Organizations often treat identity proofing like insurance: more must be better. But when governance demands meet technical limitations, implementation gets ugly. This session will share case-informed examples of how over-proofing damages user experience, leads to brittle identity infrastructure, and increases false assurance and will show actionable examples of what to do instead.