TL;DR: Retailers increasingly find that customer identity drives conversion, fraud prevention, loyalty, and operating cost, and Strivacity argues that sign-in, recovery, verification, and account linking should be measured as one connected system. The emerging control problem is that customer identity now includes agentic commerce, so governance must cover delegated authority, auditability, and risk-based access decisions.
NHIMG editorial — based on content published by Strivacity: Retail customer identity metrics and the business value of identity
By the numbers:
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.
- NHIs outnumber human identities by 25x to 50x in modern enterprises.
Questions worth separating out
Q: How should retailers measure whether identity controls are helping conversion?
A: Retailers should measure identity controls against journey outcomes, not just authentication outcomes.
Q: Why do customer identity controls affect revenue as well as security?
A: Because customers interpret identity failures as product failures.
Q: What breaks when retailers treat account recovery as a low-risk flow?
A: Account recovery becomes an easier entry point than the main sign-in flow.
Practitioner guidance
- Measure identity as part of conversion analytics Link account creation, sign-in, recovery, checkout authentication, and abandonment events so the team can see which identity controls suppress revenue.
- Review blocked-session reasons together with fraud outcomes Compare blocked sessions, false positives, step-up completion, and account takeover activity in the same operational review so fraud controls do not hide customer loss.
- Instrument recovery flows as attack surfaces Treat password reset and account recovery as primary risk paths, then measure success rates, fallback methods, and abuse signals separately from standard sign-in.
What's in the full article
Strivacity's full article covers the operational detail this post intentionally leaves for the source:
- Metric definitions and formulas for each retail identity KPI, including conversion, recovery, and loyalty measures
- Priority actions and owners for teams that need to operationalise the measurement model
- Benchmarking guidance for comparing identity friction against fraud outcomes across channels
- The complete map of identity metrics for agentic commerce readiness
Retail customer identity metrics: are your controls helping or hurting?
Explore further
Retail identity metrics are now business controls, not supporting telemetry. Retailers that measure sign-in, recovery, and checkout in separate silos miss the control effect of identity friction. The real issue is not whether authentication is successful, but whether it supports conversion, loyalty, and fraud outcomes at the same time. Practitioners should treat identity measurement as part of revenue governance, not a back-end operational report.
A few things that frame the scale:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
- Only 5.7% of organisations have full visibility into their service accounts, which is why identity governance fails when machine actors are left outside the measurement model.
A question worth separating out:
Q: Who is accountable when an AI agent runs a query on behalf of a user?
A: Accountability sits with the identity chain, not with the tool call alone. The human who delegated the action, the issuer that minted the token, and the platform that activated the role all need a traceable record. If any of those links are missing, the organisation cannot prove who authorised the access.
👉 Read our full editorial: Retail customer identity metrics now shape conversion and loyalty