IDENTITY / FRACTAL FIELD GUIDE

MFA guards the door.
Identity includes every window.

Authentication is one moment. Identity is a living system of enrollment, recovery, federation, sessions, privileges, and machines—each capable of repeating the same small trust mistake at enormous scale.

Published August 13, 2026Lawful defensive analysisPrimary sources only

EVIDENCE

The standard moved beyond the password.

NIST finalized Revision 4 of its Digital Identity Guidelines in 2025. The suite treats identity proofing, authentication, authenticator management, and federation as related but distinct assurance problems. Its authentication guidance defines phishing resistance as a protocol property: the system must prevent disclosure of usable authentication outputs to an impostor without depending on the user spotting the trick.

CISA's August 29, 2025 guidance similarly tells defenders to use the strongest MFA available and places physical security keys at the top of its practical hierarchy. These sources support stronger authentication; neither suggests that MFA alone closes recovery, session, federation, or privilege risk.

HUMANOne identity
authenticator
recovery
sessions
federation

INFERENCE

Six places where one exception becomes architecture.

The risk is not merely that one path is weak. It is that organizations copy paths: the same recovery rule, session duration, federation trust, or service credential repeats until an exception becomes the system.

01

Enrollment

Who can create the identity?

A weak proofing exception becomes the template for every account that follows.

02

Authentication

What resists an impostor verifier?

MFA is not one property: manually entered codes do not provide phishing resistance.

03

Recovery

Who can replace the authenticator?

A strong front door inherits the strength of its easiest recovery path.

04

Federation

How many services trust one assertion?

Centralized identity reduces sprawl while concentrating consequence.

05

Sessions

How long does trust survive login?

Authentication can be strong while an overlong session remains reusable.

06

Machines

Which workloads inherit human privilege?

One copied service identity can quietly connect dozens of systems.

EDITORIAL VIEW

The strongest login can still inherit the weakest reset.

Security diagrams put identity in a box. Real systems draw identity as a web. Defenders should inspect every place the web can recreate trust.

The practical shift is simple: stop auditing only the ceremony of login. Follow the entire lifecycle—creation, authentication, recovery, delegation, persistence, review, and removal—and then search for where each rule repeats.

SEVEN-MINUTE REVIEW

Trace the side doors.

  1. 01List every route that can create, recover, or replace a privileged authenticator.
  2. 02Separate “has MFA” from “uses a phishing-resistant protocol.”
  3. 03Map which relying services trust each identity provider and assertion.
  4. 04Review session duration, revocation, reauthentication, and device binding.
  5. 05Find shared service identities and remove privileges they do not require.
  6. 06Confirm dormant accounts, emergency accounts, and departed users are reviewed.

This field review is educational, not a compliance determination or a substitute for your organization's identity architects and incident-response process.

SOURCE LEDGER

Evidence with dates and boundaries.