The Team Behind the Specialisation: Meet Matt Fernandes
Building identity around people, trust and better experiences
When people think about identity, they often think about passwords, logins and the occasional MFA prompt. But for Matt Fernandes, identity is far more than that. It’s a foundation that helps people access the tools they need, enables organisations to work securely, and increasingly plays a crucial role in how businesses adopt technologies like AI.
As a Lead Solution Architect at Condatis, Matt spends his time helping organisations solve complex technology challenges by bringing together people, processes and systems in a way that works. His role is about creating the blueprint that allows information to move safely and efficiently between people, applications and services.
"Good architecture should make life easier"
Ask Matt what good identity architecture looks like, and his answer isn’t a list of technologies or frameworks. Instead, it comes down to a few simple principles: automate where possible, delegate where appropriate, and create an experience that feels frictionless for users.
In his view, the best identity systems are often the ones people barely notice. Non-privileged users should be able to access what they need when they need it, without unnecessary barriers getting in the way of their work. At the same time, privileged activities should have the right controls and oversight in place to protect the organisation.
It’s a balance between security and usability that Matt believes many organisations still struggle to achieve.
Why identity is more important than ever
One misconception Matt encounters regularly is that identity is somehow “boring” or simply the thing that lets people log into their computers. In reality, he sees identity as one of the most important foundations of modern organisations.
Over the course of his career, he has watched identity evolve from a niche, highly specialised capability into something that underpins cloud services, remote working, digital transformation and cybersecurity programmes around the world. Identity and access management is no longer viewed as just an IT problem. It has become a critical business capability that can help organisations succeed or leave them exposed to significant risk.
As more of society, work and services move online, Matt believes identity’s importance will only continue to grow.
The identity trend he's watching closely
Like many in the industry, Matt is paying close attention to the rise of non-human identities and AI-powered systems. But his perspective isn’t focused on hype. Instead, he’s interested in how organisations can adopt these technologies safely and responsibly.
He sees growing risks where tools are adopted faster than organisations can govern them, particularly when sensitive data is involved. Once information has been shared with an unsanctioned service, the consequences can be difficult to reverse, which is why establishing the right controls and visibility from the start is so important.
For Matt, identity is central to that challenge.
"Identity is a critical underpinning for anyone trying to adopt AI, particularly as organisations begin introducing autonomous agents with their own permissions, responsibilities and access to information."

A future built on trust
While AI dominates many technology conversations, one area Matt is particularly excited about is the future of privacy-first digital identity and verified credentials.
He imagines a future where proving who you are doesn’t require handing over large amounts of personal information every time you interact with a service. Instead, trusted verification could happen behind the scenes, allowing organisations and individuals to confirm key facts without exposing unnecessary data.
Just as importantly, he believes these innovations must be designed with accessibility in mind so that everyone can benefit from them. Drawing on personal experience, Matt highlights the importance of ensuring digital identity solutions work for people with different needs and abilities, rather than creating new barriers to participation.
What the specialisation means to Matt
As someone who played a role in achieving Condatis’ Microsoft specialisation, Matt is clear that the recognition goes beyond certifications alone.
While the assessments validate technical expertise, they also demonstrate real-world experience, proven delivery capability and the ability to help organisations tackle complex identity challenges. Achieving a specialisation requires organisations to show they can put that knowledge into practice.
What stands out most to him, however, is the team effort behind the achievement.
“I genuinely don’t think I’ve ever worked with a more talented and knowledgeable group of people. It really is a privilege to work alongside them.”
That collaborative expertise, combined with years of hands-on experience, is what makes achievements like the specialisation possible.
Falling into identity and staying for the people
Unlike many technology professionals, Matt didn’t set out with a clear ambition to build a career in identity. He describes entering the industry almost by accident, gradually working his way from entry-level IT roles into consultancy and identity-focused projects.
What keeps him engaged today is the constant opportunity to learn, solve problems and make a meaningful difference for customers. Every project is different, every challenge comes with its own puzzle to solve, and every successful outcome has a tangible impact on someone’s working day.
For Matt, that’s what identity ultimately comes back to.
It’s not just about technology. It’s about people.
AI security isn’t a Model Problem. It’s a Trust Problem.

Executive Perspective
By Alasdair Murray, Chief Product and Technology Officer
AI security isn't fundamentally a technology challenge. As organisations embed AI into critical workflows, trust, identity and governance become the real determinants of success.
Recent AI security incidents have generated significant discussion because they appear to demonstrate a new category of threat: autonomous AI agents taking actions beyond the expectations of their creators. In one widely discussed report, AI agents engaged in unsanctioned activity on the live internet, including activity directed at real people and organisations. The report describes behaviours including fake online identities, social engineering, malicious code, supply-chain manipulation and attempts to influence human decision-making.
It would be easy to view those incidents as evidence that AI has created an entirely new security problem. That is not the most useful lesson. The more important point is that the underlying behaviours are familiar. Security teams have dealt with social engineering, misuse of trust, misuse of access, supply-chain compromise and privilege misuse for decades. What has changed is the speed, persistence and scale with which these behaviours can now be attempted.
That distinction matters because it changes the response required from organisations. If AI security is framed primarily as a model problem, attention naturally moves towards model selection, technical safeguards and safety controls. Those controls matter, but they are not sufficient. The harder strategic question is not simply how organisations secure AI, but how they decide where AI should operate, what authority it should hold, what risks are acceptable and how accountability is maintained when AI becomes part of business execution.
The issue is not that organisations are waiting to adopt AI. The issue is that many are already experimenting, deploying and automating faster than their governance models can keep up.
As I see it, AI transformation should not start with technology. It should start with outcomes, strategy, governance and risk.
“AI adoption should be governed by outcomes, not capability.”
Alasdair Murray, Chief Product and Technology Officer, Condatis
Key Takeaways
01
AI is not creating an entirely new class of security risk. It is accelerating familiar risks such as social engineering, misuse of trust, misuse of access and supply-chain compromise.
02
Organisations are no longer in a purely strategic planning phase. AI experimentation and adoption are already underway, often moving faster than governance, which makes trusted adoption an immediate executive priority.
03
A common gap is emerging between AI adoption and identity governance. AI and Productivity teams are often moving quickly, while security and IAM teams are not always involved early enough or asking what access, authority and accountability AI tools require. Allowing access before control.
04
AI literacy is now a trust control. The AISI incident showed that human decisions about agent permissions, autonomy and guardrails directly shape AI behaviour. AI literacy helps teams understand those choices, identity controls define what agents can do and governance keeps decisions accountable.
05
Organisations should not begin AI transformation with models or agents. They should begin with business outcomes, strategy, governance and acceptable risk.
06
Strategy must include AI: which workflows should AI influence, which should remain human-led, and what level of autonomy is appropriate.
07
As AI moves from assistance to action, identity becomes more strategic because AI systems increasingly require access, authority and accountability.
08
AI adoption will create a new intellectual property challenge as prompts, corrections, workflows, evaluations and decision patterns become organisational intelligence.
09
Trusted AI adoption will require organisations to solve three connected governance challenges: Strategy Governance, Identity Governance and soon Intelligence Governance.
Why this matters now
AI adoption is accelerating at the same time as identity-based risk continues to grow. As organisations embed AI into workflows, the number of digital actors capable of accessing information, influencing decisions and taking action will increase significantly. The challenge is no longer whether AI becomes part of the enterprise. The challenge is whether organisations can establish the trust, identity and governance foundations required to scale it safely.
- Verizon analysed 22,052 security incidents and 12,195 confirmed data breaches in its 2025 Data Breach Investigations Report.
- Stolen credentials accounted for 22% of breach entry points. Identity compromise remains one of the most common routes into organisations.
- Human error contributed to 60% of breaches. Trust, social engineering and human decision-making remain central to cyber risk.
- Gartner predicts 40% of enterprise applications are expected to include task-specific AI agents by the end of 2026, up from less than 5% in 2025. Agentic capability is moving into business systems quickly.
- Microsoft's Agentic AI adoption maturity model positions enterprise-scale AI adoption as a strategy, governance and operating model challenge, not simply a technology deployment exercise.
The message is clear: organisations are no longer in a planning phase. Experimentation, deployment and execution are already underway, often moving faster than governance.
Executive implication
Most organisations already have employees experimenting with AI, teams evaluating agents and technology functions exploring automation opportunities.
The challenge is no longer whether AI will become part of the enterprise. The challenge is whether leadership teams can establish sufficient trust, governance and accountability before AI becomes embedded within critical workflows.
The organisations that succeed will not necessarily be those that adopt AI first. They will be those that can scale adoption with confidence.
The Condatis AI Adoption Sequence
Many AI programmes begin with capability. A new model is released, a new agent platform becomes available, or a new productivity feature captures executive attention. The conversation then quickly moves to deployment: where can this be used, which processes can be automated, and how quickly can the organisation scale adoption?
That sequence is understandable, but it puts the technology before the business decision.
At Condatis, we believe organisations need to follow a different sequence.
Outcomes
What business outcome is the organisation trying to improve?
Strategy
How should AI contribute to that outcome, which workflows should AI influence, where is AI genuinely appropriate and what security framework should we apply?
Governance
Change the color to match your brand or vision, add your logo and more.
Risk
What risks are introduced, and what level of autonomy is acceptable?
Technology
What technology solution best supports those decisions?
This order matters. Some workflows may be strong candidates for AI because they are repeatable, well understood and capable of being governed through clear controls. Others may involve judgement, regulation, customer trust or business risk that makes full automation inappropriate. AI strategy is therefore a critical part of risk and governance planning, but it should not be treated as a narrow technical assessment. It is part of a broader strategic decision about where AI should operate, what value it should create and how much autonomy the organisation is prepared to delegate.
Microsoft’s Agentic AI adoption maturity model points to this broader enterprise challenge. It describes the need to move beyond isolated experimentation and address strategy, process transformation, governance, value realisation, operations and responsible AI when scaling across the enterprise. Microsoft’s business strategy guidance for agentic AI places emphasis on redesigned processes, measurable business value and clarity over where agents act, what decisions agents can make and how humans remain in control.
The decision to adopt AI should therefore be driven by outcomes, strategy, governance and risk, not by technology capability alone.
“The real risk is not adopting AI. The real risk is adopting AI without a strategy for where it should operate, what outcomes it should improve and how it should be governed.”
Alasdair Murray, Chief Product and Technology Officer, Condatis
From assistance to action
For much of the last two years, enterprise AI adoption has centred on assistance. Summarising information, generating content, helping employees find answers and reducing the effort involved in everyday tasks. These use cases matter, but they are not the end state of AI transformation.
The direction of travel is towards AI systems that participate in business processes rather than merely support them. Microsoft describes the shift towards an agentic enterprise as a move from task-level automation to systems where apps and agents help organisations focus on outcomes rather than steps. Its agentic enterprise material describes a move from systems of record to systems of action, where intelligent systems influence how work is executed, owned and improved.
This shift changes the nature of the governance challenge. A system that helps a user write a report presents one type of risk. A system that can access customer information, update records, trigger workflows, approve requests or interact externally presents another. Once AI moves from assistance to action, the organisation must decide what authority has been delegated, what data informs the decision, which controls apply and who remains accountable for the outcome.
Those are not primarily model questions. They are trust questions.
The problem has always been trust
One of the most revealing aspects of recent AI security incidents is that the route to impact still depended heavily on trust relationships. The AISI report describes agents creating fake accounts, attempting to pressure administrators, sending targeted communications and pursuing actions that involved real people and public systems.
This should not be surprising. Security has always been concerned with trust: who can be trusted, under what conditions, with what access, and for what purpose. Identity establishes trust. Access governance controls trust. Privileged access management limits trust. Audit and assurance validate trust. Zero Trust architecture exists because organisations recognise that trust should not be assumed simply because a user, device, workload or system appears legitimate.
AI does not change those fundamentals. It changes the operating conditions around them.
An AI-enabled actor can process more information, identify more patterns, generate more persuasive interactions and adapt more quickly than a human working manually. The strategic risk is not that every organisation will immediately face autonomous AI-driven attacks. The strategic risk is that the speed of AI increasingly exposes weaknesses in trust, identity, access and governance models that were already under strain.
This is why AI security cannot be separated from identity and governance.
AI literacy also becomes part of the trust model.
The AISI incident was not simply a model or security failure. It showed how human decisions about agent permissions, autonomy and guardrails directly influence behaviour. Trusted AI needs informed humans, appropriate controls and ongoing accountability. AI literacy shapes how much freedom an agent is given. Identity controls determine what that agent can do. Governance determines whether those decisions remain accountable. Remove any one of the three and trusted AI becomes difficult to achieve.
Suggested literacy questions should include:
- Should the agent have internet access?
- Should it be able to create accounts?
- Should it be able to contact third parties?
- Should it be able to execute code?
- What level of autonomy is appropriate?
- What is the blast radius if it behaves unexpectedly?
The Condatis Trust Framework for AI
Trusted AI adoption requires more than a technology roadmap. It requires organisations to solve three connected governance challenges.
Every AI system needs access to something. It may need access to documents, applications, customer records, operational systems, collaboration tools, APIs, workflows or enterprise knowledge. As soon as access exists, identity becomes relevant.
Historically, identity programmes have focused on people; employees, partners, customers and administrators. Their purpose has been to establish who can access what, under which conditions, and with what level of accountability. AI extends this challenge to new populations: agents, workloads, services, bots and other non-human actors that may operate on behalf of users, teams or business processes.
This is where many organisations risk underestimating the change. An AI agent with excessive permissions is not simply a technical configuration issue. It is an authority issue. A non-human identity without a clear owner is not simply an operational gap. It is an accountability gap. An agent that can access sensitive information without appropriate controls is not simply a data issue. It is a trust issue.
As AI becomes embedded into operational workflows, organisations will need to answer questions that are already familiar from identity and access governance, but now apply them to new actors:
- What is this agent allowed to access?
- What actions can this workload perform?
- On whose behalf is the system acting?
- Who owns the risk?
- How are permissions reviewed?
- How is inappropriate access prevented?
- How is accountability demonstrated?
The more AI moves towards action, the more identity becomes the control plane through which trust is established and governed.
“AI does not reduce the importance of identity. It increases it.”
Alasdair Murray, Chief Product and Technology Officer, Condatis
The second governance challenge is strategic. Organisations need to determine where AI should influence work, which workflows are suitable for AI assistance or automation, what level of autonomy is appropriate and where human judgement should remain central.
Workflow analysis is therefore not a standalone technical assessment. It is part of AI strategy. A workflow may be suitable for AI if the outcome is clear, the process is well understood, the data sources are governed and the risks can be controlled. A workflow may be unsuitable for greater autonomy if it involves material judgement, sensitive customer impact, regulatory complexity or ambiguous accountability.
This is why AI strategy must start with business outcomes. Organisations should first understand the value they are trying to create, then assess which workflows can safely support that value through AI. AI adoption becomes credible when leaders can explain not only what technology is being deployed, but why a workflow is suitable, how autonomy is governed and how success will be measured.
Strategy also needs to address operating model impact. If AI changes who performs work, who approves decisions, who handles exceptions or who owns the outcome, then the organisation is not simply deploying a tool. It is changing how work is governed. That is why use case analysis should sit inside the strategy phase rather than being treated as an implementation checklist.
A mature strategy should answer four connected questions:
- Which outcomes are strategically important enough to improve with AI?
- Which workflows contribute most directly to those outcomes?
- Which parts of those workflows are suitable for AI assistance, automation or agentic execution?
- What authority, accountability and controls are required before AI is introduced?
This approach helps organisations avoid two common mistakes: deploying AI where it is technically possible but strategically weak, and avoiding AI where it could create genuine value because the organisation has not yet created the governance conditions for adoption.
There is another important dimension to AI adoption that is still underdeveloped in many executive conversations. Organisations are not only using AI to consume intelligence. They are also creating intelligence through the way people interact with AI systems.
The Reverse Information Paradox frames this clearly: in the AI age, firms may risk giving away proprietary knowledge in order to use the intelligence they have purchased. The article argues that prompts, corrections, traces, evaluations, feedback and institutional context all form part of the learning that can accumulate through AI use.
This matters because the value created through AI adoption is not limited to individual outputs. Every prompt, correction, workflow pattern, evaluation criterion and decision rule can capture something about how an organisation operates, what it values and how it makes decisions. Over time, this becomes a form of organisational intelligence.
That intelligence can become strategically valuable. It reflects institutional knowledge, operating context, judgement, expertise and competitive differentiation. In many cases, it may be difficult for competitors to replicate because it is not simply data. It is knowledge created through the interaction between people, processes and AI-enabled work.
This introduces an intellectual property and governance issue that organisations need to address before AI becomes deeply embedded into critical workflows. The question is not only what data AI can access. It is also what intelligence is being created, where that intelligence resides, who owns it, how it is protected and whether it compounds as an asset of the organisation.
This is where governance will need to evolve beyond traditional data governance. Organisations will still need to protect information, classify data and manage access. However, they will also need to govern the learning loop created by AI adoption: the prompts, evaluation criteria, workflow designs, feedback patterns, decisions and contextual knowledge that shape how AI performs inside the enterprise.
For many organisations, this will become a board-level issue because it touches risk, intellectual property, operational resilience and competitive advantage.
“Organisations will need to govern intelligence in the same way they govern data, because AI turns organisational knowledge into a strategic asset.”
Alasdair Murray, Chief Product and Technology Officer, Condatis
Proactive governance becomes essential
Traditional security operating models were largely designed around human speed. An event occurs, monitoring identifies something unusual, an analyst investigates and a response is initiated. Detection and response remain essential, but AI places pressure on this operating model because autonomous or semi-autonomous systems can take many actions before a human has the opportunity to intervene.
The AISI report is relevant here because it describes agents carrying out activity across multiple channels, including public infrastructure, external repositories and communications aimed at real people and organisations. The lesson is not that every organisation is about to experience the same scenario. The lesson is that AI increases the importance of preventing inappropriate authority, access and action before the event occurs.
This moves governance upstream. Organisations need to determine which workflows are appropriate for AI, what data and systems can be accessed, what level of autonomy is acceptable, what approvals are required and how actions will be monitored. Reactive controls remain important, but they should not be the primary line of defence when AI systems can operate quickly and continuously.
In an AI-enabled organisation, governance cannot be a retrospective compliance activity. It has to be designed into the strategy, into the workflow and into the identity model that controls who and what can act.
"The challenge for leadership teams is no longer deciding whether AI will be adopted. The challenge is deciding how much trust they are prepared to delegate."
Alasdair Murray, Chief Product and Technology Officer, Condatis
Trust problems are already here
The trust challenges that AI will amplify are not theoretical. Condatis is already helping organisations strengthen the identity and access foundations required to deal with increasingly sophisticated identity-based risks.
Bridgepoint, a global investment firm, worked with Condatis to address identity-based attacks such as helpdesk impersonation. This case study details a solution using Microsoft Entra Verified ID, Face Check and Microsoft Authenticator to support secure, risk-based verification in high-risk support scenarios while maintaining a seamless user experience. The outcome was a more resilient identity framework designed to help protect investor trust, reduce impersonation-driven account compromise risk and support Bridgepoint’s continued growth.
The significance is that Bridgepoint did not solve this problem with a new category of AI security technology. The response was stronger identity assurance, stronger trust controls and better verification of who was requesting access in the first place.
The relevance to AI transformation is clear. Helpdesk impersonation is not a new threat, and identity-based attacks are not new threats. However, AI can increase the sophistication, volume and credibility of trust-based attacks. The response is not simply to buy an AI security product. The response is to strengthen the trust foundations that determine who can access what, how identity is verified and how higher-risk scenarios are governed.
The same principles that help defend organisations against identity-based threats today will become foundational to trusted AI adoption tomorrow.
The next constraint to AI adoption is trust
The technology sector often describes AI adoption as a race for capability. Larger models, better reasoning, more advanced agents and deeper platform integrations are all important. However, enterprise transformation is rarely constrained by technology alone.
Cloud adoption accelerated when organisations developed confidence in security, governance and operating models. Digital transformation accelerated when organisations learned how to manage risk, data and customer trust in online environments. AI is likely to follow a similar pattern.
The next constraint to AI adoption is unlikely to be whether the technology can perform a task. It is more likely to be whether organisations trust AI enough to let it influence important workflows, decisions and outcomes.
Trust will depend on whether organisations can answer a small number of difficult questions:
- Are we applying AI to the right business outcomes?
- Do we have a clear strategy for where AI should operate?
- Do we understand which workflows are suitable for AI?
- Have we defined the right level of autonomy?
- Is access controlled?
- Is authority explicit?
- Is accountability maintained?
- Is organisational intelligence protected?
Organisations that can answer these questions will be better positioned to move from experimentation to scale. Organisations that cannot may continue to accumulate pilots, tools and proofs of concept without building the confidence required for operational adoption.
The Condatis view
Our view is that AI transformation should not begin with a technology decision. It should begin with a clear understanding of the outcomes an organisation wants to improve, the strategy for how AI should contribute to those outcomes and the risks created when workflows become AI-assisted or AI-driven.
Technology matters, but it should come later in the decision sequence. Before selecting models or agents, organisations need to decide where AI should operate, what authority should be delegated, what controls are required and how accountability will be maintained. They will also need to understand how AI-enabled workflows create organisational intelligence and how that intelligence will be governed as a strategic asset.
This is the point at which identity, AI strategy and intelligence governance become central to transformation. Identity governs who and what can act. Strategy determines where AI should operate and which workflows are suitable. Governance ensures the right controls, accountability and oversight are in place. Intelligence governance protects the organisational knowledge created through AI adoption.
That is why AI security is not just a model problem. It is a trust problem.
The Future of AI Will Be Defined by Trust
Recent AI security incidents have attracted attention because they appear novel. In reality, they reinforce a familiar lesson: trust, identity and governance matter more than ever. The threats are not new. What has changed is the speed, scale and autonomy with which they can operate. The AISI report shows AI agents engaging in unsanctioned activity on the live internet, including activity directed at real people and organisations, with behaviours including fake identities, social engineering, supply-chain manipulation and attempts to influence human decision-making.
The important point for executives is that this is no longer a theoretical planning exercise. AI adoption is already happening across organisations. Experimentation is already underway. Employees are already using AI tools. Business teams are already looking for productivity gains. Technology teams are already exploring agents and automation. In most cases, execution is moving faster than governance.
That speed imperative is real. Organisations cannot respond by slowing everything down until the perfect operating model exists, but nor can they allow AI adoption to run ahead of strategy, risk management and control. The organisations that realise the greatest value from AI will not be those that deploy the most agents or move fastest without guardrails. They will be those that move quickly with clarity: identifying the right business outcomes, defining the right AI strategy, applying AI to the right workflows and establishing the governance required to operate safely at scale.
The conversation should not start with models or agents. It should start with outcomes. Which business outcomes should AI improve? Which workflows should AI influence? Which decisions should remain human? Where is automation appropriate? What risks are acceptable? What governance is required?
Only then should technology choices be made.
As AI becomes embedded into business operations, organisations must govern more than access and actions. They must also govern the intelligence created through AI-enabled workflows. The knowledge, decisions, context and learning accumulated through AI will increasingly become a source of competitive advantage and a form of intellectual property requiring the same level of protection and stewardship as any other strategic asset. The Reverse Information Paradox makes this point clearly: in the AI era, prompts, corrections, traces, evaluations, feedback and institutional context all become part of the learning organisations create through AI use.
The future of AI will not be constrained by technology. It will be constrained by trust. Organisations need to move quickly, but they need to move deliberately. Start with outcomes, define the strategy, govern the workflow, understand the risk and then choose the technology. Trust starts with identity, but it must extend across the workflows, decisions and organisational intelligence that AI will increasingly shape.
“The future of AI will not be constrained by technology. It will be constrained by trust. The organisations that move fastest will not be those that skip governance, but those that build enough trust to scale AI with confidence.”
How Condatis Can Help
Our view is not that organisations should slow down AI adoption. The speed imperative is real, and the organisations that wait too long risk falling behind. The issue is that speed without trust creates unmanaged risk. The priority is to move quickly with a clear strategy, strong identity foundations, appropriate workflow governance and a practical understanding of where accountability sits.
Condatis helps organisations move beyond AI experimentation and towards trusted adoption. We help leaders define where AI can create meaningful business value, shape the strategy for where AI should operate, assess which workflows are suitable for AI assistance or automation, establish the identity and governance foundations required for safe adoption, and protect the organisational intelligence created through AI-enabled transformation.
Our work with Bridgepoint shows how modern identity and access management can address trust-based threats in practice. By introducing secure, risk-based verification using Microsoft Entra Verified ID, Face Check and Microsoft Authenticator, Condatis helped Bridgepoint strengthen identity assurance in high-risk support scenarios while maintaining a seamless user experience.
As AI increases the speed, scale and sophistication of trust-based risk, organisations will need identity and access governance that can protect people, systems, workflows and non-human actors. The foundations that help defend against identity-based threats today will increasingly become the foundations for trusted AI adoption tomorrow.
Successful AI adoption is not about deploying more technology. It is about creating more value, with the trust required to sustain it.
Sources and Further Reading
UK AI Security Institute - Security Incident
This report provides the incident evidence referenced in this article, including AI agents engaging in unsanctioned activity on the live internet and activity directed at real people and organisations.
Introduction to the Agentic AI adoption maturity model
This guidance describes the move from AI experimentation to enterprise-scale adoption, including strategy, process transformation, governance, responsible AI and measurable business value.
Agentic AI maturity model
This source supports the emphasis on reimagining how work gets done, ensuring agents deliver measurable business value and clarifying where agents act, what decisions agents make and how humans stay in control.
Build an Agentic Enterprise with AI Agents and Copilot
This source supports the discussion of the shift from systems of record to systems of action, and the need for trust, governance and security as agents become embedded into workflows.
The Reverse Information Paradox
This article supports the argument that AI adoption creates organisational intelligence through prompts, corrections, traces, evaluations, feedback and institutional context, raising governance and intellectual property questions.
Bridgepoint: Strengthening Identity Security
This case study demonstrates how Condatis helped Bridgepoint strengthen identity security against identity-based attacks such as helpdesk impersonation using Microsoft Entra Verified ID, Face Check and Microsoft Authenticator.
Stop Calling it Silent Failure
The Dangerous Myth at the Heart of Identity Governance
Condatis point of view: The industry has spent years calling identity risk a silent failure.
We disagree.
In Identity and Access Management (IAM) and governance, failure is rarely silent. The signals are usually there: audit findings, orphaned accounts, stale access, failed provisioning events, exception logs and unresolved governance gaps.
The real failure is when those signals are not converted into ownership, accountability, urgency and funded action.
Let’s Get with the Times
The identity industry has spent years talking about silent failure. We think that misses the point. Identity failure is rarely silent. It speaks through audit findings, orphaned accounts, dormant entitlements, failed provisioning processes and governance exceptions that organisations choose to tolerate. What has traditionally been labelled as invisible risk is often simply unowned and unexamined risk. What has been described as system drift is usually governance drift with visible symptoms.
The problem is not a lack of evidence; it is a lack of ownership, urgency, accountability and funded action.
At Condatis, we believe the conversation needs to move beyond silent failure and towards unowned identity risk. Because in modern identity environments, the greatest risk is not that warning signs are absent. It is that they are already present, but not treated with the business-level consequence they deserve.
The industry keeps calling it “silent failure”. That lets everyone off too lightly
“Silent failure” has become one of those phrases the security industry likes because it sounds sharp, technical and slightly ominous. It suggests something hidden inside the estate, quietly decaying while everyone else carries on. But in identity and access management, that framing is increasingly unhelpful.
Identity failure is not silent. It leaves fingerprints everywhere: in stale accounts, access review exceptions, failed joins between HR and directory data, over-privileged users, dormant service principals, unexplained workarounds, manual approvals, bypassed processes and long-standing audit observations. These are not whispers. They are evidence.
The uncomfortable truth is that many organisations already have enough evidence to justify action. What they often lack is the discipline to look at that evidence honestly, connect it to business risk and fund the work needed to fix it.
“The problem is not that identity failure is silent. The problem is that identity risk is allowed to sit without sufficient ownership, urgency or business-level accountability.”
Stacey Quintana – Head of Strategy Architecture


The “see no, hear no, speak no” problem in identity security
For a long time, IAM was not treated as the front line of cybersecurity. It was treated as enablement, plumbing, directory work, user administration, provisioning, ticket queues and project dependency. Important, yes, but rarely board-level until something went wrong.
That has changed. Identity is now where security strategy becomes real. Zero Trust depends on it. Privileged access depends on it. Cloud control depends on it. AI and agent governance will depend on it even more. Yet many organisations are still operating with a legacy mindset: see no ownership problem, hear no evidence problem, speak no uncomfortable truth about the state of access.
This is where the “silent failure” narrative breaks down. It implies the organisation was denied a signal. In reality, the organisation often saw the signal and normalised it. It heard the noise and called it business as usual. It had the evidence and buried it inside technical debt, migration plans, exception logs or audit remediation backlogs.
From silent failure to unowned identity risk
Condatis does not simply repeat the market language. We challenge it. The stronger position is this: identity failure is rarely silent. It is visible, measurable and repeatedly signalled. The issue is that those signals are not consistently translated into ownership, urgency, accountability and funded action.
Unowned identity risk occurs when an organisation has the data required to understand identity risk but does not turn that data into accountable action. It happens when dashboards focus on availability rather than control integrity. It happens when access still works, so the organisation assumes governance still works. It happens when ownership is diffused across HR, IT, security, application teams, service owners and transformation programmes, but nobody is accountable for the whole identity outcome.
That is not a silent failure. It is a risk without sufficient ownership, urgency or business-level accountability.
“The risk is not invisible. It is unowned.”
What Leaders See
- Users can still log in
- Provisioning dashboard is green
- Legacy and cloud directories coexist
- Access reviews are completed
- No major incident has occurred
What the Evidence May Show
- Accounts exist outside the intended lifecycle process
- Downstream applications hold stale access or failed SCIM updates
- Exceptions, scripts and manual fixes are undocumented
- Reviewers approve what they do not understand
- Audit findings, orphaned identities and excessive privileges remain unresolved
What It Really Means
- Access delivery is working, but governance is not assured
- The control plane is not providing end-to-end enforcement
- Migration has become a governance risk, not just a technical phase
- Certification activity is not the same as assurance
- The organisation is measuring impact too late
Why this matters now
The stakes have changed because identity has moved from an administrative function to a strategic security control. Modern organisations are not only governing employees. They are governing privileged identities, service accounts, external collaborators, cloud workloads, automated processes and increasingly AI agents acting on behalf of people, systems or business functions.
If the organisation cannot explain who or what has access, why that access exists, who owns it, how it is reviewed, and what happens when the business context changes, then it does not have an identity problem in the narrow technical sense. It has an assurance problem.
And assurance problems do not stay contained within IAM or security. If identity risk materialises, the impact can become operational disruption, regulatory scrutiny, loss of confidence and damage to company value.
The point is not to be alarmist. It is to be realistic about what happens when known identity risk is allowed to remain unresolved, unowned and underfunded.
“If nobody can explain the access, nobody should be comfortable with the access.”
The board-level challenge
The next generation of identity leadership needs to be more direct. Organisations do not need another warning that risk may be “hidden”. They need to be challenged on whether they are prepared to act on the evidence already in front of them.
A mature board or executive team should not only ask whether systems are available. They should ask whether access is explainable, whether governance is evidenced, whether exceptions have owners, whether legacy coexistence is controlled, and whether the identity estate can support the organisation’s future ambitions without quietly passing unmanaged risk downstream.
This is especially important in transformation programmes. During migrations from legacy platforms to modern identity architectures, coexistence is normal. Unmanaged coexistence is not. Running old and new together is not the failure. Losing sight of who owns the transition state, what evidence proves control, and when exceptions must be retired is the failure.
A sharper diagnostic: the Identity Risk Accountability Test
Instead of asking whether your organisation has silent failure, ask whether it can convert identity signals into clear ownership, evidence-based decisions and funded remediation.
Can we name the accountable owner for our highest-risk human, privileged and non-human identities?
Can we prove that access exists because it was designed, approved and reviewed, rather than inherited or forgotten?
Can we show what happens to access when someone joins, moves, leaves, changes role, changes supplier status or stops owning a system?
Can we explain how legacy and modern identity platforms are governed while both are active?
Can we identify which access exceptions are temporary, who owns them, when they expire and what risk they create?
Can we evidence who owns service accounts, app registrations, automation accounts, secrets, credentials and agent identities?
Can we demonstrate that controls are working end to end, not just that systems are available?
If the answer is unclear, the risk was never silent
If your organisation cannot answer these questions, the issue is not that identity risk is hidden. The issue is that the organisation has accepted uncertainty in a control domain that now underpins cybersecurity, compliance, resilience and digital transformation.
That is the message Condatis brings to market: stop calling it silent failure. Call it what it is. Unowned identity risk. Governance drift. Insufficient accountability. The illusion of control.
Because identity does not fail quietly. It tells you in the audit trail, the exception queue, the orphaned account, the stale entitlement, the failed provisioning event and the service account nobody can explain. The question is whether anyone has the mandate, ownership and operating model to act before the risk becomes a business consequence.
“Stop treating identity as plumbing. It is the control plane for modern security.”
Fireside Chat
If this article resonates with challenges you're facing today, our fireside chat, 'The Controlled Path to Modern Enterprise Identity', expands on many of these themes.
The Team behind the Specialisation: Brigid Mansfield
Turning Condatis’ Microsoft partnership into a strategic growth engine
Brigid Mansfield leads our Microsoft alliance strategy at Condatis, aligning deep identity expertise with Microsoft’s priorities to drive growth, innovation, and customer outcomes.In this conversation, she shares what it really takes to achieve Microsoft Security Solutions partner designation and Identity & Access Management specialisation – and what it means for our customers.
Brigid is the Microsoft Alliance Manager at Condatis, responsible for our go-to-market strategy with Microsoft.
“At its core, my role is about turning our technical depth in identity and access management into a strategic growth engine through the Microsoft partnership.”
With a background across the wider technology and security space, she now works at the heart of identity, an area that’s becoming increasingly critical for organisations navigating AI and digital transformation.

Why this matters now
Identity is rapidly becoming the control plane for modern organisations, especially as AI adoption accelerates.
As Brigid puts it, you can’t scale AI without identity governing access, behaviour, and trust.
With Microsoft investing heavily in Entra and its wider security ecosystem, identity is no longer just infrastructure — it’s a strategic enabler. This specialisation reflects years of experience helping organisations get that foundation right.
Q&A with Brigid
The Microsoft Security Solutions partner designation is effectively a licence to operate, confirming that Microsoft has assessed our capabilities, people, and customer growth over time.
On top of that, the Identity & Access Management specialisation provides independent verification of deep expertise, backed by proven delivery, real-world outcomes, and validated customer references.
In simple terms: the designation shows we meet the bar, and the specialisation proves mastery in identity.
There are three core areas organisations need to evidence.
- First is performance: consistent growth in real customer adoption, particularly across Microsoft Entra and wider security workloads.
- Second is skilling: having certified practitioners operating at expert level, with experience delivering in complex, real-world environments.
- And third is customer success; verified deployments and measurable outcomes that demonstrate impact.
Crucially, it’s all evidence-led. Microsoft independently validates delivery, usage, and results. It’s not something organisations can claim without proof.
The specialisation speaks to three things.
First, technical depth: a specialist team delivering identity solutions in complex environments across sectors like government, financial services, and healthcare.
Second, delivery quality: independently verified customer references that reflect real outcomes in environments where getting identity wrong has significant consequences.
And third, trust: Microsoft effectively validating that Condatis does what it says it does.
Achieving the designation and specialisation wasn’t a single project, it was the result of years of work across the business, brought together through a structured and evidence-led process.
For Brigid, it started with a simple but critical step: understanding the gap.
The team mapped where Microsoft required them to be, versus where they were currently, building a clear view of what needed to be evidenced across performance, capability, and customer outcomes. From there, the focus shifted to evidence gathering, which, as she explains, “sounds straightforward, but it really isn’t.”
That meant pulling together:
-
- Verified customer references and real delivery outcomes
- Documentation across projects and deployment
- Proof of certifications and expertise, linked through Partner Centre
- Evidence of customer usage and adoption across Microsoft workloads
Just as importantly, everything had to be accurate, current, and fully attributable — from ensuring the correct partner relationships were recognised, to maintaining continuous governance so that all data could be validated by Microsoft.
The process then moved through formal submission and independent validation, reinforcing that this isn’t something organisations can simply claim without proof.
But what really stands out is how cross-functional the effort was.
“Honestly, everyone,” Brigid says, when asked who was involved — and that’s what makes it meaningful.
Delivery teams provided the technical depth, certifications, and outcome evidence. Sales and marketing played a key role in engaging customers and capturing references in a way that truly reflected the impact of the work. Leadership ensured governance, alignment, and strategic direction throughout.
“This was never an alliance exercise done in isolation,” she explains. “Every piece of evidence we submitted was built by the people delivering for our customers every single day.”
It gives customers confidence — backed by independent validation from Microsoft.
“Microsoft have independently verified not just that we’re a trusted security partner, but that we have proven expertise in identity.”
“When Microsoft customers need an identity specialist, Microsoft points them to us.”
“What changes our position… is credibility.”
With the designation and specialisation, Condatis gains greater visibility within the Microsoft ecosystem — with stronger advocacy from Microsoft teams and increased exposure to the right customer opportunities.
“We’re listed as a recommended partner… Microsoft is literally pointing their own customers to us, which is huge.”
It also unlocks deeper support — from co-marketing and investment through to technical resources and partner programmes.Together, that creates a more aligned, more impactful partnership, both commercially and for customers.
“These credentials are milestones, not end destinations.”
“Identity is moving extremely fast right now… the organisations that get this right will be the ones that can scale AI safely.”
Final Reflection
For Brigid, the most meaningful part of this wasn’t the submission itself, it was what sat behind it.
It was the work delivered across the business. The customers who trusted Condatis in complex environments. The outcomes that could be evidenced, validated, and stood behind.
Because ultimately, that’s what makes any of this matter.
As she puts it:
“When a customer independently talks about the impact of an identity project on their organisation, those examples are much more powerful than anything we could ever write about ourselves.”
And that’s what this specialisation really represents.
Not just meeting a standard, but consistently delivering work that stands up on its own.
At a time when identity is becoming the foundation for how organisations scale AI, that depth of experience isn’t just valuable – it’s critical.
From ambition to execution: key takeaways from Scotland’s public sector digital transformation event
Panel Partners
Public Sector Digital Transformation | Scotland 2026
Condatis recently attended Public Sector Digital Transformation: a day of insights, inspiration and innovation, bringing together leaders across Scotland to reflect on how far the public sector has come on its digital journey – and where it is heading next.
Across the day, one thing was clear:
Scotland has a strong vision for digital and AI, but the real focus now is turning that ambition into outcomes.


1. Strategy is aligned-now delivery needs to catch up
The opening plenary on building a digital nation set the tone. Scotland has done the hard work of aligning its direction through both the Digital Strategy (2025) and the AI Strategy (2026).
There is a clear commitment to connecting people to opportunity, unlocking the value of data, driving economic growth, and delivering better public services.
But organisations are under pressure. With costs rising faster than funding, there is an urgent need to translate strategy into measurable impact.
The opportunity lies in using digital transformation to improve operational effectiveness, enhance citizen experience, and deliver better outcomes for communities.
AI plays a key role here, but as highlighted in the session:
AI is not the solution – it is a catalyst and a multiplier.
2. Start with outcomes, not technology
A consistent theme throughout the day was the need to reframe how organisations approach transformation.
Rather than leading with new tools or platforms, the focus should be:
-
- How do we make organisations more productive?
- How do we safeguard the workforce?
- How do we improve outcomes for citizens?
Only then should technology decisions follow.
This is particularly important in the context of AI, where excitement around productivity gains can sometimes outpace clarity on purpose.
3. Strong foundations still determine success
While AI dominated the agenda, the discussions highlighted a familiar challenge: Foundations still matter.
Two key barriers emerged:
-
- Workforce skills – organisations are still figuring out how to assess and build digital capability at scale
-
- Governance and data access – fragmented governance models are creating siloes, limiting how services share and use data
This raises a critical question for public sector organisations:
If data cannot flow effectively, how much value can AI truly deliver?
Without strong digital, data and governance foundations, scaling AI becomes significantly harder.
4. Smarter working depends on trust, not just tools
One panel featured our own, Head of Strategy Architecture, Stacey Quintana focussing on smart working. The conversation moved beyond productivity to something more fundamental, trust.
Smarter working is not just about using digital tools – it depends on; Security, Visibility, Accountability, and Control.
These become even more important as organisations begin to share data across boundaries and adopt AI more widely.
The principle of human in the loop came through strongly.
AI can support decisions, but responsibility – particularly around citizen data – remains with people.
5. Visibility is the starting point for governance
A simple but powerful insight from the panel:
you can’t govern what you can’t see.
Organisations need visibility across:
- Internal users
- External partners
- AI agents
Without this, governance becomes reactive and risks increase.
With it, organisations can enable collaboration while maintaining control.
This is particularly relevant in the public sector, where decisions must be traceable, auditable and accountable.
6. Identity underpins everything
Identity and access management emerged as a critical enabler across both sessions.
It is the backbone for secure data sharing, cloud transformation, AI adoption, and cross-sector collaboration.
More importantly, it is central to building public trust.
Citizens need confidence that their data is being handled safely and transparently. When organisations can provide that visibility and assurance, adoption of new technologies becomes far easier.
7. AI agents are creating a new control challenge
One of the most forward-looking discussions focused on the rise of AI agents.
Many organisations are already experimenting with agents to drive productivity, but this is exposing a growing gap:
- Limited visibility of how many agents exist
- Unclear understanding of what those agents are doing
- Controls designed for people not yet extended to machines
This is where the execution gap becomes clear.
Access to AI has been established quickly – but governance, control and visibility are still catching up.
To close this gap, organisations need to:
- Treat AI agents as first-class citizens
- Ensure their actions are auditable and governed
- Extend identity and access controls into an increasingly agent-driven world
8. Efficiency comes from collaboration, not automation
A key message from Stacey’s panel was that efficiency does not come from AI alone.
It is created through collaboration between people and AI – combining automation with human judgement, oversight and accountability.
This is what enables organisations to deliver better outcomes in a controlled and trusted way.
9. A shared ambition: a single source of truth
Across the day, one outcome stood out as a clear goal: A single source of truth across the public sector.
This would enable greater transparency, better decision-making, more joined-up services, and improved outcomes for citizens.
Achieving this will require more than technology – it depends on alignment around governance, identity and data-sharing.
Closing the gap between ambition and impact
The event reinforced a positive reality: Scotland’s public sector has a clear vision, strong leadership and a shared commitment to digital transformation.
But the next phase is about execution.
That means:
-
- Starting with outcomes
- Strengthening foundations
- Embedding governance and visibility
- Extending control into an AI-driven world
- Building trust through transparency
Condatis Achieves the Microsoft Security Solutions Partner Designation
We’re delighted to announce that Condatis has officially achieved the Microsoft Security Solutions Partner designation. This reflects our continued focus on identity and access management, and our decision to specialise within the Microsoft ecosystem. Meeting Microsoft’s standards across technical certification and delivery is an important milestone for our team. 
Identity has become a crucial part of cybersecurity. This recognition reflects our ongoing commitment to helping organisations build secure, Zero Trust–aligned foundations. For those operating in complex or regulated environments, it provides additional reassurance that our approach, people, and solutions are closely aligned with Microsoft’s security priorities.
Our relationship with Microsoft continues to evolve as we deepen our alignment with their security vision and technologies. It means that when we deliver solutions with Microsoft Entra, we do so in a way that is consistent with Microsoft’s recommended practices and direction.
This milestone reflects our focus on what we do best: identity, access management, and Microsoft Entra. Through our exclusive focus on Microsoft, and Identity and Access Management, we aim to bring unmatched clarity, depth, and consistency to the work we deliver for our customers.

“We’re really pleased to have achieved this designation. It reflects the focus our team has put into building deep expertise in identity and access management within the Microsoft ecosystem. More importantly, it strengthens how we support our customers, helping them get the most out of Microsoft Entra in a way that’s secure, practical, and aligned with Microsoft’s direction.” - Chris Tate, CEO
2026: Trust is the Strategic Currency of the Boardroom
Storytelling is the Bridge to Creating Trust

In the boardroom, trust is not a technical metric, it’s a strategic asset. Yet, conveying its importance often falters under the weight of acronyms and compliance jargon. Storytelling changes that dynamic. It transforms identity and security from abstract frameworks into narratives that resonate with business leaders. When you tell a story about how trust anchors resilience, innovation, and growth, you elevate identity from an IT concern to a strategic imperative.
Picture this: A global enterprise faces a breach through a compromised machine identity. The Board demands answers - not about protocols, but about impact. Your ability to articulate how identity governance underpins operational resilience and protects revenue is what defines leadership in 2026. This is no longer hypothetical; it’s the reality for CISOs and CIOs navigating an era of AI-driven speed and complexity.
The Strategic Imperatives for 2026
Condatis’ five critical priorities shaping the identity and trust landscape in 2026 are:
-
Move from Technology to Risk-Based Business Outcomes
Identity discussions must evolve beyond technical specifications and product features. Boards and executive teams care about risk, resilience, and revenue, not protocols. CISOs and CIOs need to frame identity strategies in terms of business risk reduction, regulatory assurance, and operational continuity. For example, rather than explaining multi-factor authentication as a security upgrade, position it as a measure that mitigates financial exposure from credential theft and ensures uninterrupted service delivery. This reframing elevates identity from an IT project to a strategic risk management initiative.
-
Identity as the Trust Anchor for Digital Ecosystems
Identity is no longer a back-office function; it’s the foundation for every digital interaction, human and machine. Organisations that embed identity into governance frameworks will unlock secure growth and customer confidence. Consider the financial services sector: as open banking expands, identity becomes the linchpin for secure API interactions. Without robust identity controls, the risk of impersonation, fraud and reputational damage skyrockets.
-
Operational Resilience Beyond Perimeter Security
Zero Trust is now table stakes. Continuous evaluation of every access request, whether human or AI-driven, is essential to mitigate evolving threats and maintain business continuity. For example, a global manufacturing firm recently adopted adaptive authentication across its supply chain partners.
This level of security, however, cannot be achieved in isolation. It requires broad organisational stakeholder engagement and effective management. Departments must collaborate to align identity strategies with business objectives, regulatory requirements, and operational realities. By fostering cross-functional dialogue between IT, compliance, operations, and executive leadership, organisations can ensure that Zero Trust principles are embedded throughout the enterprise. This holistic approach not only strengthens defences against cyber threats but also builds a culture of shared responsibility, enabling organisations to respond swiftly and confidently to emerging risks.
Equally, closer cooperation within the IT and security departments is vital. The increasing velocity and sophistication of cyber-attacks demand that security teams adopt a proactive stance. By integrating identity and network security, organisations can achieve identity-centric, continuous evaluation of access and activity. This alignment enables security teams to detect anomalies in real time, adapt controls dynamically, and create a unified defence posture that is agile enough to counter rapidly evolving threats. Such collaboration not only enhances technical resilience but also ensures that security measures are seamlessly woven into operational processes, making proactive security a core component of business strategy.
-
AI-Driven Identity Challenges
Machine identities and autonomous workflows, powered by AI, offer significant opportunities for organisations to optimise operations, enhance service delivery, and drive innovation. For instance, AI-enabled systems can automate complex processes, deliver predictive analytics, and unlock new efficiencies—transforming everything from supply chain management to customer engagement. In healthcare, AI-driven diagnostic tools can rapidly analyse patient data, leading to earlier interventions and improved patient outcomes.
However, these benefits come hand in hand with heightened security challenges. The expansion of AI capabilities exponentially widens the attack surface, necessitating robust governance that integrates AI risk management with identity controls. Without stringent identity governance, privileged access granted to AI tools could result in data leakage or regulatory breaches, especially when handling sensitive information such as patient records. Organisations must therefore balance the promise of AI-driven progress with a proactive approach to mitigating associated risks—ensuring that innovation does not come at the expense of security or compliance.
-
Regulatory Hardening and Interoperability
With frameworks like DORA, eIDAS 2.0, GDPR, and the EU AI Act tightening, identity becomes the focal point for compliance and interoperability across global ecosystems. Organisations operating across borders must ensure identity solutions align with diverse regulatory requirements while maintaining seamless customer experiences.
The age of citizen identity is finally arriving, being driven by the adoption of digital wallets. Wallets empower individual, consumers and citizens to securely manage their own identities, credentials, and transactions without relying on central authorities. As governments and organisations embrace these solutions, users gain greater control and privacy, while businesses benefit from enhanced trust and streamlined compliance across global digital ecosystems. However, to fully realise these advantages, organisations must be able to accept and utilise credentials issued under a variety of standards and by different vendors. This interoperability is crucial for supporting customer journeys that span multiple platforms and jurisdictions, avoiding vendor lock-in, and ensuring seamless user experiences.
By adopting standards-based approaches, such as supporting W3C Verifiable Credentials or integrating with protocols like OpenID Connect, businesses can facilitate the secure exchange of identity information, regardless of the technology stack or issuing authority. This capability not only strengthens regulatory compliance but also enables organisations to participate in broader digital ecosystems, fostering innovation and expanding market reach.
Why This Matters
Digital identity is now a strategic enabler of resilience, growth, and competitive advantage. Organisations that fail to integrate identity into their operational and governance models risk compliance penalties, reputational damage, and operational disruption. In 2026, identity is the key to unlocking organisational value, enabling secure, frictionless access and trust across converging digital ecosystems.
“In a world where AI can generate anything in seconds, identity has become the only reliable proof of truth — and that’s exactly why it matters more than ever. Trust isn’t something technology magically gives you; it’s what happens when identity is properly governed and aligned to how a business actually works. In 2026, identity isn’t just a technical capability anymore, it’s the operating system of trust across every digital interaction. The organisations really winning right now are the ones treating identity as a strategic currency, not an IT cost. That’s where strategy meets security, and where real resilience starts.”
- Stacey Quintana, Head of Strategy Architecture at Condatis
CISOs and CIOs must champion identity as a board-level priority. This involves: The Role of CISOs and CIOs
Turn Trust into your Strategic Asset Today
Audit your identity landscape. Address gaps in managing both human and non-human identities. Invest in adaptive, identity-first solutions that scale with AI ambitions. Bring together security, compliance, and operational stakeholders for a unified approach.
Condatis stands ready to partner with you, through strategic advisory, professional services, and managed solutions, to build trust anchors that enable innovation and resilience.
"What boards are grappling with now is not a lack of security controls, but a lack of coherence. Identity is the only discipline that spans technology, regulation, operations, and human behaviour at the same time.
When it is designed in isolation, it creates friction and blind spots. When it is designed as part of business governance, it becomes a stabilising force that allows organisations to scale, adopt AI responsibly, and meet regulatory expectations with confidence. That is the shift we believe will define successful organisations in 2026 and beyond"
-Chris Tate, CEO
How Identity Tackles Customer Experience
In consumer environments, customer experience is everything. Organisations that can deliver seamless, secure, and personalised journeys are more likely to retain users, increase revenue, and build long-term loyalty. And yet, many businesses still treat identity solely as a cybersecurity or compliance function missing its full potential as a driver of customer engagement.
Modern identity solutions, particularly those that support external (customer) users, are no longer just about securing access. They are becoming critical infrastructure for building trust, reducing friction, and unlocking meaningful connections across complex ecosystems.
The Problem: Friction in the Digital Customer Journey
Imagine a traveller planning a trip. Their journey spans multiple touchpoints:
- Booking platforms
- Airlines
- Ground transport providers
- Hotels
- Local retail and attractions
Each interaction requires some form of authentication, data exchange, or identity verification, often in isolation, with repeated logins, duplicated form-fills, and scattered user profiles.
For the end user, this creates unnecessary friction. For the business, it’s a missed opportunity to build direct relationships, capture insights, and drive engagement.
This isn’t limited to travel. Retailers, banks, and service providers across industries face the same challenge: fragmented identity experiences that erode trust, limit insight, and reduce conversion.
Taking a Holistic View of Identity in Customer Experience
To address this, forward-thinking organisations are stepping back and asking:
- Do we fully understand our user's complete journey?
Are identity touchpoints helping or hindering the experience? - Is our broader ecosystem (partners, platforms, vendors) willing and able to engage?
Do we have interoperability and trust in place to make seamless identity sharing possible? - Where are the main friction points in data exchange?
Are users constantly re-entering the same information? Are vendors missing context? - What is the business outcome we’re trying to drive?
Increased retention? Higher conversion rates? More personalised services?
By identifying and addressing these questions through the lens of identity, organisations can transform fragmented touchpoints into cohesive, personalised journeys.
Use Case: Travel Industry
In the travel sector, identity interoperability could create a much smoother experience for customers.
- A traveller books a flight using a verified digital ID.
- That ID is seamlessly used to check in at the airport, access a hotel room, and rent a car.
- At each step, vendors recognise the traveller and offer relevant, personalised services without needing the user to log in, re-register, or re-verify.
The result?
- Less frustration and fewer abandoned transactions
- Greater trust in each vendor along the journey
- Direct relationships between users and service providers, without relying solely on aggregators
This approach enables ecosystem collaboration that benefits everyone, while preserving the customer’s control over their data.
Other Industry Applications
This model extends well beyond travel:
- Retail
Connect customer profiles across loyalty programmes, in-store visits, and e-commerce platforms. Offer unified experiences that drive repeat purchases and brand advocacy.
- Financial Services
Enable secure, reusable digital IDs across services like lending, insurance, or investment platforms. Reduce onboarding friction while maintaining compliance.
- Healthcare
Allow patients to manage appointments, prescriptions, and records across providers using a single, trusted identity, improving access and care continuity.
Why Microsoft Identity Technologies - with the Right Expertise - are Key
At Condatis, we recommend taking advantage of the full breadth of Microsoft identity capabilities including Entra External ID, Verified ID, and other Microsoft Entra and Azure Active Directory features, to deliver seamless, secure, and scalable identity experiences for customers and partners.
These technologies work best when used together to:
- Manage millions of external and internal users securely and at scale
- Enable consistent branding and customised user journeys across multiple touchpoints
- Support federated access and interoperability across partners, platforms, and ecosystems
- Maintain privacy, consent, and data control for the end user
- Leverage verified attributes to reduce onboarding friction and improve trust
However, technology alone isn’t enough. The analysis, data strategy, stakeholder alignment, solution design, and implementation need to be carefully orchestrated to deliver maximum business value.
That’s where identity specialists like Condatis make the difference. With over a decade of Microsoft-only identity expertise, we work alongside in-house teams to:
- Map and optimise end-to-end customer journeys
- Ensure technologies are configured and integrated for the right business outcomes
- Manage complex business and technical stakeholder engagement
- Design for both present needs and future-readiness
- Accelerate delivery while reducing risk
By combining Microsoft’s leading identity technologies with Condatis’ proven methodology and sector-specific experience, organisations can reduce friction, boost engagement, and future-ready their identity ecosystem - all while doing more with less.
Identity as a Business Growth Enabler
When identity is approached as more than a security layer, it becomes a strategic tool to unlock the value of organisations, their data and interactions.
By investing in technologies like portable identities, federated authentication, External ID and more, organisations can unify fragmented journeys, delight customers, and build trust at every touchpoint.
The question isn’t whether you need identity solutions. The question is whether your current approach is helping, or holding you back.

















