The shape of identity in a business
Identity is the control plane for who and what can do what. The trick to keeping it sane: nest accounts into groups and roles, and never pin a permission on a user.
Notebook
Thought experiments and designs-on-the-shelf — concepts I'd reach for if the need ever lands.
Identity is the control plane for who and what can do what. The trick to keeping it sane: nest accounts into groups and roles, and never pin a permission on a user.
When an orchestrator agent delegates to a sub-agent, it can quietly hand over a token that does far more than the sub-agent should. Here's the token-chain risk, IBM and Red Hat's Kagenti blueprint, and a zero-trust pattern you can run without re-platforming onto Kubernetes.
Token prices are heading for a real-cost reckoning. The way through is the one we use for compute: own the AI baseline, burst for the bleeding edge.
Where midPoint plus Authentik can replace the Microsoft identity stack in a hybrid Windows/Linux shop. And where it can't. A thought experiment, not a build.
I measured uv against our pin-everything dependency policy. It fits. And we're still staying on stdlib venv. The why is more interesting than the verdict.