TL;DR: Forrester’s Customer Identity and Access Management Solutions Landscape, Q3 2026 profiles more than 30 vendors and says agentic AI is the single largest transformational force in CIAM, according to Strivacity’s analysis. The category is moving beyond human login and consent into AI agent onboarding, task-scoped authorization, and continuous session control, which makes legacy CIAM assumptions increasingly fragile.
NHIMG editorial — based on content published by Strivacity: its analysis of Forrester’s Customer Identity And Access Management Solutions Landscape, Q3 2026
By the numbers:
- Strivacity is named a Notable Vendor in the Q3 2026 landscape report.
Questions worth separating out
Q: How should teams govern AI agents inside CIAM platforms?
A: Treat AI agents as distinct identity subjects with scoped credentials, explicit consent, and a traceable link back to the human or organisation that authorised them.
Q: Why do AI agents change customer identity risk models?
A: Because they can act on behalf of a customer without behaving like a person at every step of the journey.
Q: When should organisations move beyond sign-in-only CIAM controls?
A: When access conditions can change after authentication, which is now common in both high-risk customer journeys and agent-assisted interactions.
Practitioner guidance
- Validate agent identity as a first-class subject Require vendors to show how an AI agent is onboarded, authenticated, consented, and revoked as a distinct identity object, including how the authorizing customer or organisation is linked to the agent’s actions.
- Test continuous authorization, not just login Ask for a live demonstration where access changes mid-session based on risk, context, or task scope, and confirm the platform can reduce or revoke access without breaking the transaction.
- Map consent and accountability together Make sure consent records, policy decisions, and audit logs can prove both who authorised the agent and what the agent was permitted to do at runtime.
What's in the full article
Strivacity's full article covers the operational detail this post intentionally leaves for the source:
- The report-framed vendor landscape context that explains how Forrester positioned the CIAM category in Q3 2026.
- The vendor’s own criteria for deciding whether an AI agent is truly supported in production versus only represented in roadmap language.
- The specific examples of how CIAM should handle onboarding, consent, and task-scoped authorization across customer journeys.
- The practical shortlist questions the vendor suggests buyers should ask when modernising legacy CIAM deployments.
👉 Read Strivacity’s analysis of the 2026 CIAM landscape and agentic AI shift →
CIAM and AI agents: what identity teams need to rethink now?
Explore further
CIAM is moving from human identity management to dual-subject governance. The important change is not that AI agents can log in, but that a single customer interaction may now involve both a human authorizer and an executing agent. That means identity records, consent, and access traces have to prove who authorised what and which actor executed it. Practitioners should treat that as a governance redesign, not a feature add-on.
A few things that frame the scale:
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage, according to the Ultimate Guide to NHIs.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
A question worth separating out:
Q: What should buyers ask before trusting AI agent support in CIAM?
A: Ask whether the vendor can onboard an agent today, authenticate it, authorize it for a specific task, and revoke it with full auditability. Then ask how the platform ties the agent back to the authorizing party and whether that control works across web, mobile, chat, and other customer channels.
👉 Read our full editorial: CIAM is shifting from human login to agent identity governance