Skip to content
Article

Identity stopped being one project. Your peers are now running several at once.

By DoGood Team · July 8, 2026

Member Signal

The Member Signal is DoGood’s weekly peer-intelligence briefing for the member network. This issue went to members on July 8, 2026, and appears here lightly edited for the web.

The Signal

This month members put identity back in motion on more than one front at the same time. Privileged access is the loudest. One telecom security architect is simply shopping for CyberArk alternatives. A hospital security director wants to get current on privileged access and password vaulting. A finance CISO opened a full review of modern privileged access management.

It does not stop at PAM. The same weeks brought identity governance reviews, Zero Trust access projects, and MFA for people who never get a full account. A newer thread showed up too: who and what can reach regulated data once AI agents are in the building.

No single vendor owns any of this. Members are not asking who is in the category. They are shopping the whole identity stack open at once, layer by layer.

From the Network

“We’re evaluating identity governance solutions to improve lifecycle management, automate access reviews, and strengthen governance across hybrid environments.”

Chief Information Security Officer, Finance

“We currently use Okta for all faculty, staff and students, but there are many situations where we do not want to create an account that would trigger all of the Okta infrastructure, and we still want MFA-like security.”

Vice President for Information Technology, Education

“We’re looking at a re-evaluation of our security stack and endpoint management. PAM, IAM, and the rest are on the dock.”

Senior Director, Tech Transformation, Manufacturing

Three seats, three layers of the same problem. One is governing the access it already grants. One is closing an edge case the standard platform cannot cover. One is putting the whole identity stack back on the table.

Top Open Priorities

“Would like current information on security aspects of PAM and Password Vault.”

Director, Information Security, Hospitals & Physicians Clinics

“CyberArk alternatives.”

Senior Security Architect, Telecommunications

Working on either of these? Both are live asks in the network.

One is getting up to speed on privileged access for the first time. One has already decided to replace the incumbent. The PAM conversation in the network now runs from first look to active swap.

Member Spotlight

Ammar Ammar, University of Tennessee Health Science Center. This week the network is rebuilding how it grants access. Ammar Ammar lives that tension every day. He is both the CTO and the CISO at a university health science center, one person holding the two jobs that usually argue with each other over exactly this question. He put his rule plainly in his DoGood spotlight: “We do security first, and then we design things to fail in a secure way, but we provide availability in a secure way.”

Read his full story →

Deep Dive: Identity & Access

Thirty-one member submissions touched identity and access in the last 90 days. The dominant pattern is re-opening, not building. Members are re-shopping privileged access and tightening governance on stacks they already run.

Where activity is concentrated

Privileged access and secrets vaulting is the largest cluster. Members want PAM, password vaults, and a place to hold secrets across cloud and hybrid. Some are learning the category. Others have already named the incumbent they want to leave. Finance, healthcare, telecom, and law firms all appear here. In a few cases a large client is the one requiring the PAM tool.

Identity governance and lifecycle is the second cluster. The asks are access reviews, joiner-mover-leaver automation, provisioning, and cleaner governance across hybrid environments. This is finance and regulated industries tightening what they already own.

Access modernization is the third. Zero Trust access, MFA, and the edge cases where a standard identity platform does not fit. One problem keeps recurring: how to secure people who should get access but never get a full account.

What your peers are buying

Booked meetings and active evaluations over the last quarter. Vendor, then buyer title and industry:

Vendor Buyer & Industry
Keeper Security (PAM, secrets, vaulting) CISOs & IT VPs · Finance, Software, Manufacturing, Insurance
Clarity Security (identity governance) CISOs & IT Directors · Finance, Healthcare, Gaming
Strivacity (workforce & customer access) Security leaders · Government, regulated industries

Three vendors, three layers. The buyers booking these meetings are not filling one gap. They are rebuilding the identity stack in pieces.

What’s still open

Identity for AI agents and machine accounts. As members roll out AI agents and copilots, they are asking who and what can reach regulated data. No vendor has pulled ahead as the answer.

MFA-grade security for people who never get a full account. Guests, short-term users, contractors at the edge. Members describe the gap clearly. No product owns it yet.

Before you sit through a PAM or governance demo, count your privileged and service accounts first. Most teams find the service-account list is longer, and no one owns it. Walk into the evaluation scoped to your real account sprawl, not the vendor’s reference diagram. Then the demo has to meet your number, instead of the other way around.

The Context

The headlines are catching up to what the network already knew.

The biggest identity vendors spent the last year buying their way into the exact fragmentation your peers are living. CyberArk acquired Venafi to own machine identity, then acquired Zilla Security to automate access reviews and governance. Okta and others are pushing the same message: privileged access, governance, and non-human identity belong in one place. Machine identities now outnumber human ones many times over, and Gartner has flagged non-human identity as a fast-rising risk. The consolidation is aimed straight at the pieces members are shopping separately this quarter.

Bottom Line

The vendors are stitching PAM, governance, and machine identity into one platform because buyers got tired of buying them one at a time. The members re-shopping right now face a real choice: ride that consolidation onto a single platform, or keep the best pieces and own the integration yourself. Decide that on purpose, before a renewal decides it for you.

What to Do About It

This week, pull one list: every privileged account and every service or machine account with standing access. Most teams find the second list is longer than the first, and no single person owns it. That gap, not the vendor demo, is where your identity project actually starts.

Build pipeline you can actually follow up on.