The increasing complexity of SaaS environments and identity sprawl has left many organizations struggling to extract full value from their IGA investments. While AI promises to transform identity governance, most companies still face operational inefficiencies, compliance risks, and low user engagement.
Modern IGA solutions infused with AI and ML capabilities offer the potential to address these long-standing issues. From enabling continuous access reviews to empowering self-service and role optimization, practical AI can streamline governance without sacrificing control or security.
Martin Kuppinger, Principal Analyst at KuppingerCole Analysts, will look at the potential of AI for IGA, beyond IGA in IAM, and why AIdentity, the intersection of AI and Identity, will become a dominant theme in the upcoming years.
Paul Walker, Field Strategist at Omada, will demonstrate how Omada Identity Cloud enables organizations to drive operational value from AI. He’ll discuss real-world use cases like AI-assisted access reviews, agentic AI for breach response, and ML-powered role mining that reduce risk while enhancing agility.
Welcome to our KuppingerCole Analysts webinar, From Hype to Help, Making AI in IGA Work for You. This webinar is supported by Omada and the speakers today are Paul Walker, who is a field strategist with Omada and me, Martin Kuppinger. I'm principal analyst at KuppingerCole Analysts. In our webinar today, we will look at AI, Artificial Intelligence, and IGA, Identity Governance and Administration. So to use life cycles, user provisioning, access governance, elements of your infrastructure, and we'll look at what really will deliver benefits to you.
And in some sense, so I think there was so much talk about AI in the past years already, that some of you may already be a bit bored. So we will really focus on where does AI turn from artificial into, I would call it augmenting intelligence in solutions that really augment the people in doing their job better and solving challenges they are facing. So this is the focus of today. And as usual, before we go into the details, there is a little bit of housekeeping. We are controlling audio. We will run two polls during the webinar. One will be right after this slide.
There's a Q&A session at the end of the webinar. And on the lower right side of the screen, you will find the Q&A or the questions area where you can enter your questions at any time. The more questions we have, the better it is. So don't hesitate raising your questions. This will help us having a lively Q&A session to provide the responses to you that you are looking for. We are recording the webinar and recording and presentation slides will be made available soon. So that's it at a high level. I want to start with a poll.
And that is a poll that looks at the impact of AI on the broader identity and access management space. So asking you where you see or you expect the biggest impact of AI on IM. Is it on the privileged identity management side, the privileged identity security posture? Is it about advanced behavioral analysis for session management? Also in that field, especially or for general session management? So if someone is accessing something and having all the controls. Is it supporting access and role analytics and management? So is it really the IGA field that would be number three?
Or is it AI-based identities threat detection and response? So four options. There might be others for you to see. But let's stick to these four ones for now. Poll is open and you can participate in poll. We always laughed us. Quick look into the agenda. I will talk about AI identity, as I call it, and AI use cases. And I am with a specific emphasis on the IGA side. So I draw a bit of a bigger picture here, but put my focus on what I see in IGA as the most compelling, most interesting use cases. And Paul will dig a bit deeper into the really relevant AI use cases in IGA.
So from practice on what he sees, what we can do, what we should do. This is really what we then dived in deeper. And as I said, after that, we will do our Q&A session. So when we look at AI and IM use cases, I put together a couple of use cases. It's sort of a speaker, a list of use cases, set of use cases we continuously or continually update. And I create out some of them which are really not that much on the IGA side, but left them in for completeness. And we'll put my focus a bit on the ones that are already IGA related.
And so when we look at some of the use cases around risk and analytics and adaptive access, then clearly there are things like adaptive access in the authentication area, risk-based authentication. But there's also broader identity analytics aspect. And identity analytics, as some of you may be aware of, has emerged as a part of the broader IGA and especially access governance field, looking at really analyzing for over-entitled users for critical access and assignments for, in some instances, orphaned accounts and other areas where we may optimize the entitlements. So analytics helps us there.
And clearly analytics, if you use it for a lot of data, then it already helps on the entitlements. If we can add further data around what is actually used to it, then we clearly enter a new stage. But this is definitely a field identifying the outliers, the anomalies, the critical entitlement combinations, all that stuff, where AI in the broader sense, I just use AI as a term, helps us in delivering better results.
Because if you go to the details of the individual entitlements and down into the specifics of some of the applications, so down to SAP transactions and down to the individual access controls within a Windows environment, then there are many, many entitlements. There are complex combinations you need to look at. So throwing AI on that definitely can help. When we go a bit further into advanced analytics, identity onboarding, passwords, yes, there's the area of identity verification.
There is potentially password management to look at critical, breached, compromised, insecure passwords, stuff like that. And password management, not that popular anymore, but it has been part of IGA for quite a while. So I left it in here. And clearly there's a predictive identity is looking then more at the actual user behavior to predict where things could go wrong. But we can clearly start on the IGA side looking at, again, what are the critical combinations of entitlements? What are the things we need to put a specific emphasis on? Where are the things that can go wrong?
And many of these use cases was very concrete samples and really advised on how to do it so that it really delivers a value beyond the high level perspective I take here. So my perspective is for now pretty high level, I'm saying. Looking at the generic use cases, Paul will dig into the details and say, what specifically could you, where does it fail? Where can it deliver a real benefit? And then we have all this stuff around roles, role assignment, and recertification.
And yes, managing entitlements, managing roles, providing role candidates, all this stuff is something where AI can help us doing these things better. It's not that we didn't do it, but I think we all learned that AI can do some things very, very smartly. And part of that is really delivering more precise, more detailed recommendations. This area also includes peer recommendations and verification. So I'm always a bit reluctant regarding peer recommendations. So if person A has this, person B should get it as well.
But AI can help to move from black-white to more nuanced decisions saying, okay, these things should be grounded as well, but be careful here. So I think this is also a huge advantage compared to traditional static algorithms, that AI has the ability to work more nuanced, more in detail, because it can better analyze huge amounts of data in a more sophisticated manner. And this is something I believe where it helps even in areas where we may say, okay, we had a bit of sort of a solution here. It can make things really much better.
And then we have this huge field of access recertification, so access reviews. I still know a single organization worldwide where a lot of people would sit and departmental managers would say, hey, great.
Next week, their next recertification campaign starts. It's so much fun. No one says it. So we need to augment this. I think it's exactly this area where we're talking about augmenting intelligence.
How can we make these things simpler, make them work better by providing information, by maybe avoiding recertifications, by removing sort of regularly or hinting regularly on critical entitlement combinations and all that stuff, so that we not even end up in the situation of needing to do that in a recertification campaign, but that we more or less, ideally, before it's granted, but latest, when the system detects, okay, there's something which is a bit problematic, that we fix it on the fly in a singular, small decision someone needs to make.
Because I think this is one of the huge challenges with recertification, when you have a huge matrix in front of you, a lot of people have entitlements, it's very complex to understand. If the system tells you, hey, here's a problem. Martin has excessive entitlements in that area, because he just got that one in addition. This and this could be done. Then it's a simple decision, much easier for people to handle, and AI can help here massively. That's also, I think, one of the areas where, to a certain extent, conversational or generative AI come into play. They can do a lot of things.
They can help text support. They can be used in the text response, but also, for instance, intelligent onboarding, but I would also say intelligent recertification. How can we onboard more simply? How can someone that said, okay, I trust whatever science to this job, or I trust became the new role of being CTO for this product, the field CTO for this region. Which entitlements would I need? This is something where, instead of searching through huge lists of entitlements, maybe not even understand, we can simplify this greatly. That is something we need to understand. Where's the big value?
Maybe as a little bit of a branch out, ML can help us in curing a lot of the symptoms we experience with static authorization. Building role models is not simple. Managing entitlements is not simple. Recertification is not simple. AI can help us. AI can help us in other areas, such as whatever building connectors for faster application onboarding. But when you go back to entitlements, as long as we rely on a role model, it can help us doing that better.
But we also need to keep in mind, and this is more a call for action to vendors and many other parties, we should try to get away from static entitlements as much as we can. AI helps us in dealing better with that, but it doesn't fundamentally fix the problem. And you will find a ton of research at the Kubernetes Core website, or a ton of content around, for instance, poly-based access control, poly-based access management, which might be helpful. But there are areas where it really generates value. And it's a bit repetitive to what I brought up before.
So, new, better onboarding processes. And the ones marked in bold are IGA-related. The ones bold and italic are somewhat IGA-related.
So, at least there's a little bit of a relationship or overlap to IGA. Augmented request and approval process, very clearly a huge opportunity. Efficiency, yes, it helps in automation of things and productivity. And it also helps in, an unburdened helpdesk.
So, reducing the workload on the helpdesk, because all the things around onboarding, requesting entitlements, et cetera, it's not only augmenting the helpdesk itself for helpdesk tasks, it's also less than needing the helpdesk. I think this is a huge opportunity. User behavior analytics is a bit more dynamic than just static.
And also, the risk detection and response automation does partly, clearly, the more static tile we look at in IGA, but also the concrete behavior of the users, how they are concretely using access entitlements, et cetera. Compliance side, we can improve through a certification process. We will need AI also when we move to optimized authorization models.
Again, a lot of content around policy-based access control and how AI can help on our website. So, also better user experience, risk mitigation at the end of the day. I could have probably marked this was in bold and added something in bold here, because spotting critical entitlement combinations, et cetera, is something where it can help.
So, I think alone for entitlement management and role mining, there's a high value. It's not entirely new. There are technologies, but AI-backed technologies can do it better. The data usually is available, so it can be gathered, like for all the other things as well. There's a need for using AI. It's probably more curing symptoms, but it's important. Why don't we go to a predictive identity saying, okay, if we do that or that, what might be a new risk?
It's also, to a certain extent, IGA-related because it goes into sort of the entire SOD and approval process, and how can we make that better? So, in that sense, it's an AI-based thing. It's probably going well beyond what we did, and it's really solving a problem at the root.
So, before something is granted. Onboarding can be very high if you have a huge regular employee turnover, and it's something we do new. We need AI to guide people there, and we, again, can make things better. But it's not where we should stop here, and it's a bit going beyond IGA right now for another two or three minutes, maybe. The term AI identity is one, I think, which is very important to look at AI and identity, the intersection, which has a lot of facets.
So, AI identity is AI plus identity. It's identity for AI, and it's AI for identity. I already touched the latter part, and I already touched this known part of it, AI for identity, because the use cases I walked through very quickly. But there's another element of that, and that is the, I would say, the thrilling part of it, of AI identity. It's identity for AI. And there's also an IGA angle.
So, I don't want to go through all the questions, and I have to admit, currently, it's more about asking questions than having the answers already. But some of the questions are around, how do we control access of AI, of LLMs to data in the context of the user? How do we control access to and to change the manipulation of data that is used by AI? And the access to the LLMs itself, again, risks of manipulation, et cetera.
And also, with respect to that AI, that LLMs, think in data, not in functions. So, they want to find the data to provide a response.
And so, there's an area which we need to keep in mind, which means IGA will become, in some sense, more complex over time and more challenging, because we'll need to deal with very different, way more complex environments. As I said, I don't want to walk through all the questions here, but it might be worth, after the webinar, to have a look at the slides, so that we will make the slides available for download. And it's also adding some more complexity to identity relationships, because we have humans or non-humans using AI agents that are acting on behalf of humans or non-humans.
They communicate with other AI agents. They even may create other AI agents, which, again, communicate back to humans. It's a fascinating challenge. Nothing can be solved here, just as a, I would say, a bit of a thought-provoking aspect. We need to start solving this challenge now, before AI goes wild. But on the other hand, we can do a lot of very, very valuable, positive things now, with applying AI to the, I would say, down-to-earth use cases, the really relevant AI use cases in IGA. And that is where I want to hand over to Paul. Thank you very much, Martin.
That was very inspiring, forward-looking vision statements around AI identity, and totally agree with many things you said there. Welcome, everybody. Good morning, good afternoon, good evening, wherever you may be. My name is Paul Walker. I'm a field webinar with you, and Martin from Kubernetico Analyst, talking about, from hype to help, going to spend the next 20 minutes or so talking about the benefits and the business outcomes of artificial intelligence in IGA. And I thought I'd start with this actual AI-generated content here. And I made full use of AI in some of these slides.
I just thought it's such a helpful tool, it's so creative. And from that perspective, that creativity, we need to keep it on guardrails when we're applying it within security. I think it goes without speaking that things need to be justified, we can't afford hallucinations, regulatory compliance scenarios. We need to keep the creativity in check. But on the other hand, creativity can offer lots of improvements in the business outcomes. So I wanted to put these four personas on the slide here. There are more personas, but these are the main ones.
And certainly, each and every one of you has been an end user. Many of you may have been an administrator of an IT system as well, or even auditors. And like I say, these are the main personas I focused around in producing the content here to talk to you about today. What are the business outcomes that these people are looking for? So rather than talking about the capabilities of software, what are the pain points that these people are experiencing today with identity governance software, especially the legacy software that may have been deployed 15, 20 years ago? And how can AI help them?
I mean, are they looking for AI or are they looking for IGA that works? Because in my humble experience talking to many customers and prospects looking to IGA, we often get asked, do you have AI? And my response to them was always, what's the outcome you're looking to enrich? What can't you do today that you're looking to improve? And that's something I'd always keep in focus when we're talking about AI. And if any of you have noticed the very colorful wallpaper in the background, I'm actually in a very old hotel in the center of London today. So that's why I appear in a museum almost.
So moving on, the first thing I was thinking was, well, what are the use cases that these people struggle with today? And then I thought, you know what, this is a webinar about AI. So I'm just going to ask AI itself and see what AI suggests for me. So without further ado, shameless plug from OpenAI here. I could have picked any engine. I picked the OpenAI engine and I just asked it straight off.
I thought, how accurate is it going to be? Is it going to hallucinate? Is it going to make stuff up or is it going to be pretty accurate?
Now, I thought this was pretty accurate. I've got four personas. I've got four slides. So end users, this could be anybody.
In fact, the end user could also be an AI itself to what Martin was saying. And the world's going very quickly. I'm going to talk about the agentic world and what that means at the end of my presentation at least. But for the moment, let's think about traditional end users, employees, contractors, suppliers, people that need access. Access is a control point. And it's often quite challenging whether you're in an ITSM system or you're in an IJ product in the web interface. And many of the challenges are on the screen there. I tend to agree with all of them.
I've got my own slides I created later where I touch on some of these points. I'm not going to this too much, but I totally agree on too many portals. Every product has got a web interface and people are saying, oh, we've got a great interface. It's really easy to use. It's very intuitive. We've got recommendations, et cetera. But I might not need a web interface. I might be using Slack or Teams. I don't want your app on my phone. I just want to use Teams or Slack or maybe a ServiceNow portal. So I agree with these points. I'd be very interested to see if you agree or not.
And that's the end user persona. So I'm going to move quickly on to the system owner. These are the admins. This is your SAP admin, your concur cloud admin, et cetera. And with the growth of SaaS applications and the budgetary restrictions that customers have, people have got more work to do. And one of the criticisms of IGA in the past over the many years has been that it causes more work. The system owners, the resource owners, the app owners, they have more work to do. So how can AI actually help them?
Because at the end of the day, IGA is a business automation and big data integration challenge. You want to aggregate the information, correlate everything, put your controls in place, and then hopefully it will just manage itself. But that's not the case, is it? We have daily challenges. We have to look on dashboards. We have to look at reports. We have to take actions. And this is, to me, is the too much noise concept. So how can AI help us reduce the noise? And very similar from an admin perspective, Martin talked about connectors and integrating to different systems.
Gen AI is awesome at writing code. It's much better than I am, much better than many people are.
Yes, it makes mistakes, but the scripts and code elements I've challenged it with, it's been pretty perfect. It's a data integration. If you need to write code, then it's going to help you. It's also going to help you with role management, too. We're going to talk about that just in a few slides' time.
So lastly, the auditors. I had the pleasure of speaking to an auditor not so long ago, and they told me that typically when they've... An external auditor, I might clarify. When they go into a customer, they have to often find the evidence to prove that the controls are working. And they're just either left with a browser or an application, native application on the desktop. They have to go and find this information themselves. So how can AI help with these people? So just an introduction really for the main topic. So now that was a persona, and I'm going to flip over to the capabilities.
And like I said, there are many more capabilities than these four on the screen, but this is where I'm going to start. So as Martin said, nobody looks forward to access certification. It's overbearing. It's time-consuming. It's boring, right? People have got lack of visibility.
The very, very little context, like historical or peer group analysis. I do find the outlier interesting myself, right? But it's the way you interpret it. And if you don't pay attention, right, there's a risk of failing the audit.
I mean, this auditor I spoke to, they were looking for the date time stamp on the certification decisions to see if everything was being made in bulk, right? There was no concentration. There was no diligence. It was just like, get this off my desk.
You know, I've got better things to be doing. And that's not security. It's not compliance. So you might get a checkbox, but it's really not adding any business value, right? And lastly, the technical jargon.
You know, the SAP folks in the world today may understand what that entitlement SAP underscore BC BMT WFM admin means. I guess it's an admin. You could probably guess the components in SAP, but to most folk, and it's just an example, to most people, these entitlements, whether they're groups or the roles, they're just confusing. And they get this grid, like Martin said, a grid of usernames, you know, maybe they get a first name, last names, and they have to approve or revoke the access, right?
They don't know who granted it or why, what was the business context, whether it's been approved before, right? Whether their peer groups have got similar access, maybe even not, whether it's requested or birthright access, right? Although we've got better in recent years on this topic. So how can AI help there?
Well, one of the, you know, the word generative, the creativity aspect of at least these large language models, one of the things we're working at Armada right now is to bring all that rich data from the entitlements database, the identity warehouse, into like the LLM, as well as the historical, the approval comments, right?
The peer group analysis and all this good stuff to actually, you know, look at the ability to create a description that's meaningful for the end users to see, to also look at the permissions that the entitlements have to to low level as well to say, you know, this entitlement may give access to the general ledger and it's given to people in finance to report to Martin Kupinger, right? Just to give some actual value, you know, additional benefit to the actual use case to reduce the frustration. So here at Armada, we're working with the term smart access certification.
This is a multi-milestone deliverable, right? So essentially, we want to reduce the amount of work that people have got to do because it's overwhelming, it's overbearing and that means they don't pay attention.
And to do that, we want to do, you know, real-time continuous certification, micro certification to keep the decision as close to the business event as we possibly can and to give as much the description of an entitlement, how it arrived, you know, whether the peer group, the machine learning aspect, the data analysis, and to do this routinely to make it part of the operational cadence that the business has. So rather than a huge interruption at the end of the quarter or half year, whenever that periodic access review is done, to make it as timely as possible.
That's what I mean by the old smart certification. So we can enforce the diligence, right? We can be critical. We've seen from our own projects here at Armada that the fewer questions we give to people, the higher the outcome of remediation, like the more access is revoked, so to speak. If you give too many questions, that percentage falls dramatically. The people just, they don't have the awareness, right? And when you come to the audit preparation, how can AI help again? And we're going to be talking about dashboards and reporting later on.
Importantly, using everyday language and using tools like Teams, right, to do your certifications, to do your access requests and approvals like we see on this slide, right, which often, you know, people don't use IGA systems every day, maybe once a week, maybe once a month, maybe once a quarter. I mean, how often, when was the last time you touched an IGA system in your day-to-day job?
So using natural language, which is a core capability of, you know, the creativity, the prompting of a large language model, it encourages participation, and that encouragement reduces potential shadow IT, right? Tapping your friendly admin on the shoulder saying, hey, Paul, I need access, but that system is just too hard to use, right? So you just give me access to SharePoint or whatever, right? It also helps with approval fatigue.
Rather than looking at a web page full of grids being prompted at your convenience, right, just like you can with our AI assistant, to tell me, according to my work schedule, when I can make the decisions and allow it to be done, you know, in a friendly way on my phone, on my tablet, on my desktop, laptop, that's really helping improve my quality of life, right? And being able to ask questions, like why has Paul got this, right? Does Paul's peers have this? Has Paul requested this before? Being able to interact with the LLM to make it more efficient, right?
To make the approvals and the time to access. People want access now, right? They don't want to wait for tickets. They don't want to wait for long, complicated approval chains, right? They want to know where your request is, and they want that access delivered as soon as possible, because they can't do their job without it, right? So on the right-hand side here, you see the natural language we've got with Amada requesting access with our AI assistant called Havi.
It's, you know, and it allows you to dig into the actual reasons behind the access request and the business context. The next scenario is auditing reporting, right?
You know, these products have a lot of data. IGA products, they store a lot of data. Nobody wants to be a report editor. Nobody wants to wait for reports. Nobody wants to really build your own dashboard anymore. Those days are long gone.
You know, they want the visibility. They don't want to deal with the complexity, right?
And, you know, the software can be difficult to use, or they might not even know what the software does or the capabilities. So when it comes to how AI can help with reporting, it's really, you know, it's the evidence collection. It's all these controls working for this company, right? And how can I use my natural language? How can I talk to the AI saying, for example, I want a list of the timeline of orphan accounts on SAP over the last two months, and I want to know what the remediation status for each of those orphan accounts was. Were they removed? Were they assigned an owner?
You know, provide that in an Excel sheet for me. Imagine the cost, right, in time and effort to actually build a new workflow, you know, do the requirements gathering, go through your promotion of dev test production, if you wanted to build a workflow, you know, in whatever tool, rather than actually ask the AI to do it.
Say, you know, would you like that Excel email to you? Would you like it as a CSV? These are the scenarios that we're actually working on right now, and it's very, very interesting. Me personally, I love the data. I love getting into those trends and the anomalies. And it's an easy, natural experience.
And again, we're trying to increase the satisfaction of people's day-to-day jobs, right? Using whatever persona they are, those four personas in particular at the beginning of the presentation, and increase user adoption. Moving on to role discovery.
Yeah, RBAC, it's been around for quite a while. Policy-based authorization has got a promising future, but depending upon the maturity of the customers, you know, some customers use RBAC, some don't. Personally, what I find most interesting outside of RBAC with the technology, the AI, right, in this scenario, is the fact that assembling the data is now easy. It's not time-consuming anymore, right? I don't need to learn Excel. I don't need to learn specialist BI tools. I don't need to learn Python. This is just running in the cloud, right?
And it's adapting easily to business change, because businesses change all the time. I can run that effective analysis, you know, daily, hourly if I want to. I can have the outcomes that I want without engaging in specialist resources.
You know, in the years gone by, you know, people who could do role mining were very, very few. Probably like Formula One racing drivers, right? Like how many times, you know, like dozens of people. That's it. It was a very specialist topic.
So, you know, modern IGA tools with cloud-based machine learning, they really democratize the ability to do the data analysis. And it may be that you don't want to use roles. Maybe you're not mature enough to roles, but the outlier analysis that you can do, right, it prompts inspection and looking at the data, you can see, well, maybe the policies are incorrect. Maybe it was through M&A. Maybe it was because there was no IGA system or the old IGA system didn't do move as effectively. That's why we see these trends or these outliers.
It's that adaptation to change and breaking down the barriers to looking at the data. So here's Javi. He's the Amada Identity Cloud AI assistant. The four rubrics around Javi there, the lowest TCO, intelligent decision-making, compliance, and the intuitive experience, these underpin our innovation and our investment in AI. And with that, I'm talking about the machine learning as well as the generative AI. This is really acting as a personal assistant. And for the cloud customers, this is live today. It's not vaporware. We've been working on this for quite some time.
And we look forward to being able to show you and get your requirements and get your feedback, most importantly. We really want to drive adoption in this area because you really see key to those four personas, the end users, the auditors, the system resource owners, and the decision makers in actually improving their day-to-day lives with IGA and AI. And finally, before I hand back to Martin, this question about agentic AI, are we really aligned with what the word agentic AI means? I'm sure Martin can do a better job than I can here.
But to me, we've been talking about AI complementing our lives as IGA consumers, where the agentic word, to me at least, is the delegation of authority. It's like I could say, hey, Javi, any requests that come in with this scope, maybe from this cost center with these characteristics, I want you to automatically approve them or automatically make a decision. But just maybe defer the decision till the end of my day so I can look at them and I can just give it a quick glance over before I'm ready to release it. And it's this automation that really I see behind the agentic world.
It's like, are we ready for this? You may have your own opinion. It's probably the topic for another webinar. But some of the aspects I see, final few words before handing back to Martin, do we trust AI to make these decisions? Are we afraid of overstepping the mark? And what's the explainability behind some of these with aspects like the EU AI Act and the regulatory compliance initiatives to actually release the range and let the horses run? It's a fascinating future.
With that, back to Martin. Thank you, Martin.
Thank you, Paul. That was very insightful and enlightening. And with that, we have another poll question before I move back to the agenda.
So, Paul, you brought up the personas. And here's the question to the audience. Which personas do you expect to benefit most from AI and IJR, the end users, the system or application owners, the admins like the IJ admins, the IT operations people, or the auditors and risk and compliance officers? So looking forward to your insights, the policies, and you'll find it on the lower right side of the screen. And next to that, you'll find the Q&A or the questions section where you can enter your own questions as well. The more questions we have already, the more questions we have, the better it is.
And you also can upvote questions there. So pick the ones you feel are most relevant. That brings us to the agenda. The next part, as I've said, is the Q&A part. So right now, we're moving to Q&A, and we'll look at the first questions here. And so the first question currently was one of the two ones that are upvoted. That is a question, which is, can AI really help users understand what they are requesting or reviewing? Or is it just more automation that doesn't solve confusion?
I think, Paul, I hand over this question to you. That's a very interesting question.
I've used, you know, we've been using our AI assistants internally, haven't we, within Armada for some time. I found it useful. I think it depends on your own personal experience.
You know, everyone's got a preferred way of interacting with computers. I think, you know, we've seen major shifts, Martin, over the years.
You know, I started my IT kind of exposure in the early 90s. And, you know, since then, we've had some shifts. And I think the first one was going from desk, you know, from command line to GUIs, right, with Windows, and then to browsers, and then to apps. And I think prompting and messaging, in particular, with our consumer lives on social media platforms, you know, like Signal, Telegram, WhatsApp, etc. There are many others.
You know, it's a new type of computing. And I think all the personas are going to benefit from using natural language.
You know, the days of asking vendors, do you support Polish? Do you support Japanese? Or whatever language?
You know, those are gone. You can talk to these LLMs using any way you want, make typos. It's very creative. So I think, Martin, in my experience, when I've spoken to customers, I've had more interest from the data owners and the admins. But I think it's going to benefit everybody. Yeah. And I like your point, Paul, about the natural language. So we talk in natural language. I also believe that we can really do a lot of things. I think we are still all in the learning phase of prompt engineering.
Prompt engineering clearly will be something that the normal quote has people will not do in the future anymore. It's like, most of the people don't care about configuring IP addresses anymore, which we needed to do in the past. So all these things will sort of triple down further down the stack. But I think at the end of the day, it's also, we all need to learn to ask the right questions or to rephrase questions, which is a bit, also, if you have a generic system, clearly, the way people interact might be a bit different. And it's a bit of a learning curve.
Clearly, also, on both ends, on the system side and the user side, how to phrase things to get a good response, and maybe also to provide sufficient input. Because what I learned with JNI is, the more input you provide, the better the quality of the responses. So it's great input, great output, or garbage in, garbage out. The gigo thing definitely is a very important thing. And clearly, it's an interesting job for vendors, I would dare to say, to build systems that work well from the very beginning for everyone. So maybe let's move to the second question.
And as I've said, everyone, please upvote. Please add your questions. That's the question I dare, I'd like to refrain from answering out of the, sort of, just directly answering. Because I think it's interesting, how do we measure the actual impact of AI in IG? So measuring, I think it's a topic for a couple of webinars on its own.
Yeah, agreed. But I'll leave the question to you.
Oh, thank you, Martin. So to measure anything, you need a baseline. You need to know where you were, where you are now, and where you're going to. So you really need to define what the business outcome is. What's the objective? And in my humble opinion, you know, many customers, they live in such a busy world, and they may not have all of this information available to them. They may already be on their journey with identity. And they're like, it's too late now. But I don't think it's ever too late to baseline your current environment. How long does it take to get that access?
How long does it take to get the approval for the access that, you know, pick a cost center or a manager, and ask them, interview them, right? Go to the ticketing that they use today, or whatever system.
And then, you know, follow the project. And if they're using AI, you know, ask them about the level of frustration, you know, just speak to people, get as much data as you can, and present this to the stakeholders.
Because, you know, there's a lot of challenges for budgets these days. And we see lots of projects, you know, have to defend their use of precious, you know, euros, dollars, pounds, and just like you would expect.
So, you know, is it making a difference? You need to baseline, you need to ask the users, you need to get the frustrations. And you can also use, you know, what we're doing here at Armada is, you know, we are tracking the actions that performed by AI.
So, if it's an access request, for example, you know, we audit the fact that it was AI generated, somebody used the AI engine to start the request or to do the approvals. So, what we're doing is building these scorecards that, you know, touch wood, would show you that the business use case, just pick approvals, it could be search or, you know, lifecycle management as well. But using the AI, the objective is sooner, like the time to access. That's my answer, Martin.
Yeah, that's a very good one. I like that acceptance, that experience aspect, because I believe it's a very important one.
And so, it's something I really like. I think for the generic aspects, by the way, if you happen to have a Coupang on call membership, there's a video still available from EIC, I think it's two, three, probably three years ago.
So, if you don't find the presentation, just send me a LinkedIn message or an email. I'll figure it out. But there's where to really look at the ways and how to set up a really a sort of a matrix system for AI. I think the problem is that IGA responsibles have an extremely good track record in forgetting to gather baseline data. And that's something I think where we, I think the good thing is when you start your AI project, there's a new opportunity to start gathering baseline data for the world without AI and the world with AI.
So, you can do that, definitely. We have currently two more questions. If you have questions, please enter them.
So, the one is many vendors say use AI, but what does good AI and IGA actually look like from a business outcome perspective? Might be a question I take.
So, I'm the one who's always looking at vendors in that sense. And my simple answer is augmenting intelligence.
So, does it really help the user? Does it reduce workload? Does it make the life of users simpler? This is the simple benchmark at the end of the day.
AI must, and you brought up the personas, Paul, must help people doing their job better. Any additional thoughts on that?
No, I think you hit the nail on the head. You know, AI is not a use case, right? AI is there to complement, to improve. And if it doesn't improve, then don't use it, right?
I mean, it's just going to add confusion. So, it's really, you know, it's up to all of us as a community of analysts and vendors and consumers, partners, customers to be as honest and transparent with each other as we can as to what AI is adding value, right?
And, you know, if it's not adding value, then let's be clear what we expect. Let's not just write RFP questions of, you know, explain your use of AI. Let's actually, you know, consider what the outcome is. We're trying to do least privilege. We're trying to do data inspection. Do we want to be able to be more creative in reporting and dashboarding? What are the challenges that you have today?
And, you know, please be as open and verbose with us as a community as you can be. At all these events, you know, in Frankfurt, Munich, let's attend and let's have the conversation. Okay. Last question I have here. It's a very simple one. Will AI eventually replace access reviewers altogether or just the program? I think it depends on, from my perspective, on the timeframe.
So, when I look at this, I would say it's a matter of time. On the long run, yes, because on the long run, we will move from static to dynamic entitlements. We will have AI doing a great job also in where we still need reviews.
So, on the long run, yes, but that's more something about years and probably for full replacement, many years. On the short run, I'd say it's a great area for augmentation. Anything to add, Paul? I totally agree, Martin. I think right now it's augmentation. I think in the future, the access certification will be the anomalies and not the majority. And the problem we have today is with static assigned access, like you hinted on earlier, Martin, and it's like that grid of just to prove everything, it's upside down. It should be inverted.
It should be the anomalies that we're doing in real time versus the majority that we're doing periodically. Back to you. Exactly.
Okay, great. Great answer here. And with that, we are at the end of the webinar. You can easily reach me via LinkedIn, via mail. Don't hesitate to come up with follow-up questions. Surely...
Oh, there's another question here. We'll quickly pick it. What about the backend? What's your thoughts on how AI can be used to optimize how we get data in and out the identity warehouse? Good question.
Yeah, it is very good question. Thank you, Martin. I was just about to get my coat. I think it's to do with the integration capability, right? Getting it into the stores and getting it out of the stores.
AI, MLMs are very adept at creating scripts. However, you don't want to be exposed to coding with this discipline. It's messy. You want to configure, not code. So it's really how vendors can instrument the, I would say, the bridge between the natural language capabilities of you typing, right? So you're in teams and you want to type. And the schematics are something that we started to consider and prove out here at Armada with our team in Alicante, Spain. It's using the AI's ability to code, basically, to understand relationships. So we don't have to do the coding itself.
It's almost like using AI for what AI is good at, right? Rather than using it as a shop window, actually leveraging AI to do these integrations, to answer the question. Maybe add a few points. I think when we look at data, AI is very good in helping us building connectors. So connected to applications, something where AI can really help in getting these things done. I would be a bit more careful when it comes to trying to improve data quality. It can work, but we need to be very, very, very careful here because sometimes it also just adds something. It starts to hallucinate. We all know that.
Or just to leave gaps. So that is something where it's probably a bit more tricky. But at the end of the day, I think there are areas where it can help. It will not be sort of a no-brainer, especially when it comes to data quality over just the technical integrations. But it's a great point to think about. So thank you for bringing up this question.
Again, then thank you to everyone for participating in this Google Analysts webinar, for Armada supporting this webinar, for the questions you've brought in, for listening to us, and hope to have you soon back at one of our other webinars and other events we are running. Thank you very much.
See All Locations
See All Locations