Every era of identity starts the same way: The perimeter moves, and the old method of proving who someone is quietly stops working. Then, organizations spend the next decade playing an expensive game of catch up.
I know because I helped build each era, first at Securant, then at Symplified, Strata, and now Rubrik.
The web broke the assumption that you could only trust identities you issued yourself. So, we wrote SAML. SaaS broke the assumption that applications lived inside your firewall. So, single sign-on had to become a federated service. Multi-cloud broke the assumption that there would be one identity system to standardize on. So, we built an abstraction layer to work across the silos instead of waiting for fragmented identity systems to collapse into one.
The pattern holds every time: The technology arrives first, the identity model arrives late, and the gap between them is where the breaches happen.
AI agents are the fourth break, and the sharpest. They act autonomously, at machine speed, with elevated permissions and credentials no human directly supervises. That's why we built the first agentic identity gateway at Strata, and it's the work I'm carrying forward as Chief Identity Architect at Rubrik.
Non-human identities already outnumber human users 82 to 1, by counts compiled by Rubrik Zero Labs. Eighty-nine percent of IT decision-makers have already wired AI agents into their identity infrastructure. And where the Web era took the better part of a decade to standardize, the AI era has been underway for about two years and is already being rolled out to production nearly everywhere.
Across the four eras (Web, SaaS, Cloud, and AI), identity did not—and could not—stay static. It evolved. Each rebuild solved a new identity security problem the era before it didn’t need to, and none of the previous eras were retired.
This blog series will cover that evolution, the accumulated fragmentation it leaves behind, and what we can do about it. This will help you understand the antecedents of identity today, and shed light on ways we can solve today’s problems.
Four Eras, One Accumulating Stack
Every era of identity was a response to a problem the previous one couldn’t solve. I’ve drawn them as a single graphic, the Four Eras of the Identity Control Plane, because the relationships between the rows are key to understanding the state of identity today.
If you read it top to bottom, the pattern should be quite clear: each era solved a foundational problem.
The Web Identity Era solved for the challenges of user scale: Millions of new users were handled by Web Access Management (WAM), directories like Active Directory and LDAP, and the first generation of User Provisioning.
As we discussed above, the SaaS Identity Era solved the boundary problem: Applications ran in multiple environments, so we federated identity with standards like SAML and OIDC and hardened the front door with multi-factor authentication (MFA).
In the early days, when we were drafting SAML, the argument was never really over XML or assertions. It was about trust: How does one company accept an identity vouched for by another when there is no shared directory between them? We designed federation around that single question. A signed assertion said, in effect, “I authenticated this user, and here is what I will attest to about them.” The alternative was giving every partner an account (and a password) inside your own directory, which didn’t scale and didn’t survive an audit. Federation was, at its core, a way to trust a stranger cryptographically. Every era since has been a variation on that same problem at a new scale.
Next, the Cloud Identity era solved fragmentation and criticality: Multiple cloud platforms and Identity Providers (IdPs) complicated deployment; legacy apps needed modernized authentication patterns; and identity became mission-critical enough to need orchestration, continuity, and Identity Threat Detection and Response (ITDR).
The AI Identity era is solving speed, scale, and delegation: Agents now act on your behalf, accessing resources thousands of times an hour through MCP servers and APIs. This means they can take unwanted actions, ranging from mildly annoying to catastrophic. For example, they can invent refund policies that don’t exist or even delete entire databases that destroy customer records.
Four problems, four rebuilds, each one legitimate. But if you take a closer look, a pattern emerges: Each era’s unsolved problem is the seed that produced the next.
Nobody Turned Anything Off: Each Era’s Technology is Still in Production Today
Nobody decommissioned Active Directory when SAML arrived. Nobody retired SAML when they adopted a cloud IdP. Nobody unplugged their cloud IdP when they started deploying agents. Every era’s technology is still in production, right now, in your environment, running alongside everything that came before it.
This is the mechanism behind identity fragmentation, and it is worth being precise about, because fragmentation is usually described as a failure of discipline. It isn’t. No team was necessarily careless. Each era’s controls were foundational when the next era began, and you cannot switch off the system a business runs on just because a better, newer one comes on the scene.
So, the layers accumulate. A single enterprise ends up authenticating through a directory built for the Web era, federating through protocols built for SaaS, orchestrating across clouds, and now issuing credentials to agents. That is four control planes deep, each with its own policy language, token format, and failure modes.
That accumulation is not transitional. There is no future state in which it resolves into one clean system. It is the structural condition of enterprise identity.
AI: The Column That Isn’t Written Yet
Look at the AI row’s control plane section: token exchange, fine-grained authorization, trust management. Then, ask how much of it you’ve actually built.
For the Web, SaaS, and Cloud rows, that column describes things most enterprises deployed years ago. For the AI row, it describes things most enterprises have not built at all. Things like token exchange, workload identity for agents, fine-grained authorization at run time, delegated authorization that lets an agent act on behalf of a user (or another agent) without impersonation or short-lived, scoped credentials a caller must prove it holds.
I am not the only one who sees it this way. Gartner, writing in 2026 (Farahmand, ID G00852165), calls for “a unified control plane to govern AI agents,” and recommends treating agents as workload identities with short-lived, just-in-time credentials. When the framework a founder proposes and the one an industry analyst proposes converge on the same words, that is usually a sign the problem is real.
That is what makes this era unlike the three before it. The other three rows are history. I helped write them. By the time anyone named them the technology already existed. The AI row is being written now, from inside the problem, before the standard patterns have been established. The primitives exist; the control plane that assembles them into something an enterprise can operate does not yet ship in most environments.
In order to solve this problem, we need to walk the four eras and learn why the stack looks the way it does. Then, we need to define what the AI-era control plane must contain, and in what sequence to build it.
Where This Series Goes
In this blog series, we’ll cover key ideas tied to understanding and solving the AI Era identity problem.
How identity became Tier 0: The three-era climb from IT plumbing to the new security perimeter, and why the perimeter is now both your availability dependency and your primary breach vector.
Assume fragmentation: Why consolidating your IdPs was not going to work, and what to build instead.
Every control you have assumes a human is watching: Why machine speed breaks the last assumption every historical layer shared.
What belongs in an identity control plane: What you need, and, more usefully, what you don’t. And the order that dependencies require, because most programs stall by starting at the wrong end.
Before, during, and after an attack: The three parts of an attack an identity program must solve, and why most can only solve one.
The stack took thirty years and four generations to reach its current shape. The fourth rebuild is the first one you get to design before it hardens. Start with the table. Everything else in the series builds from it.
SAFE HARBOR: Any unreleased services or features referenced in this document are not currently available and may not be made generally available on time or at all, as may be determined in our sole discretion. Any such referenced services or features do not represent promises to deliver, commitments, or obligations of Rubrik, Inc. and may not be incorporated into any contract. Customers should make their purchase decisions based upon services and features that are currently generally available.