Most organisations manage identity in silos: workforce IAM in one team, privileged access in another, customer identity with the digital team, secrets with platform engineering, and AI agents with whoever built them. Each silo has its own tools, data and processes. Attackers do not respect these boundaries. They phish a person, steal a token, pivot through a service account and use an AI agent's access. Identity convergence is the idea of bringing these domains together under shared visibility, policy and governance, while keeping specialised tools where they add value. This guide explains what convergence means, its benefits and limits, and how to approach it.
Key takeaways
- Convergence is about shared visibility, policy, governance and data, not necessarily one product for everything.
- The case for convergence is strongest where attack paths cross identity types: human to service account, OAuth app to data, agent to production.
- Keep specialised capabilities where requirements differ sharply, such as customer identity at scale or workload identity in platforms.
- Start with a unified inventory and ownership model, then common policy, then tool consolidation where it genuinely helps.
What convergence can mean
| Level | What is shared | Example |
|---|---|---|
| Visibility | One view of all identities, accounts and access | IVIP or identity graph across human and non-human identities. See What Is IVIP? |
| Policy | Common standards for authentication, privilege, lifecycle and logging | One least-privilege standard for people, service accounts and agents |
| Governance | Common ownership, review and exception processes | Access reviews covering users, NHIs and agents together |
| Detection | Correlated identity threat detection | ITDR linking a phished user to service account misuse |
| Platform | Shared tools for IGA, PAM, secrets and access | Consolidated identity security platforms |
| Organisation | One identity function with clear accountability | An identity security programme under one leader. See the Programme Guide |
Benefits
- Fewer blind spots: NHIs and agents are governed alongside users rather than forgotten between teams.
- Attack path visibility: understanding how a compromise in one domain leads to another.
- Consistent controls: the same standard for privilege and lifecycle regardless of identity type.
- Efficiency: fewer overlapping tools, integrations and processes.
- Simpler audit: one control set and evidence model. See the Regulatory Map.
Limits and risks
- Different requirements: customer identity needs scale, usability and privacy features that workforce platforms may lack; workload identity needs platform-native integration and speed. See the CIAM Guide and Cloud Workload Identity Guide.
- Concentration risk: a single platform controlling all identity becomes an even more valuable target, and an outage has wider impact.
- Vendor lock-in and "suite" gaps: converged suites may be strong in their original domain and weaker elsewhere.
- Organisational disruption: merging teams without clear accountability can reduce effectiveness.
Where convergence matters most
- Human and non-human governance: people create, own and use NHIs. Linking HR lifecycle to NHI ownership closes the leaver gap. See the JML Guide.
- Privileged access across types: one view of all privileged identities, whether admins, service accounts or agents. See the PAM Guide.
- AI agents: agents combine human delegation with non-human credentials, so they need both governance models. See the Agentic AI Identity Guide.
- Detection: correlating human, machine and agent activity. See the ITDR Guide.
A practical approach
- Unify inventory: one list of identities and accounts across all types, with owners.
- Unify policy: common standards with type-specific implementation guidance.
- Unify governance: shared ownership, review and exception processes.
- Correlate detection: feed all identity telemetry into shared detection.
- Consolidate tools selectively: where overlap is real and the converged option is strong enough, with resilience for tier-zero platforms.
Practitioner checklist
- Map identity domains, teams, tools and data today.
- Identify attack paths that cross domains.
- Build a unified inventory and ownership model.
- Define common policy across identity types.
- Correlate detection across domains.
- Consolidate tools only where it improves security and efficiency, managing concentration risk.
Related NHI Mgmt Group resources: Human vs Non-Human Identity · Identity Security Programme Guide · Identity Security Maturity Model · What Is IVIP?