Volume 147
Volume 147 | June 25, 2026

Reminder to JOIN the The PhySec Collective community Slack channel to network, engage, and be part of something big! You can sign up here.
|
The “who owns the identity” debate is the wrong debate. Especially when someone says “PIAM does.” And that is what this Brief is about. PIAM never lost the identity war because it was never in one. It's a middleware (adapter) business sitting in a gap that should never have existed, and middleware (adapters) don't get to own what they translate. More on that below. |
Can you lose something you never had?PIAM lost the identity war. I have spent a lot of time on this idea and have written that “whoever owns the identity database owns the future of this industry.” I have also been sloppy with the next sentence, the one where I said, “PIAM is losing that fight.” Losing implies it was in contention or that it already owned it. I do not think it has or was, and I want to correct my own framing before I ask anyone else to take it seriously. Here is the more honest question. “Can you lose something you never actually had?” Physical Identity and Access Management (PIAM) was never the system of record for who a person is. It never originated an identity. It consumed identity that originated somewhere else, HR systems, Active Directory, Okta, Entra, and reformatted it into something a door controller could act on: a badge, a credential, an access group. That is a real function and an important one. It is also, definitionally, downstream. You cannot lose ownership of something you were always downstream of. The category was never positioned to own an identity in the first place, which means the interesting question is not who wins the war. It is why we kept describing a translation layer as something it never was. So what is PIAM, actually, once you strip away the category language? It is the adapter between two systems built decades apart by different vendors for different purposes, with no shared protocol between them. Also known as “middleware.” HR and IAM platforms evolved to manage the digital identity lifecycle. Since 1983, PACs' hardware has evolved to open doors (1973-1983 was a different story, but most of what we talk about today is PACs from 1983 to today). Nobody built a clean joint between those two worlds, so an entire category was created to serve as that joint. PIAM is not spackle over a crack in a finished wall. Spackle implies a cosmetic fix to something basically sound. This is closer to duct tape between two pipes that were never designed to connect, doing real work, holding real pressure, and only existing because the proper fitting was never built. This is not the fault of the PIAM providers, but it does explain why they struggled to get traction at scale. The reframing matters because it changes what the data actually proves. PIAM as a standalone market is somewhere between $1.5 billion and $5 billion today, depending on which analyst you trust, with most forecasts landing around $10 to $13 billion by the early 2030s. Compare that to the enterprise identity governance market, which already manages digital identities for the same employees, contractors, and vendors. SailPoint, Saviynt, Omada, Okta, and Microsoft Entra are not adjacent competitors circling our category. They are a different order of magnitude entirely, and they got there first. When a $5 billion category sits downstream of a $50 billion category, the smaller one does not get to set terms. It gets absorbed, translated, or ignored. The shadow database framing I have used before is still sound, and it is worth double-clicking into it here. PIAM, at its weakest, becomes a secondary system of record that attempts to replicate what the real identity platform already knows about a person: who they are, what role they hold, what they are allowed to touch. A shadow database is not a player for ownership either. It is a duplicate, maintained because the adapter was never built cleanly, and duplicates do not keep their existing ones once the real joint is in place. That gap is closing fast, and when it closes, the duplicate stops mattering, not because it lost anything, but because the workaround it was built on disappears. The product companies become a feature of a larger value proposition. And now I have a cleaner, harder example than anything from inside our own industry, and it did not come from a PAC's vendor at all. On June 18, Cisco announced its intent to acquire WideField Security, a company whose entire product is dedicated to correlating and normalizing identity telemetry so that AI agents in a security operations center can trust the data they act on. Cisco is not a small player making a defensive move. This is its third identity-adjacent security acquisition in 2026, following Astrix Security in May and Galileo earlier in the year. Cisco is roughly a $240 billion company. It already owns Splunk, an enterprise security analytics platform with deep pockets and deep engineering talent. And it still needed a dedicated acquisition team to make its identity data clean enough for its AI agents to act on without making mistakes at machine speed. Think about it. If a company with that scale, that engineering capacity, and that much identity infrastructure already in place still cannot trust its own data without buying a company built specifically to fix it, what should we conclude about PACs vendors who are currently shipping "AI-ready" platforms on top of access control databases that have been fragmented, poorly synced, and inconsistently maintained for a decade or more? The Shadow Database problem is not unique to physical security (and not a term I made up on my own). Cisco just proved it shows up inside cybersecurity, too, at a scale most of our industry will never operate at. The difference is that Cisco recognized the problem and paid to fix it before letting its agents run. Most of our industry is shipping the AI layer first and hoping the identity layer underneath holds up. I think this plays out in one of three ways for PIAM vendors, and I have written versions of this before, but I want to apply it specifically here. Some become middleware, the translation layer between real identity providers and physical endpoints, which is a real and durable business if done well. Some retreat into vertical specialization, enterprise, government, and critical infrastructure, where audit defensibility for physical access has to live somewhere, and compliance complexity protects a niche. The rest keep building shadow databases and calling it innovation, and they will be maintained, not invested in, until they are quietly replaced. None of those three paths owns the identity layer, because none of them ever could have been. Cisco just spent real money confirming that even the companies with the most resources in the world still need someone to build the adapter properly, rather than assuming it builds itself. The adapter is real work. It has never been the same thing as owning the identity it adapts. I put a version of this argument in front of the PhySec Collective (if you are not in the Slack community, please join here), and the pushback sharpened it in ways worth discussing. Zachary Klares made the case for why the clean version of this story, IT players simply bridging the gap and absorbing PIAM and PACs outright, will not happen on any near-term timeline, even if the technical capability exists. The barrier is not capability. It is the sheer fragmentation of the installed base and the cost of transitioning hardware and systems to anything sophisticated enough to operate natively in an identity-first model. He pointed to a second barrier I had not thought of: the insular, in-group nature of physical security. Outsiders face real friction getting access to the relationships, documentation, and APIs needed to build something that actually changes the model, not just a vertically integrated point solution. He named Verkada as the example people reach for to prove this wrong, and then explained why it does not prove what people want it to: an outlier that fits a specific subset of the market end to end, not evidence of a repeatable path. His read on where this lands is more measured than my framing: smaller companies keep using low-cost, proprietary tools as long as they are convenient, while everyone else expects whatever they use to operate seamlessly as an endpoint in a larger workflow once open identity protocols bridge the digital and physical reach and production maturity. Sal D'Agostino approached it from a different angle and was more skeptical toward both PIAM and PSIM. His view is that most of what gets called middleware is really just PACs' syslog data with a more complicated name attached, a band-aid on integrated monitoring that adds identifiers and bloat rather than solving anything structural. His position is that situational awareness should be a core PACs value proposition in the first place, not a layer bought separately. That is a sharper challenge to my framing than it first appears: I have been treating PIAM as a category that needs a better strategic path. Sal is questioning whether large parts of it should have existed as a separate category at all. Mark Schweitzer's reading is the one that complicates my argument the most directly, and I here for it. His position: in the current state, PIAM has already handed off true identity management to HRIS and IAM platforms as part of its own evolution. What PIAM vendors provide now is translation, workflow automation, and security-specific features that the HRIS, IAM, enterprise platform, and PACs vendors either cannot or will not build themselves. He is direct about where this leaves the convergence conversation: the type of convergence actually happening, while real, does not solve most of the problems PIAM vendors solve today. His conclusion is that there will be a need for PIAM companies, or whatever they end up calling themselves, until that gap closes, and he does not see it closing soon. Mark's framing and mine are not as far apart as they sound, and I think the disagreement is mostly about emphasis rather than substance. I called translation a feature, not a company. He is arguing that as long as the big platforms keep declining to build that feature themselves, the feature is the company, and there is a real business in occupying that gap for as long as it stays open. I think we agree on the mechanism. We disagree on how long the gap holds and how defensible a business built entirely on occupying it can be once an HRIS or IAM vendor decides the feature is worth building natively, which is exactly what Cisco just did by buying WideField instead of leaving that gap to a third party. That is the part I keep coming back to. Cisco did not wait for a translation vendor to solve its identity telemetry problem. It bought the capability and pulled it inside. If that is the pattern enterprise IAM platforms follow as agentic security matures, the PIAM companies occupying the translation gap should assume the platforms they depend on are evaluating build versus buy on exactly the feature that the translation vendor is selling, and that buy is getting cheaper and faster every quarter as AI improves. So I want to retire my own headline: PIAM did not lose a war for identity. It was never entered in one. What it has built, at its best, is a real and valuable adapter business, a middleware, sitting in a gap that nobody upstream bothered to close. That is a legitimate place to operate, and Mark is right that it is not going away on any near-term timeline. But an adapter business and an identity-ownership business are not the same business, and much of the confusion in this category stems from describing the former with the language of the latter. It may also be a great example of one built for the cottage industry, and the other is what it looks like as we go into a mainstream market. |
Click on the above image and use code sxst3gkbkn to hear the audio version.
PS: I am sure some of you may forward this, but please do so sparingly and encourage others to sign up here. Thank you!
