SOMA-DR: Decision Receipts for Explainable Recovery and Key Rotation in Post-Quantum IAM
Identity and Access Management (IAM) increasingly relies on adaptive controls—step-up challenges, recovery verification, device and behavior signals, and continuous authorization—to reduce account takeover and misuse. At the same time, IAM systems must prepare for post-quantum cryptography (PQC) transitions that affect credentials, signing, and verification paths. These shifts create a practical governance problem: when an identity action is allowed, challenged, denied, or escalated (e.g., passwordless enrollment, recovery credential release, privileged step-up, or machine key rotation), teams must be able […]