Most Identity and Access Management (IAM) programs were built for a world that no longer exists. They were designed around a stable set of workforce accounts, a handful of contractors, and maybe a customer portal bolted on later.
That model breaks the moment Non-Human Identities (NHIs) begin to outnumber human ones by an order of magnitude, and Artificial Intelligence (AI) agents start requesting access on their own initiative.
This post looks at why architecture is the real fix for future-proofing IAM, rather than another tool. It covers the shift from siloed IAM to a modular Identity Fabric, the governance challenge posed by NHIs and agentic AI, and the growing need for orchestration and portable trust across organizational boundaries.
From Silos to a Service-Based Fabric
Traditional IAM was built tool by tool. Each addition solved an immediate problem while adding another integration to maintain, leaving most enterprises today with a patchwork of systems never designed to work together.
The Identity Fabric model, as developed by KuppingerCole Analysts, replaces that patchwork logic with a layered structure of capabilities, services, and tools mapped against every type of identity and every system that identity needs to reach. It does not demand a rip-and-replace project. Organizations can start with a converged platform and extend it piece by piece or they can combine tools from several vendors in a loosely coupled way. Either path works, because a fabric is an architecture rather than a single product.
KuppingerCole Analysts' 2025 Identity Fabric and IAM Reference Architecture sets out that layered model in detail. A follow-on advisory note, Operationalizing the Identity Fabric and Reference Architecture, translates it into roadmaps that architects and program owners can execute. Between them, the two documents answer the question every Chief Information Security Officer (CISO) eventually asks: How do we get from the diagram to a working program?
The fabric also solves a communication problem. A detailed reference architecture means little to a finance director signing off the budget, which is why KuppingerCole Analysts maintains a lean version reduced to four core capabilities:
- User lifecycle management
- Access governance
- Access management
- Authorization
KuppingerCole Analysts uses that simplified view in board briefings, because a two-minute explanation that gets the point across beats a 30-minute walkthrough that does not. Neither version replaces the other: the detailed model guides the build, while the lean model wins the budget for it.
The Machine Takeover Nobody Governed
Ask most IAM teams how many human employees they manage, and they will usually have an answer in seconds. But ask how many service accounts, API keys, and autonomous agents are running, and the answer is rarely definite.
That uncertainty itself is the problem: NHIs, a category that spans service accounts, machines, workloads, APIs, and now AI agents, do not behave like human identities. They scale faster, interact with each other, and rarely go through the onboarding and offboarding rituals built for employees. KuppingerCole Analysts' advisory note From Machine Identity to Agentic AI: Charting the NHI Continuum traces this progression from static credentials to context-aware agents that request, delegate, and act without a human in the loop.
A real tension has emerged among analysts and vendors over how to handle this. Some IAM teams treat agentic AI as another provisioning workflow: grant access at deployment time and move on. KuppingerCole Analysts' position is that autonomous agents need continuous, runtime authorization instead, because a provisioning-time decision cannot account for what an agent chooses to do days later. Organizations that only solve NHI governance at the front door are solving only half the problem.
That gap between granting access and ever revisiting it is not hypothetical. At EIC 2026, GitGuardian presented its State of Secrets Sprawl 2026 findings that 28.65 million new hardcoded secrets turned up in public GitHub commits in 2025 alone, a 34% jump over the year before, and 64% of secrets leaked back in 2022 are still valid because nobody revoked them. Few teams can name who owns a given secret, when it was created, or what it can actually reach.
KuppingerCole Analysts' report on Machine Identities walks through the lifecycle risks behind that blind spot, from orphaned credentials to forgotten repository secrets. For teams building a business case, KuppingerCole Analysts’ Buyer's Compass on Non-Human Identity Management sets out the discovery, classification, and policy controls that a credible NHI program needs.
Trust That Travels Beyond the Perimeter
Identity no longer stops at the firewall the way it used to. Employees work with partners, contractors, and customer-facing platforms that sit outside any single organization's control, and each of those relationships needs a way to establish trust without a phone call to IT.
This is where orchestration and portable credentials take over from simple authentication. An Identity Fabric only delivers value if its services can be composed on demand, routing a request through the right combination of authentication, authorization, and governance checks regardless of where the identity originated. But that composability has always assumed the organization provisioned the identity in the first place. Verifiable credentials and wallet-based models, including the EU Digital Identity Wallet (EUDIW) now moving toward production, remove that assumption, letting an identity carry proof of who it is into a relationship the organization never directly provisioned.
KuppingerCole Analysts' advisory note on Identity at the Speed of Business: From Architecture to Organizational Value makes the business case directly, arguing that shifting IAM from one-off projects to continuous, service-oriented delivery is what lets identity keep pace with the speed at which the rest of the business now moves. Faster onboarding, better policy enforcement, and fewer manual exceptions are the point of this shift, not incidental side effects of it.
None of this works if every partner and platform needs its own integration project. This is why orchestration exists inside the Identity Fabric as a distinct layer rather than a feature bolted onto a single tool. A fabric that can route a request through the right sequence of checks, whatever the source, scales in a way that direct, tool-to-tool integrations never will. Decentralized identity and wallet-based credentials push that same logic outward, letting proof of identity move with the person or system rather than staying locked inside one organization's directory.
Where the Theory Gets Tested
There is a real difference between reading an advisory note and watching architects and CISOs argue over how it holds up in production, and that is exactly what is on offer at KuppingerCole Analysts' Identity Fabric Impact Day, taking place on September 9 in Cologne, Germany.
The agenda is designed to address every challenge raised above. A dedicated Futureproofing IAM track runs alongside sessions on evolving the Identity Fabric itself. Ping Identity's Matthew Berzinski is to give a presentation on establishing continuous trust across the extended workforce, the exact population this post has argued a fabric built only for full-time employees cannot cover.
Fraunhofer IAO's Isaac Henderson and Fraunhofer FIT's Wolfgang Prinz follow will discuss decentralized identity as organizational infrastructure, and John Erik Setsaas of Setsaas Trust Advisory will close the loop with a look at what the EUDI Wallet actually means for a working Identity Fabric. That pairing is important because portable, wallet-based credentials are the clearest test of whether an organization's fabric can extend trust beyond its own perimeter, or whether it only ever worked inside one.
And Martin Kuppinger, who created the Identity Fabric model, will take questions directly from the floor in an "ask the creator" session.
Build the Architecture Before You Need It
Future-proofing IAM means adopting an architecture, the Identity Fabric, that absorbs new identity types, new trust relationships, and new governance demands without breaking, rather than buying a newer version of the same tool.
Three things worth prioritizing:
- Treat NHIs and agentic identities as a distinct governance problem.
- Build orchestration that extends trust beyond your own perimeter.
- Start from a reference architecture rather than a shopping list.
Identity Fabric Impact Day 2026 puts the analysts and practitioners solving these exact problems in one room. Register now to be part of the discussion.