Our State of Authorization: AI Edition is now available Get it now »

Identiverse 2025 Recap with David Brossard and Matt Luckett

A recap of the 2025's Identiverse in Las Vegas featuring conversations surrounding authorization, XACML, Zero Trust, and more!

We’re breaking the code — what happens in Vegas doesn’t always stay in Vegas! A few weeks ago, our team ventured out to Las Vegas to attend Identiverse. I recently sat down with our CTO, David Brossard, and our VP of Customer Relations, Matt Luckett, to hear what really happened in Vegas. Check out below to see conversations surrounding authorization, Model Context Protocol (MCP), and more!

The Axiomatics team at identiverse 2025

Authorization was a trending topic at last year’s event. How has the topic evolved since then?

David: Because OpenID AuthZEN had an interop scheduled at Identiverse and two dedicated sessions on the agenda, including a panel with all three chairs, authorization was bound to be one of the key topics this year. During the keynote, the organizers introduced a word cloud where attendees could submit topics such as AuthZEN, eXtensible Access Control Markup Language (XACML), Abbreviated Language for Authorization (ALFA), and other authorization topics that were top of mind.

In one session, Nat Bongiovanni (Chief Technology Officer at NTT Data Federal) talked about attribute-based encryption,Zero Trust, and how authorization can enable a more secure world for businesses. Other sessions included deep dives on embedding Policy Decision Points (PDPs) or applying fine-grained authorization to AI and the MCP. The Eve Maler in me feels like there is a Venn diagram of such topics:

AI, Zero Trust, AuthZ venn diagram

Matt: What was really interesting about authorization this year was the focus and interest across most organizations to look at standardizing, specifically standardizing on policies across applications and on the approach, with AuthZEN being front and center. Most organizations have found themselves inadvertently investing in many technologies and the idea of using AuthZEN to pull them all together was exciting for them.

What topics were discussed most this year? Were there any that surprised you?

David: Identity is still at the heart of every conversation. Its reach has increased. We’ve moved past workforce identity, consumer identity, and even partner identity. 2025 is truly the year of “everything identity” where even processes, workloads, and AI have identities. This is the advent of what some call non-human identities (NHI). This is truly fascinating and creates new opportunities for everyone in the near future. From an authorization standpoint, it enables new scenarios such as constrained access delegation. For example, I grant an AI agent the ability to book trips for me, but only up to a certain point.

What also surprised me, is the speed with which AI is advancing. MCP and Agent2Agent (A2A) were novelties a few weeks ago and now they are part and parcel of every conversation. One presentation even talked about applying fine-grained authorization to MCP. Fortunately, the attribute-based access control (ABAC) architecture we follow is well suited to the MCP approach.

Matt: When going to the different presentations, the topic of identity was still core to the conversation. This was really surprising to me as identity has been a challenge most organizations have invested in multiple times. What this tells me, is that these organizations investing millions of dollars aren’t getting the return on their investment that they were expecting. The problem is that identity is only the first step. Building intelligent authorization that leverages the identity store completes the investment, and sets up the access permissions.

Beyond the identity conversation, the AuthZEN conversation kept popping up. It’s very new to the market, hasn’t been released yet, and is still a widely discussed topic. This tells me organizations are fighting internally to get a handle on their authorization policies.

How do you see these conversations evolving within the next year?

David: As co-chair of the AuthZEN WG, I really want non-authorization vendors to get involved. This starts with identity providers plugging into the AuthZEN ‘fabric’ and goes beyond non-identity vendors e.g. any Software as a Service (SaaS) or Commercial-off-the-self (COTS) such as a CRM or ERP.

I am also seeing a possible convergence of multiple products and areas. Authorization as we know it is seeping into the land of Identity Governance and Administration (IGA) as it’s expanding into the land of runtime authorization. This begs the question: is it time for an overarching “authorization management platform”? My peers in the Shared Signals Working Group are also investigating the use of events to adapt rapidly to changing situations. For instance, sessions that are relatively static today could become more dynamic by adapting their scopes based on external signals.

Matt: Each organization is at their own pace for setting up their identity and access controls. For the organizations that are still trying to fix their identity problem, I think some will look at more and more identity vendors to try and solve the problem, but others will start to clean up their existing intrusion detection and prevention systems (IdPs) and look at integrating with an authorization solution. IdPs provide a great gatekeeper for access and verification, but don’t provide a solution for the time after the user is logged in.  Authorization, on the other hand, takes the user’s identity and then pulls the user’s attributes when they attempt to access information within an application.

Do you have a favorite moment or session from the conference?

David: Of course! Seeing Andrew Hindle, our host, show some dance moves on stage to the beat of a local rapper was priceless. From a technical standpoint, the presentation by Nat Bongiovanni, Chief Technology Officer, NTT DATA Federal was fascinating to understand how to get to Zero Trust.

Matt: As the VP of Customer Relations within Axiomatics, I’m biased on my favorite moment. I was fortunate to have multiple engaging conversations with customers at our booth. What stood out most in conversations is our commitment to support even when challenges arise that fall outside our direct responsibility, they know they can count on us. We were even lucky enough to introduce multiple customers to each other to collaborate and connect. It’s moments like these that get me excited about next year!

Axiomatics booth identiverse 2025

Thank you to those who visited us at Identiverse!

It was a pleasure getting to connect with both new and familiar faces at our booth. Want to read more about what we talked about at the conference?

Here are three great resources for you to look into:

Didn’t get the chance to talk with us at Identiverse? Request a demo and join the movement towards modernized, scalable runtime authorization and access control.

We look forward to seeing you again next year for Identiverse in 2026!

Have 30 minutes? Let's show you a demo!

See how our award-winning solution can help you meet today's access control and Zero Trust needs.

Request a demo

  Join us on LinkedIn for more insights
Archived under:
About Axiomatics

The world’s largest enterprises and government agencies continually depend on Axiomatics’ award-winning authorization platform to share sensitive, valuable and regulated digital assets – but only to authorized users and in the right context.