About Identity Explained

This site exists because identity infrastructure is where security fails quietly. The gap between how identity is described and how it actually works in production is significant. That gap is what this site is about.

We've spent a combined 30+ years designing and operating identity infrastructure across enterprise IAM programs, Zero Trust migrations, Vault deployments, and more recently authentication systems for AI agent workloads.

These are environments shaped by scale, audits, acquisitions, legacy platforms, and decisions that can't be undone without real cost. Over time, patterns emerge. Not from specs or reference architectures, but from seeing what breaks three years later, what quietly becomes unmaintainable, and what teams regret committing to.

Identity Explained is where those patterns get written down. We write when we're genuinely working through something: a protocol edge case, an architecture tradeoff, an emerging problem in agentic identity that doesn't have a clean answer yet. Not on a content calendar.

We occasionally take on advisory work for engineering and security teams dealing with specific identity problems. If that's relevant, the Work With Us page has the details.

What we focus on

  • Workforce identity -> enterprise IAM architecture, Zero Trust design, federation, SSO, MFA, and privileged access. FIDO2 and passkeys as the authentication layer for employees and contractors, including the protocol-level details that most implementations get wrong.
  • Consumer identity -> CIAM architecture, passkeys at consumer scale, social federation, and the design tradeoffs that make or break login UX for product teams. Same underlying protocols as workforce identity, but with entirely different constraints.
  • Agentic identity -> token delegation, OBO flows, M2M trust, scoped credentials, and secrets management for LLM-based systems. The emerging third identity population, where the existing playbook doesn't transfer cleanly and most of the serious architectural decisions haven't been made yet.

Start with the articles

Most people find this site through a specific post: a FIDO2 deep dive, a Vault architecture writeup, or something on AI agent identity patterns. That's the right entry point.

If the way problems are framed here resonates, working together might make sense. If not, the content should still be useful.