API-first architectures and microservices introduce a new class of identities - workloads - whose access needs are dynamic, unpredictable, and impossible to capture with traditional IAM models. When a single request can trigger a chain of service-to-service calls, how do we ensure every step respects the user’s entitlements, without over-privileging the services themselves?
In this session, Reiner Mertens, Lead Advisor at KuppingerCole Analysts, argues that this is not primarily a technology problem. The tools exist - policy engines, token exchange standards, workload identity frameworks. The problem is organizational: IAM programs are not designed for a world where no single team owns the full API graph, where services are built before authorization is designed, and where policy ownership has no clear home.
Participants will leave with a clear understanding of the challenge, a strong advisory perspective on what must change in IAM programs, and an initial reference model for approaching dynamic entitlements in modern service architectures.