THE SECURITY BRUTALIST

A Brutalist Approach to Identity and Access Management

Brutalist Identity and Access Management builds on proven principles rather than introducing a new framework. It strips away complexity, removes unnecessary trust, and makes every identity, permission, and authentication path explicit, visible, and auditable. The alternative, the layered convenience and implicit trust that most IAM systems accumulate over years, is what creates the blind spots attackers rely on.

Every identity, whether human, service, workload, API, or AI agent, needs a clearly defined purpose. Access follows least privilege, gets verified continuously, and gets revoked the moment it stops being needed. An identity earns trust through what it does, never through simply existing inside the environment. A brutalist system treats network location and internal placement as irrelevant to trust, since both have failed as security boundaries too many times to rely on again.

Human authentication should move toward passwordless methods, using things like passkeys, hardware security keys, biometrics, or platform authenticators. When passwords remain in use, they should be unique, protected by MFA, and managed through password managers. Automated identity lifecycle management ties provisioning and deprovisioning to authoritative business systems, so access changes the moment a person's role does, rather than weeks later when someone remembers to file a ticket. Manual offboarding is the single most common way stale access survives in most organizations, and automation removes the human delay that creates it.

Privileged access should stay rare, isolated, and short-lived. Organizations should eliminate standing administrative privileges wherever possible and replace them with Just-In-Time access, backed by strong approval workflows and automatic expiration. Every administrative action gets logged fully (with immutable logs), monitored continuously, and reviewed on a regular basis. A standing admin account is a permanent unlocked door, and no amount of monitoring changes that; the fix is removing the door, not watching it more closely.

Non-human identities now outnumber human users in most organizations, and they need the same discipline applied to people. Service accounts, workloads, APIs, and AI agents should authenticate using short-lived tokens, certificates, or workload identities instead of static secrets, and teams should work aggressively to eliminate long-lived credentials. When a secret cannot be removed, it belongs in a secure vault, rotated automatically and watched for misuse. A credential with no expiration date is a liability with no owner; once it is issued, tracking who still depends on it becomes nearly impossible, so the safest secret is one that expires before anyone needs to ask.

AI agents raise the difficulty further, since they combine identity, automation, and delegated authority in a single actor. Agent identities need tightly scoped permissions, explicit tool access, immutable logging, and a strict separation between instructions, data, and credentials. Every action an agent takes should be attributable, auditable, and reversible. An agent that can read its own credentials, rewrite its own instructions, or call tools outside its declared scope has stopped being a scoped identity and started being an open-ended liability wearing a service account.

A brutalist IAM system passes a simple test. Pull the access graph for any identity at any moment and the full picture appears on one screen: what it can reach, why, since when, and when that access ends. If answering that requires cross-referencing five systems, a spreadsheet, and someone's memory of a project from two years ago, the environment is still unknown, whatever the architecture diagram claims.