Mapping LLM Risks in Identity Workflows

May 20, 2026·
Sanaa Mironov
Sanaa Mironov
· 1 min read
blog

Identity workflows are sensitive because they connect people, permissions, access, and institutional trust. When LLMs enter those workflows, the risk surface changes.

A useful risk mapping does more than list threats. It connects technical failure modes to security outcomes, governance responsibilities, and concrete controls. That is why frameworks such as OWASP LLM Top 10 and NIST CSF 2.0 are useful starting points.

The goal is not to reject LLM-enabled tools. It is to understand where they can help, where they can fail, and what evidence teams need before trusting them in identity-related decisions.

Sanaa Mironov
Authors
Assistant Teaching Professor of Computer Science
I make operating systems and AI make sense. I teach systems at UMBC, explain OS concepts on YouTube, and study how to make AI and software systems secure and trustworthy.