In 2026, “identity” is no longer just about human login and static credentials. Cloud-native applications, automation, agents, and AI-driven services routinely execute privileged actions, often without explicit consent, oversight, or accountability.
In this keynote, the argument is made that existing IAM/PAM frameworks were not designed for this reality. The consequence is not just complexity, but blind spots, shared secrets, and silent failures.
The session illustrates why authentication is not authorisation and why privileged access management as we knew it is obsolete. We’ll introduce the concept of a dedicated authorisation control plane, one that enforces real-time, contextual decisions at the moment of action, treats all identities, human and non-human, the same, and ensures full auditability and accountability.
Finally, the keynote explains how this approach is not a new buzzword or category label, but the only realistic path forward if companies need to manage identity risk and compliance reliably in a world of automation, microservices, and machine speed.
Attendees will walk away with a clear understanding of the structural challenges in traditional access models and a practical vision for how to rebuild identity control for modern environments.