There is no single Forrester evaluation of identity and access management, and that is the most useful thing to know before shortlisting anything.

Forrester runs this space as several distinct markets. Workforce identity, most recently scored as workforce identity security platforms in Q2 2026. Customer identity and access management, scored repeatedly since 2020. Identity management and governance, covering provisioning and certification. And formerly identity-as-a-service for enterprise, evaluated in 2019 before the category was reorganised.

Four evaluations, four vendor sets that overlap only partially, and four different buyers. A vendor cited as a Leader in identity is a Leader in one of these, and vendors are not always specific about which.

Workforce and customer identity are different businesses

The split that confuses people most is between the two populations, and it is genuinely fundamental rather than a segmentation convenience.

Workforce identity governs employees, contractors, and increasingly machines. The population is known, onboarded through an HR process, and governed by policy. The requirements are provisioning and deprovisioning tied to employment status, role-based access, privileged access control, separation of duties, and periodic certification that people still need what they have. Scale is thousands to hundreds of thousands. Failure means an ex-employee retains access or an auditor finds excessive privilege.

Customer identity governs people who chose to interact with you. The population is unknown until they register, self-service throughout, and free to leave. The requirements are registration and login that does not deter people, progressive profiling, consent and preference management, fraud resistance, and the ability to survive traffic that arrives all at once. Scale is millions to hundreds of millions. Failure means abandoned registrations, account takeover, or a privacy complaint.

One optimises for control. The other optimises for conversion while remaining secure. A platform designed for the first will produce a registration flow that loses customers, and one designed for the second will not satisfy an access certification requirement.

The rename that signals the shift

Forrester's 2024 evaluation was titled workforce identity platforms. The Q2 2026 edition is titled workforce identity security platforms.

Adding one word marks a real reclassification. Identity used to be IT administration: accounts, groups, passwords, directory services, owned by infrastructure and measured on service delivery.

Forrester's framing of the current market puts it elsewhere, describing workforce identity security as a strategic pillar of modern cybersecurity, driven by the expansion of non-human identities, increasingly sophisticated identity-based attacks, and the operational demands of zero trust, with organisations already contending with identity sprawl.

The reason is that identity became the primary attack surface. When applications moved outside the network and employees moved outside the office, credentials became the thing standing between an attacker and everything, and attacks shifted accordingly toward phishing, credential theft, token theft, session hijacking, and multi-factor fatigue.

An organisation defending its perimeter with a firewall and its identities with a password reset process has its investment allocated to the previous decade's threat model.

Non-human identities are the growth problem

Forrester names the expansion of non-human identities first among the forces driving this market, and the arithmetic explains why.

An enterprise with fifty thousand employees has considerably more than fifty thousand identities. Service accounts, application credentials, API keys, certificates, robotic process automation bots, integration users, and now AI agents all authenticate to something.

These identities behave differently from human ones in ways that break the tooling built for people. They have no joiner-mover-leaver process. Nobody owns them after the person who created them changes role. Their credentials frequently do not expire because rotating them breaks something. They often hold broad permissions because narrowing them required work nobody had time for. And they do not report anomalies, because there is nobody to notice.

AI agents make this considerably worse rather than marginally worse. Agents are created programmatically, may create other agents, act on behalf of users while needing their own identity for attribution, and operate continuously rather than during working hours.

The requirement that follows is delegated authority narrower than the delegator: an agent acting for a person should hold a subset of that person's permissions scoped to its task, with the chain reconstructable afterwards. Most identity infrastructure cannot express that today, and it is the same gap that produced Forrester's separate agentic control plane category.

The CIAM lineage, and consolidation

The customer identity evaluations show a market that consolidated fast.

The Forrester Wave: Customer Identity And Access Management, Q4 2020 scored thirteen providers against thirty two criteria: Akamai, Auth0, ForgeRock, IBM, LoginRadius, Microsoft, Okta, OpenText, Optimal IdM, Ping Identity, Salesforce, SAP, and WSO2.

The Q4 2022 edition scored fifteen against twenty two criteria, adding Micro Focus, OneWelcome, ReachFive, SecureAuth, and Strivacity.

By the 2024 edition, Ping Identity's Leader placement followed its combination with ForgeRock, and Auth0 had become part of Okta.

Forrester's framing of what CIAM buyers should look for is worth carrying: a data and workflow orchestration foundation, reduced friction through risk-based authentication, and the ability to carry on under sustained load.

Orchestration is the interesting one. Modern customer identity is less about authenticating and more about deciding, per attempt, what evidence to require given the risk. A trusted device on a familiar network doing something ordinary should pass invisibly. The same account from a new device attempting something consequential should not. That decision logic is the product, and it is why low-code orchestration keeps appearing in vendor assessments.

The governance layer nobody enjoys

Identity management and governance is the third market, evaluated by Forrester in Q4 2021 across nine providers against twenty one criteria including Hitachi ID, IBM, Micro Focus, Omada, One Identity, Oracle, RSA, SailPoint, and Saviynt.

This is the unglamorous discipline: user provisioning, access certification, and separation of duties enforcement. It exists largely because auditors require evidence that access is appropriate and reviewed.

The recurring failure is rubber-stamping. A manager receives a quarterly certification listing sixty entitlements for eleven reports, understands perhaps a third of them, and approves everything because investigating would take a week they do not have. The control operates, the evidence exists, and nothing was actually verified.

That is the problem worth pressing vendors on, because it is where machine assistance genuinely helps. A certification that surfaces only the anomalies, the access nobody comparable holds, the entitlement unused for eleven months, the combination that breaks a separation rule, is a review someone can actually perform. One that lists everything is a formality.

On the services question

Forrester evaluates the products in this space rather than the implementation services around them, at least under any category name I could locate.

That gap is worth naming because implementation is where identity programmes succeed or fail, and the effort ratio is unusual. In most software categories the licence is the larger cost. In identity, integration frequently dominates, because every application has to be connected, every legacy system that predates modern protocols needs an adapter, and every existing entitlement has to be reconciled against a role model that mostly does not exist yet.

Role design is the specific work that consumes programmes. Defining what a role should grant requires understanding what people actually do, which differs from their job title, and produces a political negotiation about access people currently hold and would prefer to keep.

Organisations that skip that work import their existing permission chaos into a better tool. The tooling then faithfully manages an entitlement model nobody can defend, which is roughly where a large share of identity governance deployments end up.

What the four categories mean for a buyer

The practical translation is short.

Establish which market you are in before reading any evaluation. Workforce, customer, and governance are different products, and a vendor's Leader placement travels only within its own category.

If your identity estate spans all three, as most large enterprises do, accept that you are running a portfolio and that integration between the layers is your problem rather than any vendor's.

Weight non-human identity capability now rather than later. It is the fastest-growing part of the population, the least governed, and the part that agent deployment will expand fastest.

And treat implementation scope with more suspicion than licence cost, because the ratio between them in this category is not what your procurement process assumes.

Analyst Source

Forrester Research

Forrester covers identity and access management through several distinct evaluations rather than one. These include workforce identity platforms, scored in Q1 2024 and as workforce identity security platforms in Q2 2026; customer identity and access management, scored in Q4 2020 against 32 criteria covering 13 providers and in Q4 2022 against 22 criteria covering 15 providers, with a further edition in 2024; identity management and governance, scored in Q4 2021 against 21 criteria covering nine providers; and identity-as-a-service for enterprise, evaluated in Q2 2019.

Source research

Forrester does not endorse any vendor named here, and tier placement should not be read as a recommendation to buy.