Leadership Compass

This is an update of the previously published Leadership Compass Identity Fabrics 2025.

Identity Fabrics are meant to support a wide variety of identity types and provide the services for enabling seamless yet secure and well-governed access to a wide range of services. The tools and services that make up a concrete implementation of an Identity Fabric depend on the capabilities needed by the organization.
Identity Fabrics also expose their capabilities via APIs and an Identity API Layer so that digital services can consume these.

Thus, this Leadership Compass analyzes which of the IAM offerings in the market are best suited to form such foundation for an Identity Fabric, in delivering
• a broad range of IAM capabilities
• a comprehensive set of APIs for consuming and orchestrating these services, beyond the admin and end user UI
• a large set of pre-defined connectors to other IAM and IDaaS components, business applications, and IT and security infrastructure
• a modern architecture, following paradigms such as microservices architectures and container-based deployments
• support for different deployment models, serving the needs of customers for options in their current and aspirational operating models
• support for all types of identities, including employees, business partners, customers and consumers, and NHIs such as connected things, devices, applications, services, and AI agents
• support for established standards to facilitate integration and interoperability
Solutions must not only deliver functionality and support for all types of identities, but also meet our requirements regarding the architecture, deployment model, and their interoperability with traditional applications, cloud services, and new digital services.

How to Book a Briefing
  1. Click the red button below: Book a briefing. You will be directed to the Office365 calendar tool.
  2. Select Leadership Compass Briefing 45 mins.
  3. Select John Tolbert
  4. Choose date between June 2 and July 10
  5. You will receive a Teams invite
  6. Please prepare a slide deck and provide it to the analyst

Key Topics to Cover in your Briefing

1. Company and Product Context (5 minutes)

  • Brief company overview and positioning in the Identity Fabrics market
  • Product scope and major components relevant to this Leadership Compass
  • Primary customer profiles, deployment scenarios, and typical fabric architecture patterns your platform enables

2. Architecture and Deployment Model (10 minutes)

  • Supported delivery models (SaaS, self-managed, hybrid, on-premises) and container platform support
  • Microservices architecture and modular service decomposition
  • Multi-tenancy, data residency, and localization capabilities
  • How the platform functions as either a core identity platform supplemented by specialized solutions, or as an orchestration layer integrating diverse IAM tools — or both
  • Identity API design: how identity services are exposed for consumption by applications, other IAM components, and AI agents
  • Support for human, workforce, B2B, consumer, device, and non-human identity types within a single platform

3. Core Capabilities (can be discussed during the demonstration)

Please structure this section explicitly around the evaluation categories below. We do not expect every solution to cover all capabilities, so please focus on those you do support. You do not need to cover every feature exhaustively, but clarity and technical depth are essential.

  • Orchestration and Integration: API types, versioning, developer portal, SDK coverage, workflow builder, attribute mapping and transformation, and data normalization across heterogeneous identity sources
  • Onboarding and Identity Lifecycle: Provisioning and deprovisioning across on-premises and cloud targets, bulk provisioning, self-registration, progressive profiling, device registration, and joiner/mover/leaver process support
  • Identity Verification: Built-in IDV capabilities, document and biometric verification, liveness detection, decentralized identity and verifiable credential support (issuance, consumption, and relevant standards including OID4VCI, OID4VP, and eIDAS 2.0)
  • Authentication: Authentication method coverage, adaptive and risk-based authentication, contextual signal consumption, session management, SSO mechanisms, token security, and passkey/FIDO2 support
  • Identity Governance and Administration: Provisioning workflows, role management, access request and certification, SoD analysis, access intelligence and analytics, and entitlement management
  • Authorization Management: Policy-based access control (ABAC/PBAC), policy lifecycle management, runtime signal consumption from external systems, standards support (OPA, Zanzibar/OpenFGA, Cedar, XACML, AuthZEN), and delegated policy administration
  • Privileged Access Management and CIEM: Depth and breadth of PAM capabilities provided natively, cloud infrastructure entitlement management across IaaS platforms, and entitlement discovery, visualization, and optimization
  • Non-Human Identity and AI Agent Support: NHI discovery and lifecycle management, secrets management, certificate lifecycle management, and protocol support for AI agent identity and authorization including MCP, A2A, DCR, PAR, CIBA, and OAuth 2.0 Token Exchange
  • Identity Threat Detection and Response: ITDR capabilities provided natively, analyst interface and investigation tools, playbook support, automated response actions, and session and token attack detection and protection
  • Connectors and Standards: Directory and provisioning connector breadth, federation standards coverage including newer standards that are gaining traction and/or emerging such as IPSIE and SPIFFE/SPIRE, and out-of-the-box integration catalog across IAM, security, and operational tool categories
  • Reporting, Dashboards, and Compliance: Out-of-the-box compliance framework reports, IGA and operational reporting, dashboard customization, and audit logging

4. Demonstration (Mandatory, 20-30 minutes)

  • Platform administration console and orchestration workflow builder — show how identity services are configured, composed, and exposed
  • Connector configuration and attribute mapping across at least two heterogeneous identity sources
  • Authentication policy authoring and adaptive authentication in a realistic scenario
  • Fine-grained access control policy authoring, enforcement, and logging
  • Access request, certification, or SoD workflow as appropriate to your platform's strengths
  • API and SDK demonstration — how a developer or integration team would consume identity services from your platform
  • Non-human identity or AI agent scenarios, where applicable
  • ITDR or ISPM capabilities, where applicable

The demo should reinforce previously presented capabilities, not introduce entirely new concepts. Focus on differentiating features and realistic workflows. Please use a demo environment with meaningful organizational complexity, such as multiple identity sources, mixed application types, and realistic policy configurations.

5. Differentiation and Roadmap (5–10 minutes)

  • Clear articulation of what differentiates your platform from peers in the Identity Fabrics market specifically in terms of orchestration breadth, API quality, connector coverage, and support for emerging identity types
  • Near-term roadmap priorities relevant to Identity Fabrics, particularly around AI agent identity, NHI governance, post-quantum cryptography readiness, and decentralized identity standards
  • Known limitations or trade-offs, for example, which IAM domains or identity types are not natively covered, and how your platform is designed to complement rather than replace specialized solutions in those areas. Openness is appreciated and expected.

6. Wrap-Up and Q&A

  • Reference customers, deployments, or representative use cases that illustrate the platform functioning as a fabric foundation across multiple IAM domains
  • Time for clarification questions and discussion
Your Benefits of Participation

Benefit from Third-Party Attestation

Receive an objective evaluation of your solution that you can easily integrate into your marketing strategy. Our vendor neutral approach ensures results are trustworthy and credible. Use this assessment as a powerful marketing asset to enhance customer trust.

Increase Brand Awareness

Share your cybersecurity expertise with the world. By participating in our analysis, you gain a platform to spotlight your company. Boost your visibility and establish yourself as a leading provider in the industry.

Get Insights Into Competing Solutions

Discover how your solution compares with others in the industry. Our analysis provides insights not only into your solution but also valuable information about competitors. Utilize this knowledge to strengthen your position in the market.

Gain Valuable Insights on Your Market Standing

Benefit from a thorough, complimentary evaluation of your solution. KuppingerCole Analysts will evaluate not only your product but also your positioning in the market. Seize this opportunity to receive valuable feedback and make your solution even more effective.

Switch to dark theme

Research Assistant

Hi, I'm Kuppi, your AI-powered research assistant. Ask me about KuppingerCole Analysts' research, events, or analysts.
As an AI assistant, I can make mistakes. Please verify important information.