TL;DR: Authentication is shifting from operating fixed controls like passwords and OTPs to orchestrating trust across platform-mediated credentials, wallets, and runtime signals, according to OneSpan. That matters because passkeys, digital credentials, and delegated AI identities change where trust is evaluated, not just how users sign in.
NHIMG editorial — based on content published by OneSpan: Authentication's next era, from operating controls to orchestrating trust
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- NHIs outnumber human identities by 25x to 50x in modern enterprises.
Questions worth separating out
Q: How should security teams govern authentication when credentials are platform-mediated?
A: Security teams should treat platform-mediated authentication as a trust evaluation problem, not just a sign-in problem.
Q: Why do passkeys improve security but still require IAM governance?
A: Passkeys improve security by reducing phishing and secret theft, but IAM governance is still required because identity risk moves to enrollment, device trust, and recovery.
Q: What do security teams get wrong about authentication controls and trust?
A: They often assume that operating a control is the same as controlling trust.
Practitioner guidance
- Define credential assurance tiers Classify device-bound credentials, synced passkeys, wallet-presented credentials, and self-asserted identifiers separately, then map each to an explicit assurance level for authentication policy.
- Inventory platform trust signals Document which device, browser, wallet, issuer, and secure hardware signals your applications can actually consume through platform APIs.
- Redesign access decisions for delegation Update IAM governance so software actors acting under delegated authority are evaluated for constraints, origin, and runtime context, not only for successful sign-in.
What's in the full article
OneSpan's full article covers the operational detail this post intentionally leaves for the source:
- The platform and wallet trust model behind passkeys and digital credentials in production flows
- How banks should compare assurance across credential types and issuer ecosystems
- The role of device state, page origin, and secure hardware in runtime trust decisions
- Why delegated AI identities change the authentication operating model for enterprise apps
👉 Read OneSpan's analysis of trust orchestration in modern authentication →
Passkeys and delegated identities: what changes for IAM teams?
Explore further
Authentication control ownership is giving way to trust orchestration. The old model assumed that if the enterprise defined the authentication levers, it controlled the outcome. That premise breaks when platform APIs, credential wallets, and device-mediated flows sit between the app and the credential. The implication is that IAM governance now has to assess trust across layers the application does not directly control.
A few things that frame the scale:
- 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to Ultimate Guide to NHIs.
- 80% of identity breaches involved compromised non-human identities such as service accounts and API keys.
A question worth separating out:
Q: Who should be accountable for AI identity governance?
A: Accountability should sit with the team that owns the workflow and the team that owns identity controls, because AI access crosses both domains. Security, platform, and application owners each hold part of the lifecycle, but one business owner must remain responsible for the access decision and its removal.
👉 Read our full editorial: Authentication is moving from control ownership to trust orchestration