I prefer identity as the top layer. Give me an identity portal that acts as an account manager, access to api layer, let me perform password resets, and let me avoid 2fa if I’m logged into my identity manager account. It should allow bidirectional control: both what services have access to my identity, and what services anything in my identity are granted access to access. Things like LLM, cloud storage etc should be obscured away from services so they can’t tell my storage providers from one another. All access between services should cascade down from my identity portal.