Access governance is undergoing a fundamental shift. Traditional models based on periodic reviews and long-lived access are being challenged by automation, short-lived credentials, and event-driven decision-making. This track explores how organizations are moving toward more dynamic approaches that reduce risk while maintaining compliance.
Sessions will examine how access recertification, long a cornerstone of governance, is gradually being replaced by models that avoid standing privileges altogether. By using just-in-time access, automated workflows, and continuous evaluation, organizations can reduce the need for retrospective reviews and instead enforce policy at the moment access is granted and used.
A key theme is the growing role of non-human identities in governance. Bots, services, and autonomous agents are increasingly involved in access decisions and execution, requiring governance models that can operate at higher speed and scale. Attendees will gain insight into how to manage these identities, balance automation with oversight, and transition toward event-driven access control without losing auditability or control.
The track also explores emerging and often overlooked aspects of identity governance, such as the management of digital identity throughout the lifecycle of a person’s digital identity. Questions around digital estates, ownership, and access after death highlight gaps in current models and the need for new frameworks that address both technical and societal requirements.
Across these topics, the focus is on evolution rather than replacement. Participants will gain a clearer understanding of how to move from static governance practices toward more adaptive, automated approaches while continuing to meet regulatory expectations and real-world needs.