The method, published before the findings
The risk in this research is producing a vendor list, which is worthless and dates in weeks. Instead, every option answers one concrete scenario in the same columns — which makes the options comparable, the claims checkable, and the whole thing re-runnable by anybody. Publishing the method before any option is assessed is what makes a participant's comparison credible, and it is impossible to claim afterwards.
The scenario
I have four agents. Each needs its own identity. Each needs access to a different vault, which means each needs a secret. One also needs access to one repository. Nobody should be able to use another's access. Show me how, what it costs to set up, what it costs per agent per month, and what each agent could reach if it were compromised.
Every option gets this scenario — no substitutions, no "in the enterprise case" escapes. An option that cannot express the scenario says so in its assessment.
The columns
| Column | Why it is there |
|---|---|
| Steps to working | Countable, disputable on facts |
| Prerequisites | Accounts, subscriptions, infrastructure, a team |
| Privileges granted | What one compromised agent reaches. The differentiating column |
| Setup cost | Once, including engineering time honestly estimated |
| Cost per identity per month | The scaling axis |
| Cost per use | Where metered |
| Runs where | Their infrastructure, yours, or serverless |
| Works for rented agents | The question the thesis turns on |
| Date verified | Because this dates in weeks |
The last two columns are what make this research worth doing rather than repeating what exists.
Scope boundaries
Five things get bundled under "identity" and they are different markets. Naming them keeps the research from sprawling:
| Concern | The question | In scope? |
|---|---|---|
| Authentication | How does the thing prove it is who it says? | Yes — the scenario touches it |
| Authorisation | What may it then do? | Yes — the scenario touches it |
| Secret storage | Where do its credentials live? | Yes — the scenario touches it |
| Audit | What did it do, attributably? | Noted per option, not investigated in depth |
| Lifecycle | Who created it, who owns it, when does it die? | Noted per option, not investigated in depth |
One finding carried in from scoping: mature programmes combine a discovery-and-posture layer, a secrets layer and a workload-identity layer under one policy. Most options answer part of the question — so the assessments record which part, rather than scoring options as if they competed head-on.
The reproducible-test discipline
- Every assessment carries a verification date and states the method to re-run it.
- Anyone can dispute on facts. Steps are countable; privileges are enumerable; costs are stated with their assumptions.
- Assessments go stale honestly. A stale date is displayed, not hidden; the re-run queue is tracked on the comms page.
- The dominant cost is engineering time, and it is the number most likely to be argued with — so each estimate states what it includes and what analysis it relies on.
The participant problem
This site is hosted on the sgit domain, and vaults are a candidate answer to where an agent's secrets live. So this is a participant publishing a comparison. The treatment, visible rather than buried:
- State who is writing it. Done, on its own page and in every footer.
- Publish the method and make it re-runnable. This page — before any findings.
- Publish where our own approach loses. Vaults do not solve attestation, do not provide lifecycle governance, and do not answer the rented-agent problem either. Stated in full.
Build order
- The thesis page — done: two populations.
- The scenario and the columns — this page, published before any option is assessed.
- Three options assessed, chosen to be different in kind: the open standard, a commercial broker, and the do-nothing baseline. Currently preliminary: sourced from published analysis, not yet re-run hands-on. Each page says so.
- The collection, organised by question, with the maturity model promoted to a page.
- The infographics, linked to their sources.
- More options over time, each dated, each re-runnable.
One question, several scenarios
The four-agents-four-vaults scenario above is the anchor, but the discipline generalises: any concrete scenario, answered per option in stated columns, with a verification date. The first additional scenario is published: shared drives for agents — two sessions sharing a file area — where three requirement rows (per-agent identity, agent-level attribution, encryption to a specific agent) came back empty across the surveyed market. That research is the thesis's first concrete instance, and its empty rows are standing refutation targets.