Access the full white paper
A benchmark grounded in reality
This paper defines a clear target state for “good” identity, while recognising the environments most organisations operate in:
- Complex legacy estates
- Multi-vendor dependencies
- Bespoke line-of-business applications
- Limited tolerance for disruption
Rather than rip-and-replace, the approach is practical: building modern identity capabilities alongside what exists today, enabling phased change while reducing operational and security risk.
Identity as the control plane
From our perspective at Condatis, identity underpins modern security and operations. It determines what people, devices, workloads, and increasingly AI-enabled agents, can access, under what conditions, and with what level of assurance.
When identity is inconsistent, every other control has to compensate. The result is increased complexity, reduced visibility, and a model that is harder to govern and defend.
From benchmark to roadmap
The paper also outlines how to turn this target state into an evidence-led plan:
- Assess current maturity
- Prioritise early risk reduction
- Improve assurance over time
- Measure progress in operational confidence and control effectiveness
What “good” looks like in practice
The benchmark is defined through measurable outcomes, including:
- Authoritative identity foundations
- Strong, phishing-resistant authentication
- Policy-driven access decisions
- Privileged access control
- Lifecycle governance and visibility
- Readiness for non-human identities and agents
Co-authored by Condatis’ Chief Technology & Product Officer, Alasdair Murray and Head of Strategy Architecture, Stacey Quintana, this paper reflects real-world experience delivering identity programmes in government and high-stakes enterprise environments.
Stay Ahead of Identity, Security & AI Governance
Practical insights, real-world experiences, new research, and exclusive event invitations from the identity specialists helping organisations navigate transformation with confidence.









