<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CIAM on Control Plane by Karl McGuinness</title><link>https://notes.karlmcguinness.com/tags/ciam/</link><description>Recent content in CIAM on Control Plane by Karl McGuinness</description><generator>Hugo</generator><language>en-us</language><managingEditor>public@karlmcguinness.com (Karl McGuinness)</managingEditor><webMaster>public@karlmcguinness.com (Karl McGuinness)</webMaster><lastBuildDate>Sun, 05 Apr 2026 12:00:00 -0700</lastBuildDate><atom:link href="https://notes.karlmcguinness.com/tags/ciam/index.xml" rel="self" type="application/rss+xml"/><item><title>ID-JAG Beyond the Enterprise IdP</title><link>https://notes.karlmcguinness.com/notes/id-jag-beyond-the-enterprise-idp/</link><pubDate>Sun, 05 Apr 2026 12:00:00 -0700</pubDate><author>public@karlmcguinness.com (Karl McGuinness)</author><guid>https://notes.karlmcguinness.com/notes/id-jag-beyond-the-enterprise-idp/</guid><description>ID-JAG is a new OAuth standard for carrying identity assertions across authorization boundaries. The natural first reading makes the enterprise IdP the center of that model. The better reading makes both the enterprise IdP and the product platform first-class issuers, each authoritative for what it actually governs. That broader CIAM and product-platform use case was part of the design from the beginning.</description></item></channel></rss>