TL;DR: Retailers increasingly find that customer identity drives conversion, fraud prevention, loyalty, and operating cost, and Strivacity argues that sign-in, recovery, verification, and account linking should be measured as one connected system. The emerging control problem is that customer identity now includes agentic commerce, so governance must cover delegated authority, auditability, and risk-based access decisions.
At a glance
What this is: This is a retail identity measurement framework that argues customer identity should be treated as a revenue and security system, not just an authentication layer.
Why it matters: It matters because IAM teams in retail have to balance friction, fraud, and customer trust while preparing for AI agents that act on behalf of shoppers.
By the numbers:
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.
- NHIs outnumber human identities by 25x to 50x in modern enterprises.
Context
Retail identity is the set of sign-in, recovery, verification, and consent decisions that shape whether a shopper converts, returns, and trusts the brand. In practice, it sits inside both customer experience and identity security programmes, which is why customer identity metrics belong in the same conversation as conversion and fraud.
The governance gap is that most retailers still measure identity through separate dashboards owned by different teams. Security sees fraud, digital sees conversion, and engineering sees performance, but customers experience one journey. That split is becoming harder to sustain as AI agents begin acting on behalf of shoppers and identity must account for delegated authority as well as human users.
Strivacity's framing is typical for the market because retail has long treated authentication as a support function rather than a business control. The article shows why that model breaks once identity touches revenue, loyalty, and agentic commerce at the same time.
Key questions
Q: How should retailers measure whether identity controls are helping conversion?
A: Retailers should measure identity controls against journey outcomes, not just authentication outcomes. Track account creation, sign-in success, recovery completion, step-up rates, and checkout abandonment in the same funnel. That shows where identity is creating friction, where it is stopping fraud, and whether the control is improving revenue or merely shifting the loss elsewhere.
Q: Why do customer identity controls affect revenue as well as security?
A: Because customers interpret identity failures as product failures. When login loops, timeout resets, or overbearing challenges interrupt a purchase or service task, they abandon the interaction and often do not return. Well-tuned CIAM protects revenue by keeping trust, continuity, and assurance aligned.
Q: What breaks when retailers treat account recovery as a low-risk flow?
A: Account recovery becomes an easier entry point than the main sign-in flow. Weak recovery paths let attackers bypass stronger authentication, reset credentials, and take over accounts. That is why recovery success rates, fallback methods, and abuse indicators should be measured alongside sign-in security and fraud outcomes, not hidden in a separate support queue.
Q: Who is accountable when an AI agent runs a query on behalf of a user?
A: Accountability sits with the identity chain, not with the tool call alone. The human who delegated the action, the issuer that minted the token, and the platform that activated the role all need a traceable record. If any of those links are missing, the organisation cannot prove who authorised the access.
Technical breakdown
How retail identity metrics connect conversion to control decisions
Retail identity metrics work because they trace the customer journey through account creation, sign in, recovery, checkout authentication, and session continuity. Each step creates measurable drop-off or risk, and the same control can affect both. For example, adaptive authentication may reduce fraud, but if it is too aggressive it also increases abandonment. The technical challenge is not simply observing authentication success. It is correlating identity events with conversion outcomes so teams can see where friction is created and whether the control is doing more harm than good.
Practical implication: measure identity events against conversion funnels, not in isolation.
Why checkout abandonment is often an identity problem
Checkout abandonment is frequently blamed on pricing, UX, or shipping, but identity often sits in the critical path. Account creation, remembered devices, password reset, and step-up authentication can all interrupt the purchase journey. When identity systems force unnecessary reauthentication or recovery, the friction appears as a business loss rather than an authentication failure. Retailers need event-level telemetry that links identity controls to abandonment points, so they can distinguish genuine risk from avoidable interruption. That is especially important during peak trading periods when small delays multiply into revenue loss.
Practical implication: instrument abandonment around identity events, especially during peak periods.
Agentic commerce turns customer identity into delegated access
Agentic commerce changes the identity model because an AI agent may act on behalf of a customer, place orders, redeem loyalty benefits, or update account details. That means retailers must verify the agent, bind it to the customer it represents, scope its authority, and log the resulting actions. This is not ordinary API traffic. The actor is making decisions and executing tasks with customer authority, so auditability and consent become first-class identity controls. In governance terms, the question shifts from who authenticated to who authorized the delegation and for how long.
Practical implication: treat agent actions as delegated identity events with explicit scope and audit requirements.
Threat narrative
Attacker objective: The attacker aims to monetise legitimate customer accounts while avoiding controls that would trigger obvious detection or unnecessary friction.
- Entry occurs when attackers use stolen or automated credentials against retail sign-in and account recovery flows, often targeting the weakest verification path rather than the main login screen.
- Escalation follows when account recovery, loyalty redemptions, or weak step-up controls let the attacker move from a valid session into account takeover or fraudulent benefit use.
- Impact appears as purchase fraud, loyalty theft, personal data exposure, or blocked legitimate customers when defensive controls are tuned too aggressively.
Breaches seen in the wild
- Cisco DevHub NHI breach — IntelBroker exploited exposed Cisco credentials, API tokens and keys in DevHub.
- DeepSeek breach — DeepSeek breach exposed 1M+ log lines and sensitive secret keys.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Retail identity metrics are now business controls, not supporting telemetry. Retailers that measure sign-in, recovery, and checkout in separate silos miss the control effect of identity friction. The real issue is not whether authentication is successful, but whether it supports conversion, loyalty, and fraud outcomes at the same time. Practitioners should treat identity measurement as part of revenue governance, not a back-end operational report.
Customer identity is becoming a delegated access problem as agentic commerce matures. Once an AI agent can act for a shopper, the programme is no longer only managing human login journeys. It must govern who or what was authorised, what actions were in scope, and how long that delegation lasts. That makes customer identity a cross-domain issue spanning IAM, fraud, and consent governance.
Identity friction and fraud prevention must be measured together because they fail together. A blocked session may prevent abuse, but it may also stop a legitimate purchase. Likewise, a smooth journey may lift conversion while letting risk through. This creates a measurable identity blast radius: the wider the control, the more carefully teams must observe downstream business impact.
Agent verification will become a standard retail governance requirement before most retailers think it is necessary. The article points to a coming state where AI agents interact with loyalty balances, subscriptions, and purchases on behalf of customers. That forces a shift in accountability, because the retailer must be able to prove what authority was granted and what the agent was allowed to do. Practitioners should prepare for identity governance that spans human customers and delegated machine actors.
From our research:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
- Only 5.7% of organisations have full visibility into their service accounts, which is why identity governance fails when machine actors are left outside the measurement model.
- That visibility gap is why the 52 NHI Breaches Analysis remains a useful forward reference for teams extending retail identity governance into machine and agentic actors.
What this signals
Identity metrics will increasingly be judged by business impact, not just control activity. Retail teams that cannot connect authentication, recovery, and checkout events to conversion and fraud outcomes will struggle to prioritise remediation. The same measurement discipline that helps with customer identity will also matter as delegated machine actors appear in customer journeys.
Customer identity programmes now need an explicit delegation model for AI agents. That means aligning consent, audit, and scope management before agentic commerce becomes normal rather than exceptional. Retailers that wait for volume to force the issue will find their existing customer IAM assumptions too narrow for machine-mediated purchases.
A useful next step is to map where customer sessions, recovery flows, and loyalty actions already behave like non-human identity events. That perspective helps teams reuse governance patterns from machine identity rather than inventing a separate model for every new channel.
For practitioners
- Measure identity as part of conversion analytics Link account creation, sign-in, recovery, checkout authentication, and abandonment events so the team can see which identity controls suppress revenue.
- Review blocked-session reasons together with fraud outcomes Compare blocked sessions, false positives, step-up completion, and account takeover activity in the same operational review so fraud controls do not hide customer loss.
- Instrument recovery flows as attack surfaces Treat password reset and account recovery as primary risk paths, then measure success rates, fallback methods, and abuse signals separately from standard sign-in.
- Define delegated authority for AI shopping agents Set explicit scope, duration, and audit requirements for any agent acting on a customer’s behalf, including loyalty redemptions and order changes.
- Reduce identity complexity across channels Standardise customer recognition, consent handling, and session continuity across web, mobile, and in-store journeys to reduce support cost and inconsistency.
Key takeaways
- Retail identity is a revenue control as much as a security control, because every authentication decision can affect conversion, loyalty, and fraud together.
- AI shopping agents make delegated authority an identity governance issue, not just an automation trend, because the retailer must prove who authorised what and for how long.
- The teams that win on retail identity will measure friction and risk in the same view, so they can reduce abandonment without opening a larger attack path.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-1 | Customer identity metrics map directly to access control and identity assurance outcomes. |
| NIST SP 800-63 | SP 800-63B | Customer authentication, recovery, and session security sit within digital identity guidance. |
| NIST Zero Trust (SP 800-207) | Section 3.2 | Adaptive control and continuous verification reflect zero trust principles for retail identity. |
| OWASP Agentic AI Top 10 | Agentic commerce introduces delegated AI actors that need identity and scope governance. |
Map shopper-facing AI delegation to agent identity and tool-use controls before adoption scales.
Key terms
- Customer Identity: Customer identity is the authentication and account layer used for app users, sign-in, federation, and profile management. It is built to manage user access into applications, not to mediate privileged infrastructure activity or deep protocol-level control.
- Agentic Commerce: Agentic commerce is a buying and transaction model where software agents act on behalf of a person. The identity challenge is not just proving who owns the account, but constraining what the agent may do, for how long, and under what revocation and audit rules.
- Identity Friction: The operational drag created when access controls slow work enough that users look for shortcuts. In practice, it is a governance signal, because repeated friction usually produces credential sharing, informal exceptions, and weaker audit evidence even when the formal policy looks sound.
- Delegated Agent Authority: The permission granted to an AI agent to act on behalf of a human user or another agent, inheriting some or all of their access rights. Delegated authority must be explicitly scoped, time-limited, and auditable.
What's in the full article
Strivacity's full article covers the operational detail this post intentionally leaves for the source:
- Metric definitions and formulas for each retail identity KPI, including conversion, recovery, and loyalty measures
- Priority actions and owners for teams that need to operationalise the measurement model
- Benchmarking guidance for comparing identity friction against fraud outcomes across channels
- The complete map of identity metrics for agentic commerce readiness
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity programme, it is worth exploring.
Published by the NHIMG editorial team on August 17, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org