Raddad Ayoub

Idea

Identity stops being a human-control problem

Most identity and access frameworks were built on a quiet assumption: the actor behind a login is a person, and a person can be trained, warned, or fired. Once a meaningful share of actions inside an enterprise are taken by autonomous agents instead, that assumption stops holding.

An agent doesn't get "trained" in the disciplinary sense, and it can act at a speed and volume no human reviewer can shadow in real time. So what replaces the old controls... behavioural baselining? Revocable, scoped credentials issued per task rather than per person? Something else entirely?

Worth sitting with rather than answering too quickly.

Personal reflection. Views are my own and not those of my employer.

← All reflections