Blog

Digital identity is becoming the enterprise’s new security perimeter

Until relatively recently, protecting an organization largely meant protecting its network. Servers, applications, and important data were generally located in infrastructures controlled by the company, employees worked mainly from equipment it administered, and firewalls made it possible to control communications with the outside world. This view of security rested on a boundary that was relatively easy to understand: there was an internal environment to be protected against threats coming from outside.

That reality has changed profoundly. Employees now work from various locations, applications are distributed across several cloud environments, companies use numerous SaaS services, and partners or suppliers may access certain resources directly. Mobile devices travel with users, APIs allow applications to communicate with one another, and data can move between several infrastructures without ever crossing the company’s physical network. Artificial intelligence now adds a new dimension to this shift, since digital systems and agents are also beginning to access organizational resources and act on users’ behalf.

The traditional technological perimeter is therefore becoming much harder to define. Yet one element remains at the center of nearly all these interactions: identity. Knowing who, or what, is requesting access, determining what that identity is authorized to do, understanding the context in which it is acting, and being able to continuously reassess the level of trust granted to it are becoming essential foundations of modern security.

In traditional IT architectures, location was an important indication of the level of trust. A device connected to the company’s internal network could be granted a higher level of trust than one coming from the internet. That logic corresponded relatively well to a time when critical resources were mainly hosted in the organization’s own infrastructures. Today, an employee can access a SaaS application from home, a manager can approve a transaction from their phone, a developer can administer an infrastructure located in another country, and a cloud application can communicate directly with a platform operated by a different supplier. In this context, the distinction between “inside” and “outside” becomes far less relevant for determining what deserves our trust.

Identity is gradually taking the place of that physical boundary, but knowing who is requesting access is not enough. Authentication makes it possible to verify that a person, a device, or a system genuinely matches the identity it presents. Passwords were long the dominant mechanism for establishing that trust, while multifactor authentication, passkeys, biometrics, and various cryptographic approaches now make it possible to considerably strengthen that verification. Once the identity is confirmed, however, an equally important question remains: what can it actually do? Security depends as much on the authorization and privileges granted as on authentication itself. A perfectly legitimate identity holding excessive permissions can represent a considerable risk.

This distinction is at the heart of Zero Trust. A valid identity can be used in an abnormal context, an account may have been compromised, a session may have been hijacked, a device may present a risk, or a privileged account may suddenly perform an unusual operation. The decision to authorize an action must therefore increasingly take several elements into account at once: the identity, the device used, the context, the resource requested, its level of sensitivity, the behavior observed, and the risk associated with the operation. Trust becomes dynamic, and a successful authentication at a given moment should not necessarily constitute blanket authorization for every action that may follow.

This approach makes the principle of least privilege even more important. An employee should have the access needed to do their job, a supplier the resources required to deliver its service, an application the data it genuinely needs, and an administrator elevated privileges only when those are necessary. The apparent simplicity of this principle, however, conceals a complex organizational reality. Employees change roles, responsibilities evolve, projects end, applications are replaced, and suppliers change. Access that was initially temporary can remain active, and permissions can accumulate over several years. Identity and access governance must therefore become a continuous process able to evolve with the organization.

Artificial intelligence now gives this discipline even greater importance, since digital identity no longer concerns humans alone. IT environments already contain a multitude of non-human identities: service accounts, applications, APIs, machines, scripts, certificates, and automated processes. AI agents will considerably increase that population. A single agent may eventually consult a calendar, read documents, query a CRM, analyze data, prepare a proposal, communicate with a client, or trigger an operation in another system. To carry out these tasks, it will need a clearly defined identity and permissions.

This capability forces organizations to reconsider the very notion of privilege. Automatically granting an AI agent all of its user’s permissions may seem convenient, but the capabilities of the two are very different. An employee may have access to several thousand documents while consulting only a small portion of them in the normal course of their work. An agent with the same authorizations could technically browse, analyze, or process those documents at incomparable speed and scale. A permission that is reasonable for a human therefore does not necessarily produce the same level of risk when granted to a machine capable of performing a large number of operations in very little time.

Organizations will gradually have to assign agents their own identities, specific permissions, and limits on action suited to their functions. They will also have to be able to trace their activities in order to understand which person or system requested an operation, which agent carried it out, which authorizations were used, which information was consulted, and what result was produced. As systems become more autonomous, this traceability will become essential to governance, cybersecurity, and the assignment of responsibility.

At the same time, artificial intelligence creates another challenge for digital identity by making it easier to produce increasingly convincing synthetic content. A fraudulent request can reproduce an executive’s style, use a credible synthetic voice, include an image or a video, and exploit contextual information to make the scenario far more plausible. Human perception then becomes insufficient proof for certain sensitive operations. Organizations will have to strengthen the mechanisms that establish whether a person, a machine, or a communication genuinely holds the authority it claims.

Biometrics, cryptography, digital signatures, proof-of-possession mechanisms, and contextual checks can all contribute to this shift when they are built into an appropriate architecture. The objective becomes to establish a level of proof matching the risk associated with the action requested. A routine operation may require relatively few additional checks, while a change of privileges, a financial transfer, access to particularly sensitive information, or a critical administrative action may justify far stronger proof.

This pursuit of trust can also advance without requiring that more personal information be systematically disclosed. Zero-Knowledge approaches and other cryptographic mechanisms make it possible to envisage architectures where a person can demonstrate that they possess a characteristic, an authorization, or a right without necessarily communicating all the information used to establish it. An organization can thus seek to confirm that a condition is met while limiting the amount of personal data it must receive or retain. Identity security and privacy protection can then advance together through better control of the proofs actually required.

Digital identity also has a sovereignty dimension. When an identity infrastructure becomes essential to nearly all digital operations, it becomes strategic to understand where authentication information is stored, which suppliers take part in the process, which platforms control identities, which jurisdictions may apply to the data, and what consequences would result from a supplier becoming unavailable or being replaced. Digital sovereignty does not require every organization to build its own identity system. It rather requires a sufficient understanding of dependencies and risks to retain a level of control commensurate with the importance of that infrastructure.

Finally, no identity architecture can be considered infallible. Accounts will be compromised, devices may be lost, mistakes will be made, and new attack techniques will continue to appear. A mature strategy must therefore anticipate the consequences of a compromise and limit the ability of a compromised identity to affect the entire organization. Least privilege, resource segmentation, additional controls for sensitive operations, behavioral monitoring, fast revocation mechanisms, and the ability to reconstruct the chain of events all contribute together to this resilience.

This evolution is part of a broader vision of Hypersecurity. As environments become distributed, intelligent, and autonomous, identity is one of the layers that connects people, machines, data, applications, and operations. Trust can no longer be granted solely on the basis of where a resource is located or of a one-time successful authentication. It must be able to evolve with context and risk. It is from this perspective that Quantum Beyond is developing the principle of Continuous Trust, in which trust is continuously earned, verified, and reassessed throughout the digital relationship.

The enterprise security perimeter has been transformed. It now travels with users, devices, applications, data, APIs, suppliers, and a growing population of intelligent systems. In this environment, identity becomes an essential point of convergence between cybersecurity, governance, data protection, digital sovereignty, and the adoption of artificial intelligence. The ability to determine who or what is requesting access, what that identity is authorized to do, and under what conditions it can retain that authorization is becoming a strategic organizational competency.

This transformation also requires considering human and non-human identities together. AI agents introduce a new scale of speed and autonomy that makes it necessary to have permissions suited to their capabilities, rigorous traceability, and mechanisms for continuously reassessing their level of trust. The goal remains to give humans and machines the access their functions require while limiting the reach of an error, a compromise, or unexpected behavior.

At Quantum Beyond, our experts work alongside the IT and cybersecurity teams already in place to strengthen this capability and embed it within a broader Hypersecurity architecture. Assessment of IAM architectures, privilege management, Zero Trust, Continuous Trust, non-human identities, biometrics, Zero-Knowledge approaches, sovereignty, and cyber resilience can thus be treated as interdependent components of a single environment rather than as isolated initiatives.

In an organization where applications can run anywhere, where data can move between multiple environments, and where humans as well as machines can now act on systems, the fundamental question ultimately remains very simple: who or what is asking to perform an action, with what proof, what permissions, and within what limits? The ability to answer that question continuously is becoming one of the foundations of Hypersecurity and may well define the enterprise’s new security perimeter.