Frustrated with login friction and security gaps? CIAM solves both.

FIND OUT HOW
close-button
Decorative
BACK TO BLOG

Strivacity Named a Notable Vendor in Forrester's 2026 CIAM Landscape Report

Quick summary: Strivacity has been named a Notable Vendor in Forrester Research's The Customer Identity And Access Management Solutions Landscape, Q3 2026. The report profiles more than 30 CIAM vendors, frames CIAM's value around both customer experience and security, and identifies agentic AI as the biggest force reshaping the category. Here's our take on what that recognition, and those shifts, mean for anyone buying CIAM right now, plus answers to some of the questions we expect people to ask.

Every CIAM vendor is talking about AI agents now. Talking isn't the same as building.

Look across the CIAM market this year and you'll find plenty of language about agentic AI and AI-ready identity. Nobody wants to be the vendor without those words on the page.

But that's not the gap buyers should be paying attention to.

The real question is whether a vendor can actually onboard, authenticate, and authorize an AI agent in production today, or whether agents are still primarily a roadmap concept.

Many established CIAM architectures were designed primarily around human identities. Extending those architectures to agents is a much bigger job than adding agentic AI to a product page. That's why we think the difference between what vendors say and what they've actually built is one of the most important questions in CIAM right now: the difference between being built for AI and being retrofitted for it.

Forrester's new overview of the market reinforces the scale of that shift, calling agentic AI "the single largest transformational force" in CIAM today.

CIAM, short for customer identity and access management, is the layer that handles how your customers (and now their AI agents) register, log in, prove who or what they are, and manage accounts and consent across every channel your business operates in: web, mobile, chat, phone, and even in person.

CIAM was never just a security tool

It's easy to put CIAM in the security bucket and leave it there. Forrester doesn't. Neither do we.

The report frames CIAM's value around three things that should work together: better customer experiences, stronger security, and less work for development and compliance teams.

Make identity friction disappear

On the experience side, the point is simple. The easier it is to register, sign in, and recover credentials, the faster customers, and increasingly their AI agents, can get to what they actually came to do.

Buy something, access a service, or complete a transaction. The less visible the identity layer is, the better it's doing its job. If identity creates friction at the front door, you can lose the customer before they ever get to the product or service you built.

Know who's accessing what

On the security side, businesses need to know what both humans and AI agents can access, and under what conditions.

That same identity layer should help reduce fraudulent account creation, detect account takeover, and distinguish legitimate AI agents from malicious bots.

But that last problem goes deeper than bot detection.

If an AI agent shows up, you need to know more than whether its behavior looks suspicious. You need to know:

  • Which application authorized it
  • What it's allowed to do
  • Which human or organization it's acting on behalf of

Without those answers, you're still making access decisions based mostly on behavior.

We think an AI agent should be treated as its own identity, with its own credentials, its own consent record, and access scoped to the specific task it's supposed to perform. And every action it takes needs to trace back to two actors, not one: the customer who authorized it, and the agent that carried it out.

Give developers their time back

There's another part of Forrester's business value case that's easy to overlook: CIAM should reduce development, maintenance, and compliance work.

Your application teams shouldn't have to rebuild sign in, session handling, and access control every time they ship a new app. They shouldn't have to maintain all of that custom identity code forever either.

The same goes for compliance. Reporting should be built in and ready to prove what happened, not something your team has to reconstruct when an audit shows up. We'd call that more than cost savings.

Every sprint spent maintaining a homegrown sign in flow is a sprint not spent on the product you're actually trying to build.

Identity now means three things. CIAM platforms need to handle all three.

Forrester's definition of the category has evolved with the market.

CIAM is no longer just about onboarding, authentication, and self-service for people. It now explicitly covers AI agent customers across those same channels.

The report describes the shift in three ways: an AI agent is a new identity type, a new channel, and increasingly a new policy-management tool in its own right.

It's one thing for a platform to let an agent authenticate. It's another for the platform to accept instructions from an AI agent that can help administrators analyze, clean up, or author CIAM policies.

Those are very different levels of agent readiness, and buyers should distinguish between them.

Sign in used to be the finish line. Now it's the starting point.

We believe one of the biggest operational shifts in CIAM is happening after authentication.

Historically, many access decisions happened at the sign in gate. Once someone was authenticated, permissions often remained relatively static for the rest of the session.

That model is becoming less sufficient.

Continuous, context-aware authorization can evaluate access as circumstances change and revoke or alter permissions mid-session when risk, context, or policy changes. In our view, that kind of dynamic authorization is moving from a nice-to-have toward an expected capability for both human and agent sessions.

At the same time, identity is becoming connective tissue between systems that were often treated separately: security, fraud prevention, CRM, and the customer-data platforms businesses already use.

Authentication tells you who or what showed up. Authorization increasingly has to answer a harder question, over and over again: what should this identity be allowed to do right now?

The real obstacle isn't building new. It's replacing old without breaking anything.

This is where we think the report is especially useful for anyone shopping for CIAM right now.

Forrester identifies modernizing outdated, siloed, and heavily customized CIAM deployments without disrupting the business running on top of them as the primary challenge facing the market.

That's a major issue because identity systems sit directly in the path of customers accessing a business. Replacing them isn't like swapping out an internal tool that can tolerate a maintenance window or a rough migration.

In practice, modernization often means replacing systems designed years ago, before deepfakes and autonomous agents became meaningful parts of the threat landscape, while preserving the applications, customer journeys, integrations, and business processes that depend on them.

Most vendors weren’t built or architected for the AI era. Getting there without breaking anything is the real test.

How to actually use this report

If we were using the report to build a CIAM shortlist rather than appearing in it, here's how we'd approach it.

Start with fit, not fame.

The geographic focus, industry focus, deployment model, and size Forrester lists for each vendor are self-reported and intentionally unranked. Use those attributes as filters before you spend time evaluating individual vendors.

A vendor that doesn't serve your industry or can't deploy the way you need isn't suddenly a better fit because it's a bigger name.

Next, match the use cases to your actual requirements, not the reverse.

The report separates core use cases, including authentication and single sign-on, onboarding, and reporting from extended use cases such as B2B IAM, consent management, and IAM for AI agents.

Decide which of those your business genuinely needs before you start scoring every vendor against every possible capability.

Then read the market dynamics section as a test, not as background information.

The trends, primary challenge, and market disruptor Forrester identifies affect every vendor in the Landscape. Use them to develop your own evaluation questions instead of simply asking vendors whether they're "ready for AI."

And then don't take our word for it. Don't take any vendor's word for it. Ask for a demonstration.

If AI agents matter to your roadmap, ask every vendor on your shortlist to show you, specifically, how an agent gets onboarded, authenticated, and authorized in their platform today.

Ask how the platform knows which application or party authorized the agent. Ask how its access is scoped. Ask what consent it carries. Ask how that access changes or gets revoked.

That's the standard we think buyers should apply to the market and to us.

Frequently asked questions

What is Forrester's Customer Identity And Access Management Solutions Landscape, Q3 2026?

It's an overview report from Forrester Research that maps the CIAM, or customer identity and access management, market. It profiles more than 30 vendors, including Strivacity, by factors such as geographic focus, industry focus, deployment model, and size, and covers the business value and market dynamics shaping CIAM buying decisions.

Is Strivacity named in Forrester's 2026 CIAM Landscape report?

Yes. Strivacity is named a Notable Vendor in Forrester's The Customer Identity And Access Management Solutions Landscape, Q3 2026, alongside more than 30 other CIAM vendors profiled in the report.

What is CIAM (customer identity and access management)?

CIAM stands for customer identity and access management. It's the technology layer that handles how a business's customers, and increasingly their AI agents, register, authenticate, recover credentials, manage consent, and access services across channels such as web, mobile apps, chat, and phone.

What does Forrester say about the business value of CIAM?

Forrester frames CIAM's value around customer experience and security working together.

On the experience side, easier registration, login, and credential recovery help customers and AI agents get to important interactions and transactions faster.

On the security side, CIAM platforms are expected to extend access control and fraud-prevention capabilities across both human and AI agent activity, including detecting account takeover and distinguishing legitimate agents from malicious bots.

The report also points to reduced application development, maintenance, and compliance effort as part of CIAM's business value.

Has Forrester recognized Strivacity before this report?

Yes. Forrester previously named Strivacity a Leader in a separate report, The Forrester Waveβ„’: Customer Identity and Access Management, Q4 2024.

The two reports serve different purposes. A Forrester Wave evaluates and scores vendors, while a Landscape report maps the market without ranking the vendors it profiles.

What does Forrester say is transforming the CIAM market in 2026?

According to the report, agentic AI is the single largest transformational force in the CIAM market.

Forrester describes AI agents as creating three shifts at once: they are a new identity type, a new channel through which customers can interact with businesses, and a new potential policy-management tool inside CIAM platforms.

‍