The Iden Blog

Identity engineering, in practice.

Working notes on governance, provisioning, and access, from the team building Iden.

Third-party access audit trailJul 17, 2026

Third-Party Access Is Your Audit's Weakest Link - Here's How to Fix It

Read article

More from the team

AI agent identity landscape

AI Agent Identity Management in 2026: Standards, Players, and the Governance Gap

Jul 15, 2026
Legacy IGA migration

The Legacy IGA Migration Guide: Real Costs, Realistic Timelines, and a Step-by-Step Checklist

Jul 13, 2026
Access review automation

From Spreadsheets to Continuous Certification: A 90-Day Access Review Transformation Plan

Jul 10, 2026
AI agent lifecycle (JML)

The Machine JML Problem: A Joiner-Mover-Leaver Lifecycle for AI Agents and Service Accounts

Jul 8, 2026
IGA RFP buyer enablement

The 25-Question IGA RFP Checklist: Surface Every Coverage Gap Before You Sign

Jul 6, 2026
HIPAA 2026 identity compliance

HIPAA 2026 Identity Controls: What the Proposed Rule Makes Mandatory and How to Get Ready

Jul 3, 2026
NHI governance metrics

The 5 Metrics Every Security Team Needs to Govern Non-Human Identities

Jul 1, 2026
Mid-market IGA buying guide

The Mid-Market IGA Buying Guide: Why Enterprise Suites Are Overkill (and What to Buy Instead)

Jun 29, 2026
DORA identity compliance

DORA Identity Controls in 2026: The Six Access Gaps Supervisors Are Checking Now

Jun 26, 2026
Non-human identity governance

The NHI Explosion: Why Non-Human Identities Are the Identity Blind Spot of 2026

Jun 24, 2026
AI agent access governance

AI Agent Access Governance: The Developer's Guide to Ditching the Ticket Queue

Jun 24, 2026
IGA vendor comparison

SailPoint vs. Saviynt vs. Okta IGA vs. Iden: An Honest 2026 Buyer's Comparison

Jun 22, 2026
Audit evidence / artifacts

The Identity Evidence Playbook: Every Artifact Auditors Actually Ask For (ISO 27001 & SOC 2)

Jun 19, 2026
IGA pricing

IGA Pricing in 2026: What Vendors Won't Tell You (But the Math Will)

Jun 15, 2026
General

The CFO's Identity Governance Business Case: From Cost Center to Cost Saver in 90 Days

Team IdenMay 26, 2026
General

The SCIM Tax Explained: What "Upgrade to Enterprise" Really Costs You Per App, Per Year

Team IdenMay 25, 2026
General

Step-by-Step Guide to Auditing and Reclaiming Unused SaaS Licenses Across Your Full Stack

Team IdenMay 22, 2026
General

SaaS Management Tools vs. Identity Governance: Where They Overlap and Where They Don't

Team IdenMay 21, 2026
General

How Zombie SaaS Licenses Drain Your Budget - And Why SSO Can't Find Them

Team IdenMay 20, 2026
General

Zero Trust Without Identity Governance Is Just a Buzzword

Team IdenMay 19, 2026
General

Service Accounts, API Keys, and Bot Credentials: The Non-Human Attack Surface Your SIEM Can't See

Team IdenMay 18, 2026
General

What the Vercel and OpenAI Breaches Teach Us About OAuth Tokens and Shadow Identities

Team IdenMay 15, 2026
General

Identity Is the New Perimeter - But Most Companies Still Govern It Like It's 2015

Team IdenMay 14, 2026
General

Step-by-Step Guide to Building an Identity-First Security Architecture on a Lean Team

Team IdenMay 13, 2026
General

Time-Bound Access and Just-in-Time Provisioning: Why Contractors Should Never Have Standing Privileges

Team IdenMay 12, 2026
General

The Step-by-Step Guide to Onboarding and Offboarding Contractors Without Orphaned Accounts

Team IdenMay 11, 2026
General

Third-Party Identity Governance in Regulated Industries: When a Contractor Account Becomes a Compliance Violation

Team IdenMay 8, 2026
General

The Third-Party Access Audit: How to Prove Who Had Access When Your Auditor Asks About Contractors

Team IdenMay 7, 2026
General

NIS2 and Your Identity Blind Spots: Why Single Sign-On Alone Won't Pass an EU Audit

Max ThelanderMay 1, 2026
General

DORA Enforcement Gets Real in 2026: Can Your Access Reviews Survive a Live Audit?

Team IdenApr 30, 2026
General

Contractor Identity Chaos: Why Your Joiner-Mover-Leaver Process Breaks for Non-Employees

Team IdenApr 29, 2026
General

Step-by-Step Guide to Your First ISO 27001:2022 Surveillance Audit for Identity Management

Max ThelanderApr 29, 2026
General

The Biggest HIPAA Security Rule Shake-Up in Years: What the 2026 Update Really Means for Access Management

Team IdenApr 28, 2026
General

Spreadsheet Access Reviews vs Automated Access Reviews: SOC 2 Continuous Monitoring in 2026

Max ThelanderApr 27, 2026
General

Step-by-Step Guide to Eliminating Orphaned Veeva Accounts and Protecting Your 21 CFR Part 11 Compliance

Mario SinzApr 24, 2026
General

Why Modern Identity Governance Is Critical for Today's Healthcare Compliance

Team IdenApr 23, 2026
General

Access Governance Platforms for 2026 State Privacy Laws: A Buyer's Guide

Team IdenApr 23, 2026
General

Future-Proofing Healthcare Workforces: Why Identity Automation Belongs in Your Staffing Strategy

Team IdenApr 22, 2026
General

Step-by-Step Guide to Getting Your Access Management Ready for CMMC Level 2 C3PAO Certification by November 2026

Mario SinzApr 22, 2026
General

NERC CIP-003-9 Is Enforceable Now: Step-by-Step Guide to a Zero-Trust Identity Architecture for Electric Utilities

Team IdenApr 21, 2026
General

Enhancing Patient Data Security Amid High Staff Turnover: Why Healthcare Needs Continuous Access Control

Team IdenApr 21, 2026
General

Navigating HIPAA & GDPR: The Identity Governance Tightrope for Transatlantic Healthcare Providers

Team IdenApr 20, 2026
General

Your AI Agents Need Identity Governance Too: What the EU AI Act 2026 Really Changes

Team IdenApr 20, 2026
General

SEC Cybersecurity Rules and Identity Governance: Protecting Your 4-Day Disclosure Obligations

Max ThelanderApr 17, 2026
General

ITAR in 2026: Why an Orphaned Contractor Account Is Now an Export Control Violation

Team IdenApr 16, 2026
General

FDA Regulatory Updates in 2026: What Biotech & Pharma Teams Need to Know - and How Iden Keeps You Compliant

Team IdenApr 16, 2026
General

Step-by-Step Guide to Securing AI Agent Access and Non-Human Identities

Max ThelanderApr 15, 2026
General

2026 Buyer's Guide: Choosing the Best FDA Compliance Software for Your Biotech Business

Team IdenApr 15, 2026
General

GDPR in 2026: Why Manual Offboarding Is Now a Data Protection Liability

Team IdenApr 15, 2026
General

Non-Human Identity Governance vs Traditional Identity Management for EU AI Act, NIST CSF, ISO 27001, and NIS2

Team IdenApr 14, 2026
General

Iden vs. Traditional Compliance Tools: Side-by-Side Comparison for Biotech FDA Compliance

Team IdenApr 14, 2026
General

Identity Management for AI Agents in 2026: Trends, Risks, and What Comes Next

Team IdenApr 14, 2026
General

The Complete Guide to Regulatory-Ready Identity Governance: A Buyer's Guide from HIPAA to NIS2

Max ThelanderApr 13, 2026
General

Step-by-Step Guide to Preparing for FDA Audits with Iden

Team IdenApr 13, 2026
General

How to Build an Agentic Identity Governance Framework for Humans and AI Agents

Team IdenApr 13, 2026
General

12 Best IGA Vendors in 2026: Complete Comparison Guide for Lean IT Teams

Team IdenApr 11, 2026
General

Identity Governance and Administration: Complete Buyer's Guide 2026

Team IdenApr 10, 2026
General

Why 'Movers' Are the Hardest Part of JML (And How to Fix It)

Team IdenApr 10, 2026
General

The Complete Guide to Joiner-Mover-Leaver Automation in 2026 (Buyer's Guide for Lean IT Teams)

Max ThelanderApr 9, 2026