The IAM from First Principles series covered the complete foundational landscape — from authentication protocols and governance workflows to non-human identities and deployment models.

It ended with a deliberate open question.

Non-Human Identities are already a governance problem at 90:1 scale. But AI agents are something qualitatively different — they are not just another credential to vault or another service account to review. They are autonomous actors that request permissions at runtime, delegate authority to other agents, and operate across trust boundaries that no existing IAM standard was designed to span.

This series addresses that directly.


Part 1: Foundations — What Is Agentic Identity and Why Does It Matter?

  1. Agentic Identity — The Next Frontier
  2. Three Generations of IAM Tools — and Why None of Them Were Built for the Agentic Era
  3. The Legacy Backend Problem — LDAP, SQL, and Why Your IAM Foundation Is Holding Back Agentic Identity

Part 2: Consumer Agents — Governance Beyond the Enterprise

  1. Consumer Agents and the Consent Problem — When AI Acts on Behalf of Your Customers

Part 3: The Agentic Era — IAM for AI Agents

  1. Agentic Identity Protocols — OAuth 2.1, CIBA, OIDC-A, and the Delegation Chain Problem
  2. Building Secure AI Agent Systems — A Practical Architecture Guide
  3. NHI Governance at Scale — Discovery, Ownership, and Policy for the 90:1 World

Who This Series is For

This series assumes you have read or are familiar with the First Principles series. Specifically, you should be comfortable with:

If you are new to IAM entirely, start with the First Principles series first.


Have a question or a topic you want covered? Leave a note below. The RSS feed will alert you when new posts are published.