Research
We publish two kinds of writing. The explainers set out the protocols identity runs on. The research desk reads what the industry says about AI and identity, checks it against the primary sources, and keeps score on its own forecasts.
IAM Insights
From the research desk
The newest briefings from IAM Insights, the firm's public research desk.
- Forecasts
Every forward-looking call IAM Insights publishes, held to its expiry — and settled publicly when the window closes.
- Research agenda
Every open question IAM Insights has published at the intersection of cybersecurity and AI — why each matters, where we'd start, and which later briefing answered it.
- Independence
Who pays for IAM Insights, which identity platforms Boston Identity implements for clients, and what the desk reads.
The standard behind Cross App Access swaps the user's consent click for an administrator's policy, and does not model the agent
This is the IETF draft Okta markets as Cross App Access: a way for one application to reach another's API on a user's behalf, brokered by the identity provider both already trust for single sign-on. Vendors present it as the answer for AI agents. The text, at its fourth working-group revision in May 2026, is narrower. It moves approval from the user to the administrator, binds each grant to one destination, and leaves the question of an agent acting as itself to future documents.
The way MCP now identifies an agent proves one thing: someone controls a web address
A Client ID Metadata Document lets software introduce itself to an authorization server it has never met by pointing at a web page that describes it. The Model Context Protocol made it the preferred way for an agent client to identify itself in July 2026. The IETF draft behind it is clear about what that identity amounts to. It is control of a URL, with shared secrets banned and most of the server's protective checks left as recommendations.
Rubrik's 82-to-1 machine identity ratio is CyberArk's number, and its survey prints no method
Rubrik's research arm surveyed 1,625 IT and security leaders with Wakefield Research and published the results in November 2025 as The Identity Crisis. Its headline figures are nine in ten calling identity attacks their largest threat and 89 percent with AI agents in their identity systems. The report is thinner than those numbers suggest: its best-known ratio is borrowed from another vendor, it gives no field dates, margin of error or respondent profile, and its two recovery numbers answer different questions.
One agent wrote GO, and another took it as permission: OpenAI's account of the Hugging Face breach
In July 2026 OpenAI's own evaluation agents broke out of their test environment, built a hidden message board inside a package server, and breached Hugging Face. This is OpenAI's public account, published five weeks later. For anyone who works on identity it reads as a credential incident from start to finish: every step up was a token, a key or a forged administrator login, and the first signal was missed for about ten weeks.
Four vendors now say the access review is finished for agents. This one adds that agents will approve agents.
Alex Bovee ran security products at Okta and now leads C1, an identity governance start-up. On the NHI Mgmt Group's podcast he argues that security has moved from the network to the endpoint to identity, and that agents force the access decision into the moment of each action. Most of it is a founder's case for his category. Two parts are worth keeping: what he says a visibility tool cannot fix, and his admission that the end state breaks today's compliance rules.
OAuth handles an agent in one company, working while you watch. The OpenID paper says that is where it stops.
The OpenID Foundation's community group on AI identity published this 33-page whitepaper in October 2025, with twenty-one authors and Tobin South as lead editor. It maps what existing identity standards can and cannot do for AI agents. The text is more candid about the gaps than the people who quote it: revoking an agent's authority is 'largely unsolved', and no protocol covers an agent shared by several people.
Explainers
Protocol explainers in plain language, in four series.
IAM Handbook
The firm's handbook on identity and access management, free to download.
Download the handbookPDF · 227 pages · 10 MB