing, IT operations time, and SaaS overhead from the SCIM tax.\\\"},\\\"header\\\":{\\\"label\\\":\\\"ROI Calculator\\\",\\\"copyLink\\\":\\\"Copy link\\\",\\\"copied\\\":\\\"Copied\\\",\\\"export\\\":\\\"Export\\\"},\\\"leftPanel\\\":{\\\"headcount\\\":\\\"Headcount\\\",\\\"employeesUnit\\\":\\\"employees\\\",\\\"contractorsUnit\\\":\\\"contractors\\\",\\\"addContractors\\\":\\\"+ contractors\\\",\\\"removeContractors\\\":\\\"− contractors\\\",\\\"identityOps\\\":\\\"Identity Operations\\\",\\\"hiresUnit\\\":\\\"hires / mo\\\",\\\"departuresUnit\\\":\\\"departures / mo\\\",\\\"ticketsUnit\\\":\\\"manual access tickets / wk\\\",\\\"reviewDaysUnit\\\":\\\"UAR days / qtr\\\",\\\"scimTax\\\":\\\"SCIM Tax\\\",\\\"appsUnit\\\":\\\"apps to manage\\\",\\\"scimTaxLink\\\":\\\"See which apps gate SCIM at scimtax.org\\\",\\\"saasSpend\\\":\\\"SaaS Spend\\\",\\\"saasUnit\\\":\\\"/ mo\\\"},\\\"rightPanel\\\":{\\\"heading\\\":\\\"What you're paying for\\\",\\\"othersCol\\\":\\\"Others\\\",\\\"licensing\\\":\\\"Licensing\\\",\\\"igaTool\\\":\\\"IGA Tool\\\",\\\"empLicenses\\\":\\\"Employee licenses\\\",\\\"conLicenses\\\":\\\"Contractor licenses\\\",\\\"saas\\\":\\\"SaaS\\\",\\\"scimTax\\\":\\\"SCIM tax\\\",\\\"operations\\\":\\\"Operations\\\",\\\"itOverhead\\\":\\\"IT Overhead\\\",\\\"onboarding\\\":\\\"Onboarding\\\",\\\"offboarding\\\":\\\"Offboarding\\\",\\\"accessTickets\\\":\\\"Access tickets\\\",\\\"accessReviews\\\":\\\"Access reviews\\\",\\\"productivity\\\":\\\"Productivity\\\",\\\"newHireWait\\\":\\\"New hire wait\\\",\\\"ticketWait\\\":\\\"Ticket wait\\\",\\\"licenseWaste\\\":\\\"License waste\\\",\\\"totalYear\\\":\\\"Total / year\\\",\\\"netSavings\\\":\\\"Net savings / year\\\",\\\"itHrsReturned\\\":\\\"IT hrs returned / month\\\",\\\"hrsUnit\\\":\\\"hrs\\\",\\\"roi\\\":\\\"Return on Investment\\\",\\\"excluding\\\":\\\"Excluding\\\",\\\"tagRisk\\\":\\\"Reduced Risk Exposure\\\",\\\"tagPrivilege\\\":\\\"Least Privilege At Scale\\\",\\\"tagAudit\\\":\\\"No Audit Qualification\\\",\\\"tagExp\\\":\\\"Superior Employee Experience\\\",\\\"subOnboarding\\\":\\\"{hrs} hr → 0 per hire\\\",\\\"subOffboarding\\\":\\\"{hrs} hr → 0 per departure\\\",\\\"subTickets\\\":\\\"{mins} min → 0 per ticket\\\",\\\"subReviews\\\":\\\"{days} days/qtr → 0\\\",\\\"subNewHireWait\\\":\\\"{days, number} days/hire → 0\\\",\\\"subTicketWait\\\":\\\"{hrs} hr → 0 per ticket\\\",\\\"subLicenseWaste\\\":\\\"{waste}% → 0% of SaaS spend\\\",\\\"subScimApps\\\":\\\"{scimApps} apps × ~{covPct}% users × ${premium}/user\\\",\\\"subScimNoApps\\\":\\\"enter app count\\\",\\\"subEmpLicenses\\\":\\\"$${legacyIga} → ${idenPrice} /u/mo (vol discounted)\\\",\\\"subConLicenses\\\":\\\"$${legacyIga} → ${idenConPrice} /u/mo (half rate)\\\"},\\\"print\\\":{\\\"headerLabel\\\":\\\"ROI Calculator\\\",\\\"preparedFor\\\":\\\"Prepared for\\\",\\\"employees\\\":\\\"Employees\\\",\\\"contractors\\\":\\\"Contractors\\\",\\\"calibratedOn\\\":\\\"Calibrated on\\\",\\\"monthlySpend\\\":\\\"Monthly spend\\\",\\\"disclaimer\\\":\\\"Estimates based on industry benchmarks. Actual savings vary.\\\",\\\"generatedBy\\\":\\\"Generated by Iden · idenhq.com/roi-calculator\\\"}}},\\\"now\\\":\\\"$undefined\\\",\\\"timeZone\\\":\\\"UTC\\\",\\\"children\\\":[\\\"$L1e\\\",\\\"$L1f\\\",\\\"$L20\\\"]}]\\n\"])</script><script>self.__next_f.push([1,\"1e:[\\\"$\\\",\\\"$L21\\\",null,{\\\"isEU\\\":false,\\\"children\\\":[[\\\"$\\\",\\\"$L22\\\",null,{}],[\\\"$\\\",\\\"$L23\\\",null,{}],[\\\"$\\\",\\\"$L24\\\",null,{}],[\\\"$\\\",\\\"$L2\\\",null,{\\\"parallelRouterKey\\\":\\\"children\\\",\\\"error\\\":\\\"$undefined\\\",\\\"errorStyles\\\":\\\"$undefined\\\",\\\"errorScripts\\\":\\\"$undefined\\\",\\\"template\\\":[\\\"$\\\",\\\"$L3\\\",null,{}],\\\"templateStyles\\\":\\\"$undefined\\\",\\\"templateScripts\\\":\\\"$undefined\\\",\\\"notFound\\\":\\\"$undefined\\\",\\\"forbidden\\\":\\\"$undefined\\\",\\\"unauthorized\\\":\\\"$undefined\\\"}],[\\\"$\\\",\\\"$L25\\\",null,{\\\"isEU\\\":false}]]}]\\n1f:[\\\"$\\\",\\\"$L26\\\",null,{}]\\n20:[\\\"$\\\",\\\"$L27\\\",null,{}]\\nd:[[\\\"$\\\",\\\"meta\\\",\\\"0\\\",{\\\"charSet\\\":\\\"utf-8\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"1\\\",{\\\"name\\\":\\\"viewport\\\",\\\"content\\\":\\\"width=device-width, initial-scale=1\\\"}]]\\n\"])</script><script>self.__next_f.push([1,\"28:I[27707,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"IconMark\\\"]\\na:null\\n\"])</script><script>self.__next_f.push([1,\"f:[[\\\"$\\\",\\\"title\\\",\\\"0\\\",{\\\"children\\\":\\\"AI Agent Identity Management 2026: Standards \\u0026 Gaps | Iden Blog\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"1\\\",{\\\"name\\\":\\\"description\\\",\\\"content\\\":\\\"MCP OAuth 2.1, MCP-I at the DIF, Microsoft Entra Agent ID - the 2026 standards for AI agent identity are taking shape. Here's what's real, what's missing, and how to evaluate governance today.\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"2\\\",{\\\"name\\\":\\\"application-name\\\",\\\"content\\\":\\\"Iden\\\"}],[\\\"$\\\",\\\"link\\\",\\\"3\\\",{\\\"rel\\\":\\\"author\\\",\\\"href\\\":\\\"https://www.idenhq.com\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"4\\\",{\\\"name\\\":\\\"author\\\",\\\"content\\\":\\\"Iden\\\"}],[\\\"$\\\",\\\"link\\\",\\\"5\\\",{\\\"rel\\\":\\\"manifest\\\",\\\"href\\\":\\\"/manifest.webmanifest\\\",\\\"crossOrigin\\\":\\\"$undefined\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"6\\\",{\\\"name\\\":\\\"creator\\\",\\\"content\\\":\\\"Iden\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"7\\\",{\\\"name\\\":\\\"publisher\\\",\\\"content\\\":\\\"Iden\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"8\\\",{\\\"name\\\":\\\"robots\\\",\\\"content\\\":\\\"index, follow\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"9\\\",{\\\"name\\\":\\\"googlebot\\\",\\\"content\\\":\\\"index, follow, max-video-preview:-1, max-image-preview:large, max-snippet:-1\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"10\\\",{\\\"name\\\":\\\"category\\\",\\\"content\\\":\\\"technology\\\"}],[\\\"$\\\",\\\"link\\\",\\\"11\\\",{\\\"rel\\\":\\\"canonical\\\",\\\"href\\\":\\\"https://www.idenhq.com/en/blog/ai-agent-identity-management-2026\\\"}],[\\\"$\\\",\\\"link\\\",\\\"12\\\",{\\\"rel\\\":\\\"alternate\\\",\\\"hrefLang\\\":\\\"de\\\",\\\"href\\\":\\\"https://www.idenhq.com/de/blog/ki-agenten-identity-management-2026\\\"}],[\\\"$\\\",\\\"link\\\",\\\"13\\\",{\\\"rel\\\":\\\"alternate\\\",\\\"hrefLang\\\":\\\"en\\\",\\\"href\\\":\\\"https://www.idenhq.com/en/blog/ai-agent-identity-management-2026\\\"}],[\\\"$\\\",\\\"link\\\",\\\"14\\\",{\\\"rel\\\":\\\"alternate\\\",\\\"hrefLang\\\":\\\"x-default\\\",\\\"href\\\":\\\"https://www.idenhq.com/en/blog/ai-agent-identity-management-2026\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"15\\\",{\\\"property\\\":\\\"og:title\\\",\\\"content\\\":\\\"AI Agent Identity Management 2026: Standards \\u0026 Gaps\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"16\\\",{\\\"property\\\":\\\"og:description\\\",\\\"content\\\":\\\"MCP OAuth 2.1, MCP-I at the DIF, Microsoft Entra Agent ID - the 2026 standards for AI agent identity are taking shape. Here's what's real, what's missing, and how to evaluate governance today.\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"17\\\",{\\\"property\\\":\\\"og:locale\\\",\\\"content\\\":\\\"en_US\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"18\\\",{\\\"property\\\":\\\"og:image\\\",\\\"content\\\":\\\"https://aqynbjfkcfnrqkhzbzxl.supabase.co/storage/v1/object/public/cms-assets/5ed37a7f-297e-48c5-b007-40268093b3fa/74941670-e8c6-433e-8121-3ac624af2e95.jpg\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"19\\\",{\\\"property\\\":\\\"og:type\\\",\\\"content\\\":\\\"article\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"20\\\",{\\\"property\\\":\\\"article:published_time\\\",\\\"content\\\":\\\"2026-07-15T07:00:17.688+00:00\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"21\\\",{\\\"name\\\":\\\"twitter:card\\\",\\\"content\\\":\\\"summary_large_image\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"22\\\",{\\\"name\\\":\\\"twitter:title\\\",\\\"content\\\":\\\"AI Agent Identity Management 2026: Standards \\u0026 Gaps\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"23\\\",{\\\"name\\\":\\\"twitter:description\\\",\\\"content\\\":\\\"MCP OAuth 2.1, MCP-I at the DIF, Microsoft Entra Agent ID - the 2026 standards for AI agent identity are taking shape. Here's what's real, what's missing, and how to evaluate governance today.\\\"}],[\\\"$\\\",\\\"meta\\\",\\\"24\\\",{\\\"name\\\":\\\"twitter:image\\\",\\\"content\\\":\\\"https://aqynbjfkcfnrqkhzbzxl.supabase.co/storage/v1/object/public/cms-assets/5ed37a7f-297e-48c5-b007-40268093b3fa/74941670-e8c6-433e-8121-3ac624af2e95.jpg\\\"}],[\\\"$\\\",\\\"link\\\",\\\"25\\\",{\\\"rel\\\":\\\"icon\\\",\\\"href\\\":\\\"/favicon.ico?favicon.0i-q8a6zz7zw~.ico\\\",\\\"sizes\\\":\\\"48x48\\\",\\\"type\\\":\\\"image/x-icon\\\"}],[\\\"$\\\",\\\"link\\\",\\\"26\\\",{\\\"rel\\\":\\\"apple-touch-icon\\\",\\\"href\\\":\\\"/apple-icon.png?apple-icon.0v4oxdav-.ztw.png\\\",\\\"sizes\\\":\\\"180x180\\\",\\\"type\\\":\\\"image/png\\\"}],[\\\"$\\\",\\\"$L28\\\",\\\"27\\\",{}]]\\n\"])</script><script>self.__next_f.push([1,\"29:I[35546,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/15ozypjscxub5.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/08xg.0ckpl~2z.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"BlogArticleHeader\\\"]\\n2a:T394c,\"])</script><script>self.__next_f.push([1,\"IMPORTANT: Do not answer yet. Read this context, then ask me what I want to know before giving any assessment.\\n\\n---\\n\\nI'm reading \\\"AI Agent Identity Management in 2026: Standards, Players, and the Governance Gap\\\" on Iden's blog. Iden is a modern identity governance platform for IT teams at companies with 50 to 2,000 employees. It automates provisioning, access reviews, and offboarding across every app in the stack, including the apps that don't support SCIM. Pricing starts at $7.50/user/month. Two-week trial. No professional services.\\n\\n## Article summary\\nMCP OAuth 2.1, MCP-I at the DIF, Microsoft Entra Agent ID - the 2026 standards landscape for AI agent identity is taking shape. Here's what's real, what's missing, and how to evaluate governance today.\\n\\n## Article content\\n\\nThe numbers are no longer theoretical. {{fact}}More than 80% of Fortune 500 companies now run active AI agents built with low-code and no-code tools{{cite:1}}, and {{fact}}Gartner projects that up to 40% of enterprise applications will include integrated task-specific AI agents by the end of 2026, up from less than 5% today{{cite:2}}.{{/fact}}{{/fact}} Yet the security posture underneath that deployment wave is alarming: {{fact}}on average, only 47.1% of an organization's AI agents are actively monitored or secured{{cite:3}}.{{/fact}} The other half operate without oversight, logging, or identity controls.\\n\\nThis is not a future problem. It is the current state of your production environment.\\n\\nThe good news - if you can call it that - is that the standards community has noticed. In the first half of 2026, more governance specifications landed for AI agent identity than in the entire prior history of the field. This post maps what those standards actually say, which vendor categories are responding, where the real gaps remain, and what a buyer should demand today.\\n\\n---\\n\\n## The Standards Landscape: What's Actually Shipping\\n\\n### MCP OAuth 2.1 Under Linux Foundation Governance\\n\\nThe Model Context Protocol started as an Anthropic experiment in November 2024. {{fact}}By December 2025, Anthropic had donated MCP to the Agentic AI Foundation (AAIF) under the Linux Foundation, with OpenAI, Block, AWS, Google, Microsoft, Cloudflare, and Bloomberg joining as founding or platinum members{{cite:4}}.{{/fact}} {{fact}}Within four months, the AAIF grew to 170 member organizations - more than double the membership CNCF had at the same stage of its life{{cite:5}}.{{/fact}}\\n\\nThe governance shift matters for enterprise buyers. MCP is no longer a single-vendor protocol that any one company can deprecate or fork. It is now closer in structure to CNCF than to a proprietary API.\\n\\nOn authentication specifically: {{fact}}the MCP spec mandates OAuth 2.1 with PKCE for all protected HTTP-based deployments, requiring HTTPS on all endpoints and discoverable authorization server metadata{{cite:6}}.{{/fact}} The 2026 roadmap, published in March, makes enterprise readiness - including audit trails, SSO-integrated auth, and configuration portability - a top priority. The spec's authorization Working Group had six dedicated sessions at the April 2026 MCP Dev Summit, with the OAuth 2.1 spec author present.\\n\\n{{fact}}The 2026 MCP roadmap flagged audit trail infrastructure, SSO-integrated auth, and configuration portability as the top enterprise requests{{cite:7}}.{{/fact}} None of those are solved yet. The roadmap is a commitment, not a delivery.\\n\\n{{component:e30cc0b7-1878-4e09-b948-931b4ea6d29d}}\\n\\n### MCP-I / KYA-OS: Decentralized Identity for Agents\\n\\nOAuth 2.1 handles *authentication* - proving an agent is who it claims to be. It does not answer the harder questions: Who authorized this agent? What is it allowed to do on behalf of which human? Can a downstream service verify that chain without prior coordination?\\n\\n{{fact}}In March 2026, Vouched formally donated the Model Context Protocol - Identity (MCP-I) framework to the Decentralized Identity Foundation (DIF), where it is now stewarded by the DIF Trusted AI Agents Working Group{{cite:8}}.{{/fact}} The spec has since been renamed KYA-OS (Know Your Agent Operating System) to reflect its scope beyond MCP alone.\\n\\n{{fact}}MCP-I / KYA-OS uses Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs) to enable cryptographically secure verification of both agents and their human principals - without requiring prior coordination between parties{{cite:9}}.{{/fact}} The framework defines four identity questions every service should be able to answer: Who is the agent? Who authorized it? What is it allowed to do? What is the scope of that delegation?\\n\\nThis is the right architecture for multi-organization agent workflows - a travel booking agent acting on behalf of a user across airline, hotel, and payment systems, for example. It is also early. The spec is in active community development, and production implementations are sparse.\\n\\n### Microsoft Entra Agent ID\\n\\nMicrosoft moved fastest among the major identity platforms. {{fact}}Microsoft Entra Agent ID introduces agent identities as a distinct, purpose-built construct - not a repurposed service principal or user account - with agent identity blueprints serving as templates for creating individual agent identities with parent-child relationships{{cite:10}}.{{/fact}}\\n\\n{{fact}}Agent identities in Entra do not have credentials of their own; they rely on the agent identity blueprint to acquire tokens on their behalf, and they only authenticate using federated identity credentials{{cite:11}}.{{/fact}} This is the right model: credentials live in the blueprint, not on the agent, so a compromised agent cannot exfiltrate its own keys.\\n\\n{{fact}}Microsoft Agent 365, generally available from May 1, 2026, gives each AI agent its own Entra Agent ID for identity, lifecycle, and access management, and integrates with Conditional Access, identity protection, and Microsoft Purview{{cite:12}}.{{/fact}} Third-party agents from AWS Bedrock, n8n, and other frameworks can be onboarded via workload identity federation - no platform-specific credential management required.\\n\\nThe honest limitation: Entra Agent ID is a strong solution if your agent estate lives inside the Microsoft ecosystem. For organizations running heterogeneous stacks - Anthropic, AWS, open-source frameworks, and custom-built agents - the governance surface extends well beyond what any single IdP can cover.\\n\\n### CSA Agentic Trust Framework and CSAI Foundation\\n\\nThe Cloud Security Alliance has been the most prolific standards producer in this space. {{fact}}The CSA published the Agentic Trust Framework (ATF) on February 2, 2026 - the first governance specification applying Zero Trust principles to autonomous AI agents with a structured maturity model{{cite:13}}.{{/fact}} The ATF was co-authored by John Kindervag, the original creator of Zero Trust.\\n\\nA companion survey of 285 IT and security professionals makes the urgency concrete: {{fact}}84% of organizations cannot pass a compliance audit focused on agent behavior or access controls, and only 23% have a formal agent identity strategy{{cite:14}}.{{/fact}}\\n\\nThe CSA's MAESTRO threat modeling framework explicitly names **agent impersonation** as a distinct threat class - malicious actors deceiving users or other agents by impersonating legitimate AI agents. The prescribed mitigations are trusted agent registries, cryptographic agent identities, and short-lived OAuth/OIDC tokens scoped to the intersection of what the agent is allowed to do AND what the delegating user is allowed to do. An AND gate, not an OR gate.\\n\\n{{fact}}In March 2026, the CSA launched the CSAI Foundation at RSAC 2026, a new 501(c)3 dedicated exclusively to AI security, with a 2026 mission of \\\"Securing the Agentic Control Plane\\\" - governing identity, authorization, orchestration, runtime behavior, and trust assurance for autonomous AI agent ecosystems{{cite:15}}.{{/fact}}\\n\\n---\\n\\n## The Player Map: Four Categories, Different Strengths\\n\\nThe vendor landscape has fragmented into four distinct categories. Understanding what each does - and doesn't do - is essential before buying.\\n\\n{{component:f0d62597-013b-4953-b03d-747adcaf9cba}}\\n\\nA few notes on the landscape:\\n\\n**Identity providers** are moving fast. {{fact}}Auth0's \\\"Auth for MCP\\\" became generally available on May 6, 2026, and Okta released its own MCP server as a secure protocol abstraction layer enabling AI agents to interact with Okta's scoped management APIs with least-privilege access control enforced at each tool call{{cite:2}}.{{/fact}} These are authentication solutions. They do not govern the full identity lifecycle.\\n\\n**NHI specialists** have the discovery story right. {{fact}}Veza's 2026 State of Identity and Access report found that a mere 0.01% of non-human identities control 80% of cloud resources, while the average worker holds 96,000 entitlements{{cite:16}}.{{/fact}} Knowing that is valuable. Governing it requires more than a posture dashboard.\\n\\n**MCP gateways** solve the runtime enforcement problem elegantly for agents you build inside their ecosystem. The problem is coverage: {{fact}}only 23.7% of organizations use their existing IAM/IdP as an authorization server for their agentic MCP infrastructure{{cite:3}}.{{/fact}} The rest are running disconnected auth stacks.\\n\\n**IGA platforms** are the natural home for agent governance - if they've actually built it. {{fact}}SailPoint expanded Agent Identity Security connectors in 2026 to include SaaS versions of Salesforce, ServiceNow, and Snowflake, but governance of agent identities requires a separate Agent Identity Security license{{cite:17}}.{{/fact}} Legacy IGA vendors are adding agent support as a module. That's not the same as designing for it from the start.\\n\\n---\\n\\n## The Honest Gaps\\n\\nStandards are immature. The MCP OAuth 2.1 profile is solid for authentication but has no standardized audit trail format. MCP-I / KYA-OS is in active community development with sparse production implementations. The CSA ATF is a governance framework, not an enforcement tool.\\n\\nThe monitoring gap is severe. {{fact}}Only 14.4% of organizations have achieved full IT and security approval for their entire agent fleet, and 88% of organizations reported confirmed or suspected AI agent security incidents in the past year{{cite:18}}.{{/fact}} {{fact}}Only 21.9% of organizations currently treat AI agents as independent, identity-bearing entities within their security model{{cite:3}}.{{/fact}} Most still treat agents as extensions of human users or generic service accounts.\\n\\nThe over-permissioning problem is structural. {{fact}}70% of security leaders say AI systems have more access than a human in the same role, and 67% of organizations rely on static credentials for AI systems{{cite:19}}.{{/fact}} Static, long-lived credentials are the opposite of what every framework recommends. They persist after an agent's task is complete, survive offboarding, and create the same orphaned-account problem that has plagued human identity governance for decades - just at machine speed.\\n\\n{{fact}}The CSA-Oasis State of NHI and AI Security 2026 found that 51% of organizations cite over-permissioned access as a top NHI pain point, and 78% have no documented policy for creating or removing AI identities{{cite:20}}.{{/fact}}\\n\\n{{component:3a13a849-8155-45c7-8c5c-27430a712e8c}}\\n\\n---\\n\\n## What IGA Looks Like When It's Built for This\\n\\nThe governance problem for AI agents is structurally identical to the governance problem for human identities - and for the same reason that IGA exists: access sprawl, orphaned accounts, over-permissioning, and the inability to answer \\\"who has access to what, and should they?\\\" at any given moment.\\n\\nThe difference is velocity and scale. {{fact}}NHIs outnumber human identities 17 to 1 in the average enterprise, and the NHI population grew 44% year-over-year between 2024 and 2025{{cite:21}}.{{/fact}} AI agents are the fastest-growing segment within that already-exploding category. Quarterly access reviews cannot keep pace. Neither can spreadsheets.\\n\\nWhat's needed is a single governance plane that treats human and non-human identities with the same policy engine, the same lifecycle automation, and the same access review workflows - without requiring a separate module, a separate license, or a separate team.\\n\\nThat's the design principle behind Iden. Rather than bolting agent governance onto a human-centric IGA platform, or treating agents as a subset of NHI discovery, Iden governs all identity types - employees, contractors, service accounts, bots, and AI agents - through the same policy-driven lifecycle engine. Fine-grained control at the channel, repository, and project level means an agent gets exactly the access its task requires, and that access is revoked when the task is done. No standing permissions. No orphaned agent accounts.\\n\\nFor organizations evaluating where AI agent governance fits in their stack, the [12 Best IGA Vendors in 2026](/blog/12-best-iga-vendors-2026) post maps the full landscape, and our [NHI explosion piece](/blog/nhi-explosion-non-human-identity) covers the scale of the underlying problem in detail.\\n\\n{{component:a30e26b9-c278-4c10-b474-e6bceaaaa120}}\\n\\n---\\n\\n## How to Evaluate Agent Identity Capabilities Today\\n\\nThe standards are immature, the vendor claims are ahead of the implementations, and the threat is real. Here is a practical evaluation framework for buyers.\\n\\n{{component:1d887c11-0b30-41a3-afdc-9d89b2f6ccfd}}\\n\\n---\\n\\n## The Bottom Line\\n\\nThe 2026 standards landscape for AI agent identity is real and moving fast - MCP OAuth 2.1 under Linux Foundation governance, MCP-I / KYA-OS at the DIF, Microsoft Entra Agent ID in GA, and the CSA Agentic Trust Framework providing the governance vocabulary. These are genuine milestones.\\n\\nBut standards are not implementations. {{fact}}Only 3% of organizations have automated, machine-speed controls governing AI behavior{{cite:19}}.{{/fact}} The gap between what the frameworks prescribe and what organizations have actually deployed is enormous.\\n\\nThe organizations that close that gap fastest will be the ones that stop treating agent governance as a separate problem from identity governance. Agents are identities. They need the same lifecycle controls, the same access reviews, the same deprovisioning workflows, and the same audit trails as every other identity in your environment - just with shorter-lived credentials and faster policy enforcement.\\n\\nThat's not a new category of tooling. It's IGA, built for the full population of identities your enterprise actually runs.\\n\\n{{component:e5afe1d7-cb52-4acd-8a56-b6970002b90b}}\\n\\n\\n## What I want\\n[Ask your question here.]\"])</script><script>self.__next_f.push([1,\"7:[\\\"$\\\",\\\"article\\\",null,{\\\"className\\\":\\\"blog-article\\\",\\\"lang\\\":\\\"en\\\",\\\"children\\\":[[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"mx-auto max-w-[620px] px-6 sm:px-0\\\",\\\"children\\\":[[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"flex items-center justify-between pt-12 sm:pt-16\\\",\\\"children\\\":[[\\\"$\\\",\\\"$L19\\\",null,{\\\"href\\\":\\\"/en/blog\\\",\\\"className\\\":\\\"inline-flex items-center gap-1.5 text-sm text-[var(--blog-muted)] transition-colors hover:text-white\\\",\\\"children\\\":[[\\\"$\\\",\\\"svg\\\",null,{\\\"viewBox\\\":\\\"0 0 16 16\\\",\\\"className\\\":\\\"h-3.5 w-3.5\\\",\\\"fill\\\":\\\"none\\\",\\\"stroke\\\":\\\"currentColor\\\",\\\"strokeWidth\\\":\\\"1.5\\\",\\\"children\\\":[\\\"$\\\",\\\"path\\\",null,{\\\"strokeLinecap\\\":\\\"round\\\",\\\"strokeLinejoin\\\":\\\"round\\\",\\\"d\\\":\\\"M10 3L5 8l5 5\\\"}]}],\\\"Blog\\\"]}],[\\\"$\\\",\\\"$L19\\\",null,{\\\"href\\\":\\\"/de/blog/ki-agenten-identity-management-2026\\\",\\\"hrefLang\\\":\\\"de\\\",\\\"className\\\":\\\"rounded-full border border-[var(--blog-border)] px-3 py-1 text-xs text-[var(--blog-muted)] transition-colors hover:border-[var(--blog-accent)] hover:text-[var(--blog-accent)]\\\",\\\"children\\\":\\\"Auf Deutsch lesen\\\"}]]}],[\\\"$\\\",\\\"$L29\\\",null,{\\\"title\\\":\\\"AI Agent Identity Management in 2026: Standards, Players, and the Governance Gap\\\",\\\"description\\\":\\\"MCP OAuth 2.1, MCP-I at the DIF, Microsoft Entra Agent ID - the 2026 standards landscape for AI agent identity is taking shape. Here's what's real, what's missing, and how to evaluate governance today.\\\",\\\"readingTime\\\":10,\\\"updated\\\":\\\"2026-07-15T07:00:17.688+00:00\\\",\\\"aiContext\\\":\\\"$2a\\\",\\\"lang\\\":\\\"en-US\\\"}]]}],\\\"$L2b\\\",\\\"$L2c\\\"]}]\\n\"])</script><script>self.__next_f.push([1,\"2d:I[91729,[\\\"/_next/static/chunks/0yek_.8jq.av2.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0.gs.ae~fhg8k.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0tuki9zbj7q2o.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0i4-dr.x1t4th.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/0lg_m--jcpv9v.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/15ozypjscxub5.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\",\\\"/_next/static/chunks/08xg.0ckpl~2z.js?dpl=dpl_Dy8xiVwRSMJtvoBs5eLh16TEptge\\\"],\\\"ArticleBody\\\"]\\n2e:T3613,\"])</script><script>self.__next_f.push([1,\"The numbers are no longer theoretical. {{fact}}More than 80% of Fortune 500 companies now run active AI agents built with low-code and no-code tools{{cite:1}}, and {{fact}}Gartner projects that up to 40% of enterprise applications will include integrated task-specific AI agents by the end of 2026, up from less than 5% today{{cite:2}}.{{/fact}}{{/fact}} Yet the security posture underneath that deployment wave is alarming: {{fact}}on average, only 47.1% of an organization's AI agents are actively monitored or secured{{cite:3}}.{{/fact}} The other half operate without oversight, logging, or identity controls.\\n\\nThis is not a future problem. It is the current state of your production environment.\\n\\nThe good news - if you can call it that - is that the standards community has noticed. In the first half of 2026, more governance specifications landed for AI agent identity than in the entire prior history of the field. This post maps what those standards actually say, which vendor categories are responding, where the real gaps remain, and what a buyer should demand today.\\n\\n---\\n\\n## The Standards Landscape: What's Actually Shipping\\n\\n### MCP OAuth 2.1 Under Linux Foundation Governance\\n\\nThe Model Context Protocol started as an Anthropic experiment in November 2024. {{fact}}By December 2025, Anthropic had donated MCP to the Agentic AI Foundation (AAIF) under the Linux Foundation, with OpenAI, Block, AWS, Google, Microsoft, Cloudflare, and Bloomberg joining as founding or platinum members{{cite:4}}.{{/fact}} {{fact}}Within four months, the AAIF grew to 170 member organizations - more than double the membership CNCF had at the same stage of its life{{cite:5}}.{{/fact}}\\n\\nThe governance shift matters for enterprise buyers. MCP is no longer a single-vendor protocol that any one company can deprecate or fork. It is now closer in structure to CNCF than to a proprietary API.\\n\\nOn authentication specifically: {{fact}}the MCP spec mandates OAuth 2.1 with PKCE for all protected HTTP-based deployments, requiring HTTPS on all endpoints and discoverable authorization server metadata{{cite:6}}.{{/fact}} The 2026 roadmap, published in March, makes enterprise readiness - including audit trails, SSO-integrated auth, and configuration portability - a top priority. The spec's authorization Working Group had six dedicated sessions at the April 2026 MCP Dev Summit, with the OAuth 2.1 spec author present.\\n\\n{{fact}}The 2026 MCP roadmap flagged audit trail infrastructure, SSO-integrated auth, and configuration portability as the top enterprise requests{{cite:7}}.{{/fact}} None of those are solved yet. The roadmap is a commitment, not a delivery.\\n\\n{{component:e30cc0b7-1878-4e09-b948-931b4ea6d29d}}\\n\\n### MCP-I / KYA-OS: Decentralized Identity for Agents\\n\\nOAuth 2.1 handles *authentication* - proving an agent is who it claims to be. It does not answer the harder questions: Who authorized this agent? What is it allowed to do on behalf of which human? Can a downstream service verify that chain without prior coordination?\\n\\n{{fact}}In March 2026, Vouched formally donated the Model Context Protocol - Identity (MCP-I) framework to the Decentralized Identity Foundation (DIF), where it is now stewarded by the DIF Trusted AI Agents Working Group{{cite:8}}.{{/fact}} The spec has since been renamed KYA-OS (Know Your Agent Operating System) to reflect its scope beyond MCP alone.\\n\\n{{fact}}MCP-I / KYA-OS uses Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs) to enable cryptographically secure verification of both agents and their human principals - without requiring prior coordination between parties{{cite:9}}.{{/fact}} The framework defines four identity questions every service should be able to answer: Who is the agent? Who authorized it? What is it allowed to do? What is the scope of that delegation?\\n\\nThis is the right architecture for multi-organization agent workflows - a travel booking agent acting on behalf of a user across airline, hotel, and payment systems, for example. It is also early. The spec is in active community development, and production implementations are sparse.\\n\\n### Microsoft Entra Agent ID\\n\\nMicrosoft moved fastest among the major identity platforms. {{fact}}Microsoft Entra Agent ID introduces agent identities as a distinct, purpose-built construct - not a repurposed service principal or user account - with agent identity blueprints serving as templates for creating individual agent identities with parent-child relationships{{cite:10}}.{{/fact}}\\n\\n{{fact}}Agent identities in Entra do not have credentials of their own; they rely on the agent identity blueprint to acquire tokens on their behalf, and they only authenticate using federated identity credentials{{cite:11}}.{{/fact}} This is the right model: credentials live in the blueprint, not on the agent, so a compromised agent cannot exfiltrate its own keys.\\n\\n{{fact}}Microsoft Agent 365, generally available from May 1, 2026, gives each AI agent its own Entra Agent ID for identity, lifecycle, and access management, and integrates with Conditional Access, identity protection, and Microsoft Purview{{cite:12}}.{{/fact}} Third-party agents from AWS Bedrock, n8n, and other frameworks can be onboarded via workload identity federation - no platform-specific credential management required.\\n\\nThe honest limitation: Entra Agent ID is a strong solution if your agent estate lives inside the Microsoft ecosystem. For organizations running heterogeneous stacks - Anthropic, AWS, open-source frameworks, and custom-built agents - the governance surface extends well beyond what any single IdP can cover.\\n\\n### CSA Agentic Trust Framework and CSAI Foundation\\n\\nThe Cloud Security Alliance has been the most prolific standards producer in this space. {{fact}}The CSA published the Agentic Trust Framework (ATF) on February 2, 2026 - the first governance specification applying Zero Trust principles to autonomous AI agents with a structured maturity model{{cite:13}}.{{/fact}} The ATF was co-authored by John Kindervag, the original creator of Zero Trust.\\n\\nA companion survey of 285 IT and security professionals makes the urgency concrete: {{fact}}84% of organizations cannot pass a compliance audit focused on agent behavior or access controls, and only 23% have a formal agent identity strategy{{cite:14}}.{{/fact}}\\n\\nThe CSA's MAESTRO threat modeling framework explicitly names **agent impersonation** as a distinct threat class - malicious actors deceiving users or other agents by impersonating legitimate AI agents. The prescribed mitigations are trusted agent registries, cryptographic agent identities, and short-lived OAuth/OIDC tokens scoped to the intersection of what the agent is allowed to do AND what the delegating user is allowed to do. An AND gate, not an OR gate.\\n\\n{{fact}}In March 2026, the CSA launched the CSAI Foundation at RSAC 2026, a new 501(c)3 dedicated exclusively to AI security, with a 2026 mission of \\\"Securing the Agentic Control Plane\\\" - governing identity, authorization, orchestration, runtime behavior, and trust assurance for autonomous AI agent ecosystems{{cite:15}}.{{/fact}}\\n\\n---\\n\\n## The Player Map: Four Categories, Different Strengths\\n\\nThe vendor landscape has fragmented into four distinct categories. Understanding what each does - and doesn't do - is essential before buying.\\n\\n{{component:f0d62597-013b-4953-b03d-747adcaf9cba}}\\n\\nA few notes on the landscape:\\n\\n**Identity providers** are moving fast. {{fact}}Auth0's \\\"Auth for MCP\\\" became generally available on May 6, 2026, and Okta released its own MCP server as a secure protocol abstraction layer enabling AI agents to interact with Okta's scoped management APIs with least-privilege access control enforced at each tool call{{cite:2}}.{{/fact}} These are authentication solutions. They do not govern the full identity lifecycle.\\n\\n**NHI specialists** have the discovery story right. {{fact}}Veza's 2026 State of Identity and Access report found that a mere 0.01% of non-human identities control 80% of cloud resources, while the average worker holds 96,000 entitlements{{cite:16}}.{{/fact}} Knowing that is valuable. Governing it requires more than a posture dashboard.\\n\\n**MCP gateways** solve the runtime enforcement problem elegantly for agents you build inside their ecosystem. The problem is coverage: {{fact}}only 23.7% of organizations use their existing IAM/IdP as an authorization server for their agentic MCP infrastructure{{cite:3}}.{{/fact}} The rest are running disconnected auth stacks.\\n\\n**IGA platforms** are the natural home for agent governance - if they've actually built it. {{fact}}SailPoint expanded Agent Identity Security connectors in 2026 to include SaaS versions of Salesforce, ServiceNow, and Snowflake, but governance of agent identities requires a separate Agent Identity Security license{{cite:17}}.{{/fact}} Legacy IGA vendors are adding agent support as a module. That's not the same as designing for it from the start.\\n\\n---\\n\\n## The Honest Gaps\\n\\nStandards are immature. The MCP OAuth 2.1 profile is solid for authentication but has no standardized audit trail format. MCP-I / KYA-OS is in active community development with sparse production implementations. The CSA ATF is a governance framework, not an enforcement tool.\\n\\nThe monitoring gap is severe. {{fact}}Only 14.4% of organizations have achieved full IT and security approval for their entire agent fleet, and 88% of organizations reported confirmed or suspected AI agent security incidents in the past year{{cite:18}}.{{/fact}} {{fact}}Only 21.9% of organizations currently treat AI agents as independent, identity-bearing entities within their security model{{cite:3}}.{{/fact}} Most still treat agents as extensions of human users or generic service accounts.\\n\\nThe over-permissioning problem is structural. {{fact}}70% of security leaders say AI systems have more access than a human in the same role, and 67% of organizations rely on static credentials for AI systems{{cite:19}}.{{/fact}} Static, long-lived credentials are the opposite of what every framework recommends. They persist after an agent's task is complete, survive offboarding, and create the same orphaned-account problem that has plagued human identity governance for decades - just at machine speed.\\n\\n{{fact}}The CSA-Oasis State of NHI and AI Security 2026 found that 51% of organizations cite over-permissioned access as a top NHI pain point, and 78% have no documented policy for creating or removing AI identities{{cite:20}}.{{/fact}}\\n\\n{{component:3a13a849-8155-45c7-8c5c-27430a712e8c}}\\n\\n---\\n\\n## What IGA Looks Like When It's Built for This\\n\\nThe governance problem for AI agents is structurally identical to the governance problem for human identities - and for the same reason that IGA exists: access sprawl, orphaned accounts, over-permissioning, and the inability to answer \\\"who has access to what, and should they?\\\" at any given moment.\\n\\nThe difference is velocity and scale. {{fact}}NHIs outnumber human identities 17 to 1 in the average enterprise, and the NHI population grew 44% year-over-year between 2024 and 2025{{cite:21}}.{{/fact}} AI agents are the fastest-growing segment within that already-exploding category. Quarterly access reviews cannot keep pace. Neither can spreadsheets.\\n\\nWhat's needed is a single governance plane that treats human and non-human identities with the same policy engine, the same lifecycle automation, and the same access review workflows - without requiring a separate module, a separate license, or a separate team.\\n\\nThat's the design principle behind Iden. Rather than bolting agent governance onto a human-centric IGA platform, or treating agents as a subset of NHI discovery, Iden governs all identity types - employees, contractors, service accounts, bots, and AI agents - through the same policy-driven lifecycle engine. Fine-grained control at the channel, repository, and project level means an agent gets exactly the access its task requires, and that access is revoked when the task is done. No standing permissions. No orphaned agent accounts.\\n\\nFor organizations evaluating where AI agent governance fits in their stack, the [12 Best IGA Vendors in 2026](/blog/12-best-iga-vendors-2026) post maps the full landscape, and our [NHI explosion piece](/blog/nhi-explosion-non-human-identity) covers the scale of the underlying problem in detail.\\n\\n{{component:a30e26b9-c278-4c10-b474-e6bceaaaa120}}\\n\\n---\\n\\n## How to Evaluate Agent Identity Capabilities Today\\n\\nThe standards are immature, the vendor claims are ahead of the implementations, and the threat is real. Here is a practical evaluation framework for buyers.\\n\\n{{component:1d887c11-0b30-41a3-afdc-9d89b2f6ccfd}}\\n\\n---\\n\\n## The Bottom Line\\n\\nThe 2026 standards landscape for AI agent identity is real and moving fast - MCP OAuth 2.1 under Linux Foundation governance, MCP-I / KYA-OS at the DIF, Microsoft Entra Agent ID in GA, and the CSA Agentic Trust Framework providing the governance vocabulary. These are genuine milestones.\\n\\nBut standards are not implementations. {{fact}}Only 3% of organizations have automated, machine-speed controls governing AI behavior{{cite:19}}.{{/fact}} The gap between what the frameworks prescribe and what organizations have actually deployed is enormous.\\n\\nThe organizations that close that gap fastest will be the ones that stop treating agent governance as a separate problem from identity governance. Agents are identities. They need the same lifecycle controls, the same access reviews, the same deprovisioning workflows, and the same audit trails as every other identity in your environment - just with shorter-lived credentials and faster policy enforcement.\\n\\nThat's not a new category of tooling. It's IGA, built for the full population of identities your enterprise actually runs.\\n\\n{{component:e5afe1d7-cb52-4acd-8a56-b6970002b90b}}\\n\"])</script><script>self.__next_f.push([1,\"2f:T43f,Build an interactive AI Agent Identity Governance Readiness Assessment. It should be a short quiz (6 questions) that helps a CISO or security engineer assess their organization's current maturity for governing AI agent identities. Questions should cover: 1) What percentage of your AI agents have unique, managed identities (vs shared credentials or API keys)? 2) Do you have a formal approval process before agents go to production? 3) How are agent credentials managed (static API keys / short-lived tokens / no formal process)? 4) Can you produce a per-tool-call audit trail for any agent on demand? 5) Are AI agent identities included in your regular access review cycles? 6) Do you have automated deprovisioning when an agent is retired? Each answer should be scored (0-2 points). At the end, display a maturity score out of 12 with a label (0-4: 'Shadow Agent Risk', 5-8: 'Emerging Governance', 9-12: 'Governed Agent Estate') and a 2-sentence recommendation for the next step. Style it cleanly with a progress bar and color-coded result. Use only HTML, CSS, and vanilla JavaScript.30:T6db0,\"])</script><script>self.__next_f.push([1,\"\\u003c!DOCTYPE html\\u003e\\n\\u003chtml lang=\\\"en\\\"\\u003e\\n\\u003chead\\u003e\\n  \\u003cmeta charset=\\\"UTF-8\\\" /\\u003e\\n  \\u003cmeta name=\\\"viewport\\\" content=\\\"width=device-width, initial-scale=1.0\\\" /\\u003e\\n  \\u003cmeta http-equiv=\\\"Content-Security-Policy\\\" content=\\\"default-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://fonts.gstatic.com https://cdn.jsdelivr.net; script-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net; img-src https: data:;\\\"\\u003e\\n  \\u003ctitle\\u003eAI Agent Identity Governance Readiness Assessment\\u003c/title\\u003e\\n  \\u003clink href=\\\"https://fonts.googleapis.com/css2?family=Inter:wght@400;500;600;700\\u0026display=swap\\\" rel=\\\"stylesheet\\\"\\u003e\\n  \\u003cstyle\\u003e\\n    *, *::before, *::after { box-sizing: border-box; margin: 0; padding: 0; }\\n\\n    html, body {\\n      overflow: hidden;\\n      margin: 0;\\n      padding: 0 0 24px 0;\\n      background: #ffffff;\\n      font-family: 'Inter', 'Alliance No.1', sans-serif;\\n      color: #000000;\\n    }\\n\\n    :root {\\n      --primary: #486BF0;\\n      --accent: #4669ED;\\n      --bg: #ffffff;\\n      --text: #000000;\\n      --text-muted: #555e78;\\n      --border: #dde3f5;\\n      --card-bg: #f5f7ff;\\n      --success: #10b981;\\n      --warn: #f59e0b;\\n      --danger: #ef4444;\\n      --radius: 12px;\\n      --radius-sm: 8px;\\n    }\\n\\n    .widget {\\n      max-width: 680px;\\n      margin: 0 auto;\\n      padding: 20px 16px 0;\\n    }\\n\\n    /* HEADER */\\n    .header {\\n      text-align: center;\\n      margin-bottom: 18px;\\n    }\\n    .header-badge {\\n      display: inline-flex;\\n      align-items: center;\\n      gap: 6px;\\n      background: #eef1fd;\\n      color: var(--primary);\\n      font-size: 11px;\\n      font-weight: 600;\\n      letter-spacing: .06em;\\n      text-transform: uppercase;\\n      padding: 4px 12px;\\n      border-radius: 20px;\\n      margin-bottom: 10px;\\n    }\\n    .header-badge svg { width: 13px; height: 13px; flex-shrink: 0; }\\n    .header h1 {\\n      font-size: clamp(17px, 3.5vw, 22px);\\n      font-weight: 700;\\n      color: var(--text);\\n      line-height: 1.25;\\n      margin-bottom: 5px;\\n    }\\n    .header p {\\n      font-size: clamp(12px, 2.5vw, 13.5px);\\n      color: var(--text-muted);\\n      line-height: 1.5;\\n    }\\n\\n    /* PROGRESS BAR */\\n    .progress-wrap {\\n      margin-bottom: 16px;\\n    }\\n    .progress-meta {\\n      display: flex;\\n      justify-content: space-between;\\n      align-items: center;\\n      margin-bottom: 6px;\\n    }\\n    .progress-label {\\n      font-size: 12px;\\n      font-weight: 600;\\n      color: var(--text-muted);\\n    }\\n    .progress-count {\\n      font-size: 12px;\\n      font-weight: 700;\\n      color: var(--primary);\\n    }\\n    .progress-track {\\n      height: 6px;\\n      background: #e8ecfd;\\n      border-radius: 99px;\\n      overflow: hidden;\\n    }\\n    .progress-fill {\\n      height: 100%;\\n      background: linear-gradient(90deg, var(--primary), var(--accent));\\n      border-radius: 99px;\\n      transition: width .4s cubic-bezier(.4,0,.2,1);\\n      width: 0%;\\n    }\\n\\n    /* QUIZ CARD */\\n    .quiz-card {\\n      background: var(--card-bg);\\n      border: 1.5px solid var(--border);\\n      border-radius: var(--radius);\\n      padding: 18px 18px 16px;\\n      position: relative;\\n      transition: opacity .3s;\\n    }\\n    .q-header {\\n      display: flex;\\n      align-items: flex-start;\\n      gap: 10px;\\n      margin-bottom: 14px;\\n    }\\n    .q-num {\\n      min-width: 28px;\\n      height: 28px;\\n      border-radius: 50%;\\n      background: var(--primary);\\n      color: #fff;\\n      font-size: 12px;\\n      font-weight: 700;\\n      display: flex;\\n      align-items: center;\\n      justify-content: center;\\n      flex-shrink: 0;\\n      margin-top: 1px;\\n    }\\n    .q-text {\\n      font-size: clamp(13px, 2.8vw, 14.5px);\\n      font-weight: 600;\\n      color: var(--text);\\n      line-height: 1.45;\\n    }\\n    .q-icon {\\n      font-size: 17px;\\n      margin-right: 2px;\\n      vertical-align: middle;\\n    }\\n\\n    /* OPTIONS */\\n    .options { display: flex; flex-direction: column; gap: 7px; }\\n    .option-btn {\\n      display: flex;\\n      align-items: flex-start;\\n      gap: 10px;\\n      background: #fff;\\n      border: 1.5px solid var(--border);\\n      border-radius: var(--radius-sm);\\n      padding: 10px 12px;\\n      cursor: pointer;\\n      text-align: left;\\n      transition: border-color .18s, background .18s, box-shadow .18s;\\n      font-family: inherit;\\n      width: 100%;\\n      position: relative;\\n    }\\n    .option-btn:hover {\\n      border-color: var(--primary);\\n      background: #f0f3fe;\\n      box-shadow: 0 2px 8px rgba(72,107,240,.08);\\n    }\\n    .option-btn.selected {\\n      border-color: var(--primary);\\n      background: #eef1fd;\\n      box-shadow: 0 0 0 2px rgba(72,107,240,.18);\\n    }\\n    .option-btn.selected .opt-radio { background: var(--primary); border-color: var(--primary); }\\n    .option-btn.selected .opt-radio::after { opacity: 1; }\\n    .opt-radio {\\n      width: 16px;\\n      height: 16px;\\n      border-radius: 50%;\\n      border: 2px solid #b0bbd9;\\n      flex-shrink: 0;\\n      margin-top: 2px;\\n      display: flex;\\n      align-items: center;\\n      justify-content: center;\\n      transition: background .18s, border-color .18s;\\n      position: relative;\\n    }\\n    .opt-radio::after {\\n      content: '';\\n      width: 7px;\\n      height: 7px;\\n      border-radius: 50%;\\n      background: #fff;\\n      opacity: 0;\\n      transition: opacity .18s;\\n    }\\n    .opt-content { flex: 1; }\\n    .opt-label {\\n      font-size: clamp(12px, 2.5vw, 13px);\\n      font-weight: 500;\\n      color: var(--text);\\n      line-height: 1.4;\\n      display: block;\\n    }\\n    .opt-score {\\n      font-size: 10.5px;\\n      color: var(--text-muted);\\n      margin-top: 2px;\\n    }\\n    .score-dot {\\n      display: inline-block;\\n      width: 7px; height: 7px;\\n      border-radius: 50%;\\n      margin-right: 3px;\\n      vertical-align: middle;\\n    }\\n    .score-0 { background: var(--danger); }\\n    .score-1 { background: var(--warn); }\\n    .score-2 { background: var(--success); }\\n\\n    /* NAV BUTTONS */\\n    .nav-row {\\n      display: flex;\\n      justify-content: space-between;\\n      align-items: center;\\n      margin-top: 14px;\\n      gap: 8px;\\n    }\\n    .btn {\\n      display: inline-flex;\\n      align-items: center;\\n      gap: 6px;\\n      padding: 9px 20px;\\n      border-radius: var(--radius-sm);\\n      font-family: inherit;\\n      font-size: 13px;\\n      font-weight: 600;\\n      cursor: pointer;\\n      border: none;\\n      transition: background .18s, opacity .18s, transform .12s;\\n      line-height: 1;\\n    }\\n    .btn:active { transform: scale(.97); }\\n    .btn-primary {\\n      background: var(--primary);\\n      color: #fff;\\n      box-shadow: 0 2px 10px rgba(72,107,240,.28);\\n    }\\n    .btn-primary:hover { background: var(--accent); }\\n    .btn-primary:disabled { opacity: .4; cursor: not-allowed; }\\n    .btn-ghost {\\n      background: transparent;\\n      color: var(--text-muted);\\n      border: 1.5px solid var(--border);\\n    }\\n    .btn-ghost:hover { border-color: #b0bbd9; color: var(--text); }\\n    .btn svg { width: 15px; height: 15px; }\\n\\n    /* RESULT PANEL */\\n    .result-panel { display: none; }\\n    .result-panel.visible { display: block; }\\n    .quiz-active.hidden { display: none; }\\n\\n    .result-card {\\n      border-radius: var(--radius);\\n      padding: 20px 18px 18px;\\n      border: 1.5px solid var(--border);\\n      margin-bottom: 12px;\\n      text-align: center;\\n    }\\n    .result-card.shadow-risk  { background: #fff5f5; border-color: #fca5a5; }\\n    .result-card.emerging     { background: #fffbeb; border-color: #fcd34d; }\\n    .result-card.governed     { background: #f0fdf4; border-color: #6ee7b7; }\\n\\n    .result-tier-badge {\\n      display: inline-flex;\\n      align-items: center;\\n      gap: 6px;\\n      padding: 5px 14px;\\n      border-radius: 20px;\\n      font-size: 11px;\\n      font-weight: 700;\\n      letter-spacing: .07em;\\n      text-transform: uppercase;\\n      margin-bottom: 10px;\\n    }\\n    .shadow-risk  .result-tier-badge { background: #fee2e2; color: #b91c1c; }\\n    .emerging     .result-tier-badge { background: #fef3c7; color: #92400e; }\\n    .governed     .result-tier-badge { background: #dcfce7; color: #166534; }\\n\\n    .result-score-wrap {\\n      display: flex;\\n      align-items: center;\\n      justify-content: center;\\n      gap: 4px;\\n      margin-bottom: 8px;\\n    }\\n    .result-score-num {\\n      font-size: clamp(36px, 8vw, 48px);\\n      font-weight: 800;\\n      line-height: 1;\\n    }\\n    .shadow-risk  .result-score-num { color: var(--danger); }\\n    .emerging     .result-score-num { color: #d97706; }\\n    .governed     .result-score-num { color: #059669; }\\n\\n    .result-score-denom {\\n      font-size: 18px;\\n      font-weight: 600;\\n      color: var(--text-muted);\\n      align-self: flex-end;\\n      margin-bottom: 6px;\\n    }\\n    .result-label {\\n      font-size: clamp(15px, 3.2vw, 18px);\\n      font-weight: 700;\\n      color: var(--text);\\n      margin-bottom: 6px;\\n    }\\n\\n    /* Score bar */\\n    .result-bar-track {\\n      height: 10px;\\n      background: #e5e7eb;\\n      border-radius: 99px;\\n      overflow: hidden;\\n      margin: 10px 0 14px;\\n    }\\n    .result-bar-fill {\\n      height: 100%;\\n      border-radius: 99px;\\n      transition: width 1s cubic-bezier(.4,0,.2,1);\\n      width: 0%;\\n    }\\n    .shadow-risk  .result-bar-fill { background: linear-gradient(90deg,#f87171,#ef4444); }\\n    .emerging     .result-bar-fill { background: linear-gradient(90deg,#fbbf24,#f59e0b); }\\n    .governed     .result-bar-fill { background: linear-gradient(90deg,#34d399,#059669); }\\n\\n    .result-rec {\\n      font-size: clamp(12px, 2.5vw, 13.5px);\\n      color: var(--text-muted);\\n      line-height: 1.6;\\n      text-align: left;\\n      background: rgba(255,255,255,.7);\\n      border-radius: var(--radius-sm);\\n      padding: 12px 14px;\\n      border: 1px solid rgba(0,0,0,.07);\\n      margin-top: 4px;\\n    }\\n    .result-rec strong { color: var(--text); }\\n\\n    /* BREAKDOWN */\\n    .breakdown-title {\\n      font-size: 12px;\\n      font-weight: 700;\\n      letter-spacing: .06em;\\n      text-transform: uppercase;\\n      color: var(--text-muted);\\n      margin-bottom: 8px;\\n    }\\n    .breakdown-grid {\\n      display: grid;\\n      grid-template-columns: 1fr 1fr;\\n      gap: 7px;\\n    }\\n    @media (max-width: 380px) { .breakdown-grid { grid-template-columns: 1fr; } }\\n    .breakdown-item {\\n      background: var(--card-bg);\\n      border: 1.5px solid var(--border);\\n      border-radius: var(--radius-sm);\\n      padding: 9px 11px;\\n      display: flex;\\n      align-items: center;\\n      gap: 8px;\\n    }\\n    .bi-icon { font-size: 18px; flex-shrink: 0; }\\n    .bi-info { flex: 1; min-width: 0; }\\n    .bi-label {\\n      font-size: 11px;\\n      color: var(--text-muted);\\n      line-height: 1.3;\\n      display: block;\\n    }\\n    .bi-score {\\n      font-size: 12px;\\n      font-weight: 700;\\n      display: flex;\\n      align-items: center;\\n      gap: 4px;\\n      margin-top: 2px;\\n    }\\n    .bi-pip {\\n      width: 8px; height: 8px;\\n      border-radius: 50%;\\n      flex-shrink: 0;\\n    }\\n    .pip-0 { background: var(--danger); }\\n    .pip-1 { background: var(--warn); }\\n    .pip-2 { background: var(--success); }\\n\\n    .restart-row {\\n      text-align: center;\\n      margin-top: 12px;\\n    }\\n    .btn-outline-primary {\\n      background: #fff;\\n      color: var(--primary);\\n      border: 1.5px solid var(--primary);\\n    }\\n    .btn-outline-primary:hover { background: #eef1fd; }\\n\\n    /* Transitions */\\n    .fade-in { animation: fadeIn .35s ease; }\\n    @keyframes fadeIn { from { opacity:0; transform:translateY(8px); } to { opacity:1; transform:translateY(0); } }\\n  \\u003c/style\\u003e\\n\\u003c/head\\u003e\\n\\u003cbody\\u003e\\n\\u003cdiv class=\\\"widget\\\" id=\\\"root\\\"\\u003e\\n\\n  \\u003c!-- HEADER --\\u003e\\n  \\u003cdiv class=\\\"header\\\"\\u003e\\n    \\u003cdiv class=\\\"header-badge\\\"\\u003e\\n      \\u003csvg viewBox=\\\"0 0 16 16\\\" fill=\\\"currentColor\\\"\\u003e\\u003cpath d=\\\"M8 1a5 5 0 100 10A5 5 0 008 1zm0 9a4 4 0 110-8 4 4 0 010 8z\\\"/\\u003e\\u003cpath d=\\\"M8 4a1 1 0 100 2 1 1 0 000-2zm0 3a.75.75 0 01.75.75v2.5a.75.75 0 01-1.5 0v-2.5A.75.75 0 018 7z\\\"/\\u003e\\u003c/svg\\u003e\\n      AI Identity Governance\\n    \\u003c/div\\u003e\\n    \\u003ch1 id=\\\"h-title\\\"\\u003eAI Agent Identity Governance\\u003cbr\\u003eReadiness Assessment\\u003c/h1\\u003e\\n    \\u003cp id=\\\"h-sub\\\"\\u003e6 questions · ~2 min · Instant maturity score for CISOs \\u0026amp; security engineers\\u003c/p\\u003e\\n  \\u003c/div\\u003e\\n\\n  \\u003c!-- PROGRESS --\\u003e\\n  \\u003cdiv class=\\\"progress-wrap\\\" id=\\\"progressWrap\\\"\\u003e\\n    \\u003cdiv class=\\\"progress-meta\\\"\\u003e\\n      \\u003cspan class=\\\"progress-label\\\" id=\\\"pLabel\\\"\\u003eQuestion\\u003c/span\\u003e\\n      \\u003cspan class=\\\"progress-count\\\" id=\\\"pCount\\\"\\u003e1 / 6\\u003c/span\\u003e\\n    \\u003c/div\\u003e\\n    \\u003cdiv class=\\\"progress-track\\\"\\u003e\\u003cdiv class=\\\"progress-fill\\\" id=\\\"progressFill\\\"\\u003e\\u003c/div\\u003e\\u003c/div\\u003e\\n  \\u003c/div\\u003e\\n\\n  \\u003c!-- QUIZ --\\u003e\\n  \\u003cdiv class=\\\"quiz-active fade-in\\\" id=\\\"quizSection\\\"\\u003e\\n    \\u003cdiv class=\\\"quiz-card\\\" id=\\\"quizCard\\\"\\u003e\\n      \\u003cdiv class=\\\"q-header\\\"\\u003e\\n        \\u003cdiv class=\\\"q-num\\\" id=\\\"qNum\\\"\\u003e1\\u003c/div\\u003e\\n        \\u003cdiv class=\\\"q-text\\\" id=\\\"qText\\\"\\u003e\\u003c/div\\u003e\\n      \\u003c/div\\u003e\\n      \\u003cdiv class=\\\"options\\\" id=\\\"optionsContainer\\\"\\u003e\\u003c/div\\u003e\\n    \\u003c/div\\u003e\\n    \\u003cdiv class=\\\"nav-row\\\"\\u003e\\n      \\u003cbutton class=\\\"btn btn-ghost\\\" id=\\\"btnBack\\\" onclick=\\\"goBack()\\\"\\u003e\\n        \\u003csvg viewBox=\\\"0 0 20 20\\\" fill=\\\"currentColor\\\"\\u003e\\u003cpath fill-rule=\\\"evenodd\\\" d=\\\"M9.707 16.707a1 1 0 01-1.414 0l-6-6a1 1 0 010-1.414l6-6a1 1 0 011.414 1.414L5.414 9H17a1 1 0 110 2H5.414l4.293 4.293a1 1 0 010 1.414z\\\" clip-rule=\\\"evenodd\\\"/\\u003e\\u003c/svg\\u003e\\n        \\u003cspan id=\\\"btnBackText\\\"\\u003eBack\\u003c/span\\u003e\\n      \\u003c/button\\u003e\\n      \\u003cbutton class=\\\"btn btn-primary\\\" id=\\\"btnNext\\\" onclick=\\\"goNext()\\\" disabled\\u003e\\n        \\u003cspan id=\\\"btnNextText\\\"\\u003eNext\\u003c/span\\u003e\\n        \\u003csvg viewBox=\\\"0 0 20 20\\\" fill=\\\"currentColor\\\"\\u003e\\u003cpath fill-rule=\\\"evenodd\\\" d=\\\"M10.293 3.293a1 1 0 011.414 0l6 6a1 1 0 010 1.414l-6 6a1 1 0 01-1.414-1.414L14.586 11H3a1 1 0 110-2h11.586l-4.293-4.293a1 1 0 010-1.414z\\\" clip-rule=\\\"evenodd\\\"/\\u003e\\u003c/svg\\u003e\\n      \\u003c/button\\u003e\\n    \\u003c/div\\u003e\\n  \\u003c/div\\u003e\\n\\n  \\u003c!-- RESULT --\\u003e\\n  \\u003cdiv class=\\\"result-panel\\\" id=\\\"resultPanel\\\"\\u003e\\n    \\u003cdiv class=\\\"result-card\\\" id=\\\"resultCard\\\"\\u003e\\n      \\u003cdiv class=\\\"result-tier-badge\\\" id=\\\"tierBadge\\\"\\u003e\\u003c/div\\u003e\\n      \\u003cdiv class=\\\"result-score-wrap\\\"\\u003e\\n        \\u003cdiv class=\\\"result-score-num\\\" id=\\\"scoreNum\\\"\\u003e0\\u003c/div\\u003e\\n        \\u003cdiv class=\\\"result-score-denom\\\"\\u003e\\u0026thinsp;/ 12\\u003c/div\\u003e\\n      \\u003c/div\\u003e\\n      \\u003cdiv class=\\\"result-label\\\" id=\\\"resultLabel\\\"\\u003e\\u003c/div\\u003e\\n      \\u003cdiv class=\\\"result-bar-track\\\"\\u003e\\u003cdiv class=\\\"result-bar-fill\\\" id=\\\"resultBarFill\\\"\\u003e\\u003c/div\\u003e\\u003c/div\\u003e\\n      \\u003cdiv class=\\\"result-rec\\\" id=\\\"resultRec\\\"\\u003e\\u003c/div\\u003e\\n    \\u003c/div\\u003e\\n\\n    \\u003cdiv class=\\\"breakdown-title\\\" id=\\\"bdTitle\\\"\\u003eScore Breakdown\\u003c/div\\u003e\\n    \\u003cdiv class=\\\"breakdown-grid\\\" id=\\\"breakdownGrid\\\"\\u003e\\u003c/div\\u003e\\n\\n    \\u003cdiv class=\\\"restart-row\\\"\\u003e\\n      \\u003cbutton class=\\\"btn btn-outline-primary\\\" onclick=\\\"restart()\\\"\\u003e\\n        \\u003csvg viewBox=\\\"0 0 20 20\\\" fill=\\\"currentColor\\\" style=\\\"width:14px;height:14px\\\"\\u003e\\u003cpath fill-rule=\\\"evenodd\\\" d=\\\"M4 2a1 1 0 011 1v2.101a7.002 7.002 0 0111.601 2.566 1 1 0 11-1.885.666A5.002 5.002 0 005.999 7H9a1 1 0 010 2H4a1 1 0 01-1-1V3a1 1 0 011-1zm.008 9.057a1 1 0 011.276.61A5.002 5.002 0 0014.001 13H11a1 1 0 110-2h5a1 1 0 011 1v5a1 1 0 11-2 0v-2.101a7.002 7.002 0 01-11.601-2.566 1 1 0 01.61-1.276z\\\" clip-rule=\\\"evenodd\\\"/\\u003e\\u003c/svg\\u003e\\n        \\u003cspan id=\\\"btnRestartText\\\"\\u003eRetake Assessment\\u003c/span\\u003e\\n      \\u003c/button\\u003e\\n    \\u003c/div\\u003e\\n  \\u003c/div\\u003e\\n\\n\\u003c/div\\u003e\\n\\n\\u003cscript\\u003e\\nconst i18n = {\\n  en: { title:\\\"AI Agent Identity Governance Readiness Assessment\\\", sub:\\\"6 questions · ~2 min · Instant maturity score for CISOs \\u0026 security engineers\\\", question:\\\"Question\\\", back:\\\"Back\\\", next:\\\"Next\\\", seeResults:\\\"See Results\\\", retake:\\\"Retake Assessment\\\", breakdown:\\\"Score Breakdown\\\", rec:\\\"Recommendation\\\" },\\n  de: { title:\\\"KI-Agenten-Identitäts-Governance Bereitschaftsbewertung\\\", sub:\\\"6 Fragen · ~2 Min · Sofortiger Reifegrad für CISOs\\\", question:\\\"Frage\\\", back:\\\"Zurück\\\", next:\\\"Weiter\\\", seeResults:\\\"Ergebnisse anzeigen\\\", retake:\\\"Neu starten\\\", breakdown:\\\"Punkteübersicht\\\", rec:\\\"Empfehlung\\\" },\\n  es: { title:\\\"Evaluación de Madurez en Gobernanza de Identidad de Agentes IA\\\", sub:\\\"6 preguntas · ~2 min · Puntuación instantánea para CISOs\\\", question:\\\"Pregunta\\\", back:\\\"Atrás\\\", next:\\\"Siguiente\\\", seeResults:\\\"Ver resultados\\\", retake:\\\"Volver a evaluar\\\", breakdown:\\\"Desglose de puntuación\\\", rec:\\\"Recomendación\\\" },\\n  fr: { title:\\\"Évaluation de Maturité en Gouvernance des Identités d'Agents IA\\\", sub:\\\"6 questions · ~2 min · Score instantané pour les RSSI\\\", question:\\\"Question\\\", back:\\\"Retour\\\", next:\\\"Suivant\\\", seeResults:\\\"Voir les résultats\\\", retake:\\\"Recommencer\\\", breakdown:\\\"Détail du score\\\", rec:\\\"Recommandation\\\" },\\n  it: { title:\\\"Valutazione della Maturità nella Governance delle Identità degli Agenti IA\\\", sub:\\\"6 domande · ~2 min · Punteggio istantaneo per CISO\\\", question:\\\"Domanda\\\", back:\\\"Indietro\\\", next:\\\"Avanti\\\", seeResults:\\\"Vedi risultati\\\", retake:\\\"Ricomincia\\\", breakdown:\\\"Dettaglio punteggio\\\", rec:\\\"Raccomandazione\\\" },\\n  pt: { title:\\\"Avaliação de Maturidade em Governança de Identidade de Agentes IA\\\", sub:\\\"6 perguntas · ~2 min · Pontuação instantânea para CISOs\\\", question:\\\"Pergunta\\\", back:\\\"Voltar\\\", next:\\\"Próximo\\\", seeResults:\\\"Ver resultados\\\", retake:\\\"Refazer avaliação\\\", breakdown:\\\"Detalhamento do score\\\", rec:\\\"Recomendação\\\" },\\n  \\\"pt-BR\\\": { title:\\\"Avaliação de Maturidade em Governança de Identidade de Agentes IA\\\", sub:\\\"6 perguntas · ~2 min · Pontuação instantânea para CISOs\\\", question:\\\"Pergunta\\\", back:\\\"Voltar\\\", next:\\\"Próximo\\\", seeResults:\\\"Ver resultados\\\", retake:\\\"Refazer avaliação\\\", breakdown:\\\"Detalhamento do score\\\", rec:\\\"Recomendação\\\" },\\n  pl: { title:\\\"Ocena Dojrzałości Zarządzania Tożsamością Agentów AI\\\", sub:\\\"6 pytań · ~2 min · Natychmiastowy wynik dla CISO\\\", question:\\\"Pytanie\\\", back:\\\"Wstecz\\\", next:\\\"Dalej\\\", seeResults:\\\"Zobacz wyniki\\\", retake:\\\"Zacznij od nowa\\\", breakdown:\\\"Szczegóły wyniku\\\", rec:\\\"Zalecenie\\\" },\\n  ar: { title:\\\"تقييم جاهزية حوكمة هوية عملاء الذكاء الاصطناعي\\\", sub:\\\"٦ أسئلة · دقيقتان · نتيجة فورية للمسؤولين الأمنيين\\\", question:\\\"سؤال\\\", back:\\\"رجوع\\\", next:\\\"التالي\\\", seeResults:\\\"عرض النتائج\\\", retake:\\\"إعادة التقييم\\\", breakdown:\\\"تفصيل النتيجة\\\", rec:\\\"توصية\\\" }\\n};\\nconst lang = (window.__LANG || 'en');\\nconst t = i18n[lang] || i18n.en;\\nif (lang === 'ar') document.getElementById('root').setAttribute('dir', 'rtl');\\n\\nconst questions = [\\n  {\\n    icon: \\\"🪪\\\",\\n    text: \\\"What percentage of your AI agents have unique, individually managed identities — rather than shared credentials or generic API keys?\\\",\\n    options: [\\n      { label: \\\"Less than 25% — most agents share credentials or use untracked API keys\\\", score: 0 },\\n      { label: \\\"25–74% — we've started assigning identities but coverage is incomplete\\\", score: 1 },\\n      { label: \\\"75% or more — nearly all agents have unique, managed identities\\\", score: 2 }\\n    ]\\n  },\\n  {\\n    icon: \\\"✅\\\",\\n    text: \\\"Do you have a formal approval or security review process that every AI agent must pass before it is deployed to production?\\\",\\n    options: [\\n      { label: \\\"No — agents are deployed by developers without a centralized review\\\", score: 0 },\\n      { label: \\\"Informally — some teams do ad-hoc reviews, but it's not policy-enforced\\\", score: 1 },\\n      { label: \\\"Yes — a documented, mandatory approval workflow exists and is consistently followed\\\", score: 2 }\\n    ]\\n  },\\n  {\\n    icon: \\\"🔑\\\",\\n    text: \\\"How are credentials and secrets for AI agents currently managed in your environment?\\\",\\n    options: [\\n      { label: \\\"No formal process — static API keys stored in code, config files, or informally shared\\\", score: 0 },\\n      { label: \\\"Partial controls — secrets manager used by some teams, but no org-wide standard\\\", score: 1 },\\n      { label: \\\"Short-lived / JIT tokens — agents receive time-bound credentials via a vault or secrets manager, with rotation enforced\\\", score: 2 }\\n    ]\\n  },\\n  {\\n    icon: \\\"📋\\\",\\n    text: \\\"Can your team produce a complete, per-tool-call audit trail for any specific AI agent on demand (e.g., for an incident response or compliance review)?\\\",\\n    options: [\\n      { label: \\\"No — we have little to no visibility into individual agent actions or tool calls\\\", score: 0 },\\n      { label: \\\"Partially — some logs exist but they're incomplete, unstructured, or hard to query\\\", score: 1 },\\n      { label: \\\"Yes — we have structured, queryable logs that capture every tool call per agent, available on demand\\\", score: 2 }\\n    ]\\n  },\\n  {\\n    icon: \\\"🔄\\\",\\n    text: \\\"Are AI agent identities explicitly included in your organization's regular access review or certification cycles (e.g., quarterly entitlement reviews)?\\\",\\n    options: [\\n      { label: \\\"No — AI agents are not part of any access review program\\\", score: 0 },\\n      { label: \\\"Partially — some agents are reviewed, but it's inconsistent or manual\\\", score: 1 },\\n      { label: \\\"Yes — AI agent identities are systematically included in scheduled access reviews\\\", score: 2 }\\n    ]\\n  },\\n  {\\n    icon: \\\"🗑️\\\",\\n    text: \\\"When an AI agent is retired or decommissioned, do you have an automated process to revoke its credentials and remove its access?\\\",\\n    options: [\\n      { label: \\\"No — deprovisioning is manual, ad hoc, or often neglected entirely\\\", score: 0 },\\n      { label: \\\"Partially — we revoke some access manually but have no automated or guaranteed process\\\", score: 1 },\\n      { label: \\\"Yes — automated deprovisioning is triggered on agent retirement, with verification\\\", score: 2 }\\n    ]\\n  }\\n];\\n\\nconst tiers = [\\n  {\\n    min: 0, max: 4,\\n    cls: \\\"shadow-risk\\\",\\n    label: \\\"Shadow Agent Risk\\\",\\n    badge: \\\"⚠️ Shadow Agent Risk\\\",\\n    rec: \\\"\\u003cstrong\\u003eImmediate priority:\\u003c/strong\\u003e Start by building a full inventory of every AI agent, its owner, and the credentials it uses — you cannot govern what you cannot see. Once inventoried, enforce unique identities and migrate away from shared API keys using a secrets manager to eliminate your most critical exposure.\\\"\\n  },\\n  {\\n    min: 5, max: 8,\\n    cls: \\\"emerging\\\",\\n    label: \\\"Emerging Governance\\\",\\n    badge: \\\"🔧 Emerging Governance\\\",\\n    rec: \\\"\\u003cstrong\\u003eNext step:\\u003c/strong\\u003e Formalize the controls you've started by closing coverage gaps — ensure every agent goes through the same approval workflow and is included in access review cycles. Prioritize deploying short-lived, JIT credentials across all agents and wiring agent lifecycle events (creation, retirement) into automated provisioning/deprovisioning pipelines.\\\"\\n  },\\n  {\\n    min: 9, max: 12,\\n    cls: \\\"governed\\\",\\n    label: \\\"Governed Agent Estate\\\",\\n    badge: \\\"✅ Governed Agent Estate\\\",\\n    rec: \\\"\\u003cstrong\\u003eSustain and scale:\\u003c/strong\\u003e You have strong foundational controls — now focus on continuous assurance. Integrate per-tool-call audit telemetry into your SIEM for real-time anomaly detection, and extend your governance framework to cover third-party and low-code agents that teams are likely spinning up outside your current perimeter.\\\"\\n  }\\n];\\n\\nconst shortLabels = [\\\"Unique Identities\\\",\\\"Pre-prod Approval\\\",\\\"Credential Mgmt\\\",\\\"Audit Trail\\\",\\\"Access Reviews\\\",\\\"Auto-deprovision\\\"];\\n\\nlet current = 0;\\nlet answers = new Array(questions.length).fill(null);\\n\\nfunction init() {\\n  document.getElementById('h-title').textContent = t.title;\\n  document.getElementById('h-sub').textContent = t.sub;\\n  document.getElementById('pLabel').textContent = t.question;\\n  document.getElementById('btnBackText').textContent = t.back;\\n  document.getElementById('btnNextText').textContent = t.next;\\n  document.getElementById('bdTitle').textContent = t.breakdown;\\n  document.getElementById('btnRestartText').textContent = t.retake;\\n  renderQuestion();\\n}\\n\\nfunction renderQuestion() {\\n  const q = questions[current];\\n  document.getElementById('qNum').textContent = current + 1;\\n  document.getElementById('qText').innerHTML = `\\u003cspan class=\\\"q-icon\\\"\\u003e${q.icon}\\u003c/span\\u003e ${q.text}`;\\n\\n  const container = document.getElementById('optionsContainer');\\n  container.innerHTML = '';\\n  q.options.forEach((opt, i) =\\u003e {\\n    const scoreLabel = ['0 pts','1 pt','2 pts'][opt.score];\\n    const dotClass = ['score-0','score-1','score-2'][opt.score];\\n    const btn = document.createElement('button');\\n    btn.className = 'option-btn' + (answers[current] === i ? ' selected' : '');\\n    btn.innerHTML = `\\n      \\u003cdiv class=\\\"opt-radio\\\"\\u003e\\u003c/div\\u003e\\n      \\u003cdiv class=\\\"opt-content\\\"\\u003e\\n        \\u003cspan class=\\\"opt-label\\\"\\u003e${opt.label}\\u003c/span\\u003e\\n        \\u003cspan class=\\\"opt-score\\\"\\u003e\\u003cspan class=\\\"score-dot ${dotClass}\\\"\\u003e\\u003c/span\\u003e${scoreLabel}\\u003c/span\\u003e\\n      \\u003c/div\\u003e`;\\n    btn.onclick = () =\\u003e selectOption(i);\\n    container.appendChild(btn);\\n  });\\n\\n  const isLast = current === questions.length - 1;\\n  document.getElementById('btnNextText').textContent = isLast ? t.seeResults : t.next;\\n  document.getElementById('btnNext').disabled = answers[current] === null;\\n  document.getElementById('btnBack').style.visibility = current === 0 ? 'hidden' : 'visible';\\n\\n  const pct = (current / questions.length) * 100;\\n  document.getElementById('progressFill').style.width = pct + '%';\\n  document.getElementById('pCount').textContent = `${current + 1} / ${questions.length}`;\\n}\\n\\nfunction selectOption(i) {\\n  answers[current] = i;\\n  document.querySelectorAll('.option-btn').forEach((b, idx) =\\u003e {\\n    b.classList.toggle('selected', idx === i);\\n  });\\n  document.getElementById('btnNext').disabled = false;\\n}\\n\\nfunction goNext() {\\n  if (answers[current] === null) return;\\n  if (current \\u003c questions.length - 1) {\\n    current++;\\n    document.getElementById('quizCard').classList.remove('fade-in');\\n    void document.getElementById('quizCard').offsetWidth;\\n    document.getElementById('quizCard').classList.add('fade-in');\\n    renderQuestion();\\n  } else {\\n    showResults();\\n  }\\n}\\n\\nfunction goBack() {\\n  if (current \\u003e 0) {\\n    current--;\\n    document.getElementById('quizCard').classList.remove('fade-in');\\n    void document.getElementById('quizCard').offsetWidth;\\n    document.getElementById('quizCard').classList.add('fade-in');\\n    renderQuestion();\\n  }\\n}\\n\\nfunction showResults() {\\n  let total = 0;\\n  answers.forEach((ans, qi) =\\u003e {\\n    if (ans !== null) total += questions[qi].options[ans].score;\\n  });\\n\\n  const tier = tiers.find(t =\\u003e total \\u003e= t.min \\u0026\\u0026 total \\u003c= t.max);\\n\\n  document.getElementById('quizSection').classList.add('hidden');\\n  document.getElementById('progressWrap').style.display = 'none';\\n\\n  const panel = document.getElementById('resultPanel');\\n  panel.classList.add('visible', 'fade-in');\\n\\n  const card = document.getElementById('resultCard');\\n  card.className = 'result-card ' + tier.cls;\\n\\n  document.getElementById('tierBadge').textContent = tier.badge;\\n  document.getElementById('scoreNum').textContent = total;\\n  document.getElementById('resultLabel').textContent = tier.label;\\n  document.getElementById('resultRec').innerHTML = `\\u003cstrong\\u003e${t.rec}:\\u003c/strong\\u003e ` + tier.rec.replace(/\\u003cstrong\\u003e.*?\\u003c\\\\/strong\\u003e\\\\s*/,'');\\n  document.getElementById('resultRec').innerHTML = tier.rec;\\n\\n  const fillPct = (total / 12) * 100;\\n  setTimeout(() =\\u003e { document.getElementById('resultBarFill').style.width = fillPct + '%'; }, 80);\\n\\n  const grid = document.getElementById('breakdownGrid');\\n  grid.innerHTML = '';\\n  answers.forEach((ans, qi) =\\u003e {\\n    const sc = ans !== null ? questions[qi].options[ans].score : 0;\\n    const pipClass = ['pip-0','pip-1','pip-2'][sc];\\n    const scoreText = ['0 / 2','1 / 2','2 / 2'][sc];\\n    const div = document.createElement('div');\\n    div.className = 'breakdown-item';\\n    div.innerHTML = `\\n      \\u003cdiv class=\\\"bi-icon\\\"\\u003e${questions[qi].icon}\\u003c/div\\u003e\\n      \\u003cdiv class=\\\"bi-info\\\"\\u003e\\n        \\u003cspan class=\\\"bi-label\\\"\\u003e${shortLabels[qi]}\\u003c/span\\u003e\\n        \\u003cdiv class=\\\"bi-score\\\"\\u003e\\u003cspan class=\\\"bi-pip ${pipClass}\\\"\\u003e\\u003c/span\\u003e${scoreText}\\u003c/div\\u003e\\n      \\u003c/div\\u003e`;\\n    grid.appendChild(div);\\n  });\\n}\\n\\nfunction restart() {\\n  current = 0;\\n  answers = new Array(questions.length).fill(null);\\n  document.getElementById('quizSection').classList.remove('hidden');\\n  document.getElementById('progressWrap').style.display = '';\\n  const panel = document.getElementById('resultPanel');\\n  panel.classList.remove('visible','fade-in');\\n  document.getElementById('resultBarFill').style.width = '0%';\\n  document.getElementById('quizCard').classList.remove('fade-in');\\n  void document.getElementById('quizCard').offsetWidth;\\n  document.getElementById('quizCard').classList.add('fade-in');\\n  renderQuestion();\\n}\\n\\ninit();\\n\\u003c/script\\u003e\\n\\n\\u003cscript\\u003e\\n  window.addEventListener('load', () =\\u003e {\\n    const sendHeight = () =\\u003e {\\n      const height = document.body.offsetHeight + 24;\\n      window.parent.postMessage({ type: 'widget-resize', height }, '*');\\n    };\\n    sendHeight();\\n    new ResizeObserver(sendHeight).observe(document.body);\\n  });\\n\\u003c/script\\u003e\\n\\u003c/body\\u003e\\n\\u003c/html\\u003e\"])</script><script>self.__next_f.push([1,\"2b:[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"mx-auto max-w-[620px] px-6 sm:px-0\\\",\\\"children\\\":[[\\\"$\\\",\\\"$L2d\\\",null,{\\\"body\\\":\\\"$2e\\\",\\\"components\\\":[{\\\"id\\\":\\\"e30cc0b7-1878-4e09-b948-931b4ea6d29d\\\",\\\"content\\\":{\\\"level\\\":\\\"warning\\\",\\\"content\\\":\\\"**The authentication gap is real.** Research published in early 2026 documented more than 1,800 active MCP servers on the public internet with no authentication whatsoever. Because authentication in MCP is optional — not required by the spec — they are technically compliant and practically insecure. Before deploying any MCP server, verify OAuth 2.1 is enabled and enforced, not just installed.\\\"},\\\"position_hint\\\":0,\\\"component_type\\\":\\\"callout\\\"},{\\\"id\\\":\\\"f0d62597-013b-4953-b03d-747adcaf9cba\\\",\\\"content\\\":{\\\"rows\\\":[{\\\"gap\\\":\\\"Ecosystem lock-in; heterogeneous agent stacks require federation workarounds\\\",\\\"category\\\":\\\"Identity Providers extending to agents\\\",\\\"examples\\\":\\\"Microsoft Entra Agent ID, Okta (MCP server + Auth for MCP), Auth0\\\",\\\"strength\\\":\\\"Standards-based auth (OAuth 2.1/OIDC), existing enterprise trust, lifecycle hooks\\\"},{\\\"gap\\\":\\\"Agent governance is identity-discovery-led, not runtime-enforcement-led; agents treated as NHI subset, not first-class\\\",\\\"category\\\":\\\"NHI Security Specialists\\\",\\\"examples\\\":\\\"Oasis Security, Entro, Teleport\\\",\\\"strength\\\":\\\"Discovery, secrets rotation, posture management for service accounts and API keys\\\"},{\\\"gap\\\":\\\"Closed ecosystems; governance doesn't extend to human identities or non-MCP agents\\\",\\\"category\\\":\\\"MCP Gateways\\\",\\\"examples\\\":\\\"Arcade, TrueFoundry, Cloudflare Agents SDK\\\",\\\"strength\\\":\\\"Runtime authorization at the tool-call level; per-session ephemeral credentials; low-latency enforcement\\\"},{\\\"gap\\\":\\\"Legacy IGA platforms bolt on agent support; depth and automation vary significantly\\\",\\\"category\\\":\\\"IGA Platforms governing agents + humans\\\",\\\"examples\\\":\\\"Iden, SailPoint (Agent Identity Security add-on), ServiceNow/Veza\\\",\\\"strength\\\":\\\"Unified lifecycle governance across human and non-human identities; policy-driven provisioning and deprovisioning; access reviews\\\"}],\\\"title\\\":\\\"AI Agent Identity: Vendor Category Comparison\\\",\\\"columns\\\":[{\\\"key\\\":\\\"category\\\",\\\"label\\\":\\\"Category\\\"},{\\\"key\\\":\\\"examples\\\",\\\"label\\\":\\\"Examples\\\"},{\\\"key\\\":\\\"strength\\\",\\\"label\\\":\\\"Core Strength\\\"},{\\\"key\\\":\\\"gap\\\",\\\"label\\\":\\\"Key Gap\\\"}]},\\\"position_hint\\\":1,\\\"component_type\\\":\\\"data_table\\\"},{\\\"id\\\":\\\"3a13a849-8155-45c7-8c5c-27430a712e8c\\\",\\\"content\\\":{\\\"alt\\\":\\\"Isometric diagram showing two parallel governance tracks: on the left, a structured lifecycle flow for human employees (hire, provision, review, offboard) with clear checkpoints; on the right, a chaotic tangle of AI agents with no lifecycle, overlapping permissions, and missing audit trails - visually contrasting governed vs. ungoverned identity\\\",\\\"url\\\":\\\"https://aqynbjfkcfnrqkhzbzxl.supabase.co/storage/v1/object/public/cms-assets/5ed37a7f-297e-48c5-b007-40268093b3fa/6c51af9e-cfc7-42f5-958f-0a84c680cb69.jpg\\\",\\\"aspect\\\":\\\"16:9\\\",\\\"intent\\\":\\\"inline\\\",\\\"prompt\\\":\\\"Isometric diagram showing two parallel governance tracks: on the left, a structured lifecycle flow for human employees (hire, provision, review, offboard) with clear checkpoints; on the right, a chaotic tangle of AI agents with no lifecycle, overlapping permissions, and missing audit trails - visually contrasting governed vs. ungoverned identity\\\",\\\"status\\\":\\\"ready\\\",\\\"asset_id\\\":\\\"112c5483-c3cf-40dc-a2f0-57345e5c8c19\\\",\\\"error_message\\\":null},\\\"position_hint\\\":2,\\\"component_type\\\":\\\"image\\\"},{\\\"id\\\":\\\"a30e26b9-c278-4c10-b474-e6bceaaaa120\\\",\\\"content\\\":{\\\"cta_key\\\":\\\"book_demo\\\",\\\"label_override\\\":\\\"See Iden's Agent Governance in Action\\\",\\\"description_override\\\":\\\"Book a 30-minute walkthrough to see how Iden governs human and non-human identities — including AI agents — in a single policy plane.\\\",\\\"_resolved\\\":null},\\\"position_hint\\\":3,\\\"component_type\\\":\\\"cta\\\"},{\\\"id\\\":\\\"1d887c11-0b30-41a3-afdc-9d89b2f6ccfd\\\",\\\"content\\\":{\\\"items\\\":[{\\\"title\\\":\\\"Inventory your agent estate before you buy anything\\\",\\\"description\\\":\\\"You cannot govern what you cannot see. Start with a full discovery pass: which agents are running, who deployed them, what credentials they hold, and what systems they can reach. Shadow agents — those with no registry entry, no assigned owner, and no managed identity — are your highest-risk population. Treat them as Critical findings.\\\"},{\\\"title\\\":\\\"Demand short-lived, scoped credentials — not API keys\\\",\\\"description\\\":\\\"Any platform that relies on shared API keys or long-lived static credentials for agent authentication is not a governance solution. Require per-session ephemeral tokens scoped to the specific task, with automatic teardown at end of session. This is the single highest-leverage control against prompt injection and credential theft.\\\"},{\\\"title\\\":\\\"Verify the AND gate, not the OR gate\\\",\\\"description\\\":\\\"An agent should only be able to do what the agent is authorized to do AND what the delegating user is authorized to do — not the union of both. Service accounts that inherit broad employee credentials create authorization bypass vulnerabilities. Confirm that your chosen platform enforces the intersection, not the superset.\\\"},{\\\"title\\\":\\\"Require a full audit trail at the tool-call level\\\",\\\"description\\\":\\\"Logging that an agent 'ran' is not an audit trail. You need: which agent, which user delegated, which tool was called, with what arguments, what data was accessed, and what the result was. The EU AI Act's transparency provisions take effect August 2, 2026. If your platform cannot produce this log on demand, it cannot support compliance.\\\"},{\\\"title\\\":\\\"Evaluate lifecycle governance, not just runtime enforcement\\\",\\\"description\\\":\\\"Runtime authorization at the tool-call level is necessary but not sufficient. You also need: agent registration and approval workflows before deployment, access reviews on the same cadence as human identities, and automated deprovisioning when an agent is retired. Ask vendors specifically how they handle agent offboarding — most have no answer.\\\"},{\\\"title\\\":\\\"Insist on unified governance across human and non-human identities\\\",\\\"description\\\":\\\"Separate tools for human IGA and agent governance create blind spots at the seams. An agent acting on behalf of a human should be governed in the same plane as that human — same policy engine, same access review, same audit log. If your IGA platform treats agents as a bolt-on module, you have a coverage gap.\\\"}]},\\\"position_hint\\\":4,\\\"component_type\\\":\\\"steps\\\"},{\\\"id\\\":\\\"e5afe1d7-cb52-4acd-8a56-b6970002b90b\\\",\\\"content\\\":{\\\"prompt\\\":\\\"$2f\\\",\\\"status\\\":\\\"ready\\\",\\\"csv_data\\\":null,\\\"edit_history\\\":[],\\\"generated_at\\\":\\\"2026-06-08T10:13:20.451Z\\\",\\\"html_content\\\":\\\"$30\\\",\\\"error_message\\\":null},\\\"position_hint\\\":5,\\\"component_type\\\":\\\"widget\\\"}],\\\"sources\\\":[{\\\"id\\\":\\\"26e9916a-0ddc-4009-b3db-19495fb4bf3a\\\",\\\"idx\\\":1,\\\"url\\\":\\\"https://www.microsoft.com/en-us/security/blog/2026/02/10/80-of-fortune-500-use-active-ai-agents-observability-governance-and-security-shape-the-new-frontier/\\\",\\\"title\\\":\\\"microsoft.com — 80 of fortune 500 use active ai agents observability governance and security shape the new frontier\\\",\\\"snippet\\\":\\\"Microsoft Security Blog\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"f23a24f8-886a-4d06-9a8c-2334e7761c55\\\",\\\"idx\\\":2,\\\"url\\\":\\\"https://www.marktechpost.com/2026/05/25/best-authentication-platforms-for-ai-agents-and-mcp-servers-in-2026/\\\",\\\"title\\\":\\\"marktechpost.com — Best authentication platforms for ai agents and mcp servers in 2026\\\",\\\"snippet\\\":\\\"MarkTechPost\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"80a9ba39-24c7-4ce5-a886-58761a7a498e\\\",\\\"idx\\\":3,\\\"url\\\":\\\"https://www.gravitee.io/state-of-ai-agent-security\\\",\\\"title\\\":\\\"gravitee.io — State of ai agent security\\\",\\\"snippet\\\":\\\"Gravitee State of AI Agent Security 2026\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"2a710a07-8e89-4357-a601-455cc7829d15\\\",\\\"idx\\\":4,\\\"url\\\":\\\"https://workos.com/blog/everything-your-team-needs-to-know-about-mcp-in-2026/\\\",\\\"title\\\":\\\"workos.com — Everything your team needs to know about mcp in 2026\\\",\\\"snippet\\\":\\\"WorkOS MCP 2026 Guide\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"ae2a8a19-4f01-48a1-b34e-08bd312d4a89\\\",\\\"idx\\\":5,\\\"url\\\":\\\"https://aaif.io/blog/mcp-is-now-enterprise-infrastructure-everything-that-happened-at-mcp-dev-summit-north-america-2026/\\\",\\\"title\\\":\\\"aaif.io — Mcp is now enterprise infrastructure everything that happened at mcp dev summit north america 2026\\\",\\\"snippet\\\":\\\"AAIF MCP Dev Summit 2026\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"e556aa2b-3346-42e0-9758-a890213b0902\\\",\\\"idx\\\":6,\\\"url\\\":\\\"https://www.prefect.io/resources/mcp-oauth\\\",\\\"title\\\":\\\"prefect.io — Mcp oauth\\\",\\\"snippet\\\":\\\"Prefect MCP OAuth Guide\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"44dd868e-8148-4dbc-a948-26a420cf737d\\\",\\\"idx\\\":7,\\\"url\\\":\\\"https://epinium.com/en/blog/model-context-protocol-enterprise-guide/\\\",\\\"title\\\":\\\"epinium.com — Model context protocol enterprise guide\\\",\\\"snippet\\\":\\\"Epinium MCP Enterprise Guide\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"c496d355-e449-414d-9edc-46f8f62e24ec\\\",\\\"idx\\\":8,\\\"url\\\":\\\"https://www.vouched.id/learn/vouched-donates-mcp-i-identity-framework-to-the-decentralized-identity-foundation-to-advance-trust-and-security-for-ai-agents\\\",\\\"title\\\":\\\"vouched.id — Vouched donates mcp i identity framework to the decentralized identity foundation to advance trust and security for ai agents\\\",\\\"snippet\\\":\\\"Vouched MCP-I Donation\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"9843ca43-ff6c-4357-8018-76be068b927c\\\",\\\"idx\\\":9,\\\"url\\\":\\\"https://blog.identity.foundation/why-dif-said-yes-to-mcp-i/\\\",\\\"title\\\":\\\"blog.identity.foundation — Why dif said yes to mcp i\\\",\\\"snippet\\\":\\\"DIF Blog on MCP-I\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"c8b0257d-426a-45c7-86a6-4d04dc98f2b2\\\",\\\"idx\\\":10,\\\"url\\\":\\\"https://learn.microsoft.com/en-us/entra/agent-id/what-is-microsoft-entra-agent-id\\\",\\\"title\\\":\\\"learn.microsoft.com — What is microsoft entra agent id\\\",\\\"snippet\\\":\\\"Microsoft Entra Agent ID Docs\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"0fa2a0fa-fbeb-4076-885d-5ab791191d2a\\\",\\\"idx\\\":11,\\\"url\\\":\\\"https://learn.microsoft.com/en-us/entra/agent-id/agent-identities\\\",\\\"title\\\":\\\"learn.microsoft.com — Agent identities\\\",\\\"snippet\\\":\\\"Microsoft Entra Agent Identities\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"15e64e30-ed80-481e-b3f3-94f419304dbb\\\",\\\"idx\\\":12,\\\"url\\\":\\\"https://www.microsoft.com/en-us/security/blog/2026/03/20/secure-agentic-ai-end-to-end/\\\",\\\"title\\\":\\\"microsoft.com — Secure agentic ai end to end\\\",\\\"snippet\\\":\\\"Microsoft Secure Agentic AI\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"71b77171-b91f-4f44-9b0e-6688e2ff8788\\\",\\\"idx\\\":13,\\\"url\\\":\\\"https://cloudsecurityalliance.org/blog/2026/02/02/the-agentic-trust-framework-zero-trust-governance-for-ai-agents\\\",\\\"title\\\":\\\"cloudsecurityalliance.org — The agentic trust framework zero trust governance for ai agents\\\",\\\"snippet\\\":\\\"CSA Agentic Trust Framework\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"e7b0fde9-dc42-4e0a-8e92-6004ff059be1\\\",\\\"idx\\\":14,\\\"url\\\":\\\"https://www.oktsec.com/blog/csa-agentic-trust-framework-zero-trust-agents/\\\",\\\"title\\\":\\\"oktsec.com — Csa agentic trust framework zero trust agents\\\",\\\"snippet\\\":\\\"Oktsec CSA ATF Analysis\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"fbaa1471-c215-4927-9185-b853bd1f385f\\\",\\\"idx\\\":15,\\\"url\\\":\\\"https://cloudsecurityalliance.org/press-releases/2026/03/23/csa-securing-the-agentic-control-plane\\\",\\\"title\\\":\\\"cloudsecurityalliance.org — Csa securing the agentic control plane\\\",\\\"snippet\\\":\\\"CSA CSAI Foundation Launch\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"3bef993e-4e22-4872-80c9-e5e280b23ead\\\",\\\"idx\\\":16,\\\"url\\\":\\\"https://veza.com/blog/forrester-recognizes-veza-for-iga-ispm-and-nhi-ai-identity-management/\\\",\\\"title\\\":\\\"veza.com — Forrester recognizes veza for iga ispm and nhi ai identity management\\\",\\\"snippet\\\":\\\"Veza Forrester Recognition\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"c1b17401-81c6-42d2-9715-f539ce234d63\\\",\\\"idx\\\":17,\\\"url\\\":\\\"https://aimultiple.com/iga-solutions\\\",\\\"title\\\":\\\"aimultiple.com — Iga solutions\\\",\\\"snippet\\\":\\\"AIMultiple IGA Solutions\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"41500841-fdeb-4f0c-8ddc-b402708baffa\\\",\\\"idx\\\":18,\\\"url\\\":\\\"https://www.gravitee.io/blog/state-of-ai-agent-security-2026-report-when-adoption-outpaces-control\\\",\\\"title\\\":\\\"gravitee.io — State of ai agent security 2026 report when adoption outpaces control\\\",\\\"snippet\\\":\\\"Gravitee State of AI Agent Security 2026\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"192b69b1-d9c0-4687-abd4-3c6ca1466679\\\",\\\"idx\\\":19,\\\"url\\\":\\\"https://www.cybersecstats.com/ai-cybersecurity-statistics-2026-q1-q2/\\\",\\\"title\\\":\\\"cybersecstats.com — Ai cybersecurity statistics 2026 q1 q2\\\",\\\"snippet\\\":\\\"AI Cybersecurity Statistics 2026\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"c8371ea6-ba08-4327-ae31-8c8b818bb89e\\\",\\\"idx\\\":20,\\\"url\\\":\\\"https://secureflo.net/ai-agent-identity-management-a-2026-ciso-playbook/\\\",\\\"title\\\":\\\"secureflo.net — Ai agent identity management a 2026 ciso playbook\\\",\\\"snippet\\\":\\\"SecureFlo CISO Playbook\\\",\\\"metadata\\\":{}},{\\\"id\\\":\\\"df68d143-4627-4dab-ae88-9c4f37a6a64c\\\",\\\"idx\\\":21,\\\"url\\\":\\\"https://labs.cloudsecurityalliance.org/research/csa-whitepaper-nonhuman-identity-agentic-ai-governance-v1-cs/\\\",\\\"title\\\":\\\"labs.cloudsecurityalliance.org — Csa whitepaper nonhuman identity agentic ai governance v1 cs\\\",\\\"snippet\\\":\\\"CSA NHI Governance Vacuum\\\",\\\"metadata\\\":{}}],\\\"postId\\\":\\\"bd8d9626-eb18-40e6-89dd-f59e9670a423\\\",\\\"lang\\\":\\\"en-US\\\"}],false,\\\"$L31\\\"]}]\\n\"])</script><script>self.__next_f.push([1,\"2c:[\\\"$\\\",\\\"section\\\",null,{\\\"className\\\":\\\"mx-auto mt-20 max-w-[620px] border-t border-[var(--blog-border)] px-6 pt-12 sm:px-0\\\",\\\"children\\\":[[\\\"$\\\",\\\"h2\\\",null,{\\\"className\\\":\\\"mb-6 font-mono text-[11px] uppercase tracking-[0.22em] text-[var(--blog-faint)]\\\",\\\"children\\\":\\\"Related reading\\\"}],[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"grid gap-6 sm:grid-cols-2\\\",\\\"children\\\":[[\\\"$\\\",\\\"$L19\\\",\\\"30e99d62-3d1b-4856-b662-a5f98ad64f9d\\\",{\\\"href\\\":\\\"/en/blog/segregation-of-duties-guide-entitlement-level\\\",\\\"className\\\":\\\"group flex flex-col overflow-hidden rounded-xl border border-[var(--blog-border)] bg-[var(--blog-surface)] transition-colors hover:border-[color-mix(in_srgb,var(--blog-accent)_50%,var(--blog-border))]\\\",\\\"children\\\":[[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"relative aspect-[16/9] overflow-hidden\\\",\\\"children\\\":[[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"relative h-full w-full overflow-hidden transition-transform duration-500 group-hover:scale-[1.04]\\\",\\\"children\\\":[[\\\"$\\\",\\\"svg\\\",null,{\\\"className\\\":\\\"absolute inset-0 h-full w-full\\\",\\\"viewBox\\\":\\\"0 0 320 200\\\",\\\"preserveAspectRatio\\\":\\\"xMidYMid slice\\\",\\\"aria-hidden\\\":\\\"true\\\",\\\"children\\\":[[\\\"$\\\",\\\"defs\\\",null,{\\\"children\\\":[[\\\"$\\\",\\\"linearGradient\\\",null,{\\\"id\\\":\\\"blog-grad-segregation-of-duties-guide-entitlement-level\\\",\\\"x1\\\":\\\"50%\\\",\\\"y1\\\":\\\"0%\\\",\\\"x2\\\":\\\"50%\\\",\\\"y2\\\":\\\"100%\\\",\\\"children\\\":[[\\\"$\\\",\\\"stop\\\",null,{\\\"offset\\\":\\\"0%\\\",\\\"stopColor\\\":\\\"#D4DCDA\\\"}],[\\\"$\\\",\\\"stop\\\",null,{\\\"offset\\\":\\\"100%\\\",\\\"stopColor\\\":\\\"#47585C\\\"}]]}],[\\\"$\\\",\\\"filter\\\",null,{\\\"id\\\":\\\"blog-grain-segregation-of-duties-guide-entitlement-level\\\",\\\"x\\\":\\\"0\\\",\\\"y\\\":\\\"0\\\",\\\"width\\\":\\\"100%\\\",\\\"height\\\":\\\"100%\\\",\\\"children\\\":[[\\\"$\\\",\\\"feTurbulence\\\",null,{\\\"type\\\":\\\"fractalNoise\\\",\\\"baseFrequency\\\":\\\"0.9\\\",\\\"numOctaves\\\":\\\"2\\\",\\\"seed\\\":6543,\\\"result\\\":\\\"noise\\\"}],[\\\"$\\\",\\\"feColorMatrix\\\",null,{\\\"in\\\":\\\"noise\\\",\\\"type\\\":\\\"matrix\\\",\\\"values\\\":\\\"0 0 0 0 1 0 0 0 0 1 0 0 0 0 1 0 0 0 0.45 0\\\"}]]}],[\\\"$\\\",\\\"pattern\\\",null,{\\\"id\\\":\\\"blog-dither-segregation-of-duties-guide-entitlement-level\\\",\\\"patternUnits\\\":\\\"userSpaceOnUse\\\",\\\"width\\\":\\\"4\\\",\\\"height\\\":\\\"4\\\",\\\"children\\\":[\\\"$\\\",\\\"circle\\\",null,{\\\"cx\\\":\\\"1.5\\\",\\\"cy\\\":\\\"1.5\\\",\\\"r\\\":\\\"0.3\\\",\\\"fill\\\":\\\"#000\\\",\\\"fillOpacity\\\":\\\"0.06\\\"}]}]]}],[\\\"$\\\",\\\"rect\\\",null,{\\\"width\\\":\\\"320\\\",\\\"height\\\":\\\"200\\\",\\\"fill\\\":\\\"url(#blog-grad-segregation-of-duties-guide-entitlement-level)\\\"}],[\\\"$\\\",\\\"rect\\\",null,{\\\"width\\\":\\\"320\\\",\\\"height\\\":\\\"220\\\",\\\"filter\\\":\\\"url(#blog-grain-segregation-of-duties-guide-entitlement-level)\\\",\\\"style\\\":{\\\"mixBlendMode\\\":\\\"overlay\\\"}}],[\\\"$\\\",\\\"rect\\\",null,{\\\"width\\\":\\\"320\\\",\\\"height\\\":\\\"200\\\",\\\"fill\\\":\\\"url(#blog-dither-segregation-of-duties-guide-entitlement-level)\\\"}]]}],[\\\"$\\\",\\\"svg\\\",null,{\\\"viewBox\\\":\\\"0 0 256 256\\\",\\\"fill\\\":\\\"none\\\",\\\"stroke\\\":\\\"currentColor\\\",\\\"strokeWidth\\\":\\\"6\\\",\\\"className\\\":\\\"absolute left-5 top-5 h-9 w-9 pointer-events-none\\\",\\\"style\\\":{\\\"color\\\":\\\"#1c1c1c\\\",\\\"opacity\\\":0.78},\\\"aria-hidden\\\":\\\"true\\\",\\\"children\\\":[\\\"$\\\",\\\"path\\\",null,{\\\"d\\\":\\\"M10 128H246M71 69L10 128L71 187M186 187L246 128L186 69\\\"}]}]]}],[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"absolute right-3 top-3\\\",\\\"children\\\":[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"inline-flex items-center rounded-full border border-[var(--blog-border)] bg-[color-mix(in_srgb,var(--blog-bg)_60%,transparent)] px-2.5 py-0.5 font-mono text-[10px] uppercase tracking-[0.18em] text-[var(--blog-muted)]\\\",\\\"children\\\":\\\"Segregation of duties\\\"}]}]]}],[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"flex flex-1 flex-col gap-2.5 p-5\\\",\\\"children\\\":[[\\\"$\\\",\\\"h3\\\",null,{\\\"className\\\":\\\"text-[17px] font-normal leading-snug tracking-tight text-white\\\",\\\"children\\\":[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"blog-underline\\\",\\\"children\\\":\\\"The Definitive Guide to Segregation of Duties (SoD): From Policy to Entitlement-Level Enforcement\\\"}]}],[\\\"$\\\",\\\"p\\\",null,{\\\"className\\\":\\\"line-clamp-2 text-sm leading-relaxed text-[var(--blog-muted)]\\\",\\\"children\\\":\\\"A complete SoD guide: definition, toxic combinations, framework mapping (SOC 2, ISO 27001, SOX, PCI DSS), the conflict matrix, and why role-level SoD misses the real violations hiding inside broad entitlements.\\\"}],[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"mt-auto flex items-center gap-2 pt-2 text-xs text-[var(--blog-faint)]\\\",\\\"children\\\":[\\\"$undefined\\\",\\\"$undefined\\\",[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"tabular-nums\\\",\\\"children\\\":\\\"Jul 24, 2026\\\"}]]}]]}]]}],[\\\"$\\\",\\\"$L19\\\",\\\"a6e043fd-3d60-4e22-99b8-d4aee093492d\\\",{\\\"href\\\":\\\"/en/blog/third-party-contractor-access-audit-evidence\\\",\\\"className\\\":\\\"group flex flex-col overflow-hidden rounded-xl border border-[var(--blog-border)] bg-[var(--blog-surface)] transition-colors hover:border-[color-mix(in_srgb,var(--blog-accent)_50%,var(--blog-border))]\\\",\\\"children\\\":[\\\"$L32\\\",\\\"$L33\\\"]}],\\\"$L34\\\"]}]]}]\\n\"])</script><script>self.__next_f.push([1,\"35:T137b,\"])</script><script>self.__next_f.push([1,\"\\u003col class=\\\"bp-sources\\\"\\u003e\\u003cli id=\\\"source-1\\\"\\u003e\\u003ca href=\\\"https://www.microsoft.com/en-us/security/blog/2026/02/10/80-of-fortune-500-use-active-ai-agents-observability-governance-and-security-shape-the-new-frontier/\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003emicrosoft.com — 80 of fortune 500 use active ai agents observability governance and security shape the new frontier\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-2\\\"\\u003e\\u003ca href=\\\"https://www.marktechpost.com/2026/05/25/best-authentication-platforms-for-ai-agents-and-mcp-servers-in-2026/\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003emarktechpost.com — Best authentication platforms for ai agents and mcp servers in 2026\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-3\\\"\\u003e\\u003ca href=\\\"https://www.gravitee.io/state-of-ai-agent-security\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003egravitee.io — State of ai agent security\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-4\\\"\\u003e\\u003ca href=\\\"https://workos.com/blog/everything-your-team-needs-to-know-about-mcp-in-2026/\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003eworkos.com — Everything your team needs to know about mcp in 2026\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-5\\\"\\u003e\\u003ca href=\\\"https://aaif.io/blog/mcp-is-now-enterprise-infrastructure-everything-that-happened-at-mcp-dev-summit-north-america-2026/\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003eaaif.io — Mcp is now enterprise infrastructure everything that happened at mcp dev summit north america 2026\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-6\\\"\\u003e\\u003ca href=\\\"https://www.prefect.io/resources/mcp-oauth\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003eprefect.io — Mcp oauth\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-7\\\"\\u003e\\u003ca href=\\\"https://epinium.com/en/blog/model-context-protocol-enterprise-guide/\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003eepinium.com — Model context protocol enterprise guide\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-8\\\"\\u003e\\u003ca href=\\\"https://www.vouched.id/learn/vouched-donates-mcp-i-identity-framework-to-the-decentralized-identity-foundation-to-advance-trust-and-security-for-ai-agents\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003evouched.id — Vouched donates mcp i identity framework to the decentralized identity foundation to advance trust and security for ai agents\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-9\\\"\\u003e\\u003ca href=\\\"https://blog.identity.foundation/why-dif-said-yes-to-mcp-i/\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003eblog.identity.foundation — Why dif said yes to mcp i\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-10\\\"\\u003e\\u003ca href=\\\"https://learn.microsoft.com/en-us/entra/agent-id/what-is-microsoft-entra-agent-id\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003elearn.microsoft.com — What is microsoft entra agent id\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-11\\\"\\u003e\\u003ca href=\\\"https://learn.microsoft.com/en-us/entra/agent-id/agent-identities\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003elearn.microsoft.com — Agent identities\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-12\\\"\\u003e\\u003ca href=\\\"https://www.microsoft.com/en-us/security/blog/2026/03/20/secure-agentic-ai-end-to-end/\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003emicrosoft.com — Secure agentic ai end to end\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-13\\\"\\u003e\\u003ca href=\\\"https://cloudsecurityalliance.org/blog/2026/02/02/the-agentic-trust-framework-zero-trust-governance-for-ai-agents\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003ecloudsecurityalliance.org — The agentic trust framework zero trust governance for ai agents\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-14\\\"\\u003e\\u003ca href=\\\"https://www.oktsec.com/blog/csa-agentic-trust-framework-zero-trust-agents/\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003eoktsec.com — Csa agentic trust framework zero trust agents\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-15\\\"\\u003e\\u003ca href=\\\"https://cloudsecurityalliance.org/press-releases/2026/03/23/csa-securing-the-agentic-control-plane\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003ecloudsecurityalliance.org — Csa securing the agentic control plane\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-16\\\"\\u003e\\u003ca href=\\\"https://veza.com/blog/forrester-recognizes-veza-for-iga-ispm-and-nhi-ai-identity-management/\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003eveza.com — Forrester recognizes veza for iga ispm and nhi ai identity management\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-17\\\"\\u003e\\u003ca href=\\\"https://aimultiple.com/iga-solutions\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003eaimultiple.com — Iga solutions\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-18\\\"\\u003e\\u003ca href=\\\"https://www.gravitee.io/blog/state-of-ai-agent-security-2026-report-when-adoption-outpaces-control\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003egravitee.io — State of ai agent security 2026 report when adoption outpaces control\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-19\\\"\\u003e\\u003ca href=\\\"https://www.cybersecstats.com/ai-cybersecurity-statistics-2026-q1-q2/\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003ecybersecstats.com — Ai cybersecurity statistics 2026 q1 q2\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-20\\\"\\u003e\\u003ca href=\\\"https://secureflo.net/ai-agent-identity-management-a-2026-ciso-playbook/\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003esecureflo.net — Ai agent identity management a 2026 ciso playbook\\u003c/a\\u003e\\u003c/li\\u003e\\u003cli id=\\\"source-21\\\"\\u003e\\u003ca href=\\\"https://labs.cloudsecurityalliance.org/research/csa-whitepaper-nonhuman-identity-agentic-ai-governance-v1-cs/\\\" target=\\\"_blank\\\" rel=\\\"noopener nofollow\\\"\\u003elabs.cloudsecurityalliance.org — Csa whitepaper nonhuman identity agentic ai governance v1 cs\\u003c/a\\u003e\\u003c/li\\u003e\\u003c/ol\\u003e\"])</script><script>self.__next_f.push([1,\"31:[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"prose-body mt-12 border-t border-[var(--blog-border)] pt-8\\\",\\\"dangerouslySetInnerHTML\\\":{\\\"__html\\\":\\\"$35\\\"}}]\\n\"])</script><script>self.__next_f.push([1,\"32:[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"relative aspect-[16/9] overflow-hidden\\\",\\\"children\\\":[[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"relative h-full w-full overflow-hidden transition-transform duration-500 group-hover:scale-[1.04]\\\",\\\"children\\\":[[\\\"$\\\",\\\"svg\\\",null,{\\\"className\\\":\\\"absolute inset-0 h-full w-full\\\",\\\"viewBox\\\":\\\"0 0 320 200\\\",\\\"preserveAspectRatio\\\":\\\"xMidYMid slice\\\",\\\"aria-hidden\\\":\\\"true\\\",\\\"children\\\":[[\\\"$\\\",\\\"defs\\\",null,{\\\"children\\\":[[\\\"$\\\",\\\"linearGradient\\\",null,{\\\"id\\\":\\\"blog-grad-third-party-contractor-access-audit-evidence\\\",\\\"x1\\\":\\\"50%\\\",\\\"y1\\\":\\\"0%\\\",\\\"x2\\\":\\\"50%\\\",\\\"y2\\\":\\\"100%\\\",\\\"children\\\":[[\\\"$\\\",\\\"stop\\\",null,{\\\"offset\\\":\\\"0%\\\",\\\"stopColor\\\":\\\"#E5E4E6\\\"}],[\\\"$\\\",\\\"stop\\\",null,{\\\"offset\\\":\\\"100%\\\",\\\"stopColor\\\":\\\"#4D80E6\\\"}]]}],[\\\"$\\\",\\\"filter\\\",null,{\\\"id\\\":\\\"blog-grain-third-party-contractor-access-audit-evidence\\\",\\\"x\\\":\\\"0\\\",\\\"y\\\":\\\"0\\\",\\\"width\\\":\\\"100%\\\",\\\"height\\\":\\\"100%\\\",\\\"children\\\":[[\\\"$\\\",\\\"feTurbulence\\\",null,{\\\"type\\\":\\\"fractalNoise\\\",\\\"baseFrequency\\\":\\\"0.9\\\",\\\"numOctaves\\\":\\\"2\\\",\\\"seed\\\":4201,\\\"result\\\":\\\"noise\\\"}],[\\\"$\\\",\\\"feColorMatrix\\\",null,{\\\"in\\\":\\\"noise\\\",\\\"type\\\":\\\"matrix\\\",\\\"values\\\":\\\"0 0 0 0 1 0 0 0 0 1 0 0 0 0 1 0 0 0 0.45 0\\\"}]]}],[\\\"$\\\",\\\"pattern\\\",null,{\\\"id\\\":\\\"blog-dither-third-party-contractor-access-audit-evidence\\\",\\\"patternUnits\\\":\\\"userSpaceOnUse\\\",\\\"width\\\":\\\"4\\\",\\\"height\\\":\\\"4\\\",\\\"children\\\":[\\\"$\\\",\\\"circle\\\",null,{\\\"cx\\\":\\\"1.5\\\",\\\"cy\\\":\\\"1.5\\\",\\\"r\\\":\\\"0.3\\\",\\\"fill\\\":\\\"#000\\\",\\\"fillOpacity\\\":\\\"0.06\\\"}]}]]}],[\\\"$\\\",\\\"rect\\\",null,{\\\"width\\\":\\\"320\\\",\\\"height\\\":\\\"200\\\",\\\"fill\\\":\\\"url(#blog-grad-third-party-contractor-access-audit-evidence)\\\"}],[\\\"$\\\",\\\"rect\\\",null,{\\\"width\\\":\\\"320\\\",\\\"height\\\":\\\"220\\\",\\\"filter\\\":\\\"url(#blog-grain-third-party-contractor-access-audit-evidence)\\\",\\\"style\\\":{\\\"mixBlendMode\\\":\\\"overlay\\\"}}],[\\\"$\\\",\\\"rect\\\",null,{\\\"width\\\":\\\"320\\\",\\\"height\\\":\\\"200\\\",\\\"fill\\\":\\\"url(#blog-dither-third-party-contractor-access-audit-evidence)\\\"}]]}],[\\\"$\\\",\\\"svg\\\",null,{\\\"viewBox\\\":\\\"0 0 256 256\\\",\\\"fill\\\":\\\"none\\\",\\\"stroke\\\":\\\"currentColor\\\",\\\"strokeWidth\\\":\\\"6\\\",\\\"className\\\":\\\"absolute left-5 top-5 h-9 w-9 pointer-events-none\\\",\\\"style\\\":{\\\"color\\\":\\\"#1c1c1c\\\",\\\"opacity\\\":0.78},\\\"aria-hidden\\\":\\\"true\\\",\\\"children\\\":[\\\"$\\\",\\\"path\\\",null,{\\\"d\\\":\\\"M128 8V88M246.5 9.5L156.697 99.3026M168 128H248M246.5 246.5L156.697 156.697M128 168V248M9.5 246.5L99.3026 156.697M8 128H88M9.5 9.5L99.3026 99.3026\\\"}]}]]}],[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"absolute right-3 top-3\\\",\\\"children\\\":[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"inline-flex items-center rounded-full border border-[var(--blog-border)] bg-[color-mix(in_srgb,var(--blog-bg)_60%,transparent)] px-2.5 py-0.5 font-mono text-[10px] uppercase tracking-[0.18em] text-[var(--blog-muted)]\\\",\\\"children\\\":\\\"Third-party access audit trail\\\"}]}]]}]\\n\"])</script><script>self.__next_f.push([1,\"33:[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"flex flex-1 flex-col gap-2.5 p-5\\\",\\\"children\\\":[[\\\"$\\\",\\\"h3\\\",null,{\\\"className\\\":\\\"text-[17px] font-normal leading-snug tracking-tight text-white\\\",\\\"children\\\":[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"blog-underline\\\",\\\"children\\\":\\\"Third-Party Access Is Your Audit's Weakest Link - Here's How to Fix It\\\"}]}],[\\\"$\\\",\\\"p\\\",null,{\\\"className\\\":\\\"line-clamp-2 text-sm leading-relaxed text-[var(--blog-muted)]\\\",\\\"children\\\":\\\"Contractors and partners don't live in your HRIS - so they fall outside JML automation and become orphaned-access hotspots. Here's the evidence every auditor demands and how to produce it.\\\"}],[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"mt-auto flex items-center gap-2 pt-2 text-xs text-[var(--blog-faint)]\\\",\\\"children\\\":[\\\"$undefined\\\",\\\"$undefined\\\",[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"tabular-nums\\\",\\\"children\\\":\\\"Jul 17, 2026\\\"}]]}]]}]\\n\"])</script><script>self.__next_f.push([1,\"34:[\\\"$\\\",\\\"$L19\\\",\\\"965d11ba-e6aa-43a5-a258-7c495ed20b58\\\",{\\\"href\\\":\\\"/en/blog/legacy-iga-migration-guide-checklist\\\",\\\"className\\\":\\\"group flex flex-col overflow-hidden rounded-xl border border-[var(--blog-border)] bg-[var(--blog-surface)] transition-colors hover:border-[color-mix(in_srgb,var(--blog-accent)_50%,var(--blog-border))]\\\",\\\"children\\\":[[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"relative aspect-[16/9] overflow-hidden\\\",\\\"children\\\":[[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"relative h-full w-full overflow-hidden transition-transform duration-500 group-hover:scale-[1.04]\\\",\\\"children\\\":[[\\\"$\\\",\\\"svg\\\",null,{\\\"className\\\":\\\"absolute inset-0 h-full w-full\\\",\\\"viewBox\\\":\\\"0 0 320 200\\\",\\\"preserveAspectRatio\\\":\\\"xMidYMid slice\\\",\\\"aria-hidden\\\":\\\"true\\\",\\\"children\\\":[[\\\"$\\\",\\\"defs\\\",null,{\\\"children\\\":[[\\\"$\\\",\\\"linearGradient\\\",null,{\\\"id\\\":\\\"blog-grad-legacy-iga-migration-guide-checklist\\\",\\\"x1\\\":\\\"50%\\\",\\\"y1\\\":\\\"0%\\\",\\\"x2\\\":\\\"50%\\\",\\\"y2\\\":\\\"100%\\\",\\\"children\\\":[[\\\"$\\\",\\\"stop\\\",null,{\\\"offset\\\":\\\"0%\\\",\\\"stopColor\\\":\\\"#D4DCDA\\\"}],[\\\"$\\\",\\\"stop\\\",null,{\\\"offset\\\":\\\"100%\\\",\\\"stopColor\\\":\\\"#949495\\\"}]]}],[\\\"$\\\",\\\"filter\\\",null,{\\\"id\\\":\\\"blog-grain-legacy-iga-migration-guide-checklist\\\",\\\"x\\\":\\\"0\\\",\\\"y\\\":\\\"0\\\",\\\"width\\\":\\\"100%\\\",\\\"height\\\":\\\"100%\\\",\\\"children\\\":[[\\\"$\\\",\\\"feTurbulence\\\",null,{\\\"type\\\":\\\"fractalNoise\\\",\\\"baseFrequency\\\":\\\"0.9\\\",\\\"numOctaves\\\":\\\"2\\\",\\\"seed\\\":349,\\\"result\\\":\\\"noise\\\"}],[\\\"$\\\",\\\"feColorMatrix\\\",null,{\\\"in\\\":\\\"noise\\\",\\\"type\\\":\\\"matrix\\\",\\\"values\\\":\\\"0 0 0 0 1 0 0 0 0 1 0 0 0 0 1 0 0 0 0.45 0\\\"}]]}],[\\\"$\\\",\\\"pattern\\\",null,{\\\"id\\\":\\\"blog-dither-legacy-iga-migration-guide-checklist\\\",\\\"patternUnits\\\":\\\"userSpaceOnUse\\\",\\\"width\\\":\\\"4\\\",\\\"height\\\":\\\"4\\\",\\\"children\\\":[\\\"$\\\",\\\"circle\\\",null,{\\\"cx\\\":\\\"1.5\\\",\\\"cy\\\":\\\"1.5\\\",\\\"r\\\":\\\"0.3\\\",\\\"fill\\\":\\\"#000\\\",\\\"fillOpacity\\\":\\\"0.06\\\"}]}]]}],[\\\"$\\\",\\\"rect\\\",null,{\\\"width\\\":\\\"320\\\",\\\"height\\\":\\\"200\\\",\\\"fill\\\":\\\"url(#blog-grad-legacy-iga-migration-guide-checklist)\\\"}],[\\\"$\\\",\\\"rect\\\",null,{\\\"width\\\":\\\"320\\\",\\\"height\\\":\\\"220\\\",\\\"filter\\\":\\\"url(#blog-grain-legacy-iga-migration-guide-checklist)\\\",\\\"style\\\":{\\\"mixBlendMode\\\":\\\"overlay\\\"}}],[\\\"$\\\",\\\"rect\\\",null,{\\\"width\\\":\\\"320\\\",\\\"height\\\":\\\"200\\\",\\\"fill\\\":\\\"url(#blog-dither-legacy-iga-migration-guide-checklist)\\\"}]]}],[\\\"$\\\",\\\"svg\\\",null,{\\\"viewBox\\\":\\\"0 0 256 256\\\",\\\"fill\\\":\\\"none\\\",\\\"stroke\\\":\\\"currentColor\\\",\\\"strokeWidth\\\":\\\"6\\\",\\\"className\\\":\\\"absolute left-5 top-5 h-9 w-9 pointer-events-none\\\",\\\"style\\\":{\\\"color\\\":\\\"#1c1c1c\\\",\\\"opacity\\\":0.78},\\\"aria-hidden\\\":\\\"true\\\",\\\"children\\\":[\\\"$\\\",\\\"path\\\",null,{\\\"d\\\":\\\"M10 128C10 193.17 62.8304 246 128 246C193.17 246 246 193.17 246 128C246 62.8304 193.17 10 128 10C62.8304 10 10 62.8304 10 128ZM10 128L246 128.123M39.4543 50H216.546M39.4543 206H216.546\\\"}]}]]}],[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"absolute right-3 top-3\\\",\\\"children\\\":[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"inline-flex items-center rounded-full border border-[var(--blog-border)] bg-[color-mix(in_srgb,var(--blog-bg)_60%,transparent)] px-2.5 py-0.5 font-mono text-[10px] uppercase tracking-[0.18em] text-[var(--blog-muted)]\\\",\\\"children\\\":\\\"Legacy IGA migration\\\"}]}]]}],[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"flex flex-1 flex-col gap-2.5 p-5\\\",\\\"children\\\":[[\\\"$\\\",\\\"h3\\\",null,{\\\"className\\\":\\\"text-[17px] font-normal leading-snug tracking-tight text-white\\\",\\\"children\\\":[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"blog-underline\\\",\\\"children\\\":\\\"The Legacy IGA Migration Guide: Real Costs, Realistic Timelines, and a Step-by-Step Checklist\\\"}]}],[\\\"$\\\",\\\"p\\\",null,{\\\"className\\\":\\\"line-clamp-2 text-sm leading-relaxed text-[var(--blog-muted)]\\\",\\\"children\\\":\\\"Replacing SailPoint IIQ, Oracle, IBM, or One Identity feels terrifying. This guide breaks down the real migration costs, honest timelines, and a step-by-step checklist to de-risk the switch.\\\"}],[\\\"$\\\",\\\"div\\\",null,{\\\"className\\\":\\\"mt-auto flex items-center gap-2 pt-2 text-xs text-[var(--blog-faint)]\\\",\\\"children\\\":[\\\"$undefined\\\",\\\"$undefined\\\",[\\\"$\\\",\\\"span\\\",null,{\\\"className\\\":\\\"tabular-nums\\\",\\\"children\\\":\\\"Jul 13, 2026\\\"}]]}]]}]]}]\\n\"])</script></body></html>","snapshot_chars":230483,"live_check":"changed"}]}