Identity answers one question. Trust answers many.
Account takeover demonstrates the difference every day.
The credentials are correct. The second factor is correct. The device is
recognised. All behavioural signals are within tolerance.
Every identity control returns:
Verified.
And the transaction can still be fraudulent.
Identity was never wrong. It answered its question accurately. It was
simply asked to carry a decision it was never designed to make.
Identity answers one question: Who is this?
Trust must answer many more.
• Can I rely on this information?
• Is the person authorised to make this claim?
• Is the information still valid?
• Can it legitimately be used for this purpose? • Can I safely act on
it?
Within a single organisation, we already understand the difference.
Identity is only one part of every important decision. Authority,
policy, context and purpose all influence whether an action should be
allowed.
The problem begins when information crosses organisational
boundaries.
A recipient can usually verify who sent the information.
They often cannot verify whether the sender was authorised to make the
claim, whether that authority is still valid, or whether the information
can legitimately be relied upon.
Consider a simple example.
A company director signs instructions to update banking details.
Their identity is genuine.
But they resigned yesterday.
Identity remains valid.
Authority does not.
Identity provides evidence.
Trust combines identity, authority, policy and context into a
decision.
They are different problems.
If we continue treating identity as trust, every organisation will keep
rebuilding the same decisions independently.
𝐓𝐫𝐮𝐬𝐭 𝐩𝐫𝐞𝐜𝐞𝐝𝐞𝐬 𝐭𝐫𝐚𝐧𝐬𝐚𝐜𝐭𝐢𝐨𝐧.**