Perspectives from Catalyst Partners Sponsoring InCommon BaseCAMP 2026
Each year, the InCommon BaseCAMP program committee — a group of identity and access management (IAM) practitioners from across the research and higher education (R&E) community — looks at what IAM teams are dealing with to shape the program. The committee’s real-world experience helps ensure the topics are relevant and calibrated for people who are new to IAM, new to their role, or new to the InCommon community.
InCommon BaseCAMP 2026
Join IAM teams from around the world at BaseCAMP 2026, held virtually from June 1-5.
Some of the themes that surfaced this year include infrastructure upgrades, federation becoming more complex in hybrid environments, gaps in governance, security questions, cross-institutional collaboration challenges, and AI.
This year’s BaseCAMP sponsors — all InCommon Catalyst partners — are looking at the same landscape from a different angle. They work with institutions on these exact challenges every day.
We asked our sponsor organizations to share what they’re actually seeing in the field. Their perspectives connect directly to this year’s program themes. Here’s what they said:
Before You Pick the Tool, Define the Problem
We asked: BaseCAMP covers how IAM fits within the broader institutional structure and intersects with security, HR, and leadership. You work with institutions before the technology decisions are made. What does a sound IAM strategy process actually look like, and where do institutions tend to run into trouble when they skip it? What gets underestimated and what makes this work well in practice?
Because IAM friction is hard to ignore, it’s tempting to solve it quickly by implementing a tool. When institutions bypass strategic alignment, they can find themselves struggling to meet the tool’s needs instead of meeting their institution’s needs. This results in implementations that stall, fail, or eventually go live while only meeting a fraction of what they set out to do.
What gets overlooked is the upfront work — defining what a student is, how systems need to integrate, and what edge cases actually matter. Without that, you’re starting from a disadvantage.

One thing practitioners should think about: A sound IAM strategy starts with getting the right people aligned on the problem before anything gets selected or implemented. Only when institutions are aligned around what they’re trying to solve are they in a position to solve it.
Moran Technology Consulting has worked with hundreds of higher education institutions on IT strategy, IAM planning, and large-scale technology initiatives.
10% is Where Governance Lives or Dies
We asked: BaseCAMP is digging into access control this year and how these frameworks fit together in real higher education environments. You implement these systems on the ground, not just design them. What’s the gap between how identity governance looks in theory and what it actually takes to get it working in a real institution? What gets underestimated and what makes this work well in practice?
Higher education access governance looks clean on the whiteboard. You design your Role-Based Access Control (RBAC) model, layer in Attribute-Based Access Control (ABAC) for the nuanced stuff, write your policies, and call it a day. Then you meet the emeritus faculty member who still teaches one course, advises a grad student, and has a courtesy appointment in another college.

Multiply that by a few thousand, and you realize the model handles maybe 90% of your population. The other 10% is where governance lives or dies.
What gets underestimated is exception handling. Every institution has them, nobody plans for them, and they’re usually managed in a spreadsheet someone’s about to retire with.
What makes governance work in practice is ownership. Every role, every policy, every exception — someone has to own it. If nobody owns it, nobody governs it.
One thing IAM practitioners should be paying attention to: AI agents will need identities and entitlements of their own. That’s not far off, and most governance models aren’t ready for it.
Instrumental Identity is a specialized IAM consulting and implementation organization focused on identity governance platforms. They work directly inside institutional environments, not just at the strategy level.
Federation is a Security Architecture Problem, Not a Protocol Problem
We asked: As institutions run an increasingly diverse mix of identity platforms — from legacy SAML and CAS deployments to open source solutions like Shibboleth to commercial identity providers (IdPs) like Entra ID and Okta — maintaining consistent, trustworthy participation in InCommon Federation gets more complex. From your experience, where do institutions run into challenges, and what tends to get underestimated as environments evolve? What makes this work well in practice?
We’re seeing a familiar pattern across the community. As institutions centralize on commercial IdPs like Entra ID, Duo SSO, or Okta, protecting consistent InCommon participation is turning out to be about much more than protocol translation. It’s also about translating the security posture of an organization’s chosen provider into the federation layer.

Here’s where things tend to get messy. When commercial IdPs aren’t federation-ready out of the box, modern security signals like multi-factor authentication context, attribute release policies, and authorization policies aren’t automatically translated to federation infrastructure.
What seems to work well in practice is treating federation as part of the same security scope as everything else and giving someone clear ownership of how those signals flow through to InCommon. Good practice typically includes one place to manage policy, predictable attribute behavior across applications, and a plan for retiring systems that no longer fit.
One thing IAM practitioners should be paying attention to: Build a holistic plan to address the long tail of IAM modernization. There are a lot of exciting new tools out there, but maturity is measured by what you can retire more than what you can deploy. Balance between the two is key.
Cirrus Identity provides cloud-hosted identity proxy solutions that help institutions maintain InCommon Federation participation across a diverse and evolving mix of identity platforms. Their Cirrus Bridge is purpose-built for the R&E federation context.
When IAM Has to Work Everywhere
We asked: Your work spans some of the most demanding research environments in the world — global clinical trials, biomedical research, remote and international sites. In those contexts, what’s at stake when IAM isn’t done well? What does IAM protect or enable that people outside the research world might not fully appreciate?
Effective IAM in global research is not only about security. It also builds trust and ensures timely collaboration.
Access control failures have consequences far beyond a typical data breach. A broken audit trail can invalidate years of research and waste significant funding. Delayed access in remote clinics can stall urgent medical care. Cumbersome systems may drive researchers to insecure workarounds, increasing risk.

One thing IAM practitioners should be paying attention to: When identity is managed well, it becomes invisible. A researcher at a university in Boston can collaborate with a lab at Stanford using their existing credentials to gain access within minutes. Eliminating the need for local accounts removes a major barrier to global scientific progress.
RDCT (Research Data & Communication Technologies) builds and operates research IT infrastructure for global research environments, with a particular focus on biomedical and clinical research — including remote, low-resource, and international settings.
Where These Conversations Continue at InCommon BaseCAMP 2026
These themes show up throughout this year’s BaseCAMP program, from federation and modernization to governance, strategy, and collaborations.
Some sessions throughout the week include:
- IAM in Context
- XBAC: An Overview of Access Control
- 2 Fast 2 Federations
- Modernizing IAM Infrastructure
- Real World Collaborations in IAM
- We Need To Talk About AI
If you’re new to IAM — or newly responsible for it — BaseCAMP is where you start to connect the dots.