What is IAM?
IAM controls who — or what — can access your systems, and what they’re allowed to do once they’re in.
Think of it like the keys to your house.
When you own a house, you decide who gets a key — your family, maybe a dog walker, a contractor while the kitchen's being redone. You know how many keys exist and who has one. When someone moves out, you're supposed to get their key back. When a contractor's job wraps, same thing.
That's the idea, anyway. In practice, keys get forgotten — a spare given to a contractor two jobs ago, never collected. Nobody decides to leave the door unlocked. But when a key isn't collected, that orphan key is the unlocked door. That single gap — a key that should've been taken back and wasn't — is the most common way access actually goes wrong.
Now imagine that same problem, but with thousands of keys, handed out constantly, to people you've never met — employees, contractors, vendors, and increasingly software and AI systems that need their own set of keys too. Most companies lose track of who's still holding one. IAM is the system that keeps track — issuing keys, knowing who has which, and validating that they should still have them.
That's it at the core: IAM decides who gets in, and what they're allowed to touch once they're there.
Seven capabilities.
IAM isn't just a set of tools. It's also the ongoing work behind them — provisioning access, governing who has it, and tracking how it's actually used. Here's what each one is made of.
Access Management
Identity Governance & Administration
Privileged Access Management
Customer Identity & Access Management
Cloud Governance & FinOps
Identity Risk Management
Governance for non-human identity
IAM used to mean workforce employees. It doesn't anymore — now it needs to cover all workforce, privileged identities, contractors, consumers, AI agents, clouds — any identity that can access the company's environment.
Remember the house.
The key that should've been taken back and wasn't — that's not a rare mistake, it's the default outcome when nobody's tracking it. And a company doesn't get the luxury of one front door to watch: cloud apps, remote logins, APIs, and AI agents all create their own entry points, so the same failure now happens at a dozen doors at once. Here's what that looks like at scale, and which capability was missing in each case.
The statistics above are sourced from the cited reports. The "likely capability" column is our own interpretation of the probable cause — not something the reports themselves state.
"IAM" and "identity security" — is there a difference?
You'll see both terms used almost interchangeably. There's a real distinction underneath.
IAM
The tools that control who can get in, and what they're allowed to touch. Logins, passwords, approvals, permissions.
Identity Security
The bigger goal: keeping identities themselves safe from attack — not just controlling access, but watching for misuse. Includes AI and machine accounts, not only people.
Have a question about your own setup?
Every environment's a little different — happy to talk through yours.

