Category Archives: Market Trends

How Governance Around Identity and Access Is Changing in 2026

For decades, enterprise identity management was primarily viewed as a perimeter issue. The main objective was to verify that an employee or customer was who they claimed to be at the initial point of entry, issue a password or single sign-on (SSO) token, and grant access accordingly. Enterprise security was grounded in a foundational question: “Who are you, and what systems are you allowed to access?”

By 2026, this approach has become obsolete, and the traditional questions are no longer adequate for effective identity governance.

The proliferation of distributed multi-cloud architectures, non-human identities, and autonomous AI agents capable of executing thousands of actions per minute has created an unprecedented paradigm shift for security leaders. As a result, traditional Identity Governance and Administration (IGA) is rapidly evolving into Identity, Authorization, and Runtime Governance.

The following analysis examines how governance surrounding identity and access is undergoing fundamental transformation.

1. From Access Governance to Action Governance

Traditional IGA models governed static access paths (e.g., Jane, a Finance Manager, has access to Salesforce, Workday).

In 2026, security teams are required to govern actions rather than merely access. When an AI agent leverages delegated authority to interact with an API or update numerous accounts, the critical question extends beyond system access to whether the agent is authorized to perform specific actions on behalf of a human. As highlighted in NIST’s 2026 guidance, reliance on extensive human-in-the-loop controls or the sharing of broad credentials introduces significant risks within agentic systems.

2. Managing the Explosion of AI Agents and Non-Human Identities

Whereas previous governance models focused primarily on employees, contractors, and partners, contemporary enterprises now manage an expanding ecosystem that includes service accounts, APIs, cloud workloads, and AI agents.

Modern enterprises are no longer comprised solely of human workers. In many cloud environments, autonomous AI agents, service accounts, APIs, and automated pipelines now outnumber human users.

Traditional Identity and Access Management (IAM) tools were designed to manage human login lifecycles, resulting in significant governance gaps for non-human entities. By 2026, organizations must address the reality that AI agents or automated scripts with broad permissions can execute high-impact actions at machine speed. As a result, governance frameworks have expanded to treat non-human actors as first-class entities, requiring explicit lifecycle oversight, verifiable lineage, and stringent runtime boundaries.

In contrast to traditional service accounts that execute predefined scripts, AI agents interpret objectives, select tools, make decisions, and delegate tasks to sub-agents. In alignment with NIST’s 2026 AI Agent Standards Initiative, governance of non-human identities is becoming a core enterprise requirement, necessitating:

  • A verifiable, unique identity and defined purpose
  • An accountable human owner
  • Clear traceability through a delegation chain
  • Defined lifecycle management (from creation to retirement)

3. Moving Beyond the Front Door: The Rise of Rigorous Proofing (IAL2)

The proliferation of deepfakes, synthetic data, and automated credential stuffing has rendered basic logins increasingly untrustworthy. Consequently, organizations are raising their upfront verification standards. Frameworks such as NIST’s Identity Assurance Level 2 (IAL2) are transitioning from federal mandates to mainstream enterprise requirements.

Contemporary governance frameworks now distinguish between identity proofing (“Who are you in the real world?”) and authentication (“Do you control this digital credential?”). Organizations are implementing multi-pathway proofing processes that integrate government-issued photo validation, biometric liveness checks, and authoritative database cross-checks. These measures ensure that every high-risk digital interaction or privileged onboarding is anchored in verifiable trust prior to the issuance of any token.

​

4. Transitioning to Dynamic, Contextual Authorization

Static Role-Based Access Control (RBAC) and once-per-session checks are no longer sufficient to protect dynamic cloud architectures. Modern frameworks are adopting models that emphasize Just-in-Time, Just Enough Access, and action-specific authorization to address the demands of real-time environments.

Authorization engines now incorporate real-time context and risk, evaluating variables such as user behavior, device state, agent intent, environmental factors, and continuous risk scores prior to granting transaction-level privileges.

Current market trends emphasize continuous authorization and Zero Standing Privilege (ZSP). Identity governance systems now evaluate context in real time by analyzing device health, network anomalies, behavioral baselines, and runtime risk scores. If an entity’s risk profile changes during a session, governance platforms can automatically increase verification requirements, restrict permissions, or terminate access immediately.

5. Moving from Periodic Reviews to Continuous Governance

Quarterly access reviews and annual certifications are insufficient for environments operating at machine speed. Governance is transitioning from periodic audits to continuous, real-time, and event-driven monitoring. If an agent’s behavior becomes anomalous, policies can trigger immediate automated interventions to reduce privileges.

6. Convergence Into an “Identity Control Plane” and The Shift Toward the “AI Identity Fabric”

Historically, technologies such as IGA, Privileged Access Management (PAM), Security Information and Event Management (SIEM), and User and Entity Behavior Analytics (UEBA) operated in isolated silos. The emergence of AI is driving the convergence of these technologies into a unified Identity Control Plane, which serves as a centralized framework for organizations to discover, assess, authorize, and govern all digital actions across multicloud and SaaS environments.

To integrate these components, enterprise architecture is evolving toward an AI Identity Fabric.

Future IAM platforms will extend beyond managing human users to governing the complex relationships among humans, AI agents, tools, data, and autonomous actions. Each automated workflow must maintain a clear and traceable chain of delegation, linking every autonomous action to an accountable human sponsor.

What This Means for Identity Leaders

For Chief Information Security Officers (CISOs) and Chief Information Officers (CIOs), the operational mindset is experiencing a fundamental transformation:

  • Old Priority: “Who has access?” →  New Priority: “Who or what can act?”
  • Old Priority: Access certifications → New Priority: Continuous authorization
  • Old Priority: Human identities → New Priority: Human, machine, and AI identities
  • Old Priority: Audit access → New Priority: Audit identity, authority, and action

Conclusion

Enterprises in 2026 differ fundamentally from those for which traditional IGA was designed. The transformation of identity governance extends well beyond a product update; it signifies a shift from managing access to managing authority. Identity is increasingly serving as the mechanism by which enterprises govern digital actions.

By establishing identity as the core control plane for autonomous enterprises, organizations can securely leverage AI while ensuring that every human, machine, and autonomous agent operates with verifiable intent and accountability. Organizations that persist in treating identity as an isolated login mechanism will face challenges from automated threats and stringent compliance audits. Success will favor those who adopt identity as an observable, programmable, and deeply integrated infrastructure fabric.

​

Identity Is No Longer a Login Problem. It’s an Infrastructure Problem

For decades, enterprise identity was all about one simple question: “Who are you, and can we let you log in?” Fast forward to today, and that model is rapidly becoming obsolete. Modern enterprises are no longer just made up of employees logging into applications; they are complex ecosystems of humans, applications, APIs, service accounts, workloads, and AI agents.

Identity has fundamentally outgrown the front door. It is no longer just an authentication service it is evolving into an enterprise control plane and a critical infrastructure layer.

The Catalyst: Agentic AI and Non-Human Identities (NHIs)

The most significant driver of this transformation is the rise of agentic AI. Unlike traditional software that follows predetermined instructions, AI agents can receive a goal, reason about it, select tools, call APIs, and execute actions on our behalf. According to Okta’s 2026 Businesses at Work research, 91% of organizations are already using AI agents, yet only 10% have a well-developed strategy for managing them.

This creates a massive governance challenge. When an AI agent executes a transaction across a SaaS application, a database, and a downstream payment system, who is ultimately responsible? Traditional Identity and Access Management (IAM) struggles here because it often compresses multiple actors into a single credential. The future of identity must preserve the entire chain of authority—from the human sponsor to the agent, the delegated tools, and the final action.

From Directory to Identity Graph

To manage this complexity, identity architecture is shifting from a static directory (User → Groups → Applications) to a dynamic Identity Graph. This graph maps the complex relationships connecting human identities, machine identities, AI agents, delegated permissions, APIs, and data.

Non-Human Identities (NHIs) such as API keys, service accounts, and automated pipelines—are scaling rapidly, often dwarfing human users. An enterprise identity fabric must treat these NHIs as first-class citizens with strict lifecycles, clear ownership, and defined time boundaries. Every production agent should have a verifiable identity, an accountable human owner, a clear purpose, and a controlled retirement process.

Authorization Over Authentication

While authentication proves who the actor is, authorization determines what they are allowed to do. In an agentic enterprise, authorization must be dynamic, contextual, and time-bound.

Privileged Access Management (PAM) is also moving into the autonomous era. AI agents should operate on Zero Standing Privilege (ZSP)—requesting Just-In-Time (JIT) and least-privilege access only when needed, and immediately losing that privilege when the task is complete. Identity infrastructure must evolve to evaluate real-time trust, analyzing behavioral baselines and context before granting access.

The New Identity Security Fabric

As protocols like Model Context Protocol (MCP) and Agent-to-Agent (A2A) communication become standard, delegation must be explicit and verifiable across organizational boundaries. Identity determines who can access data, and data context determines what an identity should be allowed to access.

To prepare for this shift, organizations must:

  1. Build a comprehensive identity inventory covering every human, machine, workload, and AI agent.
  2. Give every AI agent a first-class identity with explicit human accountability and sponsorship.
  3. Move toward dynamic, risk-based authorization rather than relying solely on static Role-Based Access Control (RBAC).
  4. Create an agent activity ledger to track the entire trajectory of an automated action for compliance, forensics, and accountability.

Conclusion: Trustworthy Autonomy

Identity is no longer just answering “Can you log in?” It is now answering, “Can this actor perform this action, on this resource, under this context, with this authority and can we prove why?”

The winning enterprise architectures will treat identity as the operating system for digital trust a unified security fabric that makes the autonomous enterprise possible, observable, and deeply secure.

Important Takeaways for the Modern architecture:

  1. Identity is becoming a control plane, not simply an authentication layer.
  2. AI agents are creating a new category of first-class non-human identities.
  3. Authorization is becoming more important than authentication.
  4. PAM must evolve toward Zero Standing Privilege for autonomous actors.
  5. Identity governance must move from periodic review to continuous, automated enforcement.
  6. Identity graphs will increasingly replace isolated directories as the foundation for understanding digital relationships and authority.
  7. Agent identity must preserve the chain of accountability from human sponsor → agent → delegation → tool → resource → action.
  8. Identity, data, behavioral analytics, PAM and AI security are converging.
  9. The winning enterprise identity architecture will be a unified Identity Security Fabric spanning humans, machines, workloads and AI agents.
  10. The ultimate goal is not merely secure access. It is trustworthy autonomy.

Transitioning to Identity as a Signal: IAL2 Explained

Most organizations treat identity proofing as a one-time gate: collect a document, run a selfie match, mint an account, move on. But NIST’s Identity Assurance Level 2 (IAL2) serves as the sweet spot between low-friction onboarding and high-assurance risk mitigation.

But the benefits of Identity verification are becoming important for the following reasons.

Key Drivers

  • Combating Advanced Fraud: IAL2 directly counters synthetic identity creation, stolen credentials, and account takeover (ATO) attacks during onboarding.
  • Regulatory Compliance: Essential for adhering to Know Your Customer (KYC), Anti-Money Laundering (AML), and NIST/Federal compliance frameworks in finance, healthcare, and government digital services.
  • Zero Trust Security: Organizations must establish verifiable digital trust before granting access to high-privilege applications or sensitive data.

Implementing IAL2 verification requires balancing security with user experience.

The New Identity Security Paradigm

The shift from traditional IAM to Intelligent Identity Security means moving away from “Identity as a Record” toward “Identity as a Signal.”

IAL2 provides the necessary foundation for a true Zero Trust architecture by ensuring that the person behind the device is verified, real, and currently living.

By integrating multi-pathway verification, recording provenance, and closing the recovery loop, organizations can transition from a one-time gate to a continuously governed trust lifecycle.

Is your organization’s identity foundation built on a one-time gate, or a continuously governed trust lifecycle?

5 Surprising Realities of the New Identity Assurance Standard (IAL2)

The 2017 identity guidelines that governed the last decade of digital growth are officially obsolete. With the July 2025 release of NIST SP 800-63A-4, the “good enough” approach to identity relying on stolen passwords, compromised mobile numbers, and easily spoofed “out-of-wallet” questions has moved from a security risk to a massive organizational liability.

As synthetic identities and AI-generated deepfakes flood onboarding queues, NIST Revision 4 introduces a fundamental shift in establishing trust.

At the heart of this evolution is Identity Assurance Level 2 (IAL2). 

No longer just a checklist for a selfie and a driver’s license, IAL2 is now the mandatory foundational trust layer for any high-risk digital interaction.

To navigate this new era, executives and architects must look past the interface and understand five surprising technical and strategic realities of the modern standard.

1. The Evidence Ceiling: IAL2 is Not “IAL3 Lite”

The most persistent myth in identity architecture is that IAL3 requires more documentation than IAL2. It doesn’t. 

Under Revision 4, IAL2 and IAL3 share identical evidence collection requirements. To reach either level, you must collect one of three combinations:

  • One piece of FAIR evidence plus one piece of STRONG evidence.
  • Two pieces of STRONG evidence.
  • One piece of SUPERIOR evidence (validated cryptographically).

The difference is not how much evidence you provide but how you prove you own it.

IAL3 is strictly “on-site attended,” whereas IAL2 provides the flexibility to mix modalities, including remote, on-site, attended, or unattended pathways. 

If you have built an IAL2 process that validates a passport and a driver’s license, you have already hit the “evidence ceiling.”

2. Identity is Not Authentication (The IAL vs. AAL Divide)

A common architectural failure is bundling identity and authentication. NIST Revision 4 enforces a strict divide between them because they solve fundamentally different problems:

  • Identity Assurance Level (IAL): “Who are you in the real world?” This is a one-time or periodic proofing event.
  • Authentication Assurance Level (AAL): “Are you the same person who enrolled?” This happens at every login.

The strategic flow is: Establish trusted identity (IAL) → Authenticate trusted identity (AAL).

You can have a high-security passkey (AAL3) protecting an account that was never actually verified (IAL1). Conversely, you can prove an employee at IAL2 but allow them to authenticate with a weak SMS code (AAL1).

High-assurance security requires parity; a strong door is useless if you don’t know who you gave the key to.

3. The Rise of “Pathway Provenance” (and the Death of KBV)

In Revision 4, “IAL2” is no longer a monolithic status. There are now three distinct verification pathways:

  • Non-Biometric: Verification via a mailed confirmation code or visual comparison by a trained agent.
  • Digital Evidence: High-assurance federation or wallet credentials (e.g., mDL or bank account linking).
  • Biometric: Automated comparison of a live sample against a validated document.

The Surprising Shift: Credential Service Providers (CSPs) now have a normative obligation to record and surface “Pathway Provenance.” It is no longer enough to assert that a user is IAL2; Relying Parties are entitled to know how that level was reached.

Furthermore, Knowledge-Based Verification (KBV) is officially dead as a proofing control. Revision 4 permits KBV only for fraud management—not for validation or verification. If your flow still relies on “your first car” questions to prove identity, you are not compliant with IAL2.

4. The “Quiet Downgrade” in Account Recovery

The “Achilles’ heel” of modern security is the exception path. You might spend thousands to prove a user at IAL2 during onboarding, only to have a help desk agent reset their credentials after a low-assurance phone call.

When the recovery path is weaker than the enrollment path, the original IAL2 status is effectively nullified. Revision 4 mandates that the recovery bar must match the enrollment bar.

“The exception path is where assurance goes to die.”

If your account recovery relies on a “quiet downgrade” to SMS or simple help-desk verification, your system’s actual assurance level matches the strength of that recovery path, not the high bar of onboarding you paid for.

5. From Binary Checks to “Identity Intelligence”

IAL2 has evolved from a point-in-time “pass/fail” gate into a continuous Identity Intelligence model. Modern compliance requires technical controls that go beyond simple document scanning.

Two mandatory requirements of Revision 4 often surprise organizations:

  1. Death Records Check: A mandatory check against authoritative death records is now required for every IAL2 proofing process.
  2. Injection and Forged-Media Defense: You must implement technical controls to detect virtual cameras, emulators, and deepfakes. This includes testing your algorithms against known attack artifacts to establish baseline false-positive rates.

To assert IAL2 conformance for the Biometric Pathway, you must meet specific technical benchmarks: a False Match Rate (FMR) of 1:10,000 or better and a Presentation Attack Detection (PAD) threshold with an IAPAR below 0.07.

The Identity Confidence Profile now includes:

  • Evidence Confidence: Validating security features and authoritative sources.
  • Injection Defense: Confirming media originates from a genuine sensor.
  • Biometric Integrity: Testing against ISO/IEC 30107-3 standards for liveness.
  • Fraud Signals: SIM swap detection, device reputation, and mandatory death record checks.

The Death of the Decoy: Why Passkeys and AAL2 Are Rewriting the Rules of Digital Trust

For decades, digital security relied on a fragile illusion: the shared secret. This could be a password memorized by a person, an SMS code intercepted in the air, or a time-based one-time password (TOTP) entered into an app.

For years, enterprise security has operated on a deceptively simple assumption:

If we add another authentication factor, we make the user safer.

That assumption is no longer good enough.

Attackers have become skilled at exploiting the human interaction around authentication. They don’t need to steal your password. They can trick you into approving a push notification, entering a one-time code on a fake website, or surrendering a session to a man-in-the-middle attack.

This raises a much more important question:

What if the strongest authentication isn’t the one that gives users another factor—but the one that gives attackers nothing useful to steal?

That is where AAL2 authenticators and passkeys become particularly interesting.

Attackers realized that tricking a human into giving up that secret means owning the kingdom. This led to the era of Adversary-in-the-Middle (AiTM) phishing kits and push-fatigue scams, where human error remains the ultimate vulnerability.

This raises a more important question:

What Are AAL2 Authenticators?

The National Institute of Standards and Technology (NIST), in its SP 800-63 guidelines, outlines Authenticator Assurance Levels (AALs) to measure how strongly an authentication ceremony proves that the person logging in is actually who they claim to be.

AAL stands for Authenticator Assurance Level.

The concept comes from NIST’s Digital Identity Guidelines and describes the level of confidence a system can have that the person authenticating is actually the legitimate user.

At a high level:

  • AAL1 provides basic confidence in the claimant’s identity. AAL1 relies on single-factor authentication (like a simple password).
  • AAL2 requires stronger authentication using either a multi-factor authenticator or two distinct authentication factors. AAL2 sits as the vital baseline for modern enterprises and secure platforms. It requires Multi-Factor Authentication (MFA).
  • AAL3 provides an even higher level of assurance, including stronger requirements around the authenticator and resistance to attacks. AAL3 demands the highest tiers of hardware-backed security, often requiring specialized physical security tokens.

AAL2 is not simply synonymous with “MFA.”

Traditionally, AAL2 could be met by combining two single-factor elements—such as a password with an SMS text or a TOTP code. However, as automated phishing proxies have become sophisticated enough to harvest these codes in real time, the security industry has realized a harsh truth: not all MFA is created equal. AAL2 frameworks now emphasize methods that resist interception, replay, and man-in-the-middle attacks.

Why Passkeys Are Phishing-Resistant MFA

Passkeys—built on the FIDO2 and WebAuthn protocols—are the gold standard for achieving this modern security bar. They satisfy the core criteria of phishing-resistant MFA through three revolutionary mechanisms:

1. Cryptographic Domain Binding

Unlike a password or TOTP code, which can be typed into any convincing website, a passkey is bound to the domain where it was created. If a malicious actor sets up a look-alike phishing site (e.g., g0ogle.com), your authenticator checks the domain origin. It refuses to sign the cryptographic challenge because the URL doesn’t match the legitimate service. The phishing site gets nothing because the passkey refuses to interact with imposters.

2. Asymmetric Key Pairs (No Shared Secrets)

When you register a passkey, a unique public-private key pair is generated.

  • The public key lives on the server. If the server is breached, the public key is useless to an attacker.
  • The private key never leaves your hardware-protected key store (like Apple’s Secure Enclave, a Windows TPM, or an Android keystore).
  • Because no secret is transmitted across the network during login, there is nothing for an attacker to intercept.

3. Built-in Intent and Biometric Local Gatekeepers

To use a passkey, your device requires local physical presence or biometric confirmation (such as a fingerprint scan, face unlock, or device PIN). This satisfies the requirement for “authentication intent”—proving a human is actively participating now, not a remote script quietly harvesting a session token.

How Passkey works during Authentication 

Passkeys fundamentally change the authentication model.

Instead of asking: “What secret can the user prove they know?”

The system asks: “Can this trusted device cryptographically prove that it possesses the credential associated with this website?”

That is a radically different security model.

Passkeys are based on public-key cryptography and the WebAuthn/FIDO2 ecosystem.

During registration:

  1. Device generates a key pair.
  • Private key → stays protected on the user’s device.
  • Public key → registered with the identity provider

2. During authentication:

  • Identity Provider sends a challenge.
  • Authenticator verifies the user.
  • Device signs the challenge using the private key.
  • Identity Provider verifies the signature using the public key.

And critically, there is no reusable password or OTP for the attacker to steal.

A Paradigm Shift in Digital Trust

The brilliance of passkeys meeting AAL2 requirements is philosophical as much as it is technical: it removes human judgment from the security equation.

For decades, we blamed users for clicking phishing links, falling for social engineering, or failing spot-the-fake-domain tests. Passkeys acknowledge that humans are human and instead build an architecture where, even if you are fooled, the technology is not.

AAL2 + Passkeys: A Powerful Combination

AAL2 provides a useful assurance framework. Passkeys provide a modern authentication mechanism capable of strong phishing resistance.

Together they help organizations move from: “Do we have MFA enabled?” to a much more mature security question.

“What level of assurance does this authentication event provide, and how resistant is it to real-world attacks?”

Rather than simply Username + Password + MFA authentication policy, move to a realistic and strong enterprise identity policy that evaluates User + Device + Credential + Context + Risk.

By tying identity to immutable hardware and mathematical proof instead of shared secrets, we are moving past a world where a clever text message or fake website can compromise a digital life.

The decoy is dead; long live the key.

Rethinking Security: How Autonomous AI Challenges Traditional Models

We have moved beyond when conversational AI was just a fancy chatbot. Now, the real frontier of artificial intelligence is autonomous execution, not just answering questions or drafting emails.

Today’s AI agents can call APIs, access sensitive databases, set up cloud infrastructure, change system settings, create new digital identities, and run code in real time. They do more than just talk—they take action.

This change turns AI from a passive source of answers into an active digital worker. It also brings a serious challenge. Traditional security systems were designed for people, not fast, autonomous systems. How do you protect something that operates at machine speed, has wide digital access, and makes its own decisions?

This is where Identity, Security, and AI converge.


The Paradigm Shift: From Human Intent to Machine Autonomy

In older enterprise security models, every important action like updating a database, moving money, or changing permissions required human involvement. Even when using service accounts or API keys, a person still set up the process.

Autonomous agents change this approach. When an agent can create its own sub-identities and buy cloud resources as needed, the line between user and system disappears.

Consider the capabilities of a modern agentic workflow:

  • Dynamic Identity Provisioning: Creating ephemeral service accounts to bypass static permission checks.
  • Arbitrary Code Execution: Writing and running scripts on the fly to solve unexpected runtime errors.
  • Cross-System Orchestration: Chaining API calls across SaaS platforms, databases, and internal infrastructure.

If an autonomous agent is compromised through prompt injection, data poisoning, or a misaligned goal, it does more than leak data. It can carry out harmful actions on a large scale.


Why Legacy Security Fails Here

We can’t use old tools to solve new problems with autonomous agents. Traditional security controls don’t work well because:

  1. Static RBAC (Role-Based Access Control) is too rigid. Agents need flexibility to handle complex problems, but fixed roles can’t keep up with AI’s real-time decisions.
  2. Perimeter defense no longer works. Agents move across cloud services, third-party APIs, and microservices. The real boundary is the agent’s current context, not a firewall.
  3. Post-hoc auditing is too slow. By the time a security system alerts you to a suspicious database wipe or unauthorized purchase, the autonomous agent has already finished its task.

A New Blueprint: How We Secure Autonomous AI

To secure enterprises using autonomous agents, we need to rethink identity, context, and safeguards from the ground up. Security leaders should focus on three main pillars:

1. Identity-Aware Intent Verification (Beyond OAuth)

An agent identity should be integrated into the broader Non-Human Identity (NHI) security strategy.

But AI agents are different from traditional service accounts.

A service account generally executes predefined functions. An AI agent can interpret context, make decisions, select tools, and initiate actions.

That means identity alone isn’t enough.

We need to know not just who the agent is but also what it is trying to do. An agent should not get all the permissions of its creator. We need dynamic session identities using cryptographic proof of intent. Every risky action, like changing a configuration or running code, should trigger a real-time check: Does this action match the approved business goal, or has the agent’s context been compromised?

Agent identity has to be two-layer:

  • A durable workload identity — cryptographically attested, non-transferable, bound to the running code rather than to a secret in a config file. This is what you inventory, certify, and revoke. It answers what this thing is.
  • An ephemeral, task-scoped credential — minted at task start, carrying the delegation chain, expiring when the work does. This answers what it may do right now.

2. Zero-Trust Sandboxing for Code and APIs

When an agent can write and execute code or invoke external APIs, that execution must occur within hyper-isolated, ephemeral environments.

  • Blast-Radius Containment: If an agent is compromised during a database migration, its access must be hard-capped to that specific transaction, preventing lateral movement.
  • API Gateway Interception: All outgoing API calls made by agents should pass through intelligent proxies that inspect payloads for semantic anomalies, preventing exfiltration before the request hits the wire.

3. Continuous Runtime Guardrails & “Circuit Breakers”

We must move from deterministic firewalls to behavioral guardrails. Like high-frequency trading platforms that use circuit breakers to halt runaway algorithms, autonomous AI needs real-time circuit breakers. If an agent suddenly tries to create unauthorized user identities or rapidly purchase high-cost cloud resources, automated systems must freeze the execution graph instantly.


The Thought Leader’s Takeaway

We are standing at the precipice of a fully agentic economy. The companies that win will not be the ones that build the smartest agents, but the ones that build the most trustworthy ones.

Securing AI is no longer just about protecting data from leakage; it is about governing autonomous action. If we fail to secure the hands of our AI systems, we hand over the keys to the enterprise.

The future belongs to security architectures that treat AI not as a tool to be restricted, but as an autonomous actor requiring continuous, intelligent oversight.

You won’t just secure your agents. You’ll have to build the control plane that the enterprise software agents run on over the next decade. 

Once AI can act, Identity becomes its foundation, authorization becomes its guardrail, least privilege becomes its boundary, behavioral intelligence becomes its early-warning system, and governance becomes its accountability layer.


Six Ways AI Can Transform Enterprise IAM

AI can transform IAM from a system that manages access into an intelligent, continuously adapting system that understands identity, intent, risk, and context.

Here are the six ways AI can help you transform your Enterprise IAM strategy

1. AI-Powered Identity Risk Scoring

For example:

One of the most powerful opportunities is to move from static access policies to continuous identity risk evaluation.

Instead of simply asking:

“Does this user have permission to access this application?”

an AI-powered IAM system can ask:

“Given everything we know right now, should this identity be allowed to perform this action?”

The risk engine could combine signals from:

  • IAM, PAM, MFA, HR, Endpoint, SIEM, UEBA, Cloud, SaaS applications, Data classification, Threat intelligence, Behavioral history, Network context, AI-agent activity

This could produce a dynamic Identity Risk Score.

Identity Risk = 18 → Low

Allow normal access.

Identity Risk = 57 → Elevated

Require phishing-resistant MFA or step-up authentication.

Identity Risk = 86 → High

Block privileged access and trigger investigation.

The result is a shift from periodic authorization to continuous authorization.


2. AI Can Discover Excessive Access

Most large enterprises have an uncomfortable problem:

Nobody really knows who has access to what.

Users accumulate permissions.

Contractors retain old entitlements.

Service accounts remain active.

Applications create machine identities.

And now AI agents are being added to the mix.

AI can analyze identity relationships across the enterprise and identify:

  • Unused privileges
  • Toxic combinations
  • Excessive permissions
  • Orphaned accounts
  • Dormant identities
  • Overprivileged service accounts
  • Excessive administrative rights
  • High-risk access paths
  • Privilege escalation opportunities

Instead of asking an identity administrator to review thousands of entitlements manually, AI could say:

“These 47 identities represent the highest unnecessary privilege risk in your environment. Here is why, and here are the recommended remediation actions.”

That changes IAM from a system of record into a system of intelligence.


3. AI Agents Need Their Own Identity Lifecycle

This may become one of the biggest IAM categories of the next decade.

Imagine an enterprise deploying 50,000 AI agents.

  • Who created them?
  • Who owns them?
  • What systems can they access?
  • What data can they see?
  • Who approved them?
  • What model are they using?
  • What tools can they invoke?
  • When should they expire?
  • What happens when their owner leaves the company?

These are classic identity-governance questions — but applied to machines.

The future enterprise IAM platform should therefore manage an Agent Identity Lifecycle:

Discover → Register → Authenticate → Authorize → Monitor → Review → Revoke → Retire

Every agent should have:

  • A unique identity
  • An owner
  • A sponsor
  • A purpose
  • A risk classification
  • Defined permissions
  • Expiration policies
  • Activity history
  • Access reviews
  • Emergency revocation

In other words:

AI agents should be governed like employees — but with much tighter controls.


4. Move From RBAC to Intent-Aware Authorization

Role-Based Access Control has served enterprises well. But AI agents operate differently.

A single agent may perform hundreds of different tasks.

Instead of:

Agent → Role → 500 permissions

we should move toward:

Agent → Intent → Context → Minimum Required Permission

For example:

An HR AI agent might be permitted to:

  • Read employee benefits information.
  • But that doesn’t mean it should be allowed to:
  • Modify compensation records.

A finance agent may be allowed to:

  • Read invoices under $100,000.

But not:

  • Approve a $5 million payment.

This is where Just-In-Time Access, Zero Standing Privilege, and policy-based authorization become extremely important.

AI should receive the minimum privilege necessary for the specific action — and preferably only for the duration of that action.


5. AI Can Become the IAM Administrator’s Copilot — and Eventually Agent

Identity teams spend enormous amounts of time investigating access issues.

AI can dramatically reduce this operational burden.

Imagine an IAM administrator asking:

“Why does this employee have access to Salesforce?”

The AI could respond:

“The user received the entitlement through the Sales Operations role 14 months ago. The employee changed teams six months ago, but the role assignment was not removed. The user has not accessed the application in 120 days. Recommended action: remove access.”

Or:

“Show me all privileged identities whose behavior deviates from their normal baseline.”

The system could analyze millions of events and return the highest-risk identities.

Eventually, AI could move from recommendation to controlled remediation:

Detect → Explain → Recommend → Approve → Remediate → Verify

With appropriate human oversight, IAM teams could manage environments that would otherwise require many more personnel.


6. Continuous Access Reviews Become Continuous Governance

Traditional access reviews are often periodic.

  • Quarterly.
  • Semiannual.
  • Annual.

But AI agents can continuously change their behavior, tools, permissions, and workflows.

A quarterly review may therefore be obsolete before it is completed.

The future should be:

Continuous Access Governance.

AI continuously evaluates:

  • Identity
  • Entitlements
  • Behavior
  • Risk
  • Data access
  • Agent activity
  • Policy compliance
  • Business context

When something changes, the system responds.

For example:

Employee changes department

→ AI identifies impacted access.

Risk increases

→ Privileged access is reduced.

Agent changes behavior

→ Agent is quarantined.

Agent owner leaves company.

→ Sponsorship is reassigned, or agent access is suspended.

Unused entitlement detected

→ Access removal is recommended.

Sensitive data requested

→ Step-up authorization is triggered.

This is IAM moving from periodic governance to autonomous governance.


AI’s Impact on Enterprise Identity Management

For twenty years, Enterprise IAM has been organized around a simple assumption: identities are either people or plumbing.

People log in, get provisioned through a joiner-mover-leaver process, and sit through a quarterly access review. Plumbing service accounts, batch jobs, API integrations, gets a long-lived credential, a bounded scope, and an owner who may or may not still work here.

“Who are you, and what are you allowed to access?”

Traditionally, this question applied primarily to human users. Employees, contractors, partners, and administrators would authenticate, receive permissions, utilize applications, and subsequently have those permissions revoked as necessary.

Non-human identities already outnumber human ones by something like seventeen to one, and that population grew by double digits year over year before agents were a meaningful share of it.

However, the advent of AI is fundamentally altering this paradigm. AI agents break this binary. An agent has an identity, credentials, and a scope like a service account does, but its scope changes with every invocation. Currently, organizations deploy AI copilots, autonomous agents, AI-powered applications, and multi-agent workflows. These systems can access data, interact with APIs, execute business processes, and, in some cases, make decisions on behalf of employees.

As a result, the central question has become significantly more complex than “Who are you?”

It is: “Which human, agent, application, or machine is acting, on whose behalf, with what authority, for what purpose, and with what level of risk?”

This development represents an entirely new category of identity management challenge.

This shift presents IAM with a significant opportunity to serve as the primary control system for enterprise AI.

The Emergence of the AI Agent as a Distinct Enterprise Identity

Recent advancements clearly indicate this emerging direction.

Microsoft has introduced Entra Agent ID, specifically designed to provide identities for AI agents and govern their access throughout their lifecycle. The platform includes concepts such as agent identities, owners and sponsors, lifecycle governance, and access packages.

NIST has also launched work focused specifically on identity and authorization for software and AI agents, recognizing that agents require access to diverse data, tools, and applications and therefore need appropriate identification and auth. The security market is also evolving rapidly in this direction. For example, Cyera’s acquisition of Oasis Security, reportedly valued at approximately $1 billion, underscores the increasing significance of non-human identity and AI-agent governance and AI-agent control.

Concurrently, security researchers increasingly advise that AI agents should be regarded as potentially privileged insiders rather than as traditional software entities.

The implications for Chief Information Security Officers (CISOs) and Chief Information Officers (CIOs) are evident:

AI agents need identities.

However, identity alone is insufficient. AI agents require governed identities.

Limitations of Traditional IAM Approaches

Conventional IAM frameworks typically operate based on relatively static concepts:

User → Role → Permission → Application

In contrast, AI introduces a significantly more dynamic model:

Human → Agent → Intent → Context → Tool → Data → Action

For example, when an employee interacts with an AI agent:

“Find the latest customer renewal risks and prepare recommendations for my accounts.”

The agent may need to:

  1. Identify the employee.
  2. Determine whether the employee is authorized to access those customers.
  3. Retrieve CRM information.
  4. Query analytics systems.
  5. Access customer-support records.
  6. Invoke an AI model.
  7. Generate recommendations.
  8. Potentially update a business system.

This scenario raises a critical security question:

Should the agent inherit everything the employee can access?

This approach is not advisable. Such a practice would significantly increase the potential impact of security breaches.

Instead, access should be dynamically determined based on:

  • Who initiated the request?
  • Which agent is executing it
  • What the agent is trying to accomplish
  • What data is being requested
  • Which application is being accessed
  • The sensitivity of that data
  • The current risk level
  • The agent’s behavior
  • The duration of access
  • Whether the action is read-only or transactional

This context illustrates how AI can fundamentally transform IAM practices. More will follow in my next blog on this topic

Product Management efficiencies to drive Digital Transformation

I am currently reading the book “Slow down to Speed up” by Liz Bywater and understand the importance of leading, succeeding and thriving in the fast pacing 24/7 world of Product Management. Sharing my thoughts to help Product Managers on how you can drive business to achieve complete digital transformation around product development and innovation.

I have been in the software industry as a product manager for the last 15+ years. It’s interesting to see how Product Management and Product development is continuously evolving. Now with Cloud computing and SaaS being the main business drivers for software efficiencies, companies need to pay attention to the details around the digital transformation efforts around strategy, decision making and execution to stay innovative. Understanding the current gaps in their product development process and addressing them at the earliest is critical.

I will cover some of the areas that a Product Manager or a Product Owner can make a difference.

Digital Transformation mindset to explore business problems

Everyone is talking about digital transformation on how it is important for every organization. But there is a specific structure that every company needs to follow if they want to be successful. There are a few variables that each company needs to put in place since Product strategy is a continuous process.

  1. Executives and senior level management need a new mindset that is flexible and open to exploring a business strategy that is a continuous journey.  The strategy will have to be based on various different factors that are continuously monitored and fine-tuned.
  2. Product Managers and Product owners will need to do the following to have help defining a strategy and get buy-in from the executives on a regular basis.
    • Gain knowledge about the macro and micro trends in the industry around their business. Understand the pros, and cons and how that would have an effect on the business needs.
    • Maintain a continuous and ongoing dialogue and transparency with the customers to understand their pain points, their business needs and the changes that drive their success.
    • Monitor the competitive landscape to understand the gaps and the innovation practices.
    • Build partnerships that would add value to the business and can help address gaps.
    • Design thinking to define and understand the market problems and brainstorming various ideas driven by outcomes on how the market problems could be addressed.
    • Drive continuous experimentation on each idea to gather data on the business outcomes.

Decision-Making to build the right things

Decision-making is both an art and science. There are various frameworks that are available to help Product managers and Product owners in the decision-making process https://blog.usejournal.com/top-11-frameworks-every-product-manager-should-know-aad46dd37b62.

Irrespective of the framework that a company adopts, a data-driven decision-making process makes the decisions error proof and provides insights and learning to innovate. Remember data gathering is a continuous process just like strategy. Data helps you to make better decisions that are low risk but high business value.

Here are a few ideas on how to gather data

  1. Continuous data gathering through experimentation on ideas. Helps to identify the right market fit and defining business outcomes. Thereby helps to add value to your customers.
  2. Continuous data gathering through customer engagement with your product to enhance customer experience.
  3. Continuous data gathering from customer interactions and feedback captured as the voice of the customer.
  4. Continuous data gathering from sales around win/loss analysis.
  5. Continuous data gathering from customer success on product issues and improvements.
  6. Continuous data gathering from marketing around product promotions.
  7. Continuous data gathering from finance around product pricing

Execution to build and launch things right

Once the decision is made to build an idea into a product, the path to execution starts. The steps that are involved to trigger execution is to break down the idea into smaller and lean set of requirements that can be launched and continuously gather data and insights to improve the building process more efficiently.  This is a collaborative effort that a Product Owner drives with engineering. Agile is the popular methodology that is quite common across all companies these days when it comes to how software is built.

This would mean that you take time to do the following steps

  1. Planning: As a product owner, break down the idea into a smaller subset of requirements and define the acceptance criteria that fit into an agile sprint and add that into to the sprint backlog.
  2. Prioritization: Leverage the data that you have continuously gathered earlier to prioritize the backlog on what to build next sprint and launch.
  3. Build: As a product owner, work with engineering to make sure the implementation addresses the requirements, meets the acceptance criteria around functionality, performance baselines and data is captured around specific KPIs.
  4. Launch: As a product owner, work with marketing, sales, and support to get the market positioning and the sales and support enablement right.
  5. Analyze Data: As a product owner, analyze the data to gain insights after every launch, fine-tune the KPIs to improve the qualitative data that you capture in each build. Based on insights that you have gathered from the data, go back to Step 2 to re-prioritize the backlog

Execution now is a continuous journey where you rinse and repeat to innovate!

Conclusion

Product Management is a continuous journey of the product you manage. Hence you need to “Slow down to Speed up” to stay current and relevant in the digital transformation age.

Top 10 Points for Customer Success

customer success

More and more organizations these days focus on customer success when it comes to their go to market strategy to win, serve and retain customers. It is key that you build and deliver products that engage, retain and delight them, especially in the early stages of your product. It is well known that it is easier to keep a customer than to acquire a new one.

Here is what Gartner says:

“80% of your future business will come from 20% of your current customers”

As a product manager I am always conscious of incorporating features that are customer centric and growth centric. From the get go, it is important to have a growth hacking approach to the product development. This leads to a better customer acquisition and retention product strategy.

Here are the 10 important points for a good customer success story board:

1. Onboarding
Provide self-service customer on-boarding, free trials, product evaluation and training. Empower the customer to evaluate the product. Offer online easy to use tutorials and self training for rapid learning. Educate the customer about the value proposition to assist purchase decisio.

2. Proactive Customer Service
In a highly competitive, constantly changing market there is a strong need to engage and provide superior customer service to your customers even before they make any purchase decisions.

  • Focus on addressing the end to end product experience (download, install, configure, deploy and use) and not just making the download available.
  • Articulate the benefits that the products will offer by solving their business issue and providing a realistic expectation on the ROI instead of focusing on the price and the competitive differentiators alone.
  • Invest in resources that will tailor and provide better education and support to the buyers so the end to end experience of the product from purchase to deployment to maintenance is delightful.

3. Voice of the Customer
Understanding what your customers think, experience, and want is critical for retention and growth. Engaging customers to get feedback and responding to them positively will build more confidence and trust with the customers. Make the product sticky.

4. Analytics
From the inception, ensure that your product captures usage metrics that help educate you about different aspects of your product and its usage.

  • Product usage metrics: Track signups, logins, and application usage metrics. Capture the app version, the license type, content type,  location data, environment data, events, error conditions, peak times of usage, etc.
  • Business metrics: is the customers getting the end-result they expected by tracking their performance metrics like response time, application availability, authentication time, users per day and more
  • Service utilization metrics: gathering data to see if the customer is fully utilizing the product features, how many product defects gets raised and against which feature.
  • Customer rating metrics: Track customer happiness, their experience and their feedback. Gather metrics around sales bookings, churn, ROI and adoption metrics.
  • Support and operations metrics: are there any outstanding support, SLA or invoicing issues, unplanned outages. Track the mean time to resolve a support incident, incident initial response time, affected users on a single incident.

5. Customer Experience Mapping
There are several approaches to experience mapping. Understand how customers flow through the organization and the challenges that customers encounter, opportunities lost versus gained, the customer value and cost, their adoption journey, and ROI are all important data points that can help in generating more leads at the same time facilitate to retain existing customers.

6. Customer Segmentation
Categorizing customers into market or service groups and providing services tailored to these segments for winning and retaining the right customers.

7. Customer Engagement and Retention based Marketing
Establish proactive customer outreach programs and tools for effective Communications and Openness thereby to foster better customer relationship and creating customer value and profit margins while preserving existing revenues.

8. Customer Loyalty Rewards
Provide Customers insights to review where their money is spent and consolidate their purchasing under loyalty programs featuring rewards that they actually want. For maximum appeal, offer customer-relevant reward options and a quick, easy redemption process.

9. Customer Win-Back Program
If customers did leave, reach out to understand what happened, tell them about the changes you’ve made to resolve the issues that led to their departure; share product roadmaps and future vision; entice customers to come back with a loyalty offer they’ll value—and then keep them with excellence.

10. Employee Customer Engagement
Last but certainly not least, happy employees are a crucial prerequisite for happy customers: the relationship between employee engagement and customer engagement is undeniable. It is vital to ensure that employees are educated, encouraged, and empowered to promote and enact customer retention strategy at all times.

What is Application Platform as a Service (aPaaS)?.


For those who have worked and dealt with Middleware software in the past which provided services to software applications beyond the  operating system, the term aPaaS should not be a hard to understand concept.

An aPaaS as per Gartner’s definition is as a PaaS (app middleware + cloud characteristics) designed to enable runtime deployment, management and maintenance of cloud business application services. It supports requirements for business application and application projects and is delivered as-a-service..

Middleware has been the commonly used term for on premise software that enabled communication and management of data in distributed applications. Middleware gained popularity in the 1980s as a solution to the problem of how to link newer applications to older legacy systems. The vendors who built and offered Middleware had a strategy of building a complete and integrated suite of middleware to allow our customers to develop, deploy, and manage applications. For customers the middleware software not only offered off the self features around building and hosting application but also the ease around the integration burdens which facilitated the ability to link applications together and provide more consistent access to information.

You can now relate the same middleware software capabilities to an aPaaS in the cloud that offers the following services

  • Platform services
  • Identity Services
  • Integration services
  • Business Process Management Services
  • Development Tools
  • Deployment Tools
  • Management Tools

Why would anyone need an aPaaS?

These days cloud services is picking up lot of traction when it comes to SaaS, PaaS or IaaS. Refer to my earlier blog post ” Why Software-as-a-Service (SaaS) model matters for both customers as well as vendors” as to the reasons why oth customers and vendors are investing in the rapidly evolving application platform.

Gartner recently published their first Magic Quadrant (MQ) for aPaaS with their  focuses on public cloud enterprise aPaaS offerings. – See more at: https://www.gartner.com/doc/2645317?pcp=itg. It’s interesting to see how quickly the aPaaS market has evolved in a period of  less than 9 months, now that Gartner now has a MQ for this space. Quite a few Platform as a Service (PaaS) vendors whose primary focus in 2013 was providing Platform Services are now posiioing and evolving their services to address the aPaaS space. This is a clear indication that PaaS market has matured and the revenue opportunities are shrinking. The PaaS vendors clearly see that the growth opportunity is to move into the application space and they need to innovate quickly to become market leaders.

An aPaaS infrastructure is a self contained environment that will offer the following
1. Build applications
The application platform provides you with all the tools you need to iterate quickly, and adopt the right technologies for your project
2. Deploy apps in minutes, with tools you love. 
Reduces development and deployment time. They offer a way to rollout new application features into production has never been easier. Set up staging and test environments that match production so you can deliver functionality without fear, and continuously make improvements.
3. Scale the application to millions of users.
Tools and features that will help to scale your application at the same time ability to upgrade your database software in a few simple steps.The growth could happen over a year or overnight,  but aPaaS will facilitate you to grow on demand to capture opportunity.
4. Integrate with various other applications
Provides additional software services like operating system, database, security and vulnerability management, API and integration  infrastructure and more

Stay tuned, in my next log topic that I would like to explore is “What’s next after aPaaS for both vendors and customers?.”

Enterprise Mobility Requirements

For couple of years now, mobile innovation has primarily focused all its resources and time on the consumer market.  In 2013 there are tremendous opportunities and market demand for innovative solutions and products that address the needs of a mobile strategy for enterprises.

In 2013, analysts have forecasted 1.2 billion smartphones and tablets will be sold worldwide, up from 821 million in 2012. With more and more enterprise  encouraging the idea of BYOD for their users, having a mobile strategy is not an option anymore. It is a necessity for all enterprises.

What is it to have a mobile strategy?

Most enterprises now have aligned a strategy to address their mobile user needs to meet their business goals through evolving technologies. Hence creating a compelling mobile experience for their users is now becoming a competitive necessity.

Here is the standard requirements that companies have adopted around a mobile strategy so far:

1. Mobile Apps to provide easy and secure access: 

Most companies have a mobile strategy starts with mobile app to accommodate the user driven IT world and provide easy access to content like the ability to connect to files and documents from smartphones and tablets as efficiently as they can from laptops and desktops.

The mobile apps could be a native apps to support and meet the needs of specific mobile devices, which are made downloadable through the app stores or they it could rich HTML5 based web apps. Refer to my earlier post for more on the benefits of HTML5 : Future of Web Applications as I see it.

Also, check out this article on HTML5 vs native app

2. Maintain control and security while providing a simple End-User experience

This would require the need to support a mobile device and access management solution to make sure they can enforce and control these mobile devices on who, how, where and what resources the users can access. Refer to my earlier post for more on Mobile Security – BYOD Trends and Needs

3. Support a Social-Business context through evolving technologies

Mobile users are using the mobile devices for their personal and their professional lives— whether they’re working remotely on mobile devices or at the home office.  This means that tools around collaboration, file sharing, workflow systems, WLAN capacity, network bandwidth and other network resources should allow users to fully engage both on business and social terms at the same time. This would require enterprises to support a flexible model to support their evolving business needs through technologies to provide better, faster and secure transactions without compromising the privacy of these mobile users.

So far go good…It will be interesting to watch how this strategy will evolve in the future?.

What it means to adopt a Cloud strategy?.

Cloud computing in the areas of  Platform as a Service (PaaS), Infrastructure as a Service (IaaS) and Software as a service (SaaS) were the words of 2012. Vendors like SAP, IBM,Microsoft, RedHat, Oracle, VMWare and Citrix all entered this space early on and now we see that these solutions are  evolving into second generation products in 2013 (Read more at http://venturebeat.com/2013/01/14/the-second-generation-of-cloud-startups-is-here/#ST0T4K7MFbYxhGlA.99)

Now that cloud computing is making a huge impact in other market areas like big data, social and mobility, to help drive and support new business scenarios, we will see more and more hardware and software vendors embarking this journey around their products and solutions. ( See: Gartner: 10 critical IT trends for the next five years)

Screen Shot 2013-01-14 at 2.12.46 PM

Source: Business value of Cloud Computing

Benefits of the cloud offerings is often associated with reducing cost and increasing agility.  While this is true, the more strategic role that cloud solutions can play for the customers and the vendors are in achieving operational excellence, product leadership, customer intimacy, and open innovation.  Cloud computing is part of a long and powerful trend towards virtualization. Virtualization acts as a stepping stone for cloud which mainly helps to bring down the operation cost down, at the same time facilitate speed and agility in deployment and maintenance in the long run.

Given the above factors, the following are typical areas to consider when thinking of ROI when adopting a cloud strategy:

                  1. Hardware costs – how much will this save in terms of the servers and storage devices.
                  2. Maintenance for the hardware – will there be any savings ?
                  3. Software licenses cost – usually the license post for a cloud solution is priced less than on premise. How much cost can be reduced per seat?
                  4. Maintenance for the software – include both the vendor support and your internal support costs
                  5. Facilities costs – can you lower the power, HVAC, building costs etc.?
                  6. Productivity/efficiency costs– what is the learning curve, are the people who will use the new system more productive? what is the cost involved for training?
                  7. Agility around new opportunities – are you able to respond faster, but cheaper, to opportunities that otherwise would have taken more development time and money?

Role of Innovation in a Software Product Lifecycle

Over the weekend the CBS 60 minutes program covered the approach of  Design Thinking (http://www.cbsnews.com/video/watch/?id=50138327n) where  company like IDEO incorporates human behavior into product design, an innovative approach that is now being taught at Stanford university these days to get the younger generation to think differently.

This made me wonder why innovation is not a topic that is strictly enforced by all product development companies. When it comes to the product life-cycle,  innovation is a word that is loosely thrown around. Management tells their employees that they promote innovation but there is no goals or requirements that is tracked around innovation specifically.

Importance of Innovation

It’s a well know fact that ‘creativity’ is about coming up with ideas while ‘innovation’ is about bringing ideas to life. If product companies have to innovate  they need to take risk with their ideas which requires time, investment and resources. Let’s take the example of Proctor & Gamble (P&G), an american multinational market leader in consumer goods. This isn’t accidental. It’s the result of a strategic effort by P&G over the past decade to systematize innovation and growth. Their product portfolio at any point of time is a result of  dedicated focus on innovation. They will lose their #1 place in the consumer goods market if they do not innovate. Apple is another well know example who had dominance with its product portfolio because of its innovative culture that Steve Jobs always championed for. If Apple does not maintain its track record with innovation, the company will very soon lose its market share against other competitive vendors.

Role of Innovation in Software companies

Screen Shot 2013-01-10 at 3.28.05 PM80-90% of the  big software companies these days take small and safe bets to innovate with their products. They mostly listen to their customers and their feedback and meet their needs by adding features and functionality to the existing products. They  then tag that as their strategy for innovation.  On the other hand, all the big innovations of new ideas are brought to life in software startups.  Startups are backed by venture capitalist who fund them to convert the bigger and smarter ideas to transform them into profitable, commercial revenue generating product and services.

Overtime big software companies lose their product edge over competitors and to stay current in the market they acquire these software startup companies and integrate them into the existing product portfolio. Over the process of integration the products produced by larger companies lose their real value, the product becomes bulky and complex. Hence this strategy is not always effective. This need to change!.

Innovation as a Strategy

There are various well-known innovation frameworks and best practices that is already available, which enforces the importance of adopting the concepts of  innovation at every step of the product life cycle. This should be the new way of thinking irrespective of whether the software products are developed in large or small companies.

nine-types-of-innovation

In order to promote the cycle of innovation as the heart of a software product life-cycle, companies should enforce a strategy and  promote a culture with specific goals that can be tracked and monitored around the product.

Here are some of the steps that can turn innovation into success for any product.

Screen Shot 2013-01-10 at 3.34.53 PM1. Idea generation:

  • Encourage free flow of ideas and reward them.
  • Allow to share knowledge around the ideas across the company.
  • Allow to interact with inside as well as outside the company resources who have the knowledge around these ideas.
  • Educate and allow to seek knowledge around  market and the technology trends. 

2.   Market research:

  • Is there a need or desire for the product?
  • Is the size of the potential market adequate?

  • Will the customer buy the product?

  • Will the product satisfy the market needs?

3. Competitive and Risk analysis:

  • Will the product have a competitive advantage?
  • Is the advantage profitable ?
  • Do we have all  the internal resources to build and sustain and make the difference?
  • Can we get a buy-in from the top management and support it?

4.  Revenue and growth:

  • Are forecasted returns greater than costs?
  • Are the risks acceptable?
  • Does the product fit your overall growth strategy?
  • Can it help us tap into additional markets?
  • Can it help us to be market leaders and establish to strengthen the brand?

Security Intelligence – Role of Big Data in Fraud Prevention and Management

Fraud is a serious problem and requires new way of thinking to address this problem. Irrespective of the market  type whether its financial services, online retail, point of sale or healthcare, fraud prevention and management is the biggest pain point for all customers these days.

In the security market  to address Fraud, the real-time security intelligence along with the power of  Big Data is spearheading the growth of solution vendors to innovate and differentiate their solutions from old-school security vendors.

Fraud causes companies to lose money in many ways. These days there is a greater need for a real-time solution to help to organizations automatically detect the anomalies with their users or system behaviours early on, which then can help  to notify and  take appropriate action This will prevent fraud and the loss of revenue.

Let’s take the example of healthcare to list out some of the well know challenges around fraud.

  • Organized groups defrauding insurance companies through elaborate schemes against government-sponsored programs or private health insurers
  • Patient medical IDs are stolen or duplicated for financial benefits
  • User impersonation for prescription drug benefits and many more…

Meanwhile, hospitals and HMO pay a heavy price  through fines and litigations if they don’t comply to all the Healthcare laws that are enforced by the government.  So, they  have to ensure appropriate checks and measures to prevent violations by their users/patients/doctors when they use the applications and systems.

Old school way of Fraud management:

Screen Shot 2013-01-08 at 12.48.13 PM

Most companies have invested and adopted multi-factor authentication methods (ex: password, smart cards, One-Time Password (OTP), biometrics etc) as an only mechanism  to identify and protect their users who are using their applications and systems but also a way to manage fraud. The picture here suggests a mechanism that they enforce currently to do a fraud evaluation.

These companies have quickly understood that multi-factor authentication alone cannot scale and address fraud issues since the bad guys have figured out a way to break through these multi-factor authentication mechanisms.

This is why there is a need for  real-time intelligence  security solution!.

Real-time Security Intelligence through Big Data

The challenges that makes realtime intelligence gathering the right approach to address fraud are:

  1. No single layer or a multi factor authentication is enough to keep determined fraudsters out of enterprise systems. Multiple layers must be employed to defend against today’s attacks and those that are yet to appear.
  2. No authentication measure on its own, especially when communicating through a browser, is sufficient to counter today’s threats. Additional fraud prevention layers must be utilized.
  3. Malware is the biggest immediate threat,  malware-based attacks are spreading to multiple sectors and enterprises.

Picture _raw1 2Let’s take the example of an online retail scenario where users have to shop for good through the browser supported on the PC, smart phone or the tablet.

Like the picture shows, a typical user will make multiple clicks and will interact with multiple applications in the background through a browser before he gets to the shopping cart. This would mean there is a way for us to gather a lot more data and information about the user and analyse his behavior realtime

Here are come of the steps that will help us build real-time intelligence around the user behavior:

1. End point Data : involves capturing context of users at the endpoint which is his device. For example is he using the browser on a PC, desktop, tablet, smart phone.  Capture the user’s IP, geo-location, authentication credentials and many more.

2. Session Data:  gather, monitor and analyze user’s session (ex. http post parameters and other session attributes) and his navigation behavior on the browser.  Compare this with his earlier navigation patterns to identify abnormal patterns based on his transitional history.

3. User Data: gather to monitor and analyzes user’s behavior to identify any anomalous behaviors during the transaction .

4.  Context Analysis:  Analyse the relationships among internal and/or external entities, systems and their attributes (for example, users, accounts, account attributes, machines and machine attributes etc.). Analyze the application logs, system logs, database logs and build predictive models for the user behaviour around applications and the systems involved.

The intelligence gathering and analysis in the above steps involves gathering the right data and also analyzing the data with an effective algorithm. This is where the Big Data plays a role to help build an effective and accurate model based on the user’s interaction with the application and system, that will help detect anomalies and prevent and manage fraud efficiently.

The secret to the success of such a Real-time Security Intelligence solution boils down to the quality of data collection and the advanced algorithms that addresses the 3 Vs of Big Data not only to build accurate predictive models but also support self learning for the solution to get smarter over time.

Big Data: Why Enterprises need to start paying attention to their Data sooner?

The awareness around Big Data is  on the rise and is exciting!. As we all know in the technology  space the word Big Data revolves around the 3 V’s, the Volume, Velocity and Variety of  the data that is typically seen in all enterprises these days.

Picture 1

The blog on visualize the 3V concept is a good resource that provides a view into Big Data  if you are not so familiar with have this question: “What is Big Data?.”

It’s 2013, the time is so right  for all enterprises to pay more attention to their Big Data. With the right technology and processes around their Big Data, enterprises can now trigger new ideas around business growth in 2013.

Some of the exciting new strategies that enterprises should look at for their Big Data are:

1.  Build advanced predictive models with the information that they already have around their customers and products to create new product and marketing services that will help to differentiate them from their competitors.

2. Data Mining that will help to understand their customers buying persona that will facilitate to capture new customers and markets.

3. Real-time analytics to understand the past behavior patterns of the customers which then will provide greater ability to satify the existing customers by providing personalized  services that is relevant to meet their needs and wants.

The Beginning…

Facebook hit the Big Data issues where they had to process huge amounts of structured ( ex. …)and unstructured ( ex. video, email, text)  data half decade ago. Facebook joining forces with Yahoo then lead to the creation of Hadoop, a software platform for processing and analyzing epic amounts of data streaming across the modern web. These days the social media platforms like Twitter and LinkedIn have to deal with Big Data to keep their system operational. Guess what they are using  to process and manage their Big Data. It is all done through Hadoop. Today we have eBay, and dozens of other high-profile web vendors are using Hadoop to analyzes their vast amounts of data generated during their online operations.

Reshaping the Business Model around Big Data

Most enterprise have Big Data that they have gathered in their data warehouses over the years. But they do not know how to use them nor do they know what the benefits that the various data that they have gathered over the years or the new data that they can collect will help. This is why business needs to spend more time to understand the importance of their existing data and think of ways that they can incorporate data which can help them to grow their revenue.

Let’s look at some examples to understand the value of Big Data in these specific markets. Mobile applications, tablets and smartphones are creating customers and services to consume and integrate structured and unstructured data from a variety of sources.

1. HealthCare Market:

Business objective:  Providing, enhancing and streamlining how hospitals connect with and care for their patients. Develop and facilitate personalized therapies and diagnostics to the patients

Big Data opportunity :  Incorporate a Big Data analysis engine to build predictive models against patients cynical history, genetics, blood work etc.models.

Why: This will facilitate the doctors to make best treatment recomendations in a timely fashion for their patients. This will help to offer the best care at the same time reducing the healthcare cost by avoiding unnecessary treatments to patients.

2. Retail Online Market :

Business objective:  Revolves around connecting the merchants with the consumers in a more effective way such that the consumers can find what they want conveniently and effectively  in a timely fashion. This would require merchants to know what the consumers are looking, when and where.

Big Data opportunity :  Incorporate a Big Data analysis engine that builds predictive models that will help to make better decisions

  • Build consumer models with their transactional history, buying pattern, interest in types of goods, browsing pattern, buying power pattern in $ amount etc.
  • Generate a catalogue for the Merchants based on the type of goods, price, value and access.

Why:  The predictive models will help to effectively connect the merchants with the consumer so its a win-win for all business entities.

3. Financial Market

Business objective:  Provide a High-Performance Trading platform that is effective,accurate and reliable

Big Data opportunity :  Advanced analytical engine that will allow for the analysis of complex data sets and the ability to connect patterns and relationships applied to analysing news, social media feeds, scanning incoming emails, or disecting company regulatory filings to generate predictable models

Why: This will facilitate the traders to make effective and accurate trading decisions that is profitable

Big Data Technology and Solutions:

With the 3 Vs around Big Data, enterprises will have to look at the technologies, solutions and data stores that will help them to be successful with Big Data.

Screen Shot 2013-01-08 at 12.13.28 PM

Big Data  Technology & Data Stores: There are lot of vendors that can offer products around Big Data software platforms and data stores. This was the first areas that got a lot of attention from vendors to address the Data management, processing and operational issues around Big Data. Machine Learning engines are still evolving which will help build accurate and a reliable predictive models . Because of the nature  of volume, variety and the velocity with which Big Data has to processed it requires an accurate and a reliable model-building process which has to be automated through advanced algorithms to be effective.

Big Data Solutions:Picture 3  Right now most of enterprises are trying to build specific tailored solutions in-house to address their basic needs. The Big Data solution space is  still a evolving  and there is lot of opportunities for innovation and creativity  The solution market  for Big Data is still an untapped market.

The story is a bit different when it comes to realtime analytics. Enterprises clearly understand the importance of real-time analytics and how it provides a value to the current business. As a result  there are vendors who have already built cool realtime analytical solutions that the market wants and that help enterprises reshape their existing business model. 

 

Call for Shift in the Marketing Paradigm for Enterprise Software


Having been a product manager for the 10+ years for enterprise software, I have always watched and observed how the Product marketing teams handle product launches, their go-to market  initiatives and the ongoing marketing programs around the Enterprise software products. It’s always one thing to build a kick ass software product which the market wants but the success of market adoption of the product and the ability of  sales team to convert it into positive selling opportunities greatly depends on how the marketing is handled for the product.  I see that in the Enterprise software realm more importance is given to the product quality alone (ex. features, packaging, UX, etc) instead on the importance of the product marketing to clearly identify, understand, serve and satisfy the market.

If you look back at Microsoft and what Bill Gates did to take the company to where it is today, Microsoft became the market leader not because of better products they had then but because of better marketing. Look at how consumers are fascinated with Apple products these days. It’s because Apple has done an excellent job in understanding what its consumers want.

Picture 2We all know that the ultimate marketing secret weapon for all products whether its consumer based products or enterprise software products, is to make the consumers/buyers/customers understand the Unique Selling Proposition(USP) of a product. But as per the old school of thinking the USP always revolves around 4 Ps which is Product, Price, Place & Positioning. Based on my observation of the consumer products and comparing that to Enterprise software products, continuing the USP marketing strategy on the 4P approach for Enterprise software will not been very effective in the long run and definitely needs a paradigm shift.

Picture 3

The paradigm shift around marketing Enterprise software should now involve emphasis from Products to Solutions, Place to Access, Price to Value and Positioning to Education. The new school of thought calls it the SAVE approach of Product Marketing (see the latest Harvard Business Review magazine article “Rethinking the 4 P’s”)

Here is what Product Marketing need to do:

  • Instead of focusing on defining the product features start to highlight what are the solutions that buyers/customers can build with the product to address their business issues. This would require a good understanding of the buyer’s persona and what their pain points
  • Focus on addressing the end to end experience that the buyer/customer will have to get access to the Product instead of focusing only on the packaging and downloading aspects of the product
  • Articulate the benefits that the products will offer by solving their business issue and providing a realistic expectation on the ROI instead of focusing on the price and the competitive differentiators alone.
  • Invest in resources that will tailor and provide better education of the product  to the buyers so the end to end experience of the product from purchase to deployment to maintenance of the Enterprise software is a pleasant experience for the buyer and the customer that you are targeting in specific markets.

Sooner the Product Marketing team adopts the SAVE way of thinking, the better it would be for the overall growth and success of Enterprise software products!!.

Technology product gaps for the mobile consumer market

The article in the recent HBR magazine on how How People Really Use Mobile opened up my mind to validate how I use my smart phone on a daily basis. This also made me to look into this topic further to see if I could connect the dots between the mobile consumer behavior and the technology product gaps that I specifically see that we need to pay attention to in the mobile space.

How are consumers using a Mobile Device:

Based on a industry research study called “Seven Shades of Mobile” conducted by InsightsNow for AOL and BBDO, the data show that 68% of consumers’ smartphone use happens at home. For a typical mobile user the common activity is not shopping or socializing but engaging in what researchers at BBDO and AOL are calling it the “me time.”.

Picture 1

 Also checkout some additional interesting facts and case studies about  brand messaging through mobile apps in this webinar  “Seven Shades of Mobile: The Hidden Motivations of Mobile Users

What are the Technology product gaps for the mobile consumer market?.

The mobile growth trend is here to stay. If you want to know how big the mobile market is, take a look at the stats here. Based on the “Me time” data from I mentioned above,  it is important that the technology vendors pay attention to the market needs in the following technology space so they can build value added solutions and products to address the market need of the mobile users.

1. App Development Tools

  • Mobile consumers will use mobile apps to purchase goods and  services, do banking and billing, to do in-store kiosk transactions, support mobile portals, apps for education and training, apps for games and entertainment. 
  • The app development tools should be simple and flexible so the apps are built once and can be used on multiple mobile devices to support portability and interoperability.

2. Security Tools

  • Mobile user’s identity and privacy will have to be safe guarded at all times. So the security tools/solutions should protect user’s identity information as well his data on the mobile device and during transactions over the network.

3. User Management and Metering Tools

  • Better management tools will help to encourage mobile users to get comfortable and help improve their confidence to do more business transactions on the device.
  • Metering Tools that will help users to track, analyse and monitor their data, transactions and quality of service over a period of time.

4. Advertising and Messaging Tools

  • Need better tools to engage and educate mobile users to the brands, value and benefits, accessibility of products and help with personalize data based on consumer’s usage trend and habits.

5. Data Management Tools

  • User data could be of several forms like  the identity data,  application data,  their search data, user’s contextual data, etc. This data will grow overtime and needs to be managed effectively so they are backed up and archived timely so no data is lost and can be will be used as a knowledge base for future use.

Time to innovate and be creative!

Importance of competitive intelligence as a business strategy

Companies investing time and resources to do a regular analysis of their competitive landscape is a must  to stay innovative and  to be a visionary market leader.

How does competitive intelligence help?.

Understanding the competitive landscape helps to address these questions for any business.  Having the information to these questions will help to make the competitive information more valuable which then can be further analyzed and to make a decisions that can strengthen the overall strategy around business, sales, product and execution.

  • How do other vendors think?
  • What are their strengths?.
  • What are their weaknesses?
  • Where are they vulnerable?
  • How do they differentiate themselves?
  • What is their buyer’s requirements?

Once the competitive data is collected, several folks within the company can leverage it to make effective decisions:

  1. The leadership management team can leverage this data to drive business decisions
  2. Sales can use this as a good set of metrics to find new prospects or to up sell to existing customers.
  3. Product Managers can figure out a plan to address the gaps and weaknesses through product development or through product acquisition
  4. Marketing can prioritize their marketing budget to better address the market with the right messaging and positioning statements to validate the strengths against other vendors.

How to go about with gathering competitive intelligence?.

1. Do SWOT Analysis: Competitive intelligence professionals often use an analytical technique called SWOT — an acronym for Strengths, Weaknesses, Opportunities, and Threats. The effectiveness of SWOT’s, it can be the starting point for analyzing your position relative to that of your rivals.

2. Study competitors company website, products features, product pricing, product positioning, marketing channels and delivery models to seek their differentiation factors.

Check out additional ideas around these steps from another blog site http://productmanagementtips.com/2011/02/26/competitive-analysis-sources/

3. Talk to the analysts and read through the analyst reports to understand the market trends and the overall market scope.

4. Do regular win/loss analysis to better understand your customer’s and prospect’s buying requirements and needs.

5. Present at trade shows and speaking at conferences can facilitate a way to understand the needs of existing and future customers.

Send me your comments if you have additional ideas to make this exercise a move effective program for any company to adopt.

Future of Web Applications as I see it

If  enterprises have to stay current they have to invest and innovate to make sure that their web applications and user experience stays on top of their list when it comes to their web strategy. As cloud computing grows in 2013 and SasS becomes one of the main delivery models for the software enterprises, the Web will be the primary access model for the application users.

Enterprises will see an increases in demand for web resources. The web application development will also evolve at a faster pace with the advent of innovations like HTML5 to help support rich web applications . To keep the development and maintenance costs low and reduce the cost of ownership, there will be a greater need to make sure the web applications that the enterprises build are supported across multiple platforms, cross browsers (IE, Chrome,Safari, Mozilla) and cross devices (desktops & mobile).

What’s the magic bullet?. 

HTML5

HTML5 is the future!.  Steve Jobs saw this coming in In April 2010 when he announced the demise of Flash and what the future is for HTML5 in his public letter titled “Thoughts on Flash”.

 

Why HTML5?.

Fast, Secure, Responsive, Interactive, Rich, Easy, Portable, Stunningly beautiful are the words that is used to describe the web application developed with HTML5.

HTML5 not only supports the core HTML components to help define an enterprise quality structure of the web application but also allows support for CSS3 to have a great visual presentation and support for JavaScript helps to control and manage the behavior of the application. Will all these capabilities in HTML5 developers can have a very rich web application framework to build on top. Since most browsers already support HTML5 is becoming the de fecto standard at a faster rate than expected.

Here is what some early adopters like Apple showcased in 2010 on what HTML5 can do http://mashable.com/2010/06/03/apple-html5-showcase/

Recently, I came across a demo put together by the Sencha’s team around the power of HTML5 captured in this video http://vimeo.com/55486684. This proves how native mobile application development will soon become the topic of the past  and the future of web applications is HTML5

2013 Mobile Predictions – from Appcelerator/IDC Report

With the BYOD becoming the norm for enterprise application and its users, here is an IDC report on how the mobile development landscape will look like in 2013.

Download the Appcelerator/IDC Q4 2012 Mobile Developer Report.

Some Key findings:

  • Interest in iOS and Android Platforms Remains Stable
    Despite the introduction of new products in Q4 and the massive success of devices like the iPod mini, Amazon Kindle, Samsung Galaxy S III, and iPhone 5, developer interest in the most popular platforms (i.e. iOS, Android, Blackberry) remains high, but relatively unchanged since Q3 2012.
  • Amazon Kindle Struggles
    Despite Amazon’s sizeable investment in its signature Kindle tablet, developers doubt that the device provides significant revenue opportunities.
  • Google Nexus Starts Strong
    An unprecedented number of respondents express strong interest in developing mobile apps for the Nexus platform.
  • Microsoft Surface Insufficient
    Microsoft’s Surface tablet has yet to excite the developer community.
  • Mobile Will Forever Change Retail
    Mobile developers anticipate that it is “likely to very likely” that most retail companies will have enabled mobile commerce in 2013.