LLM-Enabled IAM Risk Mapping
May 27, 2026·
·
1 min read
Sanaa Mironov
This research project examines how LLM-enabled identity and access management tools introduce new risk patterns across common IAM workflows.
The project uses the OWASP Top 10 for LLM Applications and NIST Cybersecurity Framework 2.0 as organizing lenses for analyzing use cases such as account recovery, MFA reset, access request triage, provisioning, deprovisioning, policy Q&A, and privileged-access handling.
The repository includes manuscript materials, experiment artifacts, local-model testing notes, and reproducibility instructions.
Key themes:
- Workflow-centered AI risk assessment
- Mapping LLM threat taxonomies to governance frameworks
- Local model testing with open-weight LLMs
- Reproducibility materials for research review
Next site pass: add the final abstract, paper status, and selected figures.
