Identity answers one question. Trust answers many.

Account takeover demonstrates the difference every day.

The credentials are correct. The second factor is correct. The device is recognised. All behavioural signals are within tolerance.

Every identity control returns:
Verified.
And the transaction can still be fraudulent.

Identity was never wrong. It answered its question accurately. It was simply asked to carry a decision it was never designed to make.

Identity answers one question: Who is this?

Trust must answer many more.
• Can I rely on this information?
• Is the person authorised to make this claim?
• Is the information still valid?
• Can it legitimately be used for this purpose? • Can I safely act on it?

Within a single organisation, we already understand the difference. Identity is only one part of every important decision. Authority, policy, context and purpose all influence whether an action should be allowed.

The problem begins when information crosses organisational boundaries.
A recipient can usually verify who sent the information.

They often cannot verify whether the sender was authorised to make the claim, whether that authority is still valid, or whether the information can legitimately be relied upon.

Consider a simple example.
A company director signs instructions to update banking details.
Their identity is genuine.
But they resigned yesterday.
Identity remains valid.
Authority does not.

Identity provides evidence.
Trust combines identity, authority, policy and context into a decision.

They are different problems.

If we continue treating identity as trust, every organisation will keep rebuilding the same decisions independently.


𝐓𝐫𝐮𝐬𝐭 𝐩𝐫𝐞𝐜𝐞𝐝𝐞𝐬 𝐭𝐫𝐚𝐧𝐬𝐚𝐜𝐭𝐢𝐨𝐧.**