Identity and Access Management is rarely a one-(wo)man show: End users request access, internal IAM teams manage roles and policies, and system integrators, MSPs, and IDaaS providers each play a part. But who owns what? And who ensures it all runs reliably - not just at go-live, but every day after?
One of the most overlooked (and underestimated) success factors in IAM is the Target Operating Model (TOM). Without one, even the most advanced IAM solutions can collapse under unclear responsibilities, fragmented operations, and overlapping roles.
This session presents a pragmatic approach to transforming the KuppingerCole IAM Reference Architecture into a living TOM. You’ll learn how to:
- Define clear responsibilities across the reference architecture
- Separate roles based on required skills and expertise
- Identify functional areas such as governance, application onboarding, and policy management
- Match the right internal and external teams to each area
- Avoid operational chaos by reducing friction and embedding accountability in contracts and processes
Whether you're preparing your first IDaaS rollout or navigating a complex, multi-party IAM environment, this talk will provide you with a structured path from architecture to execution. Because a good TOM doesn’t just define what needs to be done — it defines who actually does it.