Twenty years ago, endpoint security was a dozen antivirus consoles and a spreadsheet. The sector advanced when something started recording what happened on the machine continuously and kept the recording. Detection came after that. So did the category name everyone now has a budget line for.
The same sequence played out in network security, and then again in cloud but identity security ran it backwards.
The same order, three times
Endpoint Detection became possible once an agent could record process, file and registry activity, and that history was kept somewhere queryable. EDR is what got built on top of the recording.
Network Once flow data and packet capture were retained for analysis, network detection began to work. Before that, teams were reading firewall logs and guessing.
Cloud Somebody had to collect the configuration of every account and resource on a schedule and keep it. Posture management came next, and eventually those tools consolidated into CNAPP platforms.
Collection came first in all three. People aligned on standard protocols for retrieving, normalizing and storing historical events, and the category name arrived last. Never the reverse.
Identity went in the other direction
Identity got three categories in four years and each category performed related, yet different jobs.
ITDR watches for active exploitation. Impossible travel, MFA bypass, a session that gets hijacked, lateral movement on stolen credentials. ISPM checks whether the identity infrastructure is configured the way it should be. Is MFA enforced on admin accounts, are federation trusts hardened, are there dormant service accounts holding privilege. IVIP, which Gartner introduced on its Hype Cycle, addresses what access actually means and whether it is being used at all. Yes, all three are real problems but the the trouble is the order they arrived in. ITDR came first, followed by ISPM and now we've introduced IVIP. But can you properly detect and respond without identity visibility and posture management?
Detection needs to know which identities and entitlements matter, or every anomaly gets the same priority. That is what visibility provides. Posture management can tell you a group has no MFA, but not that the same group grants root, so posture without visibility produces a list of findings with no way to rank them. And visibility itself needs something underneath it, because knowing what access exists today is a different question from knowing what existed last month and what changed in between.
Each category is actually asking for less than the last. Detect, then evaluate, then simply see. This is a sign that the identity market is still missing the foundational thing it needed first.
The missing system of record
There is exactly one step below being able to see your environment, which is keeping a record of what happened in it. Visibility answers what is true now. A record answers what was true in March, what changed since, who changed it, and how long it was that way before anyone noticed. Access reviews, audit evidence, anomaly detection, and incident reconstruction all require this and no amount of current-state visibility answers it.
Why identity was harder
Endpoint teams had one agent, one operating system surface, and one vendor's format to normalize. Identity teams have hundreds of systems, and many of them are genuinely difficult to get data out of.
- The mainframe that still runs critical transactions
- The LDAP directory nobody has touched in a decade
- The appliance that only supports a CSV export
- Unix hosts with local accounts and SSH keys that were never inventoried
- The custom app someone wrote in 2011 that keeps its own user table
The first problem with those systems is that most of them never record what changed. The second is that nothing in their data says which accounts belong to the same person or service. Finance has an employee number, the cloud role has an ARN, the local admin account on a Unix host has a username someone picked in 2014, and HR has a person with no accounts attached at all. Nothing in those four records says they are the same human being.
So identity teams did the reasonable thing and bought many individual tools that worked well with the systems that were easy to reach, and got good at manually stitching together reports.
Without a record, the same findings come back
None of this list will be new to anyone running an identity program:
- Standing administrative privilege that has survived three consecutive access reviews, because each review looked at a group name and approved it
- Privileged credentials that were never vaulted, in systems the vault cannot reach
- Accounts belonging to people who left, still enabled, because nothing ever connected the account to the person
- Service accounts holding administrative rights with no owner anyone can name
- Audit evidence that takes two weeks to assemble every cycle and arrives as a reconstruction rather than a record
Each of those is a state that persisted because nothing was keeping the history that would have surfaced and resolved it. They get treated as five problems with five owners and five remediation projects. The reality is, they are one problem appearing in five places.
The renaming stops when the record shows up
Endpoint's category names settled once continuous recording was real and everyone was building on the same kind of data. Cloud security's alphabet soup collapsed for the same reason. It happened because the layer underneath stopped being in question.
That record is what Hydden is building. We collect changes to identities across virtually any system, match up the accounts that belong to the same person or service, and keep every change rather than overwriting the last known state. Access reviews, privileged account cleanup and identity context on an alert become views built on that one record, which is why they stop being three separate projects with three separate data problems.
If you want to see what your programs look like running on a record instead of on exports, schedule a demo.
Frequently asked questions
What is an identity system of record?
One place that holds every identity in your environment and the full history of how their access changed. It captures continuously, reconciles the accounts that belong to the same person or service, keeps every change rather than the latest value, belongs to no single tool, and gives you a way to act on what it finds. Missing any one of those five makes it a report rather than a record.
Are ITDR, ISPM and IVIP competing with each other?
No. They address different problems, and most mature programs will end up doing all three. What is unusual is the order they arrived in. Detection came first, posture second, visibility third, and their dependency order runs the other way. Each one turned out to need the layer that showed up after it.
Why did endpoint, network and cloud each get a record before identity did?
Their collection problem was smaller. Endpoint had one agent on one operating system. Network had traffic that could be captured on the wire. Cloud had APIs designed for programmatic access. Identity has hundreds of systems, many of which emit nothing when something changes and share no common identifier for a person, so continuous collection was genuinely harder to build.
Is a system of record the same as visibility?
No. Visibility tells you what access exists right now. A record tells you what existed at any point in the past, what changed, and when. Audit evidence and incident investigation both depend on the second kind of answer, which is why current-state visibility alone leaves those programs assembling exports.
Does a system of record replace IGA or PAM?
No. Those tools are the systems of authority, meaning they are where access actually gets granted, revoked and enforced. The record holds what every system asserted and when, and it feeds those tools so their decisions are based on complete data. Hydden does not replace your IGA or PAM. It makes them accurate.

