Book
Identity & Access
Authentication versus authorisation, federation, the joiner-mover-leaver lifecycle, entitlements, privileged access, secrets, and machine identity.
Deliberately not framed through AI — this is a discipline in its own right. The last chapter is where the two meet.
CHAPTER 1
Authentication, authorisation, audit
Three different questions. Conflating them is the root of most identity incidents.
CHAPTER 2
Federation, SSO, SAML and OIDC
The acronym soup, deflated. Four ideas, and you only need one mental model.
CHAPTER 3
The lifecycle — joiner, mover, leaver
The least fashionable part of identity and the source of the most real exposure.
CHAPTER 4
Entitlements, RBAC and ABAC
How permission models actually decay, and why role explosion is a design failure rather than bad luck.
CHAPTER 5
Privileged access — why admin is different
The single highest-value control surface in an enterprise, and what PAM products actually sell.
CHAPTER 6
Secrets management
The problem every engineering organisation has, and most solve badly.
CHAPTER 7
Machine and agent identity
Non-human identities already outnumber humans. AI agents are about to make that worse — and it is becoming a job title.