Customer Identity and Access Management (CIAM) has expanded from basic registration and login into foundational infrastructure for trust, compliance, personalization, and resilience across B2C and B2B channels. Unlike workforce IAM, CIAM operates at massive scale in volatile environments with identities sourced from non-authoritative systems and diverse credentials (email, social, national IDs, mobile, IoT), while enforcing privacy and security. Most CIAM is delivered as multi-tenant SaaS on public IaaS for global elasticity and rapid feature delivery, but data residency and compliance pressures drive demand for alternatives such as customer-deployed software, on-premises, private cloud, and single-tenant SaaS with stronger isolation and customizable performance/SLA terms.
Functionally, CIAM must support flexible registration (social federation, passwordless, QR, document-based identity verification), progressive profiling, de-duplication, account linking, self-service credential recovery, consent management, and increasingly device identity. MFA remains crucial for account takeover mitigation, with modern methods including passkeys (FIDO2/WebAuthn), risk-adaptive step-up, and device reputation. Authorization is shifting beyond RBAC toward ABAC/PBAC, delegated admin, and standards-based integration using OAuth2 scopes and SAML attributes. Privacy regulations (GDPR, CCPA, LGPD, PIPEDA) require revocable consent, DSAR handling, and data export/deletion APIs, often integrated with external privacy tools. CIAM also depends on strong APIs (REST/GraphQL/Webhooks), connectors to CRM/CDP/CPM and fraud/IDV ecosystems, and extreme scalability with global distribution, failover, throttling, and partitioning.
Ory is presented as a modular, API-first identity platform spanning CIAM and workforce IAM. Its open-source modules (Kratos, Hydra, Oathkeeper, Polis, Keto) can be self-hosted or consumed via Ory Network SaaS, with strong observability, high availability, and flexible deployment—while key gaps remain in progressive profiling, device registration, built-in IDV, governance/lifecycle automation, and packaged integrations.
See All Locations
See All Locations