Hype Cycle for Digital Identity, 2026

6 July 2026 - ID G00846324 - 116 min read
By Zachary Smith, Nayara Sangiorgio
The digital identity landscape is being transformed by AI agents, identity visibility and identity threats. Cybersecurity leaders should use this Hype Cycle to foster innovation and investment to securely enable an adaptable digital business.

Analysis


What You Need to Know

AI agents and other workloads are spurring rapid innovations in the field of digital identity. Meanwhile, promising innovations for visibility, open standards, and fine-grained authorization shape the broader digital identity landscape.
AI technologies and practices introduce new frontiers for the identity and access management (IAM) of workloads including customer IAM (CIAM) for AI agents, workload access management, authorization management platforms, AI agent identity and intent-based access control.
Standards supporting digital identity are evolving and gaining traction. OpenID for Verifiable Credentials (OID4VC), Shared Signals Framework (including RISC and CAEP), AuthZEN and Secure Production Identity Framework for Everyone (SPIFFE) continue to see strong momentum.
Government-citizen and customer use cases see growing attention alongside organization-workforce use cases for decentralized identity models and identity assurance.

The Hype Cycle

Over the last year Gartner has observed rapid advancements, promising innovations, and increasing complexity affect how organizations approach and invest in digital identity.
Six new entrants are featured on this year’s Hype Cycle:
  • Workload access management: Provides runtime least-privilege access enforcement for workloads like services, containers and AI agents by replacing static workload credentials with dynamic, context-aware controls.
  • Intent-based access control: An authorization framework for agentic AI that augments broad, standing permissions with an approach focused on the intent of users and their AI agents.
  • CIAM for AI agents: Customer IAM solutions to manage AI agent identities in customer-facing contexts where customers send their AI agents to interact with organizations.
  • Identity security posture management: The security discipline to assess, monitor and manage IAM policies and configurations across an organization’s digital infrastructure.
  • AI agent identity: An identity-based approach to the unique digital representation of AI agents within an organization.
  • Authorization management platforms: Platforms providing shared services including authorization policy authoring, orchestration and enforcement for infrastructure, APIs, applications and data.
The hype surrounding AI agents is contributing to many innovations specifically for workload IAM. Gartner’s 2025 Machine Identity survey revealed that 94% of organizations are dealing with increased machine identities, largely driven by AI and AI agent deployments.1 However, visibility and proactive defense of identity infrastructure are behind the increasing traction seen for open standards, the growing interest in identity visibility and intelligence platforms, and the emergence of the new discipline of identity security posture management.
Strong interest remains in the adoption of machine IAM, now covered in the constituent elements of workload identity management, workload access management, and various approaches more specifically targeted for AI agents. SPIFFE, a modern protocol that provides robust mechanisms for managing managed workload identities, is at the Peak of Inflated Expectations, driven by strong market interest.
Figure 1: Hype Cycle for Digital Identity, 2026
Hype Cycle for Digital Identity, 2026, plots 29 innovations from the Innovation Trigger through the Slope of Enlightenment. Innovations range from workload access management to Secure Production Identity Framework for Everyone (SPIFFE) to verifiable credentials.

The Priority Matrix

While many innovations on this Hype Cycle are at the Innovation Trigger or the Peak of Inflated Expectations, several technologies are sliding through the Trough of Disillusionment. Some of these technologies, while steadily improving, struggle with mainstream adoption, especially as interest and investment has shifted rapidly to AI-linked identity trends.
Verifiable credentials (VCs) and decentralized identity deserve particular attention as they promise transformational value and are on the Slope of Enlightenment. Early adoption of these innovations that establish, broker, and manage trust in digital identities can lead to significant competitive advantage and time-to-market benefits.
Climbing the trigger, emerging innovations are largely centered on AI and identity visibility. In the trough and climbing the slope are technologies providing enhanced authentication, threat detection and posture management.
Several innovations remain five to 10 years away from mainstream adoption. Among these, identity visibility and intelligence platforms (IVIP) can provide a single pane of glass view of identities and access with actionable insights and recommendation. Emerging standards and protocols including AuthZEN and Shared Signals Framework also promise high value.

Priority Matrix for Digital Identity, 2026

BenefitYears to Mainstream Adoption
Less Than 2 Years2 to 5 Years5 to 10 YearsMore Than 10 Years
Transformational
High
Moderate
Low
Source: Gartner (July 2025)

Off the Hype Cycle

  • AI-augmented software engineering is now merged with AI-native software engineering.
  • Device-bound passkey was removed because it is fully mature.
  • Machine IAM is now being tracked under the individual elements, including IoT authentication, workload access management and workload identity management.
  • OpenID Connect is a mature, widely deployed standard and is now mainstream.
  • Passive behavioral biometrics was removed because it is fully mature.
  • Policy as code has evolved and is being tracked as identity as code.
  • RISC and CAEP are now being tracked under the Shared Signals Framework.
  • Third-party biometrics was removed because it is fully mature.

On the Rise

Workload Access Management

Analysis By: Steve Wessels
Benefit Rating: High
Market Penetration: 1% to 5% of target audience
Maturity: Emerging
Definition:
Workload access management, which is a part of an overall machine IAM program, secures the exploding universe of workloads, which includes AI agents, applications, containers and microservices, by enforcing least-privilege access at runtime, replacing static credentials with dynamic, context-aware controls. Workload access management eliminates standing permissions, reduces machine-to-machine attack surfaces, and closes the critical blind spot undermining most zero trust strategies.
Why This Is Important
Workload access management eliminates excess privilege, which is a large contributor to workload identity risk. Rather than relying on long-lived static credentials, workload access management grants workloads only the access they need, at the moment they need it, then revokes it automatically. This runtime control layer secures machine-to-machine interactions across cloud and on-premises environments via token exchange and credential injection.
Business Impact
Unmanaged workload access introduces security gaps. Static credentials, excessive privileges, and unmonitored machine-to-machine access are primary vectors for breach and lateral movement. Workload access management helps mitigate these risks by replacing hardcoded secrets with short-lived, identity-based credentials, enforcing least-privilege policy controls, and delivering a continuous run time control layer across hybrid and multicloud environments, directly reducing attack surface and strengthening zero trust posture.
Drivers
Several converging trends are accelerating enterprise interest and investment in workload access management:
  • AI and agentic workload expansion. The emergence of AI agents and automated pipelines as enterprise infrastructure has introduced new categories of workload identity that require dynamic, policy-driven access controls at scale.
  • Explosive growth of workload identities. The rapid adoption of AI agents, microservices, containers, and APIs has created environments where workload identities vastly outnumber human identities and human centric tooling does not support ephemeral workloads deployed across a hybrid and multicloud environment.
  • High-profile credential-based breaches. Widely publicized attacks exploiting static credentials, hardcoded secrets, and compromised service accounts have elevated workload identity security to a board-level concern, accelerating demand for automated, short-lived credential management.
  • Zero-trust mandate. Enterprisewide zero-trust initiatives explicitly require continuous verification of all identities, human and nonhuman, driving organizations to extend identity-based access controls to workloads and machine-to-machine communication.
  • Multicloud and hybrid complexity. As workloads span multiple cloud providers and on-premises environments, siloed and manual access management approaches have become operationally unsustainable and inconsistent, creating compliance and security risk.
  • Regulatory pressure on workload identities. Evolving frameworks including NIST and SOC 2 increasingly require organizations to demonstrate governance and auditability over all identities, including workloads, services, and automated processes.
Obstacles
Several factors are slowing workload access management’s path to broad enterprise maturity:
  • Legacy infrastructure incompatibility. Many enterprises operate applications and systems that cannot natively support modern identity standards such as SPIFFE, OAuth, or X.509 certificates. Retrofitting workload access management controls across these environments requires credential injection, or significant re-architecture, extending deployment timelines considerably.
  • Organizational complexity. Workload access spans security, platform, DevOps, and application teams, each with competing priorities and tooling preferences. Establishing shared ownership and consistent policy enforcement across these groups remains a significant cultural and operational challenge.
  • Market immaturity. Workload access management is an emerging category with evolving standards, overlapping vendor capabilities and inconsistent terminology (e.g., NHI, agent security, etc.). Buyers face difficulty evaluating solutions and building long-term roadmaps against a still-consolidating landscape.
  • Consensus is currently lacking on best practices for workload access management. Without an agreed-upon set of best practices, defining a clear, mature capability to work toward remains a challenge.
User Recommendations
Organizations evaluating or adopting workload access management should take the following actions:
  • Prioritize vendors with hybrid and legacy support. Given infrastructure complexity, select workload access management solutions that support credential injection and proxying for legacy systems alongside modern orchestration platforms such as Kubernetes, ensuring coverage across your full environment, not just greenfield deployments.
  • Align workload access management adoption with zero-trust and compliance initiatives. Workload access management delivers measurable value against existing zero trust mandates and regulatory requirements. Frame investment within these programs to accelerate stakeholder buy-in and budget approval.
  • Assess your workload identity access exposure now. Evaluate workload identity management solutions to inventory all workload identities, service accounts, and credentials across cloud and on-premises environments. Identify where static or hardcoded credentials remain in use, these represent your most immediate risk and the strongest case for workload access management.
Gartner Recommended Reading
Leaders’ Guide to Modern Machine IAM

Intent-Based Access Control

Analysis By: Nathan Harris
Benefit Rating: Moderate
Market Penetration: Less than 1% of target audience
Maturity: Embryonic
Definition:
Intent-based access control is an emerging authorization framework that replaces broad, standing permissions and is currently targeted at agentic AI, but offers broad applicability. Intent-based access control grants access to back-end resources based on the captured or inferred intent of users interacting with an agent and evaluates the agent’s intended actions against that intent.
Why This Is Important
The most commonly implemented authorization methods for AI agents are granting the agent the human user’s access (which is standing access not sensitive to context) or granting persistent, long-lived access without intent context. Both of these result in overpermissioning. Intent-based access control downscopes access per session/transaction to limited access in line with both the agent owner’s intent for the agent and the human user’s intent for the specific transaction.
Business Impact
By tying access strictly to intent, enterprises can identify and enforce least-privilege access per transaction for agents to the extent that the intent itself is aligned with least-privilege access. This approach substantially reduces the likelihood of broad access for AI agents being abused to access unauthorized data or perform unauthorized actions in protected resources, while still enabling agents to deliver their intended functions and realize the associated automation benefits.
Drivers
  • The proliferation of AI agents operating with broad, persistent privileges exposes organizations to severe security risks, driving the urgent need for task-specific, least-privilege authorization.
  • Malicious attacks, such as indirect prompt injection, manipulate AI agents to execute unauthorized actions; intent-driven, deterministic access control can help prevent these outcomes.
  • Defining a clear intent promises to allow organizations to establish verifiable boundaries and accountability for an agent’s operational scope rather than relying solely on inherited human permissions.
  • Enterprises seek seamless AI user experiences in which users initiate complex workflows through natural language; this requirement necessitates a hybrid approach that translates unstructured human instructions into structured, machine-readable security policies.
  • Observability and discovery tools cannot reliably infer appropriate access permissions; therefore, organizations must address this risk within access control and access management capabilities.
Obstacles
  • Confusion around which stakeholder’s intent should be included/applied (owners, IT support or users) for each agent will limit adoption until best practices are clear.
  • Translating ambiguous, unstructured natural language instructions into precise, machine-readable authorization policies is highly complex and never 100% achievable at high quality. This “error rate” will discourage some organizations from adopting this approach, even when they include human-in-the-loop implementation decisions.
  • Due to the probabilistic nature of prompt interpretation, implementing organizations that require strong risk and compliance controls will, by necessity, implement deterministic access controls based on roles, attributes and relationships, which increases the total cost of implementing effective access control.
  • Support for intent-based access control in current tooling is very limited and, at the same time, not standardized. This makes practical adoption much more difficult.
  • Balancing strict security boundaries with operational usability often creates user friction, as agents restricted by narrow intent definitions may frequently halt execution. Some organizations will prefer greater operational flexibility over strict, intent-based control.
User Recommendations
  • Invest in AI agent identity registration and governance capabilities that capture the owner’s intent and propagate this intent to access control and authorization policy management systems.
    • Provide easily accessible methods for owners to update this intent as it evolves.
    • When feasible, use business role assignment to communicate intent for AI agents as a deterministic and clear method of communicating intent.
  • Define and document explicit operational envelopes for the tasks that agents perform, ensuring that intent-based boundaries restrict access to the minimum resources required.
  • Pilot intent inference AI to translate natural language input during identity registration and runtime user prompts into authorization policies; apply human-in-the-loop quality checks before adding these policies to the effective policy set. Recognize that end-user intent alone remains susceptible to abuse when malicious intent exists.
  • Implement token exchange capabilities to exchange both agent and human identity context into transaction-specific, tightly scoped access tokens aligned with captured intent.
Gartner Recommended Reading

CIAM for AI Agents

Analysis By: Akif Khan
Benefit Rating: High
Market Penetration: Less than 1% of target audience
Maturity: Emerging
Definition:
Customer IAM solutions are engineered to manage diverse, large-scale customer identities and ensure a frictionless digital experience. Cybersecurity leaders must adopt IAM capabilities to securely manage AI agent identities in customer-facing contexts given the emergence of use cases where customers send AI agents to interact with organizations.
Why This Is Important
Customers are forecast to use AI agents to make purchases, manage accounts and other online activities, while many businesses already use AI agents to engage with customers online. IAM capabilities for managing these agent interactions operate at the intersection of customer engagement and secure access control. Businesses must balance cybersecurity imperatives with respect to protecting accounts and data with the competitive dynamics of decreasing friction and maintaining customer engagement.
Business Impact
CIAM for AI agents ensures that businesses stay competitive as customers increasingly expect engaging UX such as AI-agent-based chatbots and shopping assistants. Furthermore, as customers begin to use their own AI agents for tasks such as purchases or account management, businesses that cannot securely and seamlessly support this agent activity risk missing out. A lack of effective CIAM controls for AI agents exposes businesses to account takeover risks, theft of sensitive data and poor CX.
Drivers
  • AI agents are becoming more integral to customer-facing business operations, with many organizations implementing AI-agent-based chatbots and customer assistants. In addition, customers are forecast to send their own AI agents to organizations in increasing numbers in the future. These two contexts create a complex environment of customer interactions involving different types of AI agents that must be managed carefully.
  • Use of AI agents in customer-facing scenarios presents a range of cybersecurity challenges that will need to be addressed using CIAM for AI agents. These include managing authentication and authorization mechanisms, delegating access from customers to AI agents, and verifying the identity of customers behind AI agents and being able to bind the two securely. Prevention of account takeover will be a key priority in a customer agentic context.
  • As AI agents from service providers begin to interact with customers, these systems must incorporate consent management models that allow users to maintain trust by determining the scope and limits of an agent’s actions. For example, a user might grant an AI agent permission to access certain customer data for personalized recommendations but restrict it from handling sensitive financial information.
  • With the introduction of regulations such as the European Union’s General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and industry-specific mandates like HIPAA, organizations are legally required to protect personal data and demonstrate robust control over customer identities.
  • Customer demand for frictionless experiences is relentless, with businesses constantly innovating to remain competitive. CIAM for AI agents will play a critical role in ensuring that businesses can compete moving forward.
Obstacles
  • Customers sending AI agents to carry out tasks such as making purchases or account management is still a nascent activity. Many organizations are taking a wait-and-see approach, delaying investing in CIAM for AI agents until volumes justify the effort.
  • Best practices or widely adopted standards have not yet emerged for IAM for agents in customer contexts, particularly with respect to knowing the identity of the customer behind the agent. This is slowing down adoption of IAM for customers’ agents.
  • The challenge of balancing trust, cybersecurity, and CX is complex. Managing the fine-grained authorization needed for customer interactions (e.g., “You can book flights to here, but not to there”) without constant prompts to users for permission has yet to be demonstrated at customer scale.
  • Many customer-facing back-end systems, such as retail CRMs, weren’t built for AI. Integrating with modern, agent-aware CIAM may be complex.
User Recommendations
  • Collaborate closely with the teams managing customer-facing interfaces to be aware of deployments of AI agent-based tools such as customer assistants. In addition, use AI-agent bot management solutions to gain visibility into the volumes of AI agents being sent to your customer-facing interfaces by external users. Use all of this information to support the business in prioritizing the need to invest in CIAM for AI agents.
  • Look to vendor-provided capabilities rather than attempt to build CIAM tooling in-house in order to manage costs and demands on resources. In the first instance, evaluate whether your existing CIAM vendors can meet requirements to support agent interactions. If your incumbent CIAM vendor is incapable, look for a dedicated vendor that can manage the agent interactions and integrate with your incumbent platform.
Sample Vendors
Descope; Frontegg; IBM; Microsoft; Ping Identity; Strivacity; Transmit Security
Gartner Recommended Reading

Identity Security Posture Management

Analysis By: Rebecca Archambault
Benefit Rating: High
Market Penetration: 5% to 20% of target audience
Maturity: Early mainstream
Definition:
Identity security posture management (ISPM) is an advanced security discipline that continuously assesses, monitors, and manages IAM policies and configurations across an organization’s digital infrastructure. It complements identity visibility and intelligence platforms (IVIP) and ITDR by providing technologies and processes designed to enforce proactive controls on the policies and configurations that mediate who or what can access digital resources, when, and under which conditions.
Why This Is Important
ISPM has become critical in today’s complex digital ecosystem, where the attack surface is continually expanding to include AI, machines, IoT, and automated processes. It is essential for organizations to maintain control and visibility over this complex identity landscape.
Business Impact
ISPM delivers transformative business benefits by automating identity life cycle management, enhancing security, and ensuring continuous compliance. Through real-time evidence collection and audit-ready reporting, ISPM reduces breach risks, streamlines access controls, and minimizes manual IT workload, resulting in increased operational efficiency and cost savings.
Drivers
  • AI and identity sprawl: The rapid move to hybrid and multicloud environments has made identity management more complex, resulting in widespread identity sprawl across the digital landscape. Additionally, the rise of AI-driven attacks has become a common challenge, further complicating security efforts. Managing these evolving risks is now considered the “new normal” for organizations.
  • Zero trust: ISPM is essential for digital transformation and zero-trust strategies, as it ensures continuous validation of IAM policies and configurations for any gaps or inconsistencies. This ongoing validation applies no matter where access requests come from, supporting secure modernization efforts. As a result, organizations can confidently adopt new technologies and operating models while maintaining strong security.
  • Proactive risk mitigation: Modern cyberthreats, such as phishing, credential stuffing, and AI-driven attacks, are increasingly targeting identity vulnerabilities. ISPM helps organizations proactively mitigate these risks by continuously monitoring for access policy anomalies and misconfigurations. This approach allows organizations to close security gaps before they can be exploited. As agentic AI increases autonomous access decisions, ISPM becomes essential for enforcing adaptive guardrails and redefining acceptable risk levels.
  • Regulations: Growing regulatory demands, such as GDPR, HIPAA, and NIS2, require strong security and proof of compliance. ISPM enables continuous audit readiness and automated compliance reporting, making it vital for organizations under strict regulations.
  • Cost management and streamlined governance: ISPM improves financial efficiency by streamlining identity life cycle and legacy system management, cutting operational costs, and freeing up IT resources. Organizations using ISPM report major savings from less manual work and more efficient governance.
Obstacles
  • Legacy IAM: Many enterprises rely on siloed, legacy identity management systems that were not designed for real-time monitoring, making the adoption and integration of ISPM more complex.
  • Poor identity data: Fragmented identity data across platforms hinders unified visibility, resulting in incomplete risk assessments and potential security gaps.
  • Reactive culture: Transitioning to continuous monitoring can face resistance from IT staff and users concerned about privacy and workflow disruption, especially in organizations with a reactive cybersecurity culture.
  • Training: Upfront investments in technology, training, and process redesign can be a barrier, particularly for budget-constrained organizations.
  • Talent: ISPM adoption also demands expertise in cybersecurity, analytics, and automation, yet skilled talent is scarce and hard to retain.
User Recommendations
  • Align with zero trust by leveraging ISPM as a critical layer to monitor and remediate contextual, identity-based configuration risks in real time, continuously verifying all access policies across on-premises, cloud and SaaS infrastructure, and eliminating implicit trust in the current policy and configuration management processes — vital for hybrid and remote environments.
  • Modernize and integrate systems to reduce vendor fragmentation; ISPM’s APIs and connectors enable unified, centralized management across on-premises, cloud, and third-party applications.
  • Automate identity life cycle management with ISPM to streamline provisioning, deprovisioning, and access reviews, minimizing manual errors.
  • Use ISPM’s advanced analytics, AI-driven risk detection, and cross-functional collaboration for effective policy enforcement and adoption.
Sample Vendors
Cisco (Astrix Security); CrowdStrike (SGNL); Delinea; Microsoft; Okta; Palo Alto Networks (CyberArk); Permiso; Ping Identity; SentinelOne; Silverfort
Gartner Recommended Reading

Postquantum Authentication

Analysis By: Paul Rabinovich
Benefit Rating: High
Market Penetration: Less than 1% of target audience
Maturity: Emerging
Definition:
Postquantum authentication (PQA), also known as quantum-safe authentication (QSA), is a horizontal category that encompasses any authentication method that incorporates postquantum cryptography (PQC) to mitigate attacks that rely on quantum computing. This innovation cuts across different flavors of authentication, especially phishing-resistant MFA based on public-key cryptography (X.509, FIDO2), but also includes mobile push methods.
Why This Is Important
By 2030, advances in quantum computing will likely weaken and break the conventional asymmetric cryptography that underpins many authentication methods. This will significantly reduce the credence that these methods can provide, increasing enterprises’ exposure to ATO risks. Thus, migration to postquantum authentication is a critical task.
Business Impact
PQA is crucially important to cybersecurity leaders:
  • In all industry verticals and geographies
  • Across multiple use cases incorporating authentication methods based on asymmetric cryptography
  • To protect these methods from attacks based on advances in quantum computing
  • To avoid increasing the organizations’ exposure to ATO risks and consequent data breaches, financial loss and so on
Drivers
  • Public-key cryptography underpins three important flavors of authentication tokens: mobile push, X.509 and FIDO2; the latter two provide phishing-resistant MFA.
  • Mobile push is one of the most popular authentication methods. Mobile push apps typically embed public-key credentials, used to sign the user’s response and provide data integrity and data origin authentication, confirming possession of the token (smartphone).
  • Phishing-resistant MFA is of increasing client interest as a way of avoiding the vulnerabilities of other token-based MFA (including mobile push). Both X.509 and FIDO2 flavors incorporate public-key credentials in the sole possession of the user, activated​ by a local PIN or biometrics​.
  • Key cracking is one of the mathematically approachable problems the new generation of commercial quantum computers are positioned to solve. Gartner predicts that by 2030, quantum computing will make conventional asymmetric cryptographic systems unsafe to use.
  • In many classes of systems, replacing existing algorithms has begun and is expected to accelerate now that NIST has identified new quantum-safe algorithms and drafted deprecation dates for classical asymmetric algorithms.
  • Compliance regulations in multiple jurisdictions mandate migration to PQC.
  • Commercial PQA (i.e., authentication that incorporates quantum-safe algorithms) is currently (July 2026) generally available from only one specialist vendor. Thus, it is still at a far left position on the Hype Cycle.
  • Vendors that lag in making PQA generally available are likely to lose customers, who will seek new partners that can enable a timely implementation and rollout.
Obstacles
  • Organizations may lack a full inventory of where vulnerable authentication methods are used and who the stakeholders are. It may be difficult to orchestrate change across all dependent parties.
  • There is a key dependency on the FIDO Alliance and individual authentication vendors for PQA, but most plans are at early stages.
  • FIDO2 and X.509 methods depend on algorithm standardization and incorporation into various protocols, as well as updates to OSs, browsers, devices (especially Trusted Platform Modules [TPMs]) and other infrastructure. Some proprietary offerings may be free of such prerequisites.
  • Authentication vendors may be late incorporating PQC within their tools. PQA must be generally available sufficiently early, ideally by 2028, to enable organizations’ timely migration to PQA. If vendors are late, customers should seek alternative providers.
  • Implementing and rolling out PQA will mean updating authenticators and reprovisioning these to every user, a significant logistical effort that may present opportunities for ATO attacks.
  • Supply chain constraints may impact sourcing new PQA-compliant hardware tokens, impacting timelines and budgets.
User Recommendations
  • Include PQA within a comprehensive postquantum program, and prioritize early discovery and inventory to support migration efforts. While PQA might not be a high priority in terms of “harvest now, decrypt later” exposure, migration will still need significant effort.
  • Work with incumbent vendors to understand their timeline for PQA. Seek support for hybrid methods to enable a robust transition to pure PQA.
  • If selecting new tools, prefer vendors in this order: (1) those that offer PQA; (2) those that have a clear timeline for PQA. Prioritize solutions that support cryptoagility.
  • Establish a clear schedule that will give you sufficient time to select, implement and roll out a new PQA tool. Use this to set a watershed. If an incumbent vendor cannot offer PQA at that time, be prepared to switch.
  • Ensure timely PQA rollout. Be wary of attacks against credential management processes. Reprovision authenticators ahead of time so the process can be bootstrapped using existing methods. Later (re)provisioning will require more onerous identity verification steps.
Sample Vendors
Wultra
Gartner Recommended Reading

AuthZEN

Analysis By: Mehmet Yaliman, Paul Mezzera
Benefit Rating: High
Market Penetration: 1% to 5% of target audience
Maturity: Emerging
Definition:
AuthZEN is an authorization standard developed within the OpenID Foundation that focuses on defining protocols for evaluating user permissions and access rights across systems and applications. It aims to simplify the authorization process by providing a standardized interface that enhances security and ensures consistency in how access decisions are made.
Why This Is Important
Applications often build their own authorization systems or integrate with authorization management platforms (AMPs) through proprietary means, causing low to nonexistent interoperability and an increase in vendor lock-in. AuthZEN brings much-needed, standardized interoperability to authorization in order to simplify implementation, reduce costs, enable more sophisticated access control, and accelerate the widespread adoption of externalized authorization management systems.
Business Impact
Adopting AuthZEN:
  • Simplifies and accelerates adoption of fine-grained, externalized authorization through a standard interface, eliminating custom-made integrations.
  • Centralizes policy management to ensure consistent, dynamic authorization decisions with improved auditability and compliance.
  • Standardizes access control for the next wave of AI agents, enabling safe, scalable, and policy-driven access across systems.
  • Reduces reliance on proprietary systems, thereby reducing the risk of vendor lock-in.
Drivers
  • Modern security strategies, such as zero-trust, demand dynamic, fine-grained authorization decisions based on identity, resources, actions, and context. This requires continuous evaluation beyond simple checks. Decoupling authorization logic from applications and managing it centrally through policy-based systems enhances security, auditability, and flexibility, and simplifies development. AuthZEN supports this by offering a standardized authorization API for applications to delegate authorization decisions to external platforms, independently of the authorization framework(s) in use.
  • Authorization has lacked universal standards for integration and interoperability, resulting in a fragmented landscape. Many applications still develop proprietary access control systems or rely on constrained authorization patterns, so that managing authorization across diverse application stacks becomes complex, costly, and hard to secure.
  • The proliferation of AI agents has heightened the necessity for robust authorization mechanisms, significantly amplifying the risk associated with broken access controls.
  • The AuthZEN working group has finalized the Authorization API version 1.0, focusing on standardizing communication between Policy Enforcement Points (PEPs) and Policy Decision Points (PDPs) using a JSON-based model. Further work is being done to refine the existing specification, and the introduction of various profiles aims to streamline adoption.
  • Gartner, together with the OpenID Foundation, hosted successful interoperability sessions with 11 AuthZEN implementations at both Gartner IAM Summits in 2025, showing the protocols’ utility, interoperability, and implementability (see Gartner Identity & Access Management Summit). During and after the sessions, Gartner clients emphasized the importance of this unmet market need.
Obstacles
  • Authorization today is implemented in a multitude of locations, through diverse tooling, and is based on varying paradigms. This inherent complexity makes standardization more difficult compared to authentication.
  • There is currently very little adoption of AuthZEN as implementers wait to see if it is viable in the long term. The Authorization API 1.0 reached the “final” stage in January 2026, and the first productized implementations have started to appear. The working group remains actively engaged in defining the necessary patterns, mechanisms, protocols, and formats.
  • Many applications lack inherent support for modern identity protocols, with authorization trailing behind authentication and provisioning. Integrating externalized authorization using an AMP tool necessitates that applications are designed or modified to interact with a PDP, a process that can be particularly time-consuming for legacy systems.
User Recommendations
  • Update procurement criteria to include support for externalized authorization using the AuthZEN Authorization API. Introduce AuthZEN as an optional criterion for authorization from software vendors to reduce reliance on proprietary systems and vendor lock-in. AuthZEN’s benefits for centralizing control and enhancing security warrant its inclusion in evaluation criteria, albeit as a “nicetohave” for the time being.
  • Develop playbooks for integration patterns and potential libraries for internally developed applications. Stay updated on the OpenID Foundation AuthZEN Working Group’s progress. The working group is defining further mechanisms, protocols and formats, with efforts extending beyond the initial PEP-PDP API.
  • Leverage AuthZEN to standardize the PEP-PDP request/response independently of the authorization model or policy language. Choose a PDP based on your preferred model.
Sample Vendors
Axiomatics; Cerbos; CrowdStrike (SGNL); IndyKite; OpenFGA; Permit.io
Gartner Recommended Reading

Identity as Code

Analysis By: Mehmet Yaliman
Benefit Rating: High
Market Penetration: 5% to 20% of target audience
Maturity: Emerging
Definition:
Identity as code (IDaC) is the systematic application of code-driven practices to the management of identity and access management (IAM) systems. This includes infrastructure, configuration, access policies, and select identity-related data. Under this approach, IAM changes are defined, reviewed, tested, and delivered using modern software delivery practices such as version control and CI/CD.
Why This Is Important
IAM has become a foundational control plane for digital business. However, in many organizations it is still managed through manual processes and error-prone changes. As delivery models become more agile and environments more dynamic, spanning cloud platforms, APIs, and machine identities including AI agents, identity as code enables IAM to deliver speed, scalability, and reliability to match modern software and platform engineering practices.
Business Impact
Adopting identity as code:
  • Increases delivery agility by enabling faster, safer IAM changes aligned with application and platform life cycles
  • Improves the resilience, auditability, and traceability of IAM systems by making changes explicit, repeatable, and recoverable
  • Enables consistent IAM controls for human and machine identities, including AI agents, across complex and distributed environments
  • Promotes cross-team collaboration by aligning the IAM team with infrastructure-as-code stakeholders.
Drivers
  • The shift toward application-centric and platform-centric delivery models requires IAM to be provisioned, configured, and governed as an integral part of the delivery life cycle, because applications, platforms, and digital services inherently depend on it for secure operation.
  • IAM configuration and policy changes have become operationally critical, as IAM evolves into a foundational control plane that defines authentication, authorization, and trust relationships for user and workload access across cloud platforms, SaaS ecosystems, APIs, and distributed systems.
  • Rising security risk from static, long-lived credentials, where compromise creates large blast radii, is driving rapid adoption of ephemeral accounts and credentials across cloud workloads, services, pipelines, and AI agents. This shift requires dynamically generated roles, credentials, and policies that cannot be supported reliably through human-centric processes.
  • There is pressure to remove centralized IAM teams and processes as a bottleneck in application onboarding and platform enablement, since development and platform teams expect self-service access to standardized identity integrations that do not depend on scarce IAM specialist capacity.
  • There are growing operational and resilience risks associated with IAM failures, including outages caused by configuration errors, dependency on single IAM environments, and limited ability to recover or reconstitute IAM infrastructure across regions, cloud providers, or on-premises environments.
  • There are heightened regulatory, audit, and security expectations, which require IAM changes to be traceable, versioned, repeatable, and recoverable across environments.
Obstacles
Obstacles include:
  • Uneven and fragmented support for code-driven IAM management across platforms, where infrastructure, configuration, policy, and life cycle capabilities are exposed inconsistently, limiting end-to-end automation and portability
  • Governance, auditability, and segregation-of-duties gaps in many platform/DevOps practices, which often fall short of established IAM controls and reinforce valid concerns about shifting IAM changes to platform-owned workflows
  • Organizational separation and differing operating models between IAM, security, and platform or application teams, complicating ownership and slowing adoption of code-driven workflows
  • Lack of well-established best practices for applying identity as code, including how to model and govern IAM state through code, manage version control and environment promotion, and reliably recreate or recover IAM systems across regions or infrastructures
  • Limited standardization in how applications and platforms consume and adapt to IAM configuration changes.
User Recommendations
  • Adopt identity as code as an operating model for IAM delivery to improve collaboration and speed of delivery across all parties involved in IAM delivery.
  • Validate that the chosen automation processes include sufficient governance to meet IAM requirements and, where absent, champion governance improvements for these processes.
  • Don’t assume that fully declarative or reconciliation-based models are required early. API-based automation executed through controlled delivery pipelines can deliver the same meaningful benefits as transitional approaches.
  • Enable standardized, code-driven IAM workflows that support self-service for application and platform teams while establishing shared ownership and governance among IAM, security, and engineering functions.
  • Evaluate IAM platforms beyond functional capabilities, focusing on their ability to support versioning, testing, promotion, and recovery of IAM configuration and policies across environments.
Gartner Recommended Reading

Deepfake Detection in Meeting Solutions

Analysis By: Akif Khan, Nayara Sangiorgio
Benefit Rating: Moderate
Market Penetration: Less than 1% of target audience
Maturity: Emerging
Definition:
Attackers are using synthetic/deepfake audio or video content within calls on enterprise meeting solutions platforms such as Cisco Webex, Google Meet, Microsoft Teams or Zoom to target employees. Real-time deepfake detection solutions join calls to analyze the audio and/or video content and alert participants to a possible attack.
Why This Is Important
Attackers can easily create deepfake content. Only a few minutes of reference audio is needed to create a deepfake voice of a target. Creating convincing deepfake video of a target’s face is also achievable. Attackers can target executives and use deepfakes of them combined with social engineering to call employees with the intent of tricking them into carrying out malicious actions, subvert account recovery workflows, or mask their true identity during recruitment interviews.
Business Impact
There have been numerous reported examples of attackers using deepfakes in online meetings to trick employees into making large fund transfers. Defense against such attacks critically depends on the human factor, but employees are susceptible to social engineering, particularly when they believe they are speaking to senior executives. Other use cases involve attacks on the IT help desk to subvert account recovery or attackers hiding their identity during recruitment interviews.
Drivers
  • The barriers to use for tools that can enable the creation of deepfake audio and video continue to drop.
  • Social engineering as an attack vector is a problem with no easy solutions, and it remains a highly effective exploit. Its use in attacks on organizations continues to increase, representing a persistent risk to corporate cybersecurity.
  • Enterprise meeting solutions platforms, such as Cisco Webex, Google Meet, Microsoft Teams, or Zoom do not offer natively integrated deepfake detection.
  • A growing number of startup vendors have introduced products in which bots join calls as a participant on an enterprise meeting solution platform to access the audio and videostream. They then provide real-time alerts to the presence of deepfake audio or video content in the meeting.
Obstacles
  • The technology is unproven at scale. Vendors in this space are nascent, with many still working with design partners and running proofs of concept.
  • The scale of the threat remains largely unquantified, making it hard for security leaders to justify investment amid competing priorities.
  • Deepfake detection solutions potentially risk large-scale operational disruption to a business if employees don’t have clear remediation guidance and are leaving calls when alerted to deepfakes or attempting inappropriate verification. The problem would be exacerbated by inevitable false positives.
  • Current solutions do not protect all platforms. While enterprise meeting solutions platforms could be protected, attackers could still contact employees via WhatApp, FaceTime, or even direct phone calls. Alternative layers of protection will still be needed.
  • Since deepfake detection cannot be relied on alone and additional measures are needed, making the investment in deepfake detection becomes more challenging.
User Recommendations
  • Assess emerging deepfake detection solutions for enterprise meeting solutions with the mindset of being an early adopter.
  • Recognize that deepfake detection alone will not solve this challenge nor protect all channels.
  • Train employees to recognize and resist social engineering, using vendors who specialize in deepfake red teaming.
  • Develop playbooks to prepare employees to respond when alerted to the possible presence of a deepfake in an online meeting.
  • Audit business processes to learn which ones are most vulnerable to social engineering involving deepfakes. Add additional authorization steps such that a single online meeting cannot be the trigger for a catastrophic event.
  • Implement processes that enable an employee to authenticate themselves when required. Use identity verification for account recovery workflows where authentication cannot be carried out or to reduce risk during recruitment processes.
Sample Vendors
Clarity; DeepTrust; GetReal Security; identifAI; Netarx; Pindrop; Reality Defender; Resemble AI; Truly
Gartner Recommended Reading

Workforce Identity Impersonation Detection

Analysis By: James Hoover, Akif Khan
Benefit Rating: Moderate
Market Penetration: Less than 1% of target audience
Maturity: Emerging
Definition:
Workforce identity impersonation detection seeks to prevent attacks on enterprises arising from threat actors impersonating employee identity, most notably in social engineering contexts. These approaches may involve use of identity verification, but there may also be other approaches that do not require biometric data.
Why This Is Important
Credential management processes are increasingly targeted by attackers for initial access to an organization’s resources. Established accounts can be attacked through reset processes for authentication, where an attacker seeks to have their authentication token associated with the target’s account. Attackers, too, increasingly target the employee recruitment pipeline to gain access, whether to perform subsequent malicious actions or to bypass sanctions and funnel money to restricted regimes.
Business Impact
Cybersecurity leaders across industry verticals and geographies have discovered that formal identity verification (IDV) alone is often too intensive and invasive for use in workforce scenarios, and are therefore deploying a spectrum of capabilities to address the overarching issue of impersonation attacks.
Drivers
  • Increasing adoption of phishing-resistant multifactor authentication is pushing attackers to seek methods of gaining access that do not require technically sophisticated attacks, such as social engineering.
  • Rising candidate fraud, coupled with the prospect of legal consequences arising when unknowingly hiring citizens of a sanctioned regime.
  • Conventional service desk verification processes are based on familiarity and gaining the confidence of the agent, and are vulnerable to both conventional social engineering, deepfakes or a combination of the two.
  • Conventional remote onboarding only involves low-assurance checks for the existence of an identity.
Obstacles
  • Privacy concerns from the workforce around biometric data and information sharing/anti-fraud capabilities of formal IDV vendors.
  • Inconsistent support for workforce use cases among IDV vendors.
  • Less intensive approaches may face pushback for not “fully” verifying or identifying the employee.
User Recommendations
  • Explore IDV and adjacent capabilities provided by already deployed access management or authentication tools.
  • Deploy compensating controls for the highest-risk unauthenticated scenarios.
  • Prioritize tools that can provide confidence in an identity claim without a full doc + selfie process while gauging the appetite of your organization for full IDV deployment in certain scenarios (e.g., signaling closed source knowledge based verification, risk and recognition signaling, facilitated video calls with tamper detection).
  • Deploy IDV tools for the highest-risk scenarios or where no viable alternative exists.
Sample Vendors
1Kosmos; HYPR; Imper.ai; iProov; Microsoft; Nametag; Ping Identity; Prove; TechJutsu; Trusona
Gartner Recommended Reading

OpenID for Verifiable Credentials

Analysis By: Michael Kelley, Akif Khan
Benefit Rating: High
Market Penetration: Less than 1% of target audience
Maturity: Embryonic
Definition:
OpenID Connect (OIDC) is a well-known open standard for SSO in AM platforms and has served to make SSO more available across many disparate systems. OpenID for Verifiable Credentials (OID4VC) is a collection of open standards and protocols that makes issuance, exchanges and validation of identity data held within verifiable credentials possible among disparate decentralized identity (DCI) systems.
Why This Is Important
As more DCI vendors and use cases surface, one of the most significant challenges for DCI will be interoperability for verifiable credentials, enabling the ability to prove identity claims while on disparate trust networks. OID4VC enables open standards for the interaction of verifiable credentials created on disparate DCI products or networks. This step is foundational for the adoption of more universal DCI use cases in the market, and growth of DCI in general.
Business Impact
One of the primary challenges for the adoption of verifiable credentials is identifying use cases that make sense and are achievable. But unless the interoperability challenge is solved, the value created by these use cases will remain siloed and regional. The adoption of open standards for the exchange of verifiable credentials will allow the DCI market to grow and allow more DCI business use cases to be explored.
Drivers
  • The need for open standards for exchanging identity data and attributes contained in verifiable credentials, including:
    • OID4VC issuance — Defines an API and corresponding OAuth-based authorization mechanisms for issuance of verifiable credentials (Editors’ Draft) (Working Group Draft)
    • OpenID for verifiable presentations — Defines a mechanism on top of OAuth 2.0 to allow presentation of claims in the form of verifiable credentials as part of the protocol flow (Editors’ Draft) (Working Group Draft) (Implementer’s Draft)
    • Self-Issued OpenID Provider v2 — Enables end users to use OpenID Providers (OPs) that they control (Editors’ Draft) (Working Group Draft) (Implementer’s Draft) (see OpenID for Verifiable Credentials — Overview)
  • OID4VC is supported by many major vendors: But it requires more standardization guidance in terms of how vendors build their DCI products and for enabling interoperability among discrete networks.
  • OID4VC is credential format-agnostic: Making it useful in a variety of contexts.
  • Cybersecurity: OID4VC is a foundational component in the developing market of DCI. DCI is a disruptive IAM technology, taking a different approach to the use and storage of identity data.
  • Privacy: OID4VC enables DCI features, including providing privacy for participants, primarily through consent management and through the use of privacy-preserving protocols such as zero-knowledge proofs (ZKPs), which provide pseudonymity.
  • Cost optimization: Verifiable credentials contain proofs for claims about identity attributes, like employment status, citizenship or authorizations to access applications and data. OID4VC promises interoperability among any DCI system, representing significant improvement in terms of efficiency, cost and assurance over current approaches.
Obstacles
  • The DCI market, while established, is nascent and struggling to attract the attention and focus compared to other, more established markets like access management and authentication. This will delay efforts to adopt open standards like OID4VC.
  • Other protocols and standards related to verifiable credentials are highly in flux. The dynamic nature of standards development for verifiable claims will delay widespread adoption as anyone other than early adopters will wait to see how the market progresses.
  • OID4VC is highly dependent on the success of large, complex DCI initiatives, requiring the portability of verifiable credentials across multiple trust fabrics that OID4VC enables. If the DCI market fails to prove valuable for solving global challenges, OID4VC adoption will be impacted.
User Recommendations
  • Explore, for existing verifiable claims use cases, using OID4VC for interaction with other identity trust fabrics for issuing, exchanging or validating verifiable credentials.
  • Track maturity of the OID4VC standards and leverage the standards for use cases that would provide value outside of a confined DCI ecosystem.
  • Participate in standardization bodies like OpenID Foundation, Decentralized Identity Foundation and Trust OverIP, when possible, to help further define developing open standards like OID4VC.
Sample Vendors
Authlete; Curity; IBM; Interac; Microsoft; Okta; Ping Identity; Scytáles; SpruceID
Gartner Recommended Reading

Shared Signals Framework

Analysis By: Erik Wahlstrom
Benefit Rating: High
Market Penetration: 1% to 5% of target audience
Maturity: Emerging
Definition:
OpenID Shared Signals Framework (SSF) enables continuous, event-based IAM by standardizing how IAM, security tools and target systems share risk signals. SSF defines a mechanism for trusted parties to communicate security events and it helps create a programmable, event-based IAM architecture. SSF is profiled for use cases like continuous risk sharing, session validation, and identity life cycle management.
Why This Is Important
Traditional identity management technologies struggle with real-time session termination and just-in-time access across decentralized hybrid domains. SSF addresses this gap by standardizing how IAM tools and target systems communicate security events. SSF replaces fragmented approaches with a standardized, event-based mechanism for sharing real-time risk signals across IAM and security tools. This elevates continuous, event-based access control to a core pillar of modern threat mitigation.
Business Impact
The sharing of signals delivers increased security, continuous control, and higher assurance levels. Shared signals also provide just-in-time access and a better user experience across decentralized IT environments. By leveraging SSF, target systems and IAM tools can respond to life cycle events or detected threats by taking instant actions. Ultimately, this helps establish a zero-trust strategy, defend better against common threats and mitigate the impact on affected target systems and users.
Drivers
The decentralization of services across hybrid and multicloud environments requires continuous management of users, sessions, and risk across domains. SSF provides a single, standardized mechanism for collaboratively improving threat intelligence across systems. SSF is profiled to support specific use cases:
  • An interoperable system for responding to events during active sessions: Real-time session management, including instant session termination and access token revocation, is key to stopping attacks the moment they happen. Single logout has been challenging to implement at scale, but the SSF profile Continuous Access Evaluation Profile (CAEP) solves this. CAEP lets organizations stream risk and session signals into applications’ adaptive access engines, driving faster and more precise access decisions in complex environments.
  • The persistent challenge of credential hijacking and evolving account takeover (ATO) tactics: The SSF profile Risk Incident Sharing and Coordination (RISC) meets this need by enabling organizations to share security signals related to user account and credential state changes.
  • An event-driven, just-in-time identity life cycle: The SSF profile System for Cross-Domain Identity Management (SCIM) Profile for Security Event Tokens (SCIM-Events) enables real-time, event-based delivery of identity events, such as provisioning and deprovisioning across distributed systems, moving beyond SCIM’s traditional pull-based approach. This model ensures access is granted only when necessary and removed immediately when it is not, supporting privacy and enabling real-time, policy-based decisions.
Obstacles
SSF, CAEP, RISC and SCIM-Events are still not commonly known and understood by IAM professionals, or application and service developers.
Although implementation has started, identity standards take a long time to be commonly implemented. Identity standards have a “chicken-and-egg” problem before they reach wide deployment. Target systems wait to see if a standard takes off, and IAM vendors wait for broad support in their target applications. This is also true for SSF. While the number of implementers is growing, the overall deployment base is still small.
Another implication of the slow market adoption of new identity standards is the lack of tooling that can help modernize legacy tools and integrations by brokering and translating security events to nonsupporting environments.
User Recommendations
  • Define an IAM architecture that supports centralized control in a decentralized environment by embracing open standards. SSF and its profiles complement other modern identity protocols that enable it.
  • Require IAM vendors to support SSF. Gartner expects SSF to become increasingly important going forward.
  • Start implementing the CAEP profile first, as it currently has more vendor support, then use the same implementation to support SCIM-Events and RISC.
  • Add CAEP as an optional RFP criterion when procuring new applications, specifically SaaS apps, but expect support to be still emerging.
  • Prepare for hybrid environments by enabling translation between SSF and proprietary signaling frameworks. This approach modernizes legacy tools and integrations by brokering SSF events into systems that do not natively support them. Currently, Gartner is only aware of two such brokers at the moment: CrowdStrike (SGLN) and IBM.
Sample Vendors
Apple; Cisco; CrowdStrike (SGNL); Google; IBM; Jamf; Okta; Omnissa; SailPoint; Thales
Gartner Recommended Reading

AI Agent Identity

Analysis By: Zachary Smith, Nathan Harris
Benefit Rating: High
Market Penetration: 5% to 20% of target audience
Maturity: Emerging
Definition:
AI agent identity is the unique digital representation of AI agents within an organization. Establishing and governing identity for AI agents, including assistants and chatbots, enables identity and access management (IAM) systems to assign unique identifiers, issue targeted credentials for access to resources (e.g., APIs, data, and services), and establish clear human accountability and audit trails across enterprise systems.
Why This Is Important
Organizations face intense pressure to boost productivity and transform workflows through agentic AI. Traditional IAM controls that rely on legacy credentials or reused human identities do not establish the unique digital identity records necessary for both enabling and securing agentic AI ambitions. Formalizing AI identity allows organizations to effectively orchestrate and scale AI agent automation while ensuring least-privilege, risk- and policy-based access controls, and strict auditability for AI.
Business Impact
AI identity enables organizations to achieve safety and scalability. Orchestrating AI agents with unique identities and delegated access on behalf of humans enables scalable and adaptable automation across enterprise digital environments. AI identity also mitigates the risks of static account-based entitlements (e.g., unauthorized data access, credential compromise, and rogue agents) by reducing the exposure window and ensuring that AI agents operate with dynamic access controlled by policy.
Drivers
  • Rapid adoption of AI agents: The rapid adoption of agentic AI to augment the internal workforce is causing a massive surge in AI entities that require secure access to sensitive enterprise data and applications.
  • Epidemic of human credential sharing: The hazardous practice of deploying AI agents as proxies operating with human access credentials breaks auditing, traceability, and nonrepudiation requirements, significantly elevating the risk of overpermissioning, and the impact of credential compromise and account takeover.
  • Overprivileged AI agents: The inability to enforce granular, least-privilege access for AI agents exposes organizations to catastrophic risks, including rogue agent transactions and unauthorized lateral movement within corporate networks.
  • Legacy machine IAM practices: Existing machine IAM practices (including the use of hard-coded API keys and reused human credentials) do not work for AI agents. Legacy practices are neither secure nor agile enough for AI-orchestrated flows and suffer from technical debt and a lack of dynamic, context-aware authorization capabilities.
  • Evolution of identity-first security: The combination of identity-first security and broader zero-trust initiatives forces cybersecurity leaders to establish explicit, unique identities for all entities.
Obstacles
  • Speed of AI adoption: Rapid global adoption of AI capabilities, vendor hype, and misconceptions around AI have outpaced best practices for securely enabling AI applications.
  • Conflicting approaches for AI agent identity: Many vendors and organizations treat AI identities fundamentally differently from other workload identities, even though the foundational IAM principles remain the same. Until identity for AI agents becomes accepted best practice, disagreement on approaches will inhibit implementation and adoption.
  • Shadow AI: Developers often bypass formal cybersecurity policies by sharing human credentials with agents or using unsanctioned AI tools that obscure enterprise visibility.
  • Investment in modern machine IAM: AI identities require modern machine IAM use cases that can support registration, ephemeral or short-lived credentials, and fine-grained authorization. Updating to modern machine IAM requires serious investment in changing legacy account-based approaches.
User Recommendations
  • Identify all covered AI agent use cases (e.g., enterprise-managed, platform, embedded, customer/agentic commerce) and consider a modern machine IAM strategy appropriate for all workload identities, rather than an AI-only solution.
  • Select and implement IAM capabilities that fully support AI identity registration and governance, including identity discovery.
  • Establish identities for AI agents and integrate identity registration into AI adoption and governance processes. Treat AI applications as workload identities requiring short-lived, scoped access.
  • Upgrade legacy machine IAM capabilities to support AI identity requirements with policy-based authorization and short-lived or ephemeral credentialing.
  • Establish clear ownership and accountability for all AI agent authorization, and prohibit sharing employee credentials with AI agents. Instead, issue unique AI agent credentials to enable dynamic access that fully adapts to transaction context, including agent and human identity.
Gartner Recommended Reading

Identity Visibility and Intelligence Platforms

Analysis By: Nathan Harris
Benefit Rating: High
Market Penetration: 1% to 5% of target audience
Maturity: Emerging
Definition:
Identity visibility and intelligence platforms (IVIPs) are products that provide rapid integration and visibility for identity and access management (IAM) relevant data, paired with advanced analytics (often AI-enabled) capabilities. This innovation provides a single view of IAM data, activity/events, relationships, configuration and posture to enable rapid improvement of all other integrated IAM controls and capabilities supporting both improved security, compliance and business enablement.
Why This Is Important
Even with mature IGA, AM and PAM solutions, many organizations struggle to achieve full visibility (“single pane of glass”) in a reasonable timeline and at sustainable cost. The typical organization is still only partly integrated for IAM needs after years of investment and effort. Identity visibility and intelligence platforms enable substantially more rapid and comprehensive visibility and observability, further enabling improved intelligence leveraging the consolidated data.
Business Impact
Identity visibility and intelligence platforms (IVIPs) can significantly accelerate visibility into and discovery of IAM data, events, configuration and posture providing faster achievement of a “single pane of glass” view into all access for all actors in an organization. In turn, this enables both better IAM risk/posture assessment and recommendations, and more rapid identification of enhancements to improve business enablement and user experience.
Drivers
  • The vast majority of IAM programs have a high priority for and target of full visibility, since managing or making improvements to any area with blind spots is not possible. This is explained simply with the visibility, intelligence, action (VIA) model which makes clear that all action quality is dependent on quality of intelligence, which is further dependent on degree of visibility (including data quality).
  • Purchase and implementation of leading IGA, AM and PAM solutions have not, by themselves, enabled most IAM programs to achieve desired levels of visibility in the expected time and at sustainable cost.
  • While many IAM leaders are aware of the value of advanced analytics including AI enabled IAM analytics, the optimal architecture to achieve maximum value from analytics is connected to a single component/system, which has comprehensive visibility (vs. siloed visibility and analytics which deliver more limited value).
  • The availability of more flexible and more relational data architectures, specifically graph data stores, makes higher visibility “fidelity” with actual access configuration more easily achievable than tooling built on relational databases.
  • There is remaining, unmet demand for greater automation of IAM for both security and business enablement objectives, but automation design remains a high level of effort and high sustaining cost process without strong visibility and intelligence supporting these automation efforts.
Obstacles
  • IAM program budgets are typically constrained, especially with existing investments in IAM tooling. Many organizations will find it hard to justify extra spending on what is often viewed as a supplemental rather than foundational IAM component.
  • Most vendors are focusing sales on specific action layer scopes such as improving IGA, ITDR or IAM posture/hygiene. This diversity of action layer focus may confuse the market and reduce the perceived value of comprehensive visibility and intelligence.
  • Overall market recognition of the importance of good data management practices for IAM success is low. Therefore, adoption/use of this type of tool is not yet required/expected as a standard practice.
  • Legacy applications (not API-enabled) remain more challenging to integrate than modern applications, though some vendors offer solutions for legacy application integration as well.
  • Even with improved capabilities, IVIP adoption will be a maturity and visibility improvement journey in implementations. Progress is faster with IVIP than without, but still doesn’t result in a “one and done,” monthslong project.
User Recommendations
  • Assess your current IAM technology portfolio for its ability to provide required visibility including ease/speed of integration and ability to retain full visibility for highly relational datasets.
  • Calculate and document (using outcome-driven metrics) the impact of visibility and intelligence gaps on your target outcomes for security and business enablement, then use this assessment to justify further investment.
  • For organizations lagging in required levels of visibility and data integration with existing IAM toolsets, explore and evaluate identity visibility and intelligence platform vendors for potential value as an addition to your identity fabric.
  • For organizations lacking a formal IAM data management process, begin with establishing good IAM data engineering and management practices including planning for an analytical data foundation (IAM data warehouse or data lake as appropriate).
Sample Vendors
AKA Security; AuthMind; Axonius; CrowdStrike (SGNL); Elimity; Nexis; Oleria; Radiant Logic; ServiceNow (Veza); Silverfort
Gartner Recommended Reading

AI-Native Software Engineering

Analysis By: Manjunath Bhat, Mark Driver
Benefit Rating: Transformational
Market Penetration: 5% to 20% of target audience
Maturity: Emerging
Definition:
AI-native software engineering includes practices and principles optimized for using AI-native tools across the software development life cycle to accelerate software delivery. AI-native practices go beyond human augmentation and involve using AI agents for asynchronously and autonomously executing long-running tasks that span multiple use cases and diverse roles. AI-native ways of working can deliver both productivity improvements and a creativity boost.
Why This Is Important
AI-native software engineering practices enable teams to focus on meaningful work that requires critical thinking, creativity, and user empathy, rather than spending time on repetitive tasks. By adopting AI-native methods beyond coding tasks, software engineering leaders can maximize the impact of AI in the software development life cycle (SDLC) and realize greater return on their technology investments.
Business Impact
AI-native software engineering leads to maximizing the use of AI across the SDLC. The 2025 Gartner AI in Software Engineering Survey shows a striking contrast between teams maximizing AI use across the SDLC versus those minimally using it for fewer use cases. For example, 55% of respondents who use AI for 10 or more use cases see an increased rate of innovation while 53% cite an increase in user/customer satisfaction, and 61% report an increase in developer job satisfaction.
Drivers
The primary value drivers for AI-native software engineering include:
  • Need to go beyond productivity gains and use AI to drive innovation: As AI commoditizes code generation, the primary measure of engineering effectiveness is shifting from productivity to creativity and innovation. Used effectively, AI transforms the experience of people in upstream planning phases by serving as an ideation partner for roles such as product owners and user experience designers, enabling them to convert text prompts or visual sketches into prototypes and supporting better and faster decisions.
  • Emerging practices, such as spec-driven development and context engineering: Spec-driven development combined with agentic coding tools that have access to better quality context help software engineering teams get closer to the aspiration of implementing a zero-friction SDLC. AI agents use specs to guide planning and implementation, enabling multiple asynchronous workstreams to run in parallel and deliver faster cycle times.
  • Compounding the effects of AI-native development tools used in ensemble: AI-native development tools used in ensemble across the SDLC enable organizations to not only improve delivery speed but also build in quality guardrails. For example, AI code review tools, AI testing tools, AI code security assistants, and AI site reliability engineering tools continuously detect and remediate quality issues and incidents.
  • Need to elevate the human experience (for example, developer experience): AI tools can significantly enhance human experience by reducing cognitive load and facilitating “flow state.” By automating tedious tasks (such as writing unit tests or migration scripts) and minimizing context switching and information retrieval (such as “explain this error” or “find this dependency”), AI allows engineers to minimize distractions.
Obstacles
  • Blind trust in AI output: AI-native approaches create a new burden on developers and knowledge workers in general. Developers increasingly offload tasks to AI tools, which carry inherent risks of nondeterminism and hallucinations. Therefore, blindly trusting AI output without verification and explainability can potentially pose serious business risks, including reputational damage.
  • Increased security risk: AI tools expand the threat surface via MCP servers, agent skills, agent plug-ins, and IDE extensions, which increases the potential for unforeseen vulnerabilities and security breaches.
  • Developer burnout due to high-intensity work: While AI can free up time for creative work, there is a high risk that it actually intensifies work by drastically increasing baseline productivity expectations. Developers using AI-native techniques are more likely to experience increased cognitive load as they constantly validate AI output and take accountability for work they have not personally done.
User Recommendations
Adopt AI-native software engineering in three phases:
  • Phase 1: Resolve constraints by mapping the software delivery value stream. Identify systemic bottlenecks and resolve them by judiciously using AI where appropriate. Discover pain points and improve the experience for all roles, not just developers.
  • Phase 2: Reimagine the SDLC with asynchronous workflows. Parallelize tasks using asynchronous agentic workflows. Transform software delivery workflows — identify what steps can be eliminated and what stays the same. Enhance IDP capabilities to govern, monitor and control AI software engineering agents.
  • Phase 3: Realize zero-friction SDLC with autonomous software delivery. Implement autonomous self-correcting and self-improvement loops and address pitfalls by expanding platform support for autonomous delivery and operations. Implement appropriate human oversight for autonomous workflows based on business criticality, acceptable risk, and architectural complexity.
Sample Vendors
Amazon Web Services; Anthropic; Cognition; Cursor; GitHub; GitLab; Google; Harness; Lovable; OpenAI
Gartner Recommended Reading

Workload Identity Management

Analysis By: Steve Wessels, Erik Wahlstrom
Benefit Rating: High
Market Penetration: 5% to 20% of target audience
Maturity: Emerging
Definition:
These tools enable organizations to register workload identities and to comprehensively discover, inventory, monitor, manage, and administer associated workloads, including their accounts, credentials, and access policies. Workload identity management tools represent a crucial shift to a workload-centric model, moving beyond the limitations of the traditional, credential-centric legacy approach.
Why This Is Important
The proliferation of workload identities, encompassing VMs, containers, services, applications, and increasingly, AI agents, is significantly outpacing human identity growth, introducing substantial security and operational risk. Traditional, credential-centric “legacy models,” such as long-lived static credentials and methods lacking formal identity records, are inadequate for the demands of modern workload identities. Solutions for managing workload identities have become essential. They offer critical visibility and protection for machine-to-machine communications by governing access policies and credentials.
Business Impact
Workload identity management (WIM) solutions support proactive governance via remediation tools, security assessments, and efficient root-cause analysis for assigning ownership. WIM tools contribute to a more stable and secure business landscape by streamlining the long-term oversight of intricate legacy credentials, including service accounts and API keys.
Drivers
  • Security and compliance pressures: Rising regulatory requirements demand stronger controls over workload authentication and credential management. At the same time, the ongoing high security risk from poorly managed, static workload accounts is evidenced by the high frequency of incidents involving compromise of workload accounts and credentials.
  • Lack of visibility and guidance: Leads to an unstructured, opaque situation where many teams create workload accounts with little governance or oversight, leading to security vulnerabilities.
  • Operational resilience: Expired certificates, unmanaged secrets, and poor visibility into machine-to-machine authentication are leading causes of service outages and security incidents.
  • Cloud and DevOps enablement: Highly automated environments require seamless integration with continuous integration/continuous delivery (CI/CD) pipelines, Kubernetes, service meshes, and cloud-native platforms, necessitating life cycle automation for workload credentials.
  • Third-party risk: Third-party workloads accessing enterprise systems typically operate with privileged access but remain inadequately monitored and managed.
  • Risk reduction and governance: Centralized discovery, monitoring, and policy enforcement for workload identities reduce the attack surface and support zero-rust initiatives. Each workload identity is provisioned with a granular set of permissions, ensuring that the identity only has access to the resources that are absolutely necessary for its function.
  • Crypto-agility requirements: Credential discovery and visibility enable migration to postquantum cryptography.
  • AI-specific risks: The rise of AI and industrywide concerns about AI workloads having far more access than needed, and being able to exploit that access more easily than previous workload types, demand new approaches to workload identity and access management.
Obstacles
  • Industry confusion is widespread about both the necessity of workload identities and the best practices for managing them. The challenge goes beyond a lack of standards, there is no shared understanding of what is required for effective workload identity management.
  • Regulations and audit practices are still heavily focused on human identity and access management, and sometimes expect IAM controls that are not suitable for workloads. Until regulations and audit standards evolve, this misalignment will remain a barrier to broader adoption of WIM.
  • Diverse workload identities require different credentials, tools, and processes, making unified management difficult for vendors. Multiple tools are needed to meet workload requirements.
  • Without standardized protocols for discovering and managing workload identities, proprietary APIs for each application and service slow development.
  • Legacy service accounts and lack of awareness of modern machine identity practices perpetuate outdated methods.
User Recommendations
  • Add teams, processes, and controls to ensure that workload identities are managed in your hybrid and multicloud environment.
  • Establish a cross-functional working group to lead the transformation to a modern workload identity management practice.
  • Evaluate your current IAM tooling for its ability to support the required WIM capabilities. If current tooling doesn’t deliver the required capability, evaluate WIM tools.
  • Conduct continuous discovery and assessment to identify workloads needing management and control. Enhance observability by collecting and correlating data from diverse sources.
  • Catalog out-of-compliance systems and establish, automated if possible, otherwise manual, life cycle management processes.
  • Enable developer empowerment with self-service interfaces and code libraries to stop the bleeding.
  • Implement dynamic workload credentials using platform-provided identities or SPIFFE in conjunction with access tokens for secure workload communication.
Sample Vendors
Cisco (Astrix Security); Clutch Security; GitGuardian; Natoma; Oasis Security; SailPoint (Entro Security); Token Security
Gartner Recommended Reading

At the Peak

Authorization Management Platforms

Analysis By: Paul Mezzera, Nathan Harris
Benefit Rating: Moderate
Market Penetration: 1% to 5% of target audience
Maturity: Emerging
Definition:
Authorization management platforms (AMP) provide shared services for authorization policy authoring, access decisions, policy orchestration and policy enforcement. AMPs provide authorization services for infrastructure, APIs, applications and data. They are delivered as software or as a service.
Why This Is Important
AMPs are essential for breaking down isolated “authorization silos” and providing a consistent and coordinated approach to managing authorization policies. They strengthen security by enabling least privilege across multiple applications, effectively reducing unauthorized access risks. Furthermore, AMPs improve compliance and auditability, while freeing developers from maintaining hard-coded authorization logic, which streamlines application development and boosts organizational agility.
Business Impact
AMPs allow organizations to:
  • Consolidate authorization policy administration, increasing policy visibility and simplifying compliance and audit processes.
  • Delegate policy management, increasing organizational adaptability, agility and efficiency.
  • Centralize authorization policy management across diverse applications and systems, eliminating policy silos and blind spots.
  • Externalize authorization logic, streamlining development and ensuring policy consistency.
Drivers
Several key trends and developments are driving the interest and market movements around AMPs:
  • Amplified risk of unauthorized access from agentic AI: AI agents can exploit policy gaps by operating autonomously and at scale, often bypassing weak or inconsistent authorization controls. Their dynamic decision making adapts to real-time data, which can expose vulnerabilities in outdated policies.
  • Intensifying regulatory scrutiny: Adoption is notably accelerating in heavily regulated sectors like financial services, defense and technology. These organizations are using AMPs to enforce granular permissions, reduce unauthorized access risks and demonstrate compliance with evolving security standards.
  • Emergence of industry standards: There is a surge of interest in standards-based approaches, particularly the OpenID AuthZEN standard, which enables interoperability between different authorization components. This standard reduces the risk of vendor lock-in caused by using proprietary APIs and providing a standard that offers organizations greater flexibility and confidence in their platform adoption.
  • Continued zero trust and cloud adoption: Large enterprises undergoing digital transformation, migrating to the cloud or implementing zero trust architectures are actively driving demand as they seek scalable and consistent authorization across diverse environments.
Obstacles
  • Solely focusing on externalizing authorization: Rather than expanding to broader policy orchestration across infrastructure and commercial applications, a limited focus could further limit the overall adoption and effectiveness of these solutions.
  • Experiencing inconsistent data availability: Poor data quality and availability can negatively impact authorization policy accuracy.
  • Suffering performance degradation and latency: This is unacceptable for applications requiring high throughput or low response times when performing external authorization checks.
  • Incurring high cost and effort for refactoring custom developed applications: These could be a major factor stalling broader movement in deploying externalized authorization tools, potentially incurring implementation costs that surpass the expense of the AMP software itself.
  • Encountering organizational friction: Resistance to change and a lack of alignment between IT, security and business units frequently slow down platform adoption.
User Recommendations
  • Adopt commercial, off-the-shelf AMPs instead of custom-built solutions: Leverage robust policy life cycle management and high-quality identity data integration to strengthen authorization.
  • Mitigate AI agent risk by enforcing fine-grained and context-aware authorization: Implement access policies that account for roles, attributes, transaction data and risk levels.
  • Broaden authorization coverage: Include coverage for commercial applications, infrastructure and data platforms. Synchronize policy enforcement and decisions across components to achieve consistent, scalable access controls.
  • Evaluate your organization’s security, compliance, and operational requirements: Pinpoint high-impact use cases (e.g., sensitive data access, cross-application permissions) and drive incremental improvements that deliver measurable business value.
  • Avoid vendor lock-in and foster interoperability: Anticipate emerging standards like AuthZEN and require standards compliance in your procurement processes.
Sample Vendors
Axiomatics; CrowdStrike (SGNL); Immuta; NextLabs; Okta; Permit.io; Ping Identity; PlainID; Privacera; SecuPi
Gartner Recommended Reading

AI for Access Administration

Analysis By: Nathan Harris
Benefit Rating: High
Market Penetration: 5% to 20% of target audience
Maturity: Emerging
Definition:
Artificial intelligence (AI) for access administration is the use of AI (e.g., machine learning, generative AI [GenAI] and agentic AI) specifically for improving access governance and administration. Common applications are rapidly and efficiently identifying and resolving instances of excess access (least privilege violations) and insufficient access (justified access that isn’t provisioned), including proposing rules to standardize, automate and govern entitlements.
Why This Is Important
Nearly all organizations find it difficult to manage access effectively, even if they have implemented identity governance and administration (IGA) tooling. Ever-changing workforce populations, business applications and IT systems, combined with no standard approach for entitlements/permissions models in apps and systems, make keeping up with effective access policies nearly impossible. AI methods can help improve manageability, sustainability and overall progress of target outcomes for access administration.
Business Impact
Applying AI to access administration (including access governance) processes can reduce manual work, improve delegation to non IAM teams, and speed up value delivery for identity and access management (IAM) teams struggling to keep up with organization changes and transformation. Using AI for access administration enables more rapid improvement in access policy than is possible with human decision making alone. This can improve IAM program results for business enablement, security and compliance simultaneously.
Drivers
  • Even with access administration and governance automation tooling (pre-AI), identifying and configuring rules/policies to address both least-privilege issues and access provisioning automation needs is simply too much work for most IAM programs. Applying access policy may be automated, but analyzing, modeling and configuring policies remain manual in most organizations. Entitlement data management (entitlement names, descriptions, risk levels, etc.) requirements further increase IAM team workload and amplify this driver.
  • Rapid advancement in AI capabilities, including (but not limited to) GenAI and agentic AI, makes AI more capable of processing high data volumes of access in most organizations. This can also deliver recommendations for access policy improvements (access modeling) more quickly and responsively to organization and IT system changes.
  • Most IAM programs have a security mandate to keep assigned access well-maintained and as close to the least-privilege principle as possible. Many successfully address access termination when an individual leaves the organization, but most are unable to successfully maintain good access hygiene overall, especially related to mover/transfer activity, even when using leading IGA tooling. AI for access administration enables faster response to changes and identification of hygiene issues to be addressed.
  • Most IAM programs also have a business enablement mandate to grant access that is justified as quickly as possible (right-time access). This enables their business to operate effectively, yet progress on the automation to accomplish this is slow in most organizations, with little to no “sight line” to fully achieving target outcomes. Applying AI can accelerate access automation efforts.
Obstacles
  • Machine intelligence is no better than human intelligence at dealing with data that doesn’t exist. As a result, the value of AI to access administration in each organization will be limited to use cases where the organization can provide the necessary identity, entitlement and access event data to drive AI models. Organizations need to make improvements in IAM data management to realize full value from this innovation.
  • All AI is probabilistic rather than deterministic. It will not be able to recommend the right access for 100% of client use cases and will sometimes misinterpret intent. Highly risk- and compliance-sensitive organizations may have difficulty getting to an acceptable comfort level with AI recommendations for access policies and decisions.
  • AI implementation is still expensive and complex, including model selection per use case, necessary tuning, and requirements to address trust, risk and security management (TRiSM). While capability is rapidly improving, the cost of entry to this capability for vendors and client companies remains high.
User Recommendations
  • Ask for AI-driven access administration capabilities from your IGA vendors. Incase of unavailablity, evaluate supplemental solutions.
  • Improve data management/engineering capability of IAM programs to improve both manual access administration and AI-facilitated access administration.
  • Test and implement AI-driven access administration improvements from IAM vendors. Evaluate the outcome primarily on its impact on the speed of delivering process improvements (do not expect 100% accuracy).
  • Expect technology vendors, including, but not limited to, IGA vendors, to incorporate AI methods and models into their solutions to help customers get more rapid and sustainable value. Use best-available AI models to improve both access provisioning/deprovisioning processes and access review/certification processes.
  • Implement and maintain with human in the loop design for any high-risk use cases. Full autonomous AI is only appropriate for tested, proven and moderate to low-risk access administration scenarios.
Sample Vendors
Gurucul; IBM; Linx Security; Lumos; Nexis; Ping Identity; Radiant Logic; SailPoint Technologies; Saviynt; ServiceNow (Veza)
Gartner Recommended Reading

SPIFFE

Analysis By: Nathan Harris, Mehmet Yaliman
Benefit Rating: Moderate
Market Penetration: 5% to 20% of target audience
Maturity: Early mainstream
Definition:
Secure Production Identity Framework for Everyone (SPIFFE) defines a set of specifications to securely identify and authenticate services in dynamic environments. It aims to provide a consistent, infrastructure-agnostic approach to workload identity management, enabling secure service-to-service communication in cloud-native and distributed systems. SPIFFE decouples workload identity from underlying infrastructure, enhancing security, scalability and interoperability.
Why This Is Important
SPIFFE aims to solve the hard problem of securely identifying workloads in distributed systems. This enables organizations to move away from a model based on service accounts with static credentials or shared secrets (legacy practices). These legacy practices have a high overhead because they require administration of account life cycles, and are also less secure and less flexible because they often rely on static and shared credentials.
Business Impact
SPIFFE supports organizations that deploy AI agents, APIs or IT infrastructures with automated processes. It enhances security in service-to-service interactions through credentialing and authentication, addressing vulnerabilities inherent in static credential use by eliminating the need for workloads to store credentials. SPIFFE provides a secure-by-design approach, offering flexibility and agility in deploying new infrastructure and services.
Drivers
  • Organizations on the way to implementing zero-trust security must deal with the difficult problem of credentialing and authenticating machine-to-machine interactions. Most approaches require a “secret zero” secret in order to retrieve their runtime secret (the bootstrapping issue), which SPIFFE addresses.
  • SPIFFE accelerates development and deployment because developers can focus more on writing application logic and less on managing credentialing and authentication in distributed systems.
  • Both SPIFFE (the framework) and SPIRE (an open-source implementation of SPIFFE) are projects from the Cloud Native Computing Foundation (CNCF) with “graduated” status, indicating their maturity. This helps SPIFFE’s adoption in cloud-native infrastructure, especially Kubernetes, OpenShift and derivatives.
  • The boom in AI agents requires careful consideration of how AI interactions are secured. SPIFFE provides an elegant solution to address one major part of this problem: bootstrapping identity, that is, securely identifying and issuing a credential to a workload.
  • SPIFFE offers more granular control over identity issuance and lower operational complexity than the model of using managed service accounts. SPIFFE can issue a credential to an individual process, whereas managed service accounts tend to project the credential to the entire container, which would require additional mitigation to ensure that unauthorized processes do not access it.
  • Google Cloud Platform (GCP) is using SPIFFE to underpin its managed service identities.
Obstacles
  • Culture shift: While SPIFFE is a key enabler of a zero-trust security model for workload identities, it requires a change in mindset and practices across development, operations, security and IAM teams that are accustomed to legacy practices.
  • Available viable alternatives: As shown by Microsoft and Amazon’s approaches, there are viable alternatives to solving the static credentials for workloads problem. While these are not standards based like SPIFFE, the mere existence of alternatives could reduce the demand for SPIFFE adoption.
  • Integration with existing infrastructure: SPIFFE works great for new deployments, but integrating it with the diverse heterogeneous landscape found in most organizations can face challenges. Although multiple integration patterns exist, they sometimes require supplemental components such as proxy servers, service meshes or secrets managers.
  • Skills: SPIFFE requires expertise in areas such as public key infrastructure (PKI), cryptography and distributed systems. Credentials issued by SPIFFE rely on workload attestation, that is, the process of verifying the identity of a workload at runtime, which must be planned carefully.
User Recommendations
  • Build expertise: SPIFFE and its underlying concept of workload attestation are likely new and a departure from legacy service account models. Invest in knowledge sharing and prototyping to build internal expertise and develop internal champions that can help others.
  • Integrate with other systems: SPIFFE integrates well with existing security infrastructure, such as PKI, secrets managers, access management tools, and service meshes. However, integrating with existing applications may require additional patterns, tools or customization.
  • Extend reach: Use SPIFFE in combination with workload identity federation to extend the trust of SPIFFE credentials outside your domain.
  • Achieve observability: Ensure that SPIFFE events and logs integrate into, and correlate with, monitoring and logging tools to achieve observability.
  • Integrate with authorization systems: SPIFFE focuses on authentication, that is, verifying the identity of a workload. However, workloads also need authorization, which SPIFFE does not cover. Yet, SPIFFE does provide some of the critical information that an authorization service can use to make decisions.
Sample Vendors
Aembit; CyberArk; Defakto Security; Google; Hush Security; IBM (HashiCorp); Red Hat; Teleport
Gartner Recommended Reading

Sliding into the Trough

Cybersecurity AI Assistants

Analysis By: Jeremy D'Hoinne
Benefit Rating: Moderate
Market Penetration: 20% to 50% of target audience
Maturity: Adolescent
Definition:
Cybersecurity AI assistants leverage generative AI (GenAI) techniques to discover existing knowledge available from cybersecurity tools, generate content or code and assist security teams in their daily tasks. Cybersecurity AI assistants are mostly available as companion features in existing products, but can also take the form of a dedicated front end and can integrate software agents to take action.
Why This Is Important
Most cybersecurity technology providers are now embedding a GenAI assistant into their existing products. These cybersecurity AI assistants promise improved productivity but primarily reduce friction to use complex cybersecurity tools. They are evolving to be agentic, integrating further through the use of existing APIs in the tools they support. Many GenAI features presented as “AI agents” by cybersecurity providers today fall under the cybersecurity AI assistant category.
Business Impact
  • Organizations use cybersecurity AI assistants as part of their existing tools to augment existing workflows.
  • Cybersecurity can improve operator accuracy, resulting in lower business downtime and potentially less data loss due to security incidents.
  • Organizations with high cybersecurity administrative turnover have shorter training periods due to the advantages of these assistants.
  • Cybersecurity AI assistants help surface key alerts, configuration issues and suggest recommended next actions.
Drivers
  • The biggest driver of adoption is that these assistants are automatically added to existing cybersecurity tools.
  • Cybersecurity teams, pressured to cut costs and automate repetitive tasks, are seeing a surge in interest for the promises of AI agents, despite concerns over agent washing.”
  • Cybersecurity AI assistants help teams to quickly create general best-practice guidance, synthesize and analyze threat intelligence, automate the first steps in incident response and generate remediation suggestions for application security.
  • Organizations continue to experience skill shortages and look for opportunities to automate resource-intensive cybersecurity tasks.
  • Cyber risk analysts need to speed up cyber risk assessments and be more agile and adaptable through increased automation and prepopulation of risk data in context.
  • More broadly, GenAI augments existing cybersecurity programs by better aggregating, analyzing and prioritizing inputs. These assistants then offer a guided response within the scope of the tool it supports.
Obstacles
  • Assistants’ pricing is the biggest factor for the pace of adoption. Providers want to monetize investments, but buyers don’t see enough value to justify a paid option.
  • Cybersecurity is plagued with false positives. One inaccurate GenAI response will cause caution about adoption and usage.
  • Automated actions require accountability and lower false positive tolerance. Most assistants lack features to implement human in the loop (HITL) and convincing proofs of low false positive rates.
  • Many organizations lack the process maturity and structured data flows for AI assistants’ benefits.
  • Best practices and tooling to implement responsible AI, privacy, trust, security and safety don’t fully exist yet. Security teams might be reluctant to enable GenAI features without guarantees regarding data security and privacy.
  • Cybersecurity AI assistants’ scope is often limited to the product they’re part of, creating fragmented insights and limited value.
User Recommendations
  • Build AI literacy and develop metrics to measure the success of the pilot program.
  • Be sure to have a control group to validate improvements attributed to AI against previously implemented processes
  • Monitor the addition of GenAI assistants from your existing providers and beware of “agent washing.” Don’t pay a premium before obtaining measurable results.
  • Evaluate privacy features and the model architecture to ensure the security of data shared with the GenAI assistant.
  • Implement a documented approval workflow for allowing new generative cybersecurity AI experiments to avoid the unmanaged sharing of sensitive data.
  • Implement a policy requiring that any content (that is, configuration or code) generated by an AI is fully documented, peer-reviewed by humans and tested before it is implemented. Otherwise, consider any AI-generated content as “draft only” when used for critical use cases.
Gartner Recommended Reading

IoT Authentication

Analysis By: Michael Kelley
Benefit Rating: High
Market Penetration: 5% to 20% of target audience
Maturity: Adolescent
Definition:
Internet of Things (IoT) authentication is the mechanism of establishing trust in the identity of a device interacting with other entities, such as devices, applications, cloud services or gateways. Authentication in IoT takes into account potential resource constraints of IoT devices, the bandwidth limitations of networks they operate within and the automated nature of interaction among various IoT entities.
Why This Is Important
IoT is expanding as a market, spanning automotive, smart homes, buildings, consumer devices, industrial and cyber-physical systems, autonomous robots, and Internet of Medical Things (IoMT). These connected devices can bridge cyber and physical worlds, and open up entirely new threat vectors. Among other requirements like encryption, sound IoT security requires a strong identity for IoT devices coupled with strong IoT authentication.
Business Impact
IoT authentication is foundational for protection of newer mechanisms in the market, including IoT applications and agentic AI components. IoT authentication can mitigate:
  • Privacy issues that directly impact liability and brand reputation for consumer devices.
  • Attacks against connected devices that could lead to disruption in product or service offerings.
  • Attacks against industrial devices that lead to operational impacts and, potentially, catastrophic events in safety-critical production areas.
Drivers
  • The growth of IoT and Industrial Internet of Things (IIoT) is creating connectivity between humans and machines, and machines to machines, in an unprecedented way.
  • IoMT, solving obstacles for legacy hospital and device integrations, poor security and sensitive data are driving hype.
  • Long-term spending growth is expected to be led by automotive, insurance, transportation and manufacturing. Organizations are investing in IoT technologies to drive cost optimization and operational efficiency (see Forecast: Internet of Things, Endpoints and Communications, Worldwide, 2023-2032, 1Q26).
  • Ongoing work for defining secure credential storage and rotation approaches for IoT authentication is helping to drive the market.
  • Many use cases stemming from IoT are changing traditional business models, such as continued developments in telehealth.
  • Identifying devices in a reliable way is driving the IoT market and the popularity of public-key infrastructure (PKI) as an identification approach. Certificates continue to be the primary way devices are identified and authenticated.
  • Poor visibility of IoT devices and poor adoption of Industry standards like NIST SP 800-213, and the Open Worldwide Application Security Project (OWASP) IoT Security Verification Standard will continue to introduce vulnerabilities and drive proprietary approaches toward cybersecurity (see Emerging Tech: Top Security Concerns for IoT).
Obstacles
  • The IoT landscape is complex, including determining the right people, processes and technology to employ due to a fragmented market, with highly industry-specific requirements and difficulties productizing due to inconsistent device types and operating environments.
  • The fragility of many IIoT environments, including the potential for abuse and catastrophic impact, will drive the continuation of proprietary and isolated approaches for authentication in cyber-physical environments.
  • Some authentication methods are not good candidates due to certain IoT devices that are resource- or feature-constrained with low computing power and limited secure storage capacity.
  • Support of authentication methods via IoT platforms is immature or incomplete. Use-case areas, such as IIoT, have protocols that are not interoperable with each other and often not operable with standards like TCP/IP, creating ongoing challenges for authentication approaches.
User Recommendations
  • Catalog and establish IAM capabilities for each category of device in its IoT network.
  • Evaluate and adopt authentication frameworks that support the range of device types across the IoT realms in operation.
  • Ensure that policy and process for authentication in IIoT environments continue to prioritize safety over interoperability, including traffic isolation.
  • Use trusted computing techniques, such as hardware root of trust, that help to protect against physical attacks on devices and sensors, and against external software attacks. Educate leadership on the regulatory and privacy risks associated with IoT. Identify use cases where the high cost of people or processes in existing approaches would justify investment in IoT solutions to secure funding for tools.
  • Use cross-functional working groups to manage the disparate technical and regulatory requirements of IoT projects and implementations (see Launching Fusion Product Teams: Key Decisions That Define Success).
Sample Vendors
CyberArk (Venafi); Device Authority; DigiCert; IN Groupe (Nexus); Keyfactor; Microsoft; Phosphorus; Sectigo; ServiceNow (Armis); Xage Security
Gartner Recommended Reading

Identity Wallets

Analysis By: Michael Kelley, Akif Khan, Arthur Mickoleit
Benefit Rating: High
Market Penetration: 5% to 20% of target audience
Maturity: Early mainstream
Definition:
Identity wallets, in the form of both mobile and web apps, enable users to store, manage and selectively disclose encrypted digital identity data from different sources and for various purposes. Users can facilitate proof and authentication without exposing unnecessary personal information.
Why This Is Important
An identity wallet provides individuals with greater control over their identity data and can potentially enable higher trust for verification of identity claims. For service providers, identity wallets can surface new service models for consented sharing of identity data. Use cases include commercial and government entities for issuers and verifiers of credentials. Governments can drive adoption of identity wallets through regulation, including more recent proposals for business wallets.
Business Impact
Identity wallets help individuals manage personal identity data. Use cases can include ID cards, digital passports, mobile driver’s licenses, and employment status and payments. The data managed by identity wallets may include verifiable credentials for decentralized identity (DCI), which can be used for authentication and authorization, as well as other digital representations of electronic data, like access cards and airline or concert tickets.
Drivers
  • Privacy and security: Identity wallets containing verifiable credentials prioritize benefits like security, privacy and anonymity through privacy-preserving protocols and selective disclosure.
  • Health information: Identity wallets can safely and securely share health information from patients to medical providers.
  • Citizen credentials: Identity wallets help manage mobile driver’s licenses and other documents providing proof of identity and entitlements. eIDAS regulations will require all EU member states to offer identity wallets free of charge for citizens by the end of 2026. Further, 21 of 50 states in the U.S. now offer the ability for citizens to use mobile driver’s licenses (mDLs).
  • Growing traction of DCI: Interest in identity wallets is growing, with increased interest in DCI. Global standards bodies, such as the Open Wallet Foundation, the World Wide Web Consortium and Trust Over IP, are defining standards for how verifiable credentials and decentralized identifiers function in identity wallets. This is driving additional use cases. These standards enable the creation of open interoperable identity wallet services.
  • User experience (UX): Identity wallets will reduce the need for users to repeatedly verify their identity across multiple service providers. Mobile devices will become the primary means for verifying identity claims, especially as services, payments and other use cases move to mobile consumption. Asserting an identity claim from already-verified identity attributes will reduce onboarding friction and likely serve as a competitive advantage for service providers.
  • Future monetization of identity data: Identity wallets are focused on nonremunerated consent for sharing personal identity data. Gartner anticipates new markets where individuals grant consent of their personal data for commercial use in return for remuneration or other rewards (for example, the announced dWallet in Brazil).
  • Regulatory compliance: This refers to simplified compliance with privacy regulations like GDPR and KYC.
Obstacles
  • Service provider registry: Currently, there is no universal way to identify authoritative sources for claims and credentials, nor for legitimate relying parties requesting data residing in identity wallets. The EU has mandated the establishment of national registers for relying parties.
  • Market understanding: There is confusion about the term “identity wallet.” It can refer to a proprietary mobile ID app, an open-standards-based interoperable identity wallet, or a superapp including payment and other services.
  • Wallet standards: The market is actively working on standards and strategies for interoperability. A universal wallet is still not available, nor is widespread interoperability.
  • User acceptance: The adoption of identity wallet technologies will be driven by discrete use cases, instead of a universal use case that applies to all users.
  • UX: The identity wallet interface must be easy to use and intuitive. A focus on device-based approaches could disenfranchise users with no access to mobile phones.
  • Trust and recoverability: Robust, standardized and secure recovery options, regardless of the wallet manufacturer, have yet to surface in the market.
User Recommendations
  • Support different digital identity wallets for varied use cases. Examples include a wallet for concert tickets; a government-issued wallet for citizen identity information; a personal wallet holding banking, employment and educational credentials; and a wallet for storing cryptocurrency or processing payments.
  • Explore emerging use cases, like verifiable credentials for DCI, cryptocurrency and non-fungible tokens, while supporting traditional use cases. Examples include, digital representations of physical things, such as airline and events tickets, and government-related documents like driver’s licenses, ID cards and passports.
  • Observe or participate in shaping regulations, standards and reference frameworks that are relevant to your geography; for example, the revised EU regulation, eIDAS 2.0, was ratified in 2024, and other governments are involved in large-scale pilots.
Sample Vendors
Apple; Google; ID.me; Interac; Lissi; Microsoft; Nuggets; Ping Identity; Scytáles; Walt.id
Gartner Recommended Reading

Multidevice Passkeys

Analysis By: James Hoover, Yemi Davies, Nayara Sangiorgio
Benefit Rating: High
Market Penetration: 5% to 20% of target audience
Maturity: Early mainstream
Definition:
Multidevice passkeys are public-key credentials used within FIDO2 user authentication protocols published by the FIDO Alliance. Credentials can be synchronized across multiple devices (phones, tablets and PCs). Authentication from each device is typically enabled by a device-native biometric method, unlocking the credentials. Passkeys on a phone can be used on another unsynced device via a QR-code-initiated Bluetooth connection.
Why This Is Important
User authentication methods should provide credence in an identity claim sufficient to reduce account takeover risks within an organization’s risk tolerance, ideally without adding unnecessary friction to the user experience (UX). In some use cases, multidevice passkeys may obviate the need for multifactor authentication (MFA).
Business Impact
Cybersecurity leaders across all industry verticals and geographies can benefit from adopting multidevice passkeys for customer authentication, which can:
  • Reduce the risk of account compromise.
  • Improve UX by eliminating passwords.
  • Let customers enroll once and use the same credentials for login from any synced device.
Drivers
  • The imperative to avoid the vulnerabilities, risks and user frustration associated with passwords, which drives interest in passwordless authentication generally.
  • Wide availability of FIDO2 platform authenticators in Apple, Google and Microsoft OSs and passkey support in personal password management (PPM) apps (e.g., 1Password and Dashlane). Specifically, users can sync multidevice passkeys across all their devices within the vendor’s ecosystem, eliminating the need to enroll each device separately for every service provider.
  • Cross-device authentication enables a user to use a passkey-enabled phone as a FIDO2 roaming authenticator to log in to an app or website from another device that can’t support passkeys, sits in a different vendor ecosystem or is not owned by a customer.
  • Web browsers and customer IAM tools widely support FIDO2 and web authentication, allowing the use of various FIDO2 authenticators, including multidevice passkeys. Specialist vendors further facilitate the use of passkeys for customer authentication.
  • Increasing advocacy of passkeys by Apple, Google and Microsoft. Visible support for login with passkeys from well-known social networks and from service providers, such as Best Buy, Cloudflare, eBay, GitHub, Google, Microsoft, PayPal, Stripe and WordPress.com.
Obstacles
  • There is currently minimal adoption of passkeys and limited customer awareness regarding their availability as an authentication method. Consequently, there is caution about deprecating traditional passwords until passkeys demonstrate consistent reliability and user acceptance at scale.
  • Synced passkeys can be shared among contacts at the user’s discretion. They are no longer in the user’s sole possession and do not constitute a possession factor for the purposes of MFA and do not generally provide enterprise controls.
  • People’s privacy concerns that ecosystem vendors might collect and monetize information about their online behaviors may be an inhibitor.
User Recommendations
  • Support and advocate passkeys as an alternative to passwords for those who can use them. Focus on the UX benefits, highlight passkeys as a login option and make enrollment easy.
  • Introduce an additional authentication factor for MFA. However, this might be waived if regulatory requirements are absent.
  • The weakness of most passwords leads to a need for a second factor, and a passkey is a stronger alternative. Even if a passkey doesn’t qualify as MFA, it may still be strong enough by itself for low-risk transactions.
  • Consider device-bound passkeys as an alternative to multidevice passkeys for some customer authentication needs (e.g., in mobile apps enabling high-value or sensitive transactions).
  • Prefer device-bound passkeys for workforce authentication. Take care to segregate device-bound and multidevice passkeys.
Sample Vendors
1Password; Apple; Bitwarden; Dashlane; Google; Microsoft; Okta; Ping Identity
Gartner Recommended Reading

Secrets Management Tools

Analysis By: Paul Mezzera, Steve Wessels
Benefit Rating: Moderate
Market Penetration: 20% to 50% of target audience
Maturity: Adolescent
Definition:
Secrets management tools programmatically issue, store, retrieve, rotate and manage secrets like keys, passwords, OAuth client credentials and certificates. They manage these secrets for workloads such as containers, applications, services, scripts, DevOps pipelines and AI agents. These tools provide service through APIs, command line interfaces (CLIs) and software development kits (SDKs). They are delivered as software or as a service and include a secure and encrypted vault.
Why This Is Important
Machine-to-machine communication is ubiquitous, with various workloads like containers, applications, services, functions and AI agents requiring access to sensitive data and infrastructure. Failing to secure this access can lead to — and has led to — security breaches. Workloads use credentials that must be protected to prevent exposure. Secrets management tools are essential in environments where API keys and similar secrets are prevalent, securely issuing and storing them.
Business Impact
Effective secrets management enhances security for transactions, operations and communications between nonhuman actors, such as workloads. It mitigates risks of breaches by safeguarding and rotating secrets used to implement controls and access restrictions. It also manages IAM technical debt, serving as a pragmatic necessity for workloads and DevOps pipelines where the use of API keys and similar secrets remains prevalent.
Drivers
  • Threat landscape: Secrets used by workloads often contain privileged entitlements and grant access to critical systems and sensitive data. Unprotected secrets are a lucrative target for cybercriminals. Securing secrets is now a priority after years of neglect and resulting secrets sprawl.
  • Operational efficiency: Managing secrets using manual processes, such as storing them in configuration files or using spreadsheets or workforce password managers, is both inefficient and insecure. Secrets management tools automate issuing, storing and retrieving secrets, improving operational efficiency by automating and reducing the manual administrative burden.
  • Cloud and API adoption: Continuing migration to cloud and hybrid environments requires secrets to be managed across distributed environments, which entails consistent visibility and control over secrets across cloud infrastructure providers, container orchestration systems, APIs and on-premises systems.
  • AI and AI agents: The rise of AI and AI agents, which require access to sensitive data and systems, further underscores the need for effective secrets management to safeguard credentials used by these applications.
  • Regulatory landscape: Many regulatory frameworks mandate protection of sensitive data. When workloads access sensitive data, credentials must be protected. Regulations also require management of cryptographic keys, which secrets management tools can secure.
  • DevOps: The adoption of DevOps requires developers to securely access secrets during build, deploy and runtime. Secrets management tools eliminate storing secrets in configuration files or code repositories and integrate with CI/CD pipelines to automate build, test, delivery and deployment.
  • Auditability and accountability: Secrets management tools provide audit logs and monitoring to track and monitor the use of secrets. This enhances accountability, supports forensic investigations and enables compliance audits with clear records of secrets-related activities.
Obstacles
  • Lack of visibility and observability: Organizations struggle to track all credentials and secrets used across their infrastructure due to insufficient discovery and continuous monitoring mechanisms.
  • Vendor lock-in and interoperability: Proprietary APIs and SDKs make it difficult to switch vendors, leading to dependency issues.
  • Fragmentation: Organizations often use multiple secrets management tools (commonly provided by cloud service providers [CSPs]), sometimes chosen independently by teams, leading to inconsistent policies and the need for standardization.
  • Overreliance on secrets management: Relying solely on secrets management can cause vendor lock-in and hinder unified machine identity strategies, often resulting in static, hard-to-manage credentials instead of adopting broader identity management solutions.
  • Pricing: Inconsistent pricing models, especially per-client fees for stand-alone tools, make adoption costly and complicate budgeting compared to native CSP solutions.
User Recommendations
  • Eliminate reliance on static secrets, especially in new deployments: Minimize the use of static secrets where possible and prioritize solutions that support dynamic secret generation and automated rotation to enhance workload-to-workload security.
  • Embrace fragmentation: Don’t rely on a single secrets manager, which can lead to vendor lock-in and poor fit for diverse needs. Instead, prioritize features that provide observability and governance and platform-managed workload identities across multiple tools, vaults and clouds. Begin by discovering secrets across platforms; then, expand to cover exposed locations like cloud apps, collaboration tools and chats.
  • Prohibit storing credentials in cleartext: Workloads need to identify themselves to the secrets management tool, often through an authentication mechanism. Do not authenticate a workload to a secrets manager using a credential stored at rest within the workload.
Sample Vendors
Akeyless; Amazon Web Services; ARCON; Delinea; Google; IBM (HashiCorp); Infisical; Microsoft; Palo Alto Networks (CyberArk)
Gartner Recommended Reading

Identity Threat Detection and Response

Analysis By: Mary Ruddy
Benefit Rating: High
Market Penetration: More than 50% of target audience
Maturity: Adolescent
Definition:
Identity threat detection and response (ITDR) is a discipline that leverages advanced tools and best practices to secure the entire identity and access management (IAM) environment — including IAM controls, configurations and related assets — from sophisticated attacks. ITDR solutions focus on proactive detection capabilities, responses to diverse attack vectors and restoration back to normal operations as necessary.
Why This Is Important
Identity is foundational for security (identity-first security). Therefore, IAM must be operated with a security mindset as threat actors are targeting the identity systems themselves. Credential abuse is a top attack vector, according to the 2025 Data Breach Investigations Report by Verizon Business. Organizations must increase the maturity of their process for protecting their IAM infrastructure. ITDR adds additional layers of security to IAM and cybersecurity deployments.
Business Impact
Securing IAM is mission-critical for identity and security operations. If accounts or the IAM infrastructure itself are compromised, attackers can take control of systems and disrupt operations. Protecting IAM is a top priority. “Business-as-usual” processes that seemed adequate before attackers targeted IAM directly are no longer sufficient. This can require multiple ITDR-enabling tools, which may include tools already in the organization’s portfolio.
Drivers
  • Sophisticated attackers actively target IAM. Administrator credential misuse is now a primary vector for attacks against IAM tools. Attackers can use administrative permissions to gain access to a global administrator account or a trusted token-signing certificate to forge tokens for lateral movement.
  • Modern attacks prove conventional identity hygiene is only part of the solution. There is no such thing as perfect prevention. Multifactor authentication and entitlement management processes can be circumvented.
  • ITDR is needed as an additional layer beyond access management (AM), identity governance and administration, privileged access management, security information and event management, and identity posture management.
  • IAM and infrastructure security controls have major detection gaps. IAM is traditionally used as a preventive control, whereas infrastructure security often has limited depth when detecting identity-specific threats. ITDR demands more specific capabilities that operate with lower latency than general-purpose detection and response tools.
  • Ensuring the integrity of IAM infrastructure requires deploying a more granular govern, identify, protect, detect, respond and recover loop. This includes combining foundational practices with ITDR. Govern to ensure that ITDR activities are effective and evolve with your organization. Identify resources and threats in your environment to ensure your ITDR program meets current requirements. Protect root IAM administrator account posture to anchor ITDR. Detect indications of abnormal activity quickly and accurately before material damage is done. The state of the art is sub second. Respond to incidents with playbooks and appropriate levels of automation, both to block the activity and to adjust policies and configuration posture to avoid recurrences. Recover quickly in the rare circumstances when this is necessary.
Obstacles
  • ITDR requires coordination between IAM and security functions, which can be challenging for both.
  • ITDR effectiveness is dependent on the integration architecture, data and signals ingested.
  • IAM hygiene, detection and response best practices are often immature. Organizations tend to operate identity tools in silos, which prevents them from sharing risk signals and prioritizing overall hygiene activities.
  • Multiple capabilities are required to fully protect IAM. These include closely monitoring configuration changes to root IAM administrator accounts, detecting when IAM tools are compromised, enabling rapid investigations and efficient remediation and reverting quickly to a known good state. This can require multiple vendors.
  • There are many different tools with ITDR capabilities that vary widely in their strengths. Therefore, organizations may need to choose multiple tools to achieve full coverage.
User Recommendations
  • Include ITDR in your formal SecOps and IAM programs. Prioritize securing IAM with tools to discover and monitor identity attack techniques, detect when attacks are occurring and remediate quickly.
  • Look for capabilities to provide visibility across your IAM ecosystem, prioritize remediation efforts and demonstrate (over time) a reduction in the attack surface. Use multiple tools to provide all needed ITDR capabilities.
  • Use emerging IAM standards to enable your IAM infrastructure to operate as an identity fabric that shares risk signals. Direct ITDR alerts to a security operations center or identity alert response team, or use a managed service.
  • Mature organizations can use the MITRE ATT&CK framework to correlate ITDR techniques with attack scenarios to ensure that at least well-known attack vectors are addressed.
  • To achieve your desired security risk posture, assess your entire set of IAM controls and implement complementary controls to IDTR as needed.
Sample Vendors
Cisco; CrowdStrike; Delinea (Authomize); Gurucul; Microsoft; Netwrix; Proofpoint; Semperis; SentinelOne; Silverfort
Gartner Recommended Reading

Climbing the Slope

Decentralized Identity

Analysis By: Michael Kelley, Akif Khan, Arthur Mickoleit
Benefit Rating: Transformational
Market Penetration: 5% to 20% of target audience
Maturity: Adolescent
Definition:
Decentralized identity (DCI) democratizes digital identity by decentralizing both the storage and the use of identity data. The primary benefits of DCI are privacy, anonymity, and user autonomy. DCI components include an identity trust fabric, a digital wallet, which is tied to an entity (user), verifiable credentials (VCs), which represent identity attributes used to prove identity claims, and interfaces for issuers and verifiers of those credentials.
Why This Is Important
DCI can establish trust in the identity of a person, which can help solve problems related to identity verification, account takeovers, privacy, and security. It is driven by a decentralized approach to identity data in the form of VCs, which represent proofs for claims about identity attributes, like employment status, citizenship, or authorizations for access. DCI, compared with existing approaches, represents magnitudes of improvement in terms of efficiency, cost, privacy, and assurance.
Business Impact
Users gain control of their identities and data, and service providers (SPs) gain higher trust, speed to value, and lower exposure to risk. SPs collect huge amounts of identity data about users for every interaction to increase assurance to an acceptable level. DCI can provide trust, security, privacy, convenience, and portability of identity data for end users without needing centralized data, thereby reducing the risks of data breaches, account takeovers, and privacy compliance violations.
Drivers
  • Vendor investments in DCI: In addition to observing influential vendors (such as IBM, Microsoft, and Ping Identity) making significant investments in DCI, Gartner has tracked more than 80 startups or established vendors of DCI technologies and DCI components.
  • Government activity: Public sectors are increasingly shaping DCI trends. The EU has ratified eIDAS 2.0, which mandates the provisioning of identity wallets (used in DCI) to citizens by the end of 2026. Other national, regional, and local authorities are exploring and investing in DCI use cases across public and private sectors. Examples include Finland, Buenos Aires in Argentina, and the Basque Country region in Spain.
  • Regulations: Countries continue to formalize requirements for user privacy, establishing regulations for collecting and securing large amounts of user data. DCI complies with privacy regulations through decentralizing user data. In addition, basic use cases for know your customer (KYC) and anti-money-laundering are being developed for DCI use cases.
  • Client and overall market interest in DCI: Interest is increasing due to the momentum of companies beginning to use DCI approaches to enable new digital business opportunities while maintaining client privacy.
  • Standards: Standards are maturing, led by entities such as the World Wide Web Consortium (W3C), Trust Over IP, the OpenWallet Foundation, and OpenID for Verifiable Credentials (OID4VC) to create a consistent approach to DCI.
  • User experience (UX): Asking users to repeatedly go through identity verification (IDV) and affirmation processes for every new online interaction with an SP is a broken model. Significant friction can be removed from UX if users could verify once and then assert their identity to each new SP, as needed, using an identity wallet with full control over their identity data. DCI can make high-trust IDV available to a larger number of SPs without having to invest in discrete IDV tools.
Obstacles
  • Authority of issuers: There is no global standard for ensuring that an organization has the authority to issue a VC (such as only an accredited facility issuing educational credentials).
  • Infrastructure standardization: A uniform standard for adding issuers of VCs, as well as verifiers, for any DCI network does not yet exist.
  • Interoperability: Most development is taking place in pockets, and standards continue to mature slowly.
  • Technical challenge: Concerns exist about performance, scalability, maturity, and wallet standards.
  • Regulations: More work is required for how verifiable claims can be used in regulated use cases, such as driver’s licenses and other government records, or KYC and AML.
  • Security: Identity wallets must enforce strong authentication controls to ensure that only the person whose identity attributes are held within the wallet can make identity assertions. Wallet recovery processes must also be secure.
  • Market competition: Commercial wallets like Apple and Google.
User Recommendations
  • Explore use cases by identifying use cases that are expensive, complex, and time-consuming in the real world, which will benefit from a VC approach.
  • Follow government progress on DCI for citizen ID for “bootstrap” opportunities, as well as the various open-source initiatives (like those from Walt.ID and SpruceID).
  • Leverage platforms that were developed to help clients build and test use cases for DCI.
  • Track new developments in emerging standards, like Trust DID Web (did:tdw) and Key Event Receipt Infrastructure (KERI), which may help address some of the technical challenges for decentralized trust infrastructure and registries.
  • Observe the development of organization credentials taking place with verifiable legal entity identifiers from the Global Legal Entity Identifier Foundation for the potential of establishing authoritative VC issuers.
  • Be prepared for early disruption in the DCI market. Gartner expects some chaos with mergers and acquisitions, as well as vendors exiting the business.
Sample Vendors
1Kosmos; Avast; IBM; IdRamp; Interac; Lissi; Microsoft; Ping Identity; Scytáles
Gartner Recommended Reading

Journey-Time Orchestration

Analysis By: Nathan Harris
Benefit Rating: High
Market Penetration: 5% to 20% of target audience
Maturity: Early mainstream
Definition:
Journey-time orchestration (JTO) solutions improve risk management along digital user journeys and deliver optimized user experience (UX). Most organizations manage multiple identity verification, authentication and account takeover (ATO) prevention tools, and adjacent capabilities such as user registration. A JTO solution manages the integration of these tools, simplifies assessment of risk at each event in the journey, and facilitates tailored and risk-appropriate UX delivery.
Why This Is Important
Securing digital user journeys and offering strong UX is the foundation on which digital transformation is built. Organizations without available developers struggle to manage the broad range of capabilities that this requires, including identity verification, user authentication, user registration, ATO prevention, service resilience and A/B testing. Further complexity arises when integrating with adjacent capabilities, such as access management, fraud mitigation, analytics and UI components.
Business Impact
Using a JTO solution can:
  • Reduce the operational complexity and cost of managing multiple integrations, while integrating multiple required functions into shared journeys.
  • Improve agility for process improvements and empower business users to do more in a low-code/no-code manner by removing the need to customize business logic in code.
  • Improve risk management along the digital user journey, and help organizations increase security while improving UX.
Drivers
  • Managing multiple vendor integrations is a drain on an organization’s resources at a time of skills shortages. Moving that development effort to the JTO tool reduces cost and complexity.
  • Security teams and app developers are both seeking more tailored, risk-appropriate UX, which is easier to achieve with a JTO solution due to the fine-grained user journey control intrinsic to such solutions. The JTO solution optimally acts as the connective thread between the analytics solutions and the UI layer to reduce fraud risk while enabling a great UX.
  • The need to facilitate A/B testing in DevOps is pushing the adoption of JTO. Optimization of a risk management strategy is facilitated by a strong JTO platform in the form of A/B testing. For example, traffic could be split across two different identity verification vendors to assess which delivers better conversion rates.
  • Organizations seek to improve resilience in their vendor connections. In high-throughput customer use cases, vendor uptime is critical. For certain categories of capability, a JTO platform can improve such resilience. For example, if a given vendor is down or showing too high a degree of latency, the JTO vendor can be configured to use a designated alternative vendor, if appropriate.
  • Enabling robust integrations with access management and other identity and access management (IAM) tools introduces additional efficiencies to cybersecurity organizations. Many customer identity and access management (CIAM) vendors have developed or acquired JTO capabilities. This lowers one barrier for adoption by implementing companies.
  • In some instances, JTO can enable access to nonstandard applications, avoiding the need for expensive application upgrades.
Obstacles
  • The cost of acquiring and implementing JTO capabilities, on top of existing IAM capabilities and tools, may not pass a cost vs. benefit analysis where the value of JTO is hard to accurately determine until tested in production.
  • JTO vendors are expected to maintain updated and certified integrations with a large number of downstream IAM and ATO prevention vendors. This can be mitigated by a model in which some JTO solutions allow clients to add their own integrations.
  • Organizations rely too much on the JTO vendor’s roadmap for enabling new features from downstream vendors and on the JTO vendor to make all top-level data available. For example, decision or risk scores, along with metadata (the basis for the signal) from vendors that could be used in rules and policies.
  • The consolidation within the market of JTO capabilities within CIAM platforms is raising the barrier to usage for those organizations who are not using a vendor-provided CIAM platform. The acquisition of many JTO platforms has left a gap in the market for JTO capabilities that can be easily used by an organization without the need for locking in with a given CIAM platform.
User Recommendations
  • Distill the complexity of managing multiple vendor integrations by leveraging a JTO solution to deliver a marketplace of readymade connections to identity verification, authentication and ATO prevention solutions.
  • Deliver tailored and risk-appropriate UX by using a JTO solution to connect the analytics and UI layers to broker calls between systems along the user journey.
  • Assess JTO vendors’ resilience and business continuity plans carefully, given the risk of using a single vendor to manage connectivity to multiple downstream vendors.
Sample Vendors
Callsign; Darwinium; Descope; IBM; Monokee; Okta; Ping Identity; Strivacity; Transmit Security
Gartner Recommended Reading

Age Assurance and Parental Consent Tracking

Analysis By: Bernard Woo
Benefit Rating: High
Market Penetration: More than 50% of target audience
Maturity: Early mainstream
Definition:
Age assurance uses digital, biometric, and validation techniques to verify users’ age group participation. It is used to prevent minors from accessing age-restricted content and digital social media platforms, and ensure compliance with many recent child-protection regulations. “Age assurance” is the umbrella term for age estimation and age verification. Many regulations include parental consent tracking, a requirement often overlooked in identity assurance solutions.
Why This Is Important
Driven by the U.S. Children’s Online Privacy and Protection Act (COPPA), the UK’s Online Safety Act, Australia’s Online Safety Amendment Act, and similar laws, a new wave of age assurance regulations is emerging. Lawmakers are defining what content is in scope, determining valid age checks and enforcement and parental consent use cases, and aiming to limit minors’ access to age-restricted content and services to protect their data and restrict targeted ads.
Business Impact
Online vendors of age-restricted content need fast, reliable age verification that doesn’t disrupt the user experience. They must comply with evolving global laws while minimizing friction for eligible users to prevent abandonment. Solution providers must factor in the complexity of regulatory requirements. Managing parental consent is also required by many regulations, but not always supported by identity vendors.
Drivers
  • Parental concerns: The rise of social media, increased availability of age-restricted products and services, as well as ever expanding amounts of tracking (and the potential of misuse and/or breach of the accumulated data) has parents concerned about their children’s online activities.
  • Compliance needs for businesses: Organizations offering these products and services must comply with new legislation to avoid legal repercussions, including significant fines.
  • Innovation in age assurance and consent: The new wave of regulations is prompting technology vendors to develop innovative solutions that help businesses integrate age assurance services and comply with parental consent requirements.
  • Expansion of laws and growing market: Regulatory considerations started with a focus on processing minors’ personal data, with requirements modeled after the EU’s GDPR. The goals were to limit targeted advertising to minors and safeguard their personal data, with the primary difference being the age at which an individual is considered a minor. New laws are now emerging to move beyond the processing of minors’ personal data and focus on restricting access to content and/or platforms, adding more complexity to the list of the requirements. This new wave of legislation expands the demand for age assurance offerings and attracts new service providers.
  • Client needs: Organizations are seeking assistance in understanding the relevant laws and implementing compliance measures to avoid the penalties outlined in the legislation(s).
  • Age-gated content management: Many online vendors offer a mix of products and services with varying age restrictions. For instance, a movie streaming platform may need different age assurance methods for content rated G, PG, PG-13, R, and NC-17.
Obstacles
  • Lack of traditional credentials: Unlike adults, minors often have no formal IDs, making age and parental consent verification challenging for sellers.
  • User experience versus assurance: If not balanced with usability, age checks and parental consent can add friction, risking customer loss.
  • Cost considerations: Risk-based analysis is needed, as age assurance adds costs and may affect business models.
  • Parental consent technology: This technology continues to evolve, which may hinder effective compliance in the near term.
  • Law versus market readiness: New regulations have been observed to have differing requirements and often outpace solution provider capabilities, leading to legal uncertainty and slow adoption.
  • Free speech concerns: Lawsuits have overturned some age assurance rules, citing infringement on legal adult access and free speech rights.
User Recommendations
  • Determine whether your services are affected by age assurance or parental consent laws on a product-by-product basis.
  • Choose solution providers with user-friendly age assurance methods that minimize user disruption.
  • Ensure that partners understand local child protection and age assurance regulations in their service areas.
  • Solicit existing solution providers first to determine whether their roadmaps include age assurance capabilities and relevant integration experience, before onboarding new vendors.
  • Collect only the minimum data needed to verify a user’s age and avoid retaining a minor’s personal data. Regulations limit the collection and storage of such data.
  • Partner with reputable age assurance vendors and consult organizations like the U.S. NIST, the EU’s eIDAS, or the Age Verification Providers Association for guidance.
Sample Vendors
AU10TIX; BlueCheck; FaceTec; Jumio; Persona; PRIVO; Veridas; Veriff; Yoti
Gartner Recommended Reading

SCIM

Analysis By: Brian Guthrie
Benefit Rating: Moderate
Market Penetration: 20% to 50% of target audience
Maturity: Early mainstream
Definition:
The System for Cross-Domain Identity Management (SCIM) specifications provide a protocol, schema definition and extension model for provisioning and managing identity data in cloud and/or hybrid applications and services. The protocol supports create, read, update and delete (CRUD) operations of identity resources, such as users, groups and custom resources.
Why This Is Important
SCIM has become a popular starting point for user provisioning to cloud-based targets, given its broad adoption by access management (AM) vendors and ease of deployment due to standardization. SCIM helps establish and standardize the communications and identity data exchange between identity and access management (IAM) systems and applications. Formalizing and integrating SCIM standards enables postimplementation efficiency and optimization.
Business Impact
SCIM:
  • Reduces the costs of building connectors for things that can communicate with SCIM.
  • Helps manage users, machine identities and other resources in target applications that are deployed on-premises and in the cloud.
  • Is designed to be a standards-based provisioning protocol that increases an organization’s application portfolio agility and eases provisioning without needing custom connectors.
  • Instantly and continuously synchronizes and consolidates identity data, enabling continuous IAM requirements spanning decentralized environments using the new SCIM events extensions.
Drivers
SCIM:
  • Reduces technology friction by enabling user-event-based correlation of user attributes, entitlements and directory synchronization.
  • Offers implementation libraries (such as i2scim) that are mature enough to dynamically discover and represent different schemas and identity resources out of the box.
  • Reduces IAM vendor lock-in.
  • Has emerged as a protocol for developing user management interfaces in SaaS and internal applications.
  • Supports additional use cases due to its extensible architecture; for example, in the new device schema extension.
  • Is a replacement for many proprietary provisioning protocols.
  • Has emerged as the standard automating the exchange of user identity information between identity domains or IT systems.
  • Can translate identity data between proprietary approaches and SCIM-supported IAM platforms.
Obstacles
  • Organizations may encounter limitations when attempting to add custom attribute extensions — even after extended schemas are finalized.
  • Insufficient support for SCIM among both homegrown and vendor-supplied applications presents a significant obstacle, as it can hinder seamless identity provisioning and integration.
  • SCIM is not widely accepted by some application developers that favor proprietary approaches and create their own APIs for user provisioning. This lack of standardization complicates integration efforts and undermines interoperability across IAM systems.
  • Implementation demands a high level of technical expertise and specialized knowledge. This can lead to extended project timelines and increased implementation challenges.
  • Core SCIM schemas do not natively support all attributes and use cases, requiring a discoverable extension mechanism for any nonstandard entities or attributes. This can complicate implementation and limit immediate compatibility with IAM systems.
User Recommendations
  • Improve identity hygiene by prioritizing and selecting applications that support SCIM when evaluating new IAM solutions for your organization.
  • Adopt SCIM as the standard protocol when developing inbound identity provisioning, to enhance interoperability, simplify integration and ensure consistent user management across systems.
  • Leverage SCIM when implementing life cycle management in third-party systems to ensure standardized, efficient and scalable identity provisioning processes.
  • Adopt SCIM to reduce the risk of IAM vendor lock-in and maintain flexibility in your IAM strategy.
  • Implement SCIM gateways to reduce technical debt in environments lacking standardized protocol support.
  • SCIM-to-SCIM gateways can translate incoming SCIM requests and provide CRUD functionality to target systems using proprietary protocols, enabling smoother integration and management.
  • Adopt SCIM to replace outdated custom connectors and avoid the need to develop new ones, reducing maintenance overhead.
Sample Vendors
Aquera; Curity; Radiant Logic; SITS | Traxion; UNIFY Solutions
Gartner Recommended Reading

Verifiable Credentials

Analysis By: Homan Farahmand
Benefit Rating: Transformational
Market Penetration: 5% to 20% of target audience
Maturity: Early mainstream
Definition:
A verifiable credential (VC) is a self-contained and trusted piece of information about an entity. VCs refer to the entity’s attributes that establish its existence or uniqueness. A VC is issued and cryptographically signed by an issuer, held by a user and presented to relying entities, or verifiers. VCs can be validated independently of the trusted issuer and used as proof of identity, entitlement, qualification achievement or ownership.
Why This Is Important
VCs, as standardized by W3C, significantly improve data sharing, privacy (via selective disclosure), data security and data quality in decentralized identity ecosystems. This approach enables independent issuance, custody and verification of verifiable attributes. VCs also reduce the need for intermediaries to attest to the validity of data, streamlining the data‑exchange process.
Business Impact
VCs enable the digitalization and automation of standardized, secure and compliant data exchange in multiparty business processes at lower cost and higher velocity. These validations, common across most industries, usually require verification of entities’ credentials to admit users, assess eligibility, perform tasks and generate outputs for handoff to other parties. VCs can reduce onerous verification steps and lower the risk of data proliferation and exposure.
Drivers
  • Decentralized identity (DCI) trend: Growing adoption of DCI is a key driver for implementing VCs to streamline business processes. DCI enables VCs by providing pairwise and unique identifiers for each relationship between an identity and other entities, independent of any ecosystem participant. Early deployments may rely on bring‑your‑own‑identity (BYOI) models or pseudo‑DCI architectures that maintain some centralized components.
  • Overall interest and adoption urgency: VCs can unlock new digital business opportunities while preserving entities’ privacy. They improve process efficiency in data-exchange use cases by streamlining eligibility checks, credential validation, and document or identity verification.
  • Government identification and trust initiatives: VCs are becoming central to government identification and trust-architecture strategies. Europe’s Electronic Identification, Authentication and Trust Services (eIDAS 2) and EU Digital Identity (EUDI) wallet regulations, along with NIST SP 800‑63‑4, support cross‑sector identification and attribute sharing through citizen‑held identity wallets. Governments across multiple regions are evaluating or piloting similar wallet models and VC‑based approaches.
  • Continuous investment: Ongoing investment from influential vendors continues to advance the market. Organizations across industries, including government agencies, are allocating significant resources to this space. Many vendors, including identity-verification providers, access-management vendors and blockchain platform providers, have adopted VCs.
  • Consistency through standards and open-source libraries: Standards and open‑source libraries continue to develop. Current efforts are led by W3C‑recommended standards for decentralized identifiers and verifiable credentials, along with the OpenID family of verifiable‑credential specifications.
Obstacles
  • Establishing viable ecosystems: Ecosystems with authoritative issuers and verifiers are essential for VC adoption. However, it takes time to educate organizations and users, develop use cases and expand the user base to build these ecosystems.
  • Changing business processes and refactoring applications: Organizations must adapt their business processes to exchange data using VCs. They also need to refactor identity and access management applications to issue and consume VCs.
  • Lacking interoperability and standardization: As VC standardization advances, parallel efforts are required to enable interoperability across VCs issued or consumed in different ecosystems and with existing identity protocols, both of which are major industrywide undertakings.
  • Decentralized identity maturity: Although organizations can implement VCs in the interim using wallet‑based BYOI models or pseudo‑DCI infrastructure, the full benefits will be realized only when DCI reaches mainstream maturity.
User Recommendations
  • Evaluate candidate ecosystem participants and business processes. Identify issuers, users and verifiers, and understand the data flows among them. This analysis will reveal opportunities to implement VCs to automate data exchange.
  • Make a business case for implementing VCs in the ecosystem. Educate participants on benefits such as reducing friction, enhancing efficiency and improving privacy, compliance and security.
  • Implement proof‑of‑concept VCs that can scale over time. Start with a minimum viable solution using existing vendor capabilities. Ensure a future‑proof architecture that accounts for market turbulence as key players evolve. This is critical to expanding and scaling the solution. Examples include proof of employment, remote onboarding, passwordless authentication, entitlement verification and certification verification.
Sample Vendors
1Kosmos; filancore; Finema; IBM; Microsoft; Ping Identity; SpruceID; Thales; Var Group Iberia; walt.id
Gartner Recommended Reading

Appendixes


See the previous Hype Cycle: Hype Cycle for Digital Identity, 2025

Hype Cycle Phases, Benefit Ratings and Maturity Levels

Hype Cycle Phases

Phase
Definition
Innovation Trigger
A breakthrough, public demonstration, product launch or other event generates significant media and industry interest.
Peak of Inflated Expectations
During this phase of overenthusiasm and unrealistic projections, a flurry of well-publicized activity by technology leaders results in some successes, but more failures, as the innovation is pushed to its limits. The only enterprises making money are conference organizers and content publishers.
Trough of Disillusionment
Because the innovation does not live up to its overinflated expectations, it rapidly becomes unfashionable. Media interest wanes, except for a few cautionary tales.
Slope of Enlightenment
Focused experimentation and solid hard work by an increasingly diverse range of organizations lead to a true understanding of the innovation’s applicability, risks and benefits. Commercial off-the-shelf methodologies and tools ease the development process.
Plateau of Productivity
The real-world benefits of the innovation are demonstrated and accepted. Tools and methodologies are increasingly stable as they enter their second and third generations. Growing numbers of organizations feel comfortable with the reduced level of risk; the rapid growth phase of adoption begins. Approximately 20% of the technology’s target audience has adopted or is adopting the technology as it enters this phase.
Years to Mainstream Adoption
The time required for the innovation to reach the Plateau of Productivity.
Source: Gartner

Benefit Ratings

Benefit Rating
Definition
Transformational
Enables new ways of doing business across industries that will result in major shifts in industry dynamics
High
Enables new ways of performing horizontal or vertical processes that will result in significantly increased revenue or cost savings for an enterprise
Moderate
Provides incremental improvements to established processes that will result in increased revenue or cost savings for an enterprise
Low
Slightly improves processes (for example, improved user experience) that will be difficult to translate into increased revenue or cost savings
Source: Gartner

Maturity Levels

Maturity Levels
Status
Products/Vendors
Embryonic
In labs
None
Emerging
Commercialization by vendors
Pilots and deployments by industry leaders
First generation
High price
Much customization
Adolescent
Maturing technology capabilities and process understanding
Uptake beyond early adopters
Second generation
Less customization
Early mainstream
Proven technology
Vendors, technology and adoption rapidly evolving
Third generation
More out-of-box methodologies
Mature mainstream
Robust technology
Not much evolution in vendors or technology
Several dominant vendors
Legacy
Not appropriate for new developments
Cost of migration constrains replacement
Maintenance revenue focus
Obsolete
Rarely used
Used/resale market only
Source: Gartner

Acronym Key and Glossary Terms


CIAM
Customer IAM
IDaC
Identity as Code
IDV
Identity Verification
OID4VC
OpenID for verifiable credentials
SCIM
System for Cross-domain Identity Management
SPIFFEE
Secure Production Identity Framework For Everyone
SSF
Shared Signals Framework
VC
Verifiable Credentials

Evidence


1 2025 Gartner Machine Identity Management in a Hybrid, Automated AI World Survey. The survey was conducted to understand the current landscape of machine identity management and at what stage organizations are in the adoption of machine identity and access management (IAM) strategy and formal policies to manage various machine identities and credentials. The research also aims to understand the primary ownership of machine IAM activities across key stakeholders within the organization. The research was conducted online from September through October 2025 among 299 respondents from organizations across North America (43%), EMEA (37%), and Asia/Pacific (20%), covering industries and revenue bands ($100 million and above). Surveyed respondents were senior cybersecurity or IT leaders with direct involvement in machine identity management within their organization. Disclaimer: The results of this survey do not represent global findings or the market as a whole, but reflect the sentiments of the respondents and companies surveyed.