Identity Security • Yokozuna Intelligence
IDENTITY SECURITY HAS A
STANDING ACCESS PROBLEM.
Enterprises have spent years improving how access is granted and reviewed. The next question may be whether so much access should exist continuously in the first place.
Enterprise identity environments are rarely the result of poor planning. Most organizations built their identity infrastructure one reasonable decision at a time — adding an identity provider, layering in governance tooling, deploying privileged access management, connecting cloud platforms and SaaS applications as the business grew.
The problem is not the individual decisions. The problem is what accumulates between them.
HOW ENTERPRISE ACCESS BECAME SO COMPLICATED
Most companies did not create complicated identity environments because they made bad technology decisions. They accumulated reasonable decisions over time.
A typical enterprise identity stack runs through several layers: an HR system such as Workday or SuccessFactors that manages the employee lifecycle; an identity provider such as Okta or Ping that handles authentication and single sign-on; an identity governance platform such as Saviynt or SailPoint that manages provisioning, access reviews and compliance; a privileged access management layer from CyberArk, Delinea or Saviynt for sensitive administrative credentials; and finally the applications, cloud platforms and data systems where access is actually exercised.
None of these systems are inherently the problem. The complexity comes from the way access accumulates across them.
THE STANDING ACCESS PROBLEM
The traditional access lifecycle follows a familiar pattern. Someone requests access. A manager or system approves it. The access is granted. And then — in most environments — it simply remains.
Someone needed an entitlement six months ago. Do they still? A developer changed teams. Did every associated permission change with them? A contractor finished a project. Did everything disappear? An engineer received privileged access during an incident. Does that privilege still exist?
Access certifications help answer those questions, but they often do so after the access already exists — and long after the business reason for it may have disappeared.
The problem is not the gap between request and grant. The problem is the gap between grant and revoke.
"We have become very good at deciding who should get access. We may need to get better at deciding why that access should still exist."
WHAT IF ACCESS EXPIRED BY DEFAULT?
The concept of just-in-time access inverts the default assumption. Instead of granting access and waiting for someone to remove it, access is granted for a defined purpose and expires automatically when that purpose is fulfilled.
Traditional
Dynamic / Just-in-Time
The difference is not simply faster approval. It is whether access has a defined life.
The idea is straightforward: grant access when it is needed, scope it to the task or business requirement, give it a defined life, and remove it when the reason for the access disappears.
Just-in-time access is not unique to one vendor. Established identity platforms, including Saviynt, are also moving aggressively toward JIT and zero-standing-privilege models.[5] The direction is becoming a mainstream architectural expectation rather than a niche capability.
THEN AI SHOWED UP.
Identity programs were already governing employees, contractors, administrators, applications and service identities. AI introduces another class of identities capable of operating at machine speed.[2]
The governance questions that were already difficult become considerably harder when the identity in question is an autonomous agent rather than a person:
Who or what is requesting access?
On whose behalf?
To what resource?
For what purpose?
For how long?
What is the risk?
Can the decision be automated?
When should a human remain accountable?
Quarterly access reviews were designed for human organizations. Increasingly autonomous systems may require governance that operates much closer to machine speed.
THE IDENTITY STACK MAY NEED ANOTHER EVOLUTION
The answer is not to throw away Okta, replace Saviynt, or get rid of PAM. Those platforms continue to evolve, and large enterprises have substantial investments in the identity systems they already operate.
The more interesting question is whether enterprises can move from periodically governing persistent access toward continuously governing access decisions — where the identity, context, purpose and risk are evaluated at the moment access is requested, and where the authorization carries a defined expiration rather than persisting indefinitely.
A Company That Caught Our Attention
Opal Security
While looking more closely at this problem, one company caught our attention.
Opal Security approaches access governance from the perspective that access should increasingly be dynamic rather than permanent.[1] Its platform is designed to make time-bounded, just-in-time access the default rather than the exception.
Why It Caught Our Attention
Access That Expires
Opal makes time-bounded access and automatic revocation central to the access model, rather than treating expiration as an optional configuration.
Works With Existing Identity Infrastructure
Its approach can potentially sit across technologies organizations already operate rather than automatically requiring wholesale replacement of existing IGA or PAM investments.
Humans, Machines and Agents
Opal is extending access governance toward human identities, non-human identities and AI agents — addressing the expanding identity perimeter described above.
Opal also includes Paladin, an AI-assisted governance layer that applies policy and risk context to access decisions and can recommend, decide or escalate depending on the workflow. Security teams should understand where Paladin acts autonomously and where human accountability is preserved.
Opal may complement existing IGA and PAM investments rather than automatically replacing them. Any evaluation should assess how it integrates with the specific platforms already in use.
WHAT WE WOULD VALIDATE BEFORE BUYING
What actually gets replaced?
Does the platform eliminate parts of an existing IGA or PAM footprint, or primarily make those investments more effective?
Where does JIT enforcement end?
JIT only matters where downstream applications, infrastructure and entitlements can be reliably governed and revoked.
How much standing access can realistically disappear?
Some persistent access will remain appropriate. The objective is eliminating access that does not need to be permanent.
How mature is AI-agent governance in the customer's environment?
Agent identity, ownership, authorization and lifecycle models are still developing.
Where does AI decide versus recommend?
Security teams should understand where automation acts autonomously and where people remain accountable.
Does the operating model actually become simpler?
Adding another security platform that creates another administrative layer would undermine the value proposition.
These aren't reasons not to buy. They're questions worth answering before you do.
The Yokozuna View
For years, identity security has concentrated heavily on answering:
"Who should have access?"
We believe the next phase will put considerably more emphasis on:
"Why does this access exist right now?"
Traditional IAM, IGA and PAM platforms are not disappearing. Many of them are already moving toward JIT, finer-grained governance and more dynamic access themselves.
But standing access remains an important architectural problem. AI agents make that problem more urgent.
The idea of granting broad permissions indefinitely and asking humans months later whether those permissions are still appropriate becomes increasingly difficult to scale.
That is why Opal Security caught our attention. Not because it is new. Not because it uses AI. And not because we believe every enterprise should replace its existing identity stack with Opal.
We like the direction because Opal is attacking the underlying question:
"Access should exist because there is a current reason for it to exist. When that reason disappears, the access should disappear with it."
Its combination of JIT access, continuous governance, existing-stack integrations and governance across human, non-human and AI identities makes it a company we believe identity and security leaders should understand.
Whether it belongs in a particular environment requires evaluation.
But we believe it deserves a seat at the table.
Worth Evaluating: Opal Security
Identity Governance • JIT Access • Privileged Access • Non-Human Identity • AI Agents
Yokozuna Cyber Defense has not been compensated by Opal Security for this analysis. Product capabilities and customer claims should be independently validated during any technology evaluation.
Rethinking Your Identity Architecture?
Yokozuna can help you understand the market, compare approaches and evaluate technologies against your existing environment.