The identity governance trends worth planning around all started as engineering decisions, and governance is catching up. Teams connected agents to production systems, moved entitlements into cloud consoles, and issued credentials that no joiner, mover, or leaver process ever saw.
Most of the access an attacker uses was granted on purpose. It went to a person who has since changed roles, to a script that outlived its project, or to an agent a team stood up in an afternoon. Nothing has to break for it to be abused, and the sign-in looks ordinary in the log.
That gap is what the next planning cycle has to close, which is why the direction of travel matters more than any single control.
Key Takeaways
- Governance is moving from periodic certification to continuous evaluation, which changes what teams instrument more than what they decide. AI is most credible in that shift as a recommendation and explanation layer, with autonomous revocation a smaller and higher-assurance subset.
- Agent adoption is outpacing the governance model built for employees, and the gap shows up first in attribution rather than in access.
- Standardized agent connectivity narrows the integration problem and widens the authorization one, because a common protocol makes reach easier to acquire than to bound.
- Non-human identities are taking the larger share of governance attention, and budgets built around headcount will lag that.
- Identity security and identity governance are converging on the same data, which is why separate posture and governance programs increasingly duplicate each other.
- The practical value of an identity fabric is a single answer to the access question, not the architecture diagram that produces it.
The State of Identity Governance in 2026
Three things changed since the last planning cycle, and together they set the identity governance trends 2026 will be judged by. Access moved into consoles that no central workflow fulfills. Credentials started being issued at the edge, by the teams that need them. A new class of actor arrived that can hold an entitlement without ever appearing in a directory.
For most of the last decade, identity governance and administration trends followed the audit calendar, which is why so many IGA programs are still organized around campaigns. The definition of identity governance has not moved: deciding who and what should have access, granting it, and being able to prove the decision afterward. The practice is intact. The cadence it was built on is not.
A campaign run on a schedule assumes the population is stable between runs, and that a reviewer can still tell whether an entitlement is justified. Both assumptions held when the population arrived through an HR feed. Neither holds for a token minted this morning by a team that owns the pipeline and not the governance model.
Trend 1: Continuous Identity Governance Becomes the New Standard
The signal. The OpenID Foundation announced on September 2, 2025 that its membership had approved the Shared Signals Framework and the Continuous Access Evaluation Profile as Final Specifications. In OpenID terms they are no longer subject to revision. The profile defines event types that let one system tell another that a session's conditions have changed, so the receiver can attenuate access already in flight. The same direction shows up in an unrelated domain: the CA/Browser Forum's Baseline Requirements capped the validity of publicly trusted TLS certificates at 200 days in March 2026, with 47 days scheduled for March 2029.
Neither is a governance product. Both encode the same assumption: a decision made once and left standing decays. Continuous verification stops being an architecture preference at the point where the protocols around it assume it.
What this changes for a planning cycle is narrower than it sounds. The judgment a reviewer makes is unchanged. What moves is where it gets made and how quickly it can be revised, which is an instrumentation problem before a policy one. A roadmap that funds better campaign tooling and no event plumbing is funding the half that already worked.
Trend 2: AI Agents Create a New Identity Governance Challenge
The agent count often surfaces for the first time during an audit. Someone asks which AI systems can read the customer database. The answer takes three weeks and four teams, because the groups that needed agents connected them and registered them nowhere.
The access was often reasonable. The missing part is the record of who authorized it and on whose behalf it runs.
The standards community names the gap plainly. In January 2026, NIST's Center for AI Standards and Innovation issued a request for information on securing AI agent systems, asking how to constrain and monitor the extent of agent access in a deployment environment.
An Agent Identity Registry Protocol Community Group launched at the W3C three months later, on the premise that "there is no agreed upon mechanism for verifying an agent's identity, its controlling entity, or its authorization scope before interaction begins." Both are artifacts of a problem the field understands and has not solved.
The sequence inverts the usual governance order. For employees, access came first and attribution was implicit in the account. For an agentic workforce, attribution is the harder half, and the agent governance gap surfaces in the audit trail before it surfaces in the entitlement report. The subject has its own analyst literature now, including a complimentary report on securing agentic AI.
The twelve-month version is unglamorous. Record an owner, a purpose, and an expiry for every agent holding a credential, before anyone designs a policy engine.
Trend 3: MCP Becomes the Standard for Secure AI Connectivity
The Model Context Protocol (MCP) is making it easier to connect agents to tools and data. Authorization is the less settled half. Its current revision is dated 2026-07-28, and its own roadmap is a reason to be careful about the timing.
The roadmap acknowledges that MCP authorization still largely assumes a person approving access in a browser, while more callers are agents acting without that person present. It prioritizes ways for servers to recognize agent identities without relying on pasted API keys and long-lived tokens. An Agent Identity Working Group is forming to help close that gap.
Work is moving. The OpenID Foundation's AI Identity Management Community Group opened an interoperability event in July 2026 to test whether MCP clients, gateways, and servers from different vendors can secure the same flows. The standards under test are OAuth 2.1, the OAuth Client ID Metadata Document, and the Identity Assertion JWT Authorization Grant. Participants committed by 10 August and must show at least one successful cross-vendor test by 16 October 2026.
Paul Carleton, an MCP core maintainer, framed the two problems under test as agent governance and identity that survives crossing organizational boundaries. The honest form of this prediction is asymmetric. Standardized connectivity is arriving faster than standardized AI agent authorization, and a protocol that makes reach easy to acquire makes bounding it the scarce skill. Plan for integration to get easier and authorization to get louder, and treat any roadmap that assumes both are settled as optimistic.
Trend 4: Non-Human Identity Governance Overtakes Human Identity Management
Overtakes is a claim about attention, not a headcount. Published ratios of non-human to human identities vary by an order of magnitude depending on who counted what, so the defensible version tracks where the work is going.
The work is going somewhere observable. The IETF chartered Workload Identity in Multi System Environments to standardize how workload identity is represented and propagated across trust boundaries. The group also liaises with the Cloud Native Computing Foundation and the OpenID Foundation.
MCP's proposal queue includes workload identity federation. Standards bodies rarely charter working groups for problems enterprises have already solved.
Governance attention follows that, and budgets follow later. An identity program sized around joiners, movers, and leavers tracks a population that grows with headcount. The population generating most of the access questions, including service accounts, pipeline credentials, and agents, grows with the number of systems a company runs. Those are different curves, and a budget built on the first keeps arriving a year late to the second.
What to do about it. Treat the next twelve months as a counting exercise before a control one. One register of non-human identities, each with a named owner, drawn from the systems that issue them and not the system that hires people.
Trend 5: Identity Security and Governance Converge
Identity security posture management and identity threat detection and response get introduced as opposites, and they are not. ISPM is mainly concerned with standing weaknesses in how access is configured, ITDR with detecting and responding to identity abuse while it happens. Both read the same facts about who holds what. That overlap is the point, and governance shares it with both.
The convergence signal is architectural. A continuous access standard only works if a security signal can change an access decision with no human in the middle. That requires posture, threat, and entitlement data to resolve to the same identities.
Running posture and governance on separate inventories gives two answers to one question, and the second is the one an auditor finds. Teams already running identity security posture management hold most of the data a governance program needs, which is why the two increasingly buy against the same requirements.
Organizationally this lands before tooling does. Some identity and security teams that reported separately are merging reporting lines. Arguing whether an over-privileged service account is a hygiene issue or a threat issue stopped being productive. For a planning cycle, posture and governance requirements belong in one document, against one inventory.
Trend 6: Autonomous Identity Governance Powered by AI
Two claims travel under this heading, and they deserve different levels of confidence. AI that reads an identity graph and explains an access path in a sentence is demonstrated and already useful. AI that revokes production access on its own judgment, at scale, with no human in the loop, is not something any published standard or conformance test currently defines.
Look at what is being specified. The agent identity work in progress is deterministic: proof of possession, so holding a token is not enough to replay it; federation, so a workload attests to what it is instead of presenting a secret; and policy ceilings that bound what an actor may do regardless of what it attempts. In January 2026 NIST was still asking the field how to constrain agent access. That is not the posture of an industry about to hand revocation to a model.
The useful reading is a division of labor. Governance work that is expensive because it is tedious, like reconstructing how someone got access or drafting the evidence an auditor asked for, is where a recommendation and explanation layer earns its place this year. Work that is expensive because it is consequential stays deterministic, with automation bounded by policy rather than by confidence. Expect the autonomous share to grow from the low-assurance end, and slower than the marketing around it.
Trend 7: Identity Fabrics Unify Modern Identity Ecosystems
The term has a traceable origin, worth knowing before it goes into a budget request. KuppingerCole introduced the identity fabric around 2017 and 2018. Co-founder Martin Kuppinger has described it as starting life as a visualization before it became a framework for designing and operating identity and access management.
Two details matter. Non-human identities sat in the model from the beginning, before machine identity was a category. And the concept was published openly, in Kuppinger's words "not our secret sauce."
That history explains both its usefulness and its failure mode. A fabric is a way of thinking from capabilities to services to tools instead of from products backward. That makes it a common language between an identity team and the people funding it. It is also a diagram, and a diagram is easy to adopt without changing anything.
The test worth applying is behavioral. Ask what a named person or agent can reach across every connected system. If one current answer comes back, the fabric is doing its job, whatever the architecture looks like. If the answer still takes four consoles and a spreadsheet, the diagram has been adopted and the identity graph underneath it has not.
Conclusion: Preparing for the Next Era of Identity Governance
Readiness is less about tooling than about what a team can answer on an ordinary Tuesday. Two questions carry the weight: which identities here can reach a given system, and how each of them got that access. An organization that answers both without opening a project can absorb what the next two years bring. One that cannot meets each shift as a separate program.
Of the modernizing identity governance trends companies can act on before the next budget cycle, two change the plan more than the rest. Fund the inventory and the event plumbing first, in that order, and leave the policy engines until the population they would govern is known. The reason is sequencing: a continuous control applied to a partial list produces continuous confidence in an incomplete picture, which is worse than a slow control applied to a complete one.
The architectural version of that argument, that retrofitting a fifteen-year-old identity stack is not the same as modernizing it, is set out in the new identity manifesto. What it asks of a planning cycle is modest: decide what you intend to be able to answer twelve months from now, then work backward from it.
What NewCore Is Building for the Next Governance Era
Every one of these shifts assumes something not yet true in most environments: a current and complete list of the identities inside it. Continuous evaluation of a partial inventory is a partial inventory, evaluated faster. NewCore's view is that the list is the prerequisite, and the part nobody predicts because nothing about it is forward-looking.
NewCore was built around that problem, as a complement rather than a replacement. Whatever a team's stack looks like after these shifts, it will still need one current answer to who and what can reach a given system, and the governed action that follows.
- Identity Discovery: connects HRIS, directories, IdPs, IGA, PAM, cloud, SaaS, and AI platforms, then continuously indexes every identity, account, credential, and access relationship into one record and graph. The risk it removes is planning continuous governance on top of a list that was incomplete from the start.
- Agentic Governance: Agentic SSO, Task-Scoped Tokens, AI Inventory, and Machine-Speed Security, applied inline on governed agent access requests, with each agent classified by where its authority comes from. The risk it removes is agent adoption outpacing a governance model built for people.
- Ask NewCore: identity questions asked in plain language and answered from the identity graph, with governed action on the same screen. The risk it removes is an access answer that arrives after the decision had to be made.
No second IAM stack, no standing secrets, no second governance process invented for agents. Identity Discovery, Agentic Governance, and Ask NewCore run against the same graph, for humans, machines, and AI agents alike. Predictions are cheap. The list is not.
The next era of identity governance is already being planned. Start from what you can see. Request a Demo →
Frequently Asked Questions
Do these shifts change what auditors ask for?
Not immediately, and not uniformly. Audit expectations follow the control frameworks an organization is assessed against, and those move slower than the technology. What changes sooner is the evidence a reviewer accepts: a list of identities that excludes agents and pipeline credentials answers a narrower question than the one being asked.
Should an identity team wait for the agent identity standards to settle?
Waiting on the specifications is reasonable. Waiting on the inventory is not. The authorization standards for agents are in active development, and the working groups closest to them call the work unfinished. Recording an owner, a purpose, and an expiry for each agent holding a credential costs little and stays useful whichever specification wins.
Is continuous evaluation a replacement for access certification?
For most organizations certification is likely to stay and continuous evaluation to sit beside it. Certification produces a dated attestation that a named person signed off, which is what many control frameworks are written around. Continuous evaluation produces a current state. The near-term pattern is certification narrowing to access that warrants a human signature.
How should a small identity team prioritize these shifts?
Start with the question you are asked most often and cannot answer quickly. For most teams that is who and what can reach a specific system. One reliable answer serves the agent problem, the non-human identity problem, and the next audit request at once. Policy sophistication is worth less than coverage until coverage exists.
Does adopting an identity fabric mean replacing the existing IAM stack?
No, and treating it that way tends to stall the project. The concept was published as a way to think from capabilities to services to tools, with connectors to legacy systems built into the model. In practice it usually starts as a layer that resolves what the existing systems hold into one view.