A few weeks ago, the Axiomatics team went to London to attend the Gartner Identity and Access Management (IAM) summit. I sat down with our CTO, David Brossard, to get an in-depth look on the conversations that happened surrounding authorization, AI, application programming interfaces (APIs), and more.
What was a standout moment or session from the event?
I went to a handful of sessions — never enough, as always — and the one that stood out to me was Paul Mezzera’s session on “authorization management platforms” (AMP). Paul achieves two important things: first, he redefines AMP as a key initiative attendees should focus on next. Second, he broadens the scope or focus of AMP. Gartner evolved from externalized authorization management (EAM) to a more inclusive approach to authorization.
The new approach includes:
- The ‘traditional’ approach, as recommended by NIST ABAC 800-162 and NIST 800-207 (Zero Trust Architecture)
- A token-based approach, where identity/access tokens are enriched with dynamically generated claims coming from a policy decision point (PDP)
- A provisioning-based approach, where the authorization platform (Axiomatics) provisions rich entitlements or even policy snippets to a target system
This aligns with Homan Farahmand’s vision for policy orchestration.
But perhaps the biggest highlight, however, was the opening keynote. Michael Kelley and Akif Khan redefined the required layers in IAM and surfaced “runtime authorization” in the layers. It’s clearly no longer a second-rate topic.
What were the major authorization trends highlighted at the event?
To paraphrase my co-chair on the OpenID AuthZEN working group: “Authorization wasn’t tucked into a single session this year. It was everywhere woven through at least a dozen analyst presentations and most of the hallway conversations.”
Homan Farahmand, Erik Wahlström, and Paul Mezzera all talked about authorization, as reflected in this article. Authorization management platforms now have their own dedicated section and guidance.
Erik also highlighted emerging standards, including OpenID AuthZEN and its sibling group, Shared Signals.
This signals that vendors must adopt AuthZEN sooner rather than later to enable Identity Fabric 2.0. It also acknowledges the work done by members of the working group.
Are there any trends that you see growing based on what you heard at the conference?
Obviously, AI is going to grow. That’s a given. The keynote alone emphasized the need to regulate authorization rights for AI agents.
Homan Farahmand shared key data points on agent adoption. The AI concept is no longer a thing of the future. It’s already happening and companies are now expected to securely support these deployments.
He also outlined the different layers of authorization required to properly secure AI agents. The layers include:
- Fine-grained access control
- Context-aware access control
- Resource-level access control
- Delegation of authority
- Human-in-the-loop authorization flows
- Rich authorization requests
There’s also another interesting trend. We’ve been talking about Zero Trust for years now but it’s a topic that’s largely been the prerogative of the network layer. In fact, Zero Trust is often equated with Zero Trust Network Access (ZTNA). Today, however, we are getting closer to achieving true Zero Trust through identity everywhere, continuous authorization enforcement, and runtime access control.
The concept of identity fabric — bringing together the best of user management (authentication, workforce, consumer) with runtime, policy-based access control — promises to achieve a real plan for Zero Trust. As Erik Wahlström noted in one of his sessions: “Zero-trust journeys require an identity-first security approach, and it must be powered by a radically modernized IAM infrastructure.” He later proposed an architecture for Identity Fabric 2.0, where the Authorization Management Platform (AMP) has its own dedicated role.
How did the AuthZEN session go?
It was fantastic. It’s always a pleasure to co-present with Homan and my fellow chairs. We ran through the achievements of the past twelve months including achieving standardization for the core specification back in January.
We also discussed the roadmap for the next 12 months, including expanding into AI with an MCP-dedicated profile and support for advanced use cases like partial evaluation. We wrapped up with a live demo, showing how a range of PDPs can be used interchangeably, and how access tokens can be enriched with dynamically generated claims.
What are your top insights/takeaways from the summit?
My top takeaways are:
- Identity Fabric 2.0 is becoming a reality and is enabling Zero Trust
- Authorization is becoming a core topic
- The definition of authorization has broadened to Authorization Management Platform (AMP) including at least 3 ways to tackle fine-grained access control
- AI will require runtime, fine-grained access control. AMP can help tackle AI authorization needs.
- AI Agent authorization will require consent management and access delegation
Thank you to those who visited us at Gartner!
It was a pleasure connecting with both new and familiar faces at our booth, as well as with everyone who attended our session on Zero Trust for AI.
While at the summit, David Brossard also participated in an interview with iSMG Studio, discussing how modern applications have outgrown role-based access control, along with other trends highlighted at the event, including AI. You can watch the full interview here.
Want to read more about what we talked about at the conference? Here are three great resources for you to look into:
- Securing the AI frontier: A CISO’s guide to access control for MCP
- Agentic AI and NHIs: Why authorization is a must-have
- Secure your RAG: Where to start?
GARTNER is a trademark of Gartner, Inc. and its affiliates.



