Writing
The Last Mile of Identity

The Rational Refusal: Why the Only Party Who Can Own the Mile Won't

The MSSP is the only party structurally able to own the last mile of identity — and it rationally refuses, because today the deal is unbounded liability for systems it doesn't control, on margins that don't price catastrophe. The refusal, not laziness, is why the mile stays ownerless.

Michael AbramovichAugust 13, 20267 min read

In the last piece I argued that the last mile of identity is ownerless by construction, and that the MSSP is the only party structurally positioned to take it. I ended on the obvious objection: if that's true, why don't they? I said the answer isn't laziness. This is that answer.

The claim

The MSSP's refusal to own client identity is rational. Under today's structure, taking the mile means accepting open-ended accountability for systems the operator does not control, using tooling built for somebody else, on margins that were never priced for catastrophe. A competent operator, running the numbers, declines — and is correct to.

That reframes the whole problem. The mile isn't ownerless because the one party who could own it is negligent. It's ownerless because that party is doing the sane thing. Every incentive an MSSP faces points away from accepting accountability for a residual it can't fully see, can't fully control, and can't price. You do not fix that with exhortation — with conference talks about "shared responsibility" and "owning your posture." Those are moral arguments aimed at an economic problem, and they lose every time. The mile stays empty until someone changes the deal.

Why now

The deal is getting worse, fast, for the exact reason I laid out in the 75/25 piece. AI is commoditizing the deployable three-quarters of identity work — and that productized layer was the MSSP's traditional, safe, priceable value. Standing up the provider, wiring the connectors, configuring policy: that work was bounded, repeatable, and easy to put on an invoice. It's collapsing toward free.

When your priceable value evaporates, margin pressure follows, and it pushes in one direction: more clients per operator. Thinner service per client. Automate the deployment, add logos, keep the lights on. But that is precisely the wrong direction for the operational quarter, which is per-client, judgment-heavy, and does not get cheaper when you add clients — it gets more expensive and more dangerous, because now you're accountable for holding posture across two hundred estates instead of twenty, and no two are alike. So the squeeze arrives from both sides at once: the safe revenue commoditizes, the margin math demands scale, and scale is the enemy of owning the mile. The economics were already tight. AI is tightening them exactly as the ownerless residual grows.

The evidence

Start with the liability asymmetry, because it's the whole spreadsheet. An MSSP earns a bounded, recurring fee. If it formally owns client identity and something breaks, it absorbs an unbounded loss it could not fully have prevented — a vendor's stolen OAuth token, a shadow tenant a client's own admin spun up last week, a public portal a client's marketing team misconfigured into handing out records to anonymous guests. No rational P&L signs a contract to be accountable for failures whose root cause lives outside its control, for a fixed monthly fee. The downside is uncapped; the upside is a line item.

Then the tooling gap, which makes the asymmetry unfixable with effort. Every identity product on the market is built for one of two buyers: the vendor selling the platform, or the single enterprise defending itself. Almost nothing is built for the multi-tenant operator who has to govern the ownerless machine-identity population across two hundred unlike clients at once. You cannot own what you cannot see, and no one sells the operator the instrument to see it at their scale. So even an MSSP that wanted to own the mile would be doing it half-blind, by hand, per client — which is another way of saying "at a loss."

And here's the part that should be the loudest: the MSSP is already standing in the blast radius, just without the mandate or the tools. When MGM and Caesars went down, and again when M&S and the Co-op did, the way in ran through the outsourced service desk and outsourced IT — the operator was the entry point. Yet "own the client's identity posture" was nobody's line item in those relationships. The current arrangement is the worst of all worlds for the MSSP: it already carries the exposure of being in the path, with neither the explicit mandate to own the residual nor the instruments to govern it. It gets the liability without the deal.

I'll add the field version, kept anonymous. Operators do not dodge "own posture across the whole estate" because they don't understand it. They dodge it because when you price it honestly — the tail risk, the per-client judgment, the tooling you'd have to build yourself — it pencils out as a loss leader with catastrophic variance. The refusal is not a knowledge gap. It's a spreadsheet, and the spreadsheet is right.

The objection

Two counters, and the honest versions are worth stating.

The first: then the client should own it — it's their data, their risk, their problem. But the client can't, for exactly the reasons the mile slid downhill to the MSSP in the first place: no cross-system vantage, no continuity, no operational muscle to govern a machine-identity population that grows between review cycles. "The client should own it" is how the mile has stayed ownerless for a decade. Repeating it louder doesn't create an owner; it just relocates the blame back to the party least able to act, which is where these incidents keep starting.

The second is sharper: contracts and cyber-insurance already allocate this risk. Price it in, buy coverage, move on — the market solved this. This conflates two different things, and the conflation is the error. A contract and an insurance policy allocate who pays after the failure. They do not create anyone who prevents it. Naming who holds the bag is not the same as naming who does the work, and the mile is unowned operationally no matter whose name is on the liability. Worse, you cannot actuarially price a residual you cannot enumerate — which is why insurers are already retreating from exactly this exposure, tightening terms and carving out the ownerless machine-identity failures precisely because nobody, including them, can size the tail. Allocating the loss and owning the prevention are different jobs. The market has a mechanism for the first and a vacuum where the second should be.

What follows

If the refusal is rational, then the only thing that gets the mile owned is changing what a rational operator would decide. That requires three things to move together, and none of them is a pep talk.

First, accountability has to become bounded and legible. An operator can only accept the mile if the ownerless population — tokens, service accounts, guests, agents — becomes enumerable and governable at multi-tenant scale, so that "own client identity" turns from infinite, unseeable liability into a finite, instrumented surface with coverage you can actually measure. You cannot underwrite what you cannot count. Step one is making it countable.

Second, the residual has to become a product the operator can own and price — a defined service with a defined scope and a defined edge, not open-ended heroics that expand to fill every incident. Unbounded accountability is uninsurable and unsellable. Bounded accountability is a service line.

Third, the leverage has to become visible. As I argued last time, whoever owns the ownerless mile owns the client relationship — in a world where deployment is nearly free, the operational quarter is the only defensible ground left. When operators can see that owning the mile is the moat and not the charity, the refusal stops being rational, because the deal has stopped being a loss.

The practical read for anyone running an MSSP today: stop treating "own client identity" as either a moral duty or an unbounded risk to be avoided. Both framings keep the mile empty. The move is to make it a bounded, instrumented, priced service — and that is impossible with tooling built for the vendor or the single enterprise. It requires an instrument built for the party that actually stands on the mile.

Where this is going

Which narrows the whole series to one concrete question. If the deal only changes when the ownerless population becomes countable, ownable, and priceable at operator scale — then what does the instrument that makes it countable actually look like? What would an identity platform built for the multi-tenant operator, rather than the vendor or the enterprise, have to be?

That's the last piece. It's the one where I stop describing the shape of the problem and point directly at what I think the answer is — including the part I've been building.

The principles behind all of this are written down separately; the incidents keep proving them.

#last-mile #mssp #economics #accountability #nhi #thesis