Manifesto

Principles of the Last Mile

A working manifesto for how I think about identity. These principles come before any product I build. They are the frame my writing, my architecture, and my code all answer to — so that you know how I think before you judge what I made.


1. The last mile is no one's land

Between "the product is deployed" and "identity is actually under control" lies a stretch of work that never ends. The vendor's responsibility stops at the edge of their product. The client doesn't have the expertise to carry it the rest of the way. The zone between them belongs to no one — and that is where identity breaks. I call it the last mile, and naming it is the first step to owning it.

2. Only an operator on the mile can own it

The mile can be owned only by someone who stands on it continuously and sees the same failures repeat across dozens of clients. A single client sees their own incident once; an operator across many sees the pattern. That operator is the MSSP — not because the client shouldn't own their identity, but because they can't: they have neither the standing exposure nor the scale to recognize what's coming. "Should" is not "can."

3. Responsibility splits, and incidents live in the seams

The vendor is accountable for the mechanism, the MSSP for the process, the client for the decisions. None of these is wrong on its own — yet incidents almost never happen inside one of them. They happen at the seams, where responsibility and tooling have drifted apart. Authority without instruments and instruments without authority are equally useless; the breach is the gap between them.

4. Source-available is a principle, not a tactic

You cannot ask an MSSP for the keys to their identity infrastructure and hide your own code. My code is open because the alternative is incoherent — not because it is good marketing.

5. I don't promise "secure"

No product — including mine — closes the last mile on its own. What a tool can do is make the mile ownable: give someone the standing to hold it. Security is not a finished state you purchase and file away; it is a process you run. Anyone selling you "done" is selling you the wrong thing.

6. Posture is a process, not a state

A dashboard shows you yesterday. Posture is what you do tomorrow with what the dashboard showed you. Compliance answers the auditor — "is MFA defined in policy?" — at a single point in time. Posture answers the attacker — "is MFA actually enforced on every account right now, or was it quietly turned off on three legacy tenants six months ago?" You can be fully compliant and wide open.

7. AI moves the line, not the owner

AI automates the vendor's side of the stack faster than it touches the client's reality. The deployable, repeatable, day-1 work gets cheaper; the messy, per-client, day-2 work does not. So the mile gets longer, not shorter — and it still has no owner. Automation without someone accountable for it is not a solution to the last mile; it is a new layer of it.


These principles are stable but not frozen; operational reality sharpens them over time.