After many systems, one person has many identities: ERP ID, OA email, warehouse login, portal phone. Agents aggregating "this person's tasks and permissions" mismatch. Leavers still approve somewhere; new hires blocked elsewhere. Inconsistent identity is not capability—it is missing subject.
SSO solves authentication once. Lifecycle solves where authority comes from and when it ends. Neither—and automation amplifies wrong authorization.
How Identity Fragments Break AI
Models match on name—homonyms cross permissions. Match on email—contractor domains mix with staff. No lifecycle—old permissions after transfer; suggestions reach wrong eyes. Security audit shuts whole AI program.
Self-built accounts are fast to open, slow to trace—systems that trace slowly should not host agents.

Establish the Person First
- Org master as source—hire open, transfer adjust, leave close with deadlines and escalation.
- Business systems use SSO; required local accounts bind master identity and sync disable.
- Agent operator identity matches audit log ID—no anonymous robot writers.
- Reconcile accounts to active roster—ghost accounts closed same day.
The XYN digital intelligence system puts org permissions in one framework; apps share identity. AI prerequisite: person uniquely recognized and authority disappears on exit. Unrecognized people—best algorithms only authorize shadows.
