A few weeks ago, our team travelled to Berlin for the KuppingerCole European Identity Conference (EIC) in Berlin. With the festivities coming to an end, it’s given our team some time to reflect on all of the inspiring conversations surrounding authorization and access control, and the interactions at the event.
I sat down with our Chief Technology Officer, David Brossard, to get an in-depth look at everything EIC.
What were the major authorization trends or issues highlighted at the event?
Authorization was definitely front and center at the European Identity Conference. It started off with a pre-conference workshop dedicated to OpenID. During the morning session, we presented the results from OpenID AuthZEN, the new standard for interoperable authorization, and OpenID Shared Signals, a new approach to authentication and authorization. My peers and I showed the progress achieved in AuthZEN with an additional 8 parties interoperable: 8 API gateways that took part in the Gartner IAM London 2025 Interop.
The highlight was definitely Martin Kuppinger’s opening keynote. In one of his early slides, he outlines the top trends reshaping identity access and management (IAM). In spot #1 came policy-based access control (PBAC).
Policy-based access control:
- Zero standing privileges
- Decision based on static data, context, signal, behavioral data, risk data
- Shifting towards autonomous, AI-based decision, beyond policies
To quote my former manager and mentor at Salesforce, Ian Glazer,
"It’s a fundamental shift in how we approach access. The days of static roles and permanent entitlements are numbered. Instead, access decisions will be made in real-time based on a rich tapestry of contextual signals and data points, eventually moving beyond traditional policy constructs to AI-driven decisions." - Ian Glazer, Salesforce
Last year, the event focused on topics around authorization. How did this year’s event build on that, if at all?
It was a direct evolution of last year’s focus on authorization. PBAC is definitely more important than ever. Additionally, a new term (and acronym) surfaced: zero standing privilege (ZST). This can be seen as a rebuttal of IGA-driven authorization which uses standing privileges to define access control. We’ve now seen the limitations of this approach and the risks associated with it.
Based on what you saw at the conference, what trends do you think will evolve in the near future? Are there any new trends that you think will emerge?
One of the emerging working groups at OpenID is the Shared Signals Framework (OpenID SSF). They take an interesting, perhaps more pragmatic, approach to zero standing privilege and fine-grained access. Rather than relying on the more dynamic policy enforcement point-policy decision point (PEP-PDP) approach to authorization, they acknowledge many apps are built with tokens in mind (OAuth or OpenID Connect and even SAML). If that’s the case, then these very tokens should be used to carry authorization data to the apps. This will allow legacy apps (COTS and SaaS) to benefit more quickly from fine-grained authorization.
Identity fabric is also an interesting topic I’ve heard more about both at EIC and the Gartner IAM even back in March. Analysts are observing that previously disconnected and independent IAM solutions (for user management, authentication, privileged access management, and access control) must now be orchestrated in a consistent and coherent manner. I’m definitely pleased to see this. As an authorization provider, we benefit from more orchestration and consistency to help inform richer policies and decision-making processes.
Last but not least, AI-dentity is the portmanteau du jour. What it reveals is two-fold:
- AI is everywhere and will continue to grow
- We need identity everywhere: end-user identity, delegated access, agent identity, machine identity, and workload identity.
Does it impact authorization? Yes, it provides us with the ability to make smarter decisions. It enables policy-based products to fully implement constrained delegated access (such as letting an agent act on my behalf but only to a certain extent).
And speaking of agents, my friend and peer Alex Babeanu presented on the topic of authorization applied to AI. Three models emerge:
- Authorization applied to RAG-based models. This is very similar to the way we’ve been tackling data-centric access control (for dynamic data filtering and masking at runtime).
- Authorization applied to the Model Context Protocol (MCP). The MCP defines an architecture and API that is compatible with NIST’s SP 800-162 attribute-based access control (ABAC) architecture, as well as the NIST Zero Trust architecture in 800-207. We can insert PEPs in the MCP architecture to enforce fine-grained authorization.
- According to Google who pioneered the term, A2A is an open protocol that provides a standard way for agents to collaborate with each other, regardless of the underlying framework. The A2A architecture defines a natural place for PEPs to be inserted so they can enforce authorization.
What surprised you the most about this year’s conference?
Perhaps two dimensions:
- The diversity of customers present at the conference. We had people from manufacturing, defense, retail, and many more industries at the Axiomatics booth.
- The importance of the developer. Traditionally, those who worry about authorization tend to come from the world of IAM, but there is an emerging trend around developer efficiency that’s driving engineering managers to consider externalizing authorization.
Are there conversations that impacted you the most either through the sessions or on the floor?
I had the privilege of talking to Eve Maler of Venn Factory and Allan Foster, both of whom are former CTOs at ForgeRock. Allan and I mused about future authorization models, perhaps informed by even more signals and AI-driven insights. Maybe we will reach a world where our activities will determine whether we should get access. This is particularly interesting for the insider threat where a disgruntled, but entitled, employee starts stealing data. Is there a policy to prevent that? Not really. Can AI detect the deviation in behavior? Definitely. It sounds scary, but I think it is definitely a reality that is closer to our present than ever before. Either that or I should call Black Mirror’s writing team to work on a new episode for the show, one about a dystopian, authorization-fueled world where bad guys cannot get away with anything.
Thank you to those who visited us at EIC!
It was a pleasure getting to meet new and familiar faces at our booth and sessions. Want to read more about what we talked about at the conference?
Here are three great resources for you to look into:
- State of Authorization: Playbook Edition (newly updated!)
- Introducing the era of authorization with AuthZEN
- Alleviating IAM technical debt through policy-driven authorization
Didn’t get the chance to talk with us at EIC? Request a demo and join the movement towards modernized, scalable runtime authorization and access control.



