Application-owned identity is the pattern where authentication, session logic, tenant boundaries, and some lifecycle decisions are implemented inside the product rather than centrally in IAM. It gives teams flexibility, but it also increases governance burden because control quality depends on application code, configuration, and integration discipline.