KuppingerCole Analysts have been developing and working with the Identity Fabric for years. It is not a new concept, nor is it a short-lived trend. It has proven to be a reliable framework that helps organizations structure and benchmark their Identity and Access Management (IAM) initiatives across a wide variety of environments and use cases.
While the Identity Fabric has stood the test of time, the IAM landscape is certainly not static. While frameworks such as this aim to provide structure, the reality they depict is constantly changing. This creates an interesting dynamic leading to a fundamental question: How static can a framework remain when the domain it describes is evolving rapidly?
From isolated components to a unified identity approach
The KuppingerCole Identity Fabric represents a clear shift in perspective. Instead of focusing on isolated IAM components, it presents a unified, service-oriented approach. This is less a matter of technical preference than a necessary response to increasingly heterogeneous IT landscapes.
Organizations no longer operate within clearly defined boundaries. Identities interact across cloud services, on-premises systems, partner ecosystems, and customer facing platforms. Managing these interactions with isolated tools is not only inefficient but also risky.
The Identity Fabric addresses this by providing a structured, high-level framework. It does not replace detailed architectures, but it gives them an overarching context. In particular, the “Capabilities” block serves as the direct integration point to the IAM Reference Architecture. While the Identity Fabric provides a high-level conceptual framework, the IAM Reference Architecture offers detailed architectural insights and design patterns for each capability. This combination creates something that is often missing in IAM: A consistent link between strategy and implementation.
Further details on the KuppingerCole Identity Fabric and the IAM Reference Architecture can be found on our website: https://www.kuppingercole.com/research/an80978/the-2025-identity-fabric-and-iam-reference-architecture
A changing identity landscape requires a stable strategic compass
For a long time, the identity space seemed relatively stable with just some minor changes over the years. Organizations differentiated IAM mainly by identities such as workforce, partners, contractors, and consumers. While there were variations, the overall structure remained largely unchanged.
This established state is currently rapidly changing. Non-Human Identities (NHI) are not simply another identity type added to the list. NHI represents a new category of identities, introducing fundamentally different requirements and characteristics. Machine identities, service accounts, APIs, workloads, and now AI agents, behave differently than human identities. They scale differently, interact differently, and require different governance and lifecycle approaches.
Interestingly, these NHIs are not really new, other than AI agents. What is new is the way the market and organizations are defining, structuring, and prioritizing them. This increased focus has led to new requirements that are not only technical, but also functional and organizational. Questions around ownership, lifecycle, accountability, and security become significantly more complex, perfectly represented by the emergence of AI agents.
Such developments inevitably impact frameworks. They must adapt, extend, and sometimes redefine their scope. One of the strengths of the Identity Fabric is that it does not break under such changes. Instead of becoming obsolete, it expands. The emergence of NHI does not invalidate the existing structure of the Fabric Identity but broadens its perspective.
This is a critical distinction. Many models fail when confronted with fundamental change because they are too tightly bound to specific assumptions. The Identity Fabric, however, provides enough abstraction to remain valuable while remaining concrete enough to offer guidance. In this sense, it still acts as a strategic compass. Especially in times of change, such guidance becomes even more valuable.
Extending IAM instead of redefining it
With the growing importance of NHI, it might be tempting to speak of a completely new discipline. However, what we observe is not a replacement of Identity Management, but an extension of IAM to encompass them.
Existing IAM reference architectures have focused on human identities such as workforce, partners, and consumers. These areas are well understood, and mature patterns exist for their implementation. For NHIs, the maturity is still evolving. Definitions are evolving, best practices are emerging, and architectural patterns are still being shaped. This makes the development of useful reference architectures more challenging, as NHI is still moving.
Nevertheless, developing a Reference Architecture for NHI is exactly the next logical step. Since the Identity Fabric provides the overarching framework, additional reference architectures will follow to address the specific requirements of NHIs. This layered approach ensures that IAM evolves without losing coherence.
At the moment, many IAM experts are actively contributing to the definition and structuring of NHI management and security. This collective effort is essential to transform an emerging domain into a well-defined discipline. For KuppingerCole, this means translating these developments into structured guidance. The goal is not only to observe the market but to provide frameworks that help organizations navigate it.
EIC 2026 will be an important milestone for this. Bringing together IAM experts in Berlin once again will accelerate the shared understanding of NHIs, the evolution of the Identity Fabric, and the broader IAM landscape.
Because while technologies and requirements change, the need for clear, structured, and adaptable guidance remains constant. See you in Berlin!