The guards at the gate never had absolute certainty about anyone. They had criteria.
Who is asking to enter? What are they trying to access? What proof should they provide? And how much confidence is enough to let them through?
That question has not changed. What has changed is everything around it: the volume of digital interactions, the speed at which transactions happen, the sophistication of identity threats, and how quickly businesses expect an answer.
That was one of the central themes of a recent presentation by Aware Sales Engineer, Rubens De Souza, at Daycoval’s annual IT Leaders Day 2026.
The discussion highlighted an important shift in cybersecurity: identity can no longer be treated as a single authentication event at the edge of a system. Increasingly, it is a dynamic security decision that must be made throughout the user journey.
The Security Perimeter Did Not Disappear. It Multiplied.
For years, cybersecurity was built around a perimeter: protect the network, control who enters, and defend what sits inside.
Cloud computing, mobile applications, APIs, and digital services changed that model. But the perimeter did not disappear.
It multiplied.
Today, the gate can sit at virtually every product, process, and transaction: opening an account, accessing sensitive information, recovering a password, authorizing a payment, or changing account credentials.
That is what zero trust ultimately describes. Trust is not granted simply because someone successfully crossed an initial boundary. Identity and risk must continue to be evaluated as the interaction evolves.
Which makes the quality of the identity decision increasingly important.
Authentication is Only as Strong as Enrollment
One of the most important distinctions in identity security is also one of the easiest to overlook: identity and authentication are not the same thing.
Authentication can establish continuity. It can provide evidence that the person attempting to access an account is the same person associated with an enrolled credential or biometric.
What it cannot do is fix a compromised enrollment.
If a fraudster successfully establishes a stolen or synthetic identity during onboarding, every successful authentication afterward may simply confirm the identity that was originally enrolled.
A system can therefore be very good at answering: “Is this the same person?”
Without adequately answering: “Who was this person in the first place?”
As deepfakes, synthetic identities, and manipulated documents become easier to create, protecting that initial identity establishment process becomes even more important.
Biometrics Reads the Body. Identity Tells the Story.
Biometrics provides powerful evidence because biometric characteristics are tied to a person rather than something they know or possess. But a biometric is not, by itself, an identity.
A face match can determine whether two facial images likely represent the same individual. Liveness detection can help determine whether the biometric sample comes from a real, present person rather than a presentation attack or synthetic artifact.
Identity requires additional context.
Who does that biometric belong to? What document or credential supports the claim? Was that credential legitimately issued? Does the transaction make sense? Are other risk signals pointing toward fraud?
The biometric layer and the identity layer fail in different places. That is the real argument for multimodal identity and biometric orchestration.
Organizations increasingly need to combine biometric matching, liveness, document verification, device intelligence, and other signals based on the circumstances of the transaction. The goal is not to use every signal every time. It is to apply the right evidence at the right moment.
The Economics of Fraud Have Changed
At the same time, the economics of attacking identity systems have shifted dramatically.
Fraud once required meaningful time, technical expertise, or manual effort. Generative AI and increasingly capable automated agents are reducing those barriers.
Synthetic images can be created quickly. Identities can be assembled from combinations of real and fabricated information. Automated systems can attempt attacks at a scale that would be impossible for human fraud operations to sustain manually.
The attacker does not necessarily need to steal another person’s identity anymore. The attacker can increasingly be someone who never existed. That changes the defensive equation.
When the cost of creating and testing attacks falls, organizations must assume that identity systems will face increasingly persistent and automated pressure.
Matching Became a Commodity. Defense Did Not.
Biometric matching technology has advanced enormously. High-quality matching capabilities are widely available and continue to become faster and more accurate.
But matching is only one part of identity security. A matcher answers whether two biometric samples appear to represent the same person. It does not necessarily answer whether the sample itself can be trusted.
That distinction becomes critical in the age of generative AI.
Even an extremely accurate face matcher can potentially match a convincing synthetic image if manipulated media or injected imagery reaches it unchecked.
This is why some of the most important differentiation in biometric technology is shifting toward the defensive layers surrounding the match: liveness detection, synthetic media detection, presentation attack detection, and injection prevention.
The question is no longer simply: “How accurate is your matcher?”
It is also: “How well can your system determine whether the evidence reaching that matcher should be trusted?”
There is No 100%
Perhaps the most important principle in identity security is that there is no absolute certainty. Every system operates somewhere along a continuum between security and usability.
Demanding maximum proof for every interaction could increase assurance, but it would also make many routine experiences slow and unnecessarily difficult. Requiring too little evidence creates the opposite problem.
A customer checking an account balance should not necessarily face the same identity challenge as someone transferring a large amount of money, changing critical account details or recovering control of an account.
The objective is not certainty. It is calibrated doubt. How much evidence does this particular operation warrant?
Lower-risk interactions may require relatively little friction. As risk increases, organizations can introduce stronger verification, additional biometric signals, or other evidence.
This is where orchestration becomes especially valuable. Instead of applying one rigid identity workflow to every user and transaction, organizations can adjust which technologies, vendors ,and signals are used based on the level of risk involved.
Identity Security is Becoming a Decisioning Problem
This may be the biggest shift occurring in digital identity.
The industry has spent years improving individual technologies: better matching, better document verification, better biometrics and better fraud detection. Those advances remain essential. But increasingly, the challenge is deciding how those technologies should work together.
Can organizations increase assurance when risk rises? Can they introduce new liveness or fraud detection capabilities as attack techniques evolve? Can they apply different levels of proof to different transactions? And can they recognize when a successful biometric match is not enough?
The modern identity perimeter sits everywhere. Protecting it requires more than asking whether someone passed authentication. It requires continuously deciding how much proof is enough for what they are trying to do.
The guards at the gate never had perfect certainty. Neither will we. The goal is to give that guard better evidence, stronger defenses, and a more intelligent way to decide when the gate should open.