How it works
How the security landscape actually works
Identity did not become fragmented by accident. It became fragmented because of how the market grew — and understanding that is the fastest way to see where the risk sits.
The market organised itself by category, not by risk
Five separate industries formed, each solving one slice of the same problem:
Governance
Who should have access, and can you prove you checked. Sold to audit and risk.
Access management
Letting the right person in. Sold to IT, priced per employee.
Privileged access
Controlling the keys to the kingdom. Sold to security, priced per administrator.
Directory & network
The plumbing underneath. Usually inherited rather than chosen.
Agent identity
The newest layer, arriving faster than anyone’s governance.
So every buyer ends up assembling the same stack
You buy the leader in each category. That is the sensible decision, made four or five times. What you end up owning is four to six vendors, four to six contracts, and four to six audit scopes.
Attackers do not respect the category boundaries
Nobody attacks “your governance tool”. They take a credential from one place, use it somewhere the first tool cannot see, and escalate in a third. The categories are a map of the vendor market, not a map of how an intrusion moves.
The gaps between the tools are where the risk concentrates — and they are precisely the part no vendor will take responsibility for.
The arithmetic
Ten tools leave forty-five places to get it wrong
Any two tools that must agree about identity have to be joined. Ten tools means forty-five possible joins to build, watch and defend. One fabric means ten connections that answer to the same rules.
45 joins
Each one built by hand, owned by whoever happened to build it, and quietly rotting the day that person changes role.
10 connections
Each one governed by the same rules, written to the same record, and visible in the same place.
Fewer things to trust
You are not adding a single point of failure. You are removing the nine seams that nobody was watching.
How we solve it
One fabric across all five layers
Not another tool in the stack. The same five jobs, done in one place, so the joins stop being your problem.
One record
Every action, in every part of the platform, written to the same tamper-evident record. There is only one version to reconcile, and the auditor can read it.
One set of roles
What a role means does not change depending on which console you opened. Access granted, reviewed and revoked all reference the same definition.
One set of rules
A policy written once applies to a person signing in, an administrator checking out a credential, and an agent making a call.