惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

MyScale Blog
MyScale Blog
博客园 - 三生石上(FineUI控件)
人人都是产品经理
人人都是产品经理
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
L
LINUX DO - 热门话题
N
Netflix TechBlog - Medium
S
Schneier on Security
T
The Exploit Database - CXSecurity.com
Vercel News
Vercel News
P
Palo Alto Networks Blog
C
CERT Recently Published Vulnerability Notes
Simon Willison's Weblog
Simon Willison's Weblog
I
Intezer
L
Lohrmann on Cybersecurity
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
D
Darknet – Hacking Tools, Hacker News & Cyber Security
P
Proofpoint News Feed
The Register - Security
The Register - Security
T
Threat Research - Cisco Blogs
P
Privacy & Cybersecurity Law Blog
A
Arctic Wolf
F
Fortinet All Blogs
V
Vulnerabilities – Threatpost
The Hacker News
The Hacker News
V
Visual Studio Blog
Know Your Adversary
Know Your Adversary
博客园 - Franky
C
Check Point Blog
P
Privacy International News Feed
NISL@THU
NISL@THU
T
Tenable Blog
云风的 BLOG
云风的 BLOG
T
Tailwind CSS Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
B
Blog RSS Feed
A
About on SuperTechFans
L
LangChain Blog
Cyberwarzone
Cyberwarzone
Security Latest
Security Latest
C
CXSECURITY Database RSS Feed - CXSecurity.com
G
Google Developers Blog
WordPress大学
WordPress大学
T
Threatpost
Y
Y Combinator Blog
Last Week in AI
Last Week in AI
The GitHub Blog
The GitHub Blog
爱范儿
爱范儿
T
Tor Project blog
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Spread Privacy
Spread Privacy

SECURITY.COM

4 Application Control Updates That Help Teams Move Faster 3 Ways to Defend Against LOTL Attacks Now Humble Brag: Symantec® Data Center Security Achieves Common Criteria Certification Tips to Harden Your Air Gapped Environments The Visibility Challenge Nobody Asked For Your DLP Incident Backlog Owes You Closure 5 Reasons Symantec® CBX Delivers Total Endpoint Visibility 8 XDR Questions From the Show Floor Locking Down the Server Data Security Is Having A Moment 5 Ways XDR Helps SOCs Act Faster 5 Ways To Keep AI in Check DLP Made Easier on the Teams Running It Web Traffic Visibility is the New Non-Negotiable The Agentic AI Tsunami is Here: Is Your Legacy IAM Sinking or Swimming? For Financial Services, a Wake-Up Call for Reclaiming IAM Control How Cloud-Managed DLP Lowers the Barrier to Entry As Identity Takes Control, Telecom Needs Repatriated IAM Capable of Keeping Up Post-Quantum Security Starts at the Edge The Public Sector Case for Repatriating IAM in the Age of AI The Data Sovereignty Paradox The Unseen Wall: How Billions of Attacks Were Blocked in 2025 The “Zero-Blindness” Roadmap: Achieving Maturity in the DLP Endpoint Workspace IAM Has a Fix for the Modern Identity Crisis
Identity is the Control Plane, and AI Just Changed the Game
About the Author · 2026-02-13 · via SECURITY.COM
  • In the age of AI, identity is king—it drives the system (and with it, security itself).
  • As metrics expand at AI scale, it’s time to rethink SaaS IAM risk and utility.
  • With a new understanding of identity solutions, repatriating IAM is worth the risk.

I need to make a confession. A few years ago, I was firmly in the “buy, do not build” camp for Identity and Access Management (IAM). I was the architect for a private SaaS vendor solution that met all requirements and even addressed data sovereignty concerns. SaaS IAM delivered the results– with fewer servers to patch, fewer midnight alerts, and easier access for customer understanding and success.

Since then, my perspective has shifted. Of course, SaaS vendors didn’t suddenly get worse. But as AI transforms the identity ecosystem, we need an approach better suited to its continued evolution. 

In the current security landscape, identity is not a passive login screen. It’s the control hub for every action in the enterprise: data access, raising privileges, API permissions, machine-to-machine trust, session risk, and, increasingly, the governance of semi-autonomous AI. In 2026, identity drives the system.

It’s time to repatriate an IAM built for the moment

With identity now in the driver’s seat, it’s time to repatriate IAM with an awareness of the risks and a willingness to address them. I know “repatriation” can sound like giving up, but IAM repatriation is not a step backward. This is not a call to "kill the cloud," turn off SaaS, or pull everything back into the data center. Instead, it’s a call for clarity about the risks that happen when your identity control plane is both mission-critical and externally rate-limited. Ultimately, repatriation is a move toward resilience, agility, cost predictability, and security at AI scale.

Repatriation is not an all-or-nothing plan

While it might sound like a step backward, IAM repatriation has potential to:

  • Bring authorization decisioning (policy evaluation) closer to workloads
  • Own token services, signing keys, and high-assurance session controls
  • Reclaim identity telemetry (auth logs and signals) as first-class security data
  • Manage machine identities and service accounts with the same rigor as human access

Within a repatriation approach, there is still a place for SaaS, leveraging it in places like user lifecycle workflows, while moving parts that must be deterministic, scalable, and always available to your repatriated Identity system. This flexible approach is ideal because fraud networks work best when the reach of SaaS services can be combined to better evaluate signals. 

Risk-free repatriation requires understanding AI

To fully grasp the value of repatriation, you must understand the game-changing impact of AI. AI adds a whole new class of actors to the environment:

  • Agentic assistants that take actions on behalf of users with AI-driven automation running 24/7
  • Bots that call the APIs at machine speed, processing each request as fast as the machine can handle
  • Copilots embedded across tools, each needing scoped permissions
  • Retrieval and orchestration layers that access data domains every time a prompt is used

AI multiplies identities and explodes authorization events

Traditional IAM models were built on a series of assumptions:

  • A predictable number of employees and contractors
  • A bounded number of apps
  • Login peaks around business hours
  • Reasonable ratios of users to auth requests
  • Static policies

AI upends those assumptions with:

  • More non-human than human identities
  • High-frequency token exchanges
  • Burst traffic driven by automation
  • Authorization checks inside every agent workflow, not just at login
  • Dynamic policies

Even if the AI agent is just another service account, the rate and fan-out of access checks multiplies. A single user prompt can start dozens or even hundreds of backend calls. When the AI agent does that across teams, the IAM system ceases to be a directory and becomes a high‑throughput transaction platform. 

How to respond when AI tips the scale

This reality complicates scalability. Many SaaS IAM discussions focus on availability, noting vendor outages that are real and painful. But those outages can’t compare to the scalability needs created by this new age of identity.

When IAM is SaaS hosted, you inherit the constraints. Those constraints are often fine, until…

1) Rate limits become security limits

At AI scale, IAM must be able to keep high-volume operations running without compromising security. But, in practice, rate limits push people into choices like:

  • Caching drives to last longer than they should
  • Skipping real-time risk checks during bursts
  • Making exceptions for trusted workloads, often allowing them to drift into over-privilege
  • Delaying revocation propagation when it matters most

When identity bottlenecks, engineering teams route around it, acting as humans do under pressure

2) AI renders cost models nonlinear

Many SaaS IAM vendors charge enterprises by:

  • Monthly active users
  • Premium feature tiers
  • Connection counts
  • Event volume or log ingestion
  • API calls/token operations (directly or indirectly)

AI workloads upset the events side of the equation—issuance, self-checks, policy checks, step‑up challenges, device posture, anomaly detection, and logging. Even if the initial unit cost seems small, the total can become a bloated line item prompting everyone to look for ways to bypass costs. Unfortunately, a bypass like turning off controls weakens the whole system.

When authorization is essential, latency becomes an existential crisis

In order to resolve the latency challenge, we must consider:

  • Fine-grained authorization (ABAC/ReBAC)
  • Just-in-time privilege
  • Continuous session evaluation
  • Real-time data access decisions

Authorization affects application performance, with service-to-service calls routed through a SaaS decision point adding delay. If developers avoid these calls because of a slow SaaS decision point, the system loses enforcement. Neither lost performance nor lost enforcement is acceptable.

Multi-tenant realities mean noisy neighbors and shared fate

Even the best SaaS vendors operate multi-tenant platforms with shared risk. In these platforms, global incidents affect customers regularly, while platform-wide policy changes, deprecations, or behavior shifts affect everyone unequally. As for regional dependencies and cross-zone propagation delays, those are outside of your control.

The model has to work this way, but when IAM is the control plane, “shared fate” is a much bigger deal than “fate” was when the SaaS tool was only for expense reporting.

What do you want first–good news or bad?

This entire blog may feel like “the bad news.” But even in an uncertain identity landscape characterized by rapid evolution and new risks, there’s reason for hope. That hope requires revisiting what we think we know. Hang tight for “the good news,” with actionable suggestions coming in Part 2 of this multi-part series. In that blog, we’ll explore vendor risk and give you some informed suggestions on the very best sequence for repatriating IAM while reducing risk. 

You might also enjoy