Skip to content

The Identity Explosion, Humans Were Only the Beginning

Joseph Miceli Sep 10, 2026

For most of the history of identity and access management, we built our systems around people.

Employees joined companies, received accounts, changed jobs, accumulated permissions, and eventually left. Contractors came and went. Customers authenticated to applications. Partners were granted access to specific systems. Even when machine identities began appearing in larger numbers, they were generally created for a defined purpose, assigned predictable permissions, and expected to perform a relatively narrow set of functions.

That world is disappearing.

The enterprise identity population is exploding, and humans will soon become the minority.

Today, the identity ecosystem includes employees, customers, partners, contractors, applications, APIs, service accounts, cloud workloads, containers, bots, robotic processes, machines, devices, and, increasingly, autonomous AI agents. Some of these identities may exist for years. Others may exist for hours. An AI agent may exist for minutes, perform hundreds of actions, delegate portions of its objective to other agents, interact with multiple systems, and disappear before a traditional governance process even knows it existed.

This is not simply an increase in the number of identities. It is a fundamental change in what an enterprise identity population looks like. And that distinction matters a great deal.

In the first article in this series, I argued that IAM was built around the assumption that somewhere behind the identity was a person. AI agents broke that assumption because they introduced autonomy into a model historically built around relatively predictable actors.

The next problem follows naturally from that change: once identity is no longer predominantly human, the architecture built to govern identity must change with it.

We are moving from static identity management to dynamic identity management. That may sound like semantics. It is not.

For decades, enterprises could organize identity into relatively understandable categories. There were employees inside the organization, customers outside it, contractors somewhere in between, and a collection of service accounts and applications supporting the technology underneath them. The boundaries were imperfect, but they were understandable.

Cloud computing changed that considerably. Microservices, APIs, containers, serverless workloads, automated processes, DevOps pipelines, secrets, certificates, service accounts, and machine-to-machine interactions dramatically increased the number of identities operating inside the enterprise.

Now AI is adding another order of magnitude to the problem. The result is an identity environment in which the most active participants may increasingly be identities that have no face, no employee record, no traditional organizational role, and, in some cases, no meaningful lifespan. That creates an entirely different governance problem.

A human employee may have an identity for ten years. A contractor may have one for six months. A workload may exist for several hours. A container may disappear in minutes. An AI agent might be created to accomplish a single objective, execute dozens or hundreds of transactions, invoke other agents and services, and cease to exist almost immediately afterward.

Yet every one of those identities may touch sensitive data, invoke privileged functions, create transactions, or affect the business.

The sheer scale alone should concern security leaders. Organizations that historically managed tens of thousands of identities are now confronting hundreds of thousands or even millions of identities spread across cloud platforms, applications, APIs, infrastructure, devices, workloads, and autonomous systems. But scale is only part of the problem. The more important problem is diversity.

A customer is not governed like an employee. An employee is not governed like a workload. A workload is not governed like a privileged service account. A service account is not governed like an AI agent. Each has a different lifecycle, different behavior, different risk profile, different ownership model, and different relationship to authority. Trying to govern all of them with the same identity assumptions is becoming increasingly unrealistic.

For years, the identity industry has tended to solve new identity problems by creating new categories and new products. Workforce IAM manages employees. CIAM manages customers. PAM manages privileged access. Cloud infrastructure creates workload identities. API platforms manage API credentials. Machine identity products manage certificates and secrets. New NHI platforms attempt to discover and classify non-human identities.

Each technology can solve an important part of the problem. The difficulty is that the enterprise does not experience identity in isolated product categories. The enterprise experiences all of them at once.

A business transaction may begin with a human employee, move through an AI agent, invoke an API, use a service account, trigger a cloud workload, retrieve information from a database, and interact with another autonomous system.

From the perspective of the business, that is one transaction. From the perspective of most identity architectures, it may cross five or six different administrative domains. That is where fragmentation becomes dangerous. Each system may understand its individual portion of the transaction perfectly while none of them understands the complete chain of authority.

Who initiated the action? 

Which identity was acting on behalf of whom? 

What authority was delegated? 

Which system granted that authority? 

How long was it intended to remain valid? 

Could the receiving identity delegate it again? 

What happened when the identity crossed into another platform?

And perhaps most importantly: Who is watching the entire transaction rather than one small piece of it?

Those questions become much harder as non-human identities proliferate. AI agents make the problem particularly acute because they combine characteristics we have historically treated separately.

They are identities because they authenticate and receive permissions. They are applications because they invoke services and APIs. They are users because they make decisions and initiate actions. And in some circumstances, they may behave almost like administrators because they can coordinate multiple systems and influence what other identities do.

That is why simply creating a new category called "AI Agent" will not solve the problem.

The identity itself is only one part of what matters. We need to understand the authority behind it, the purpose for which it exists, the context surrounding its actions, the systems it can reach, the identities it can invoke, the decisions it makes, and the transactions that result.

The identity record of the future cannot simply be a username, entitlement set, role, authentication method, and lifecycle status.

It will increasingly need to include lineage.

Where did the authority originate? Who or what delegated it? What limitations accompanied that delegation? What objective was the identity created to accomplish? What resources did it access? What other identities participated? And did the resulting behavior remain consistent with the purpose for which the authority was originally granted?

That becomes especially important when identities become ephemeral.

Traditional IAM was designed around identities that lived long enough to be provisioned, reviewed, certified, modified, and eventually deprovisioned. Much of our governance model assumes there will be time to discover the identity, assign ownership, review access, and periodically determine whether its permissions remain appropriate.

An autonomous agent operating for three minutes does not fit comfortably into that model.

By the time a quarterly access certification asks whether the identity should have possessed a permission, the agent may have completed its objective, transferred data, initiated transactions, delegated authority to three other agents, and disappeared three months earlier.

Governance after the fact is not governance. It is archaeology.

The enterprise therefore needs a different concept of identity control. Access increasingly has to become contextual, dynamic, and tied to purpose. Short-lived identities require short-lived authority. Autonomous identities require continuous evaluation. Delegated authority requires traceability.

High-risk actions require the ability to intervene while the transaction is occurring, not merely report on it afterward. This is where the identity explosion intersects directly with the rise of runtime identity.

Traditional lifecycle controls remain essential. We still need provisioning, deprovisioning, authentication, federation, entitlement management, privileged access, certification, directories, and governance.

Nothing about the emergence of AI suddenly makes forty years of IAM irrelevant. The mistake would be believing those systems, operating independently, are sufficient for what comes next. They are not. The future identity environment requires an architecture capable of seeing across them. That is the role of the identity fabric and the orchestration layer in IAM 3.0.

The identity fabric provides the connective structure necessary to recognize identities across the enterprise, regardless of where they originate. Human identities, machine identities, workloads, service accounts, APIs, applications, devices, and AI agents become part of a broader enterprise identity environment rather than isolated populations trapped inside individual administrative systems.

But visibility alone is not enough.

Knowing that millions of identities exist does not secure them. The orchestration layer becomes the control plane that coordinates what happens next. It correlates identity information with authentication, authorization, risk, behavior, delegation, policy, data sensitivity, transaction context, and threat intelligence. It coordinates decisions across existing IAM, PAM, IGA, CIAM, cloud, API, security, and authorization systems without requiring enterprises to discard investments that may have taken decades to build.

That point is important because the answer to the identity explosion is not another massive rip-and-replace program.

Enterprises have spent enormous sums building their existing identity infrastructure. Much of it performs exactly the function it was designed to perform.

The problem is not that every existing system suddenly stopped working. The problem is that the environment around those systems changed. IAM 3.0 addresses that problem by changing how the identity ecosystem is coordinated.

Instead of asking every individual product to understand every identity, transaction, delegation path, behavioral signal, and security event across the enterprise, orchestration allows those technologies to operate as parts of a coordinated identity architecture. The distinction resembles the evolution we have seen in other areas of computing.

As systems become more complex, control increasingly moves above individual components. Networks evolved control planes. Cloud environments evolved orchestration. Containers created Kubernetes.

Complex environments eventually require something capable of coordinating the pieces. Identity has reached that moment.

We are building enterprises in which humans, software, machines, workloads, and autonomous agents will operate side by side. Some will act independently. Some will act on behalf of humans. Some will act on behalf of other machines. Some will delegate authority across systems. Some will exist only long enough to complete a single transaction. And increasingly, the most active identities in the enterprise may not be people at all. That should change the way we think about identity security.

For years, organizations have asked questions such as: Who has access? What permissions do they have? Did they authenticate correctly? Should they still possess that entitlement?

Those questions remain important. But the identity explosion adds others.

What kind of identity is this? Why does it exist? Who created it? What authority does it represent? How long should it exist? What is it doing right now? What other identities is it interacting with? Can it delegate authority? Should that delegation be allowed? Does its behavior still match the purpose for which it was created?

And can the enterprise stop it immediately if the answer changes?

Those are not questions traditional IAM architecture was designed to answer continuously. Yet they are quickly becoming the questions that matter most. The identity landscape is not simply growing. It is mutating.

The traditional model assumed identities were relatively stable, humans were the primary actors, authority moved slowly, and governance could operate largely through static policies and periodic reviews. The emerging model looks very different.

Identity populations are dynamic. Authority moves rapidly. Machines interact with machines. Agents interact with agents. Transactions cross multiple identity systems in seconds. Some identities may generate more activity in five minutes than a human employee generates in a month. Security architecture has to catch up.

The future enterprise will not be governed by asking whether every identity fits neatly into an employee directory or an application account table.

It will be governed by whether the organization can understand the complete identity ecosystem and coordinate control across it.

  • Humans were chapter one.

  • Machines were chapter two.

  • Autonomous agents are beginning chapter three.

  • And there will be more chapters after that.

The organizations that succeed will not be those that attempt to force every new identity into the architecture of the past.

They will be the ones that build an identity fabric capable of recognizing what exists and an orchestration layer capable of governing what those identities actually do.

That is the larger promise of IAM 3.0. It is not simply a better way to manage users. It is an approach and architecture for governing an enterprise in which the definition of "user" itself is disappearing.

The identity explosion has already begun. The question is no longer whether humans will remain at the center of the identity universe. They will not.

The question everyone should be asking today is whether the architecture surrounding them is ready for everything that comes next, in real time.

Leave a Comment