Workforce Identity and Access Management (IAM) secures enterprise environments by ensuring only properly authenticated and authorized people gain access to digital resources. Core requirements include identity verification at onboarding, user and device management, identity lifecycle governance, strong authentication, secure authorization, access recertification, adaptive risk evaluation, consent management, and federation with other Identity Provider (IdP) services using standards like SAML, OAuth, and OpenID Connect. Modern approaches emphasize passwordless MFA, step-up authentication based on real-time risk, and fine-grained policy enforcement through RBAC and ABAC, where authorization decisions can depend on user, resource, and environmental attributes.
Widas’ cidaas, launched as a CIAM product in 2018 and now positioned for workforce IAM via the same “identity fabric,” is primarily delivered as SaaS across multiple public IaaS providers plus company facilities. It supports migration via LDAP, SCIM, and APIs, and allows self-registration from OIDC-compliant IdPs; it also supports Decentralized Identifiers, but not the W3C DID specification. A standout feature is AutoIdent for remote onboarding, combining document capture and facial recognition with liveness detection, optionally enhanced by NFC reads from chipped IDs; typical verification completes in 20–60 seconds and supports many document types to help meet eIDAS needs.
cidaas provides lifecycle management (deduplication, keepalive checks, de-registration), device intelligence and OAuth2 Device Flow, and a risk engine that can require step-up authentication or deny access. Authentication options include biometrics via a mobile app, FIDO U2F/FIDO2, OTP, push, and third-party authenticators; policies are configured via a flow-chart interface. Governance and fraud detection address recertification, bots, brute force, and credential stuffing. Differentiators include B2B IAM capabilities, extensive APIs, and integrated Physical Access Control Systems (PACS) with geofencing and offline validation. Challenges include no FIDO certification yet, lack of SOC 2 Type 2, and a partner ecosystem still maturing beyond the DACH region.
See All Locations
See All Locations