Reading Time: 3 minutes

Signal #2 in our “6 Signals from ACAMP” Series

InCommon is publishing a series of blogs to recap what we learned from the IAM community during Advance Camp at the 2025 Internet2 Technology Exchange. This blog is the second installment in the series.

Last year, identity and access management (IAM) professionals from all corners of the world gathered at Advance Camp (ACAMP) during the 2025 Internet2 Technology Exchange. Together, the collection of thought leaders and practitioners discussed everything from trust federation to operations to emerging tools and much more.

What is ACAMP?

Advance CAMP is held at the end of every Internet2 Technology Exchange.

Every year, IAM professionals — from IAM novices to late-career IT professionals — gather to pitch their own topics, run demos of tools, and participate in breakout discussions. Attendees build the agenda live and on the spot. Each session is collaborative and conversational, and dedicated scribes take notes to capture the conversations for the broader IAM community.

Read the 2025 ACAMP Scribing Notes

Following ACAMP, the InCommon team reviewed scribing document notes and identified six distinct signals that cut across the conversations. These signals offer insight into what is shaping IAM and what is likely to drive focus and action for the research and higher education community in 2026.

InCommon has launched a blog series to share these insights. We will share the discussions that took place at ACAMP and connect them to past or ongoing efforts from InCommon and the broader IAM community.

This second installment focuses on operational approaches, automation strategies, and emerging practices that emerged during ACAMP discussions. 

Continue reading to see how IAM teams are responding to challenges around scale, security, and sustainability.

IAM Innovations You Should Know

Now more than ever, IAM teams across the country face understaffing, often compounded by turnover. 

At ACAMP, we heard that IAM teams are increasingly adopting an “Agile IAMOps” model that applies software development practices to their daily operations. This strategy can help reduce operational slowdowns that occur when critical expertise is owned by just one person — and the panic that happens when that person leaves the organization.

As information is democratized, so are the tools that institutions use. We heard from IAM practitioners that a single tool won’t solve all your problems; you have to establish good patterns and behaviors while using multiple solutions.

IAM teams from across diverse institutions shared how they are adapting their architectures, workflows, and tools to address real operational needs. 

Here is a brief rundown of the patterns and approaches that surfaced in those discussions:

Grouper ABAC and AI

In 2025, the Grouper team communicated with the IAM community on different ways to incorporate AI-assisted tasks with Grouper ABAC. Those conversations continued at ACAMP, where campus teams shared their own use cases. Notably, practitioners reported using Grouper with AI-assisted scripts to collapse thousands of manual loader jobs into real-time, dynamic logic.

Join the discussion! The Grouper team has launched a new Grouper AI Slack channel. Email help@incommon.org if you would like to be added.

Email us

Whenever and wherever you need Grouper training, there is something in store for you. Learn more about InCommon Academy’s flexible Grouper courses.

Learn more

MidPoint Academic Baseline

A Trusted Access Platform component, midPoint handles complex user information and identity data. At ACAMP, midPoint users shared that they are collaborating on pre-built templates that include common lifecycle workflows, role patterns, self-service interfaces for account claiming, and sponsored accounts.

Want to master midPoint configuration? From April 7-9, 2026, InCommon Academy is running an advanced training course about configuring midPoint to handle multiple identity relationships.

Sign up today

Certificate Automation

One message about certificates was loud and clear at ACAMP: certificate lifetimes are shrinking. Certificates lasted up to 398 days in 2025, but that will compress to 200 days in 2026. By 2029, certificate lifetimes will dwindle to an estimated 47 days. Manual renewal won’t scale. If certificate management isn’t automated yet, now is the time to start.

GitOps for Knowledge Transfer

As a means of combating critical information siloes and information loss due to staff departures, IAM teams reported they are moving their SOPs and release playbooks into Markdown-based Git repositories. Some teams have even made these depositories searchable by AI. Release playbooks can include rollback procedures, QA proof requirements, and “lessons learned the hard way.”

Credential-Free Deployments

During ACAMP, institutions shared that they are moving toward dynamic, short-lived access tokens. These tokens replace stored credentials to reduce risk and improve auditability.

Log Explosion

Splunk licensing costs are driving what gets logged and where. Keep only security-critical logs, use cheaper tools for everything else, and replace full logs with metrics when possible. A universal pattern emerged from discussions: delete logs as they age, because keeping everything is unaffordable at scale.

Stay Connected for More From ACAMP 2025

Keep your eyes open for more blogs in this series about everything we learned about the IAM landscape during ACAMP.

You can find InCommon blogs on our social media channels. Want to get the news delivered directly to your inbox? Sign up for the monthly InCommon Newsletter.


Note from the author: These signals were informed by a review of ACAMP session notes, with artificial intelligence used to help summarize themes and surface patterns. We encourage you to explore the 2025 ACAMP scribing documents and draw your own insights from the community’s discussions.