Identity and Access Management (IAM) evolved from application-embedded controls into dedicated systems in the 1990s built on shared user directories (often LDAP), simplifying account creation and maintenance for employee users. Traditional workforce IAM focuses inward on provisioning, authentication, authorization, and storing relatively high-assurance identity data sourced during HR-led onboarding, with access entitlements flowing from groups, roles, and attributes. As collaboration and e-commerce expanded in the 2000s, enterprises began storing partner, supplier, and customer identities and building federations to authenticate users from external domains. By the late 2000s and early 2010s, consumer-facing organizations commonly deployed separate IAM instances for consumer identities, whose data and lifecycle differ materially from workforce identities and may include preferences, demographics, purchase histories, and user-generated content. Consumer identity creation is typically self-service registration (email/password or social login), with growing emphasis on privacy dashboards that let users grant and revoke consent under multiple global regulations.
The Thales OneWelcome Identity Platform is a multi-tenant SaaS CIAM offering (rebranded after Thales acquired OneWelcome in 2022) designed for consumers, B2B, workforce, and other scenarios. It comprises modules for core identity and access, user journey orchestration, delegated user management, externalized authorization (OPA-based), consent and preference management, mobile identity, and identity brokering, with in-country data residency across Europe, the Americas, and APAC. It supports customizable, white-labeled registration and login journeys using progressive profiling; broad authentication options including OTP, push, biometrics, and FIDO/U2F; configurable risk actions; extensive interoperability with identity proofing and national eID services (including eIDAS); IoT device linking via OAuth2 Device Flow; analytics and event streaming; and extensibility through APIs and connectors. Key strengths include consent/privacy management (GDPR, CCPA, Kantara Consent Receipts), B2B delegation and relationship management, and fine-grained authorization, with noted challenges around compromised-credential intelligence, passive biometrics, and some admin self-service for risk tuning.
See All Locations
See All Locations