IAM: Enabler, Not Gatekeeper
Combined Session
Wednesday, September 09, 2026 11:30—12:30
Location: Jupiter III
Wednesday, September 09, 2026 11:30—12:30
Location: Jupiter III
Identity programs that are designed and measured purely as security or IT initiatives consistently underdeliver. This track examines how leading organizations are repositioning IAM as a business enabler - connecting identity decisions to workforce productivity, partner and customer experience, regulatory compliance efficiency, and digital business models. Practitioners share how to build the organizational case for identity investment, translate IAM outcomes into business language, and align identity architecture with enterprise strategy rather than IT roadmaps alone.
IAM teams are often perceived as the department that says "No". Yet some Nos protect an organization's future, while others simply reveal missing standards, resources, or direction. Drawing on real-world experiences from ransomware response, large-scale IAM transformation, and application onboarding, this session explores how IAM organizations can better distinguish between good and bad Nos and Gos. Attendees will leave with practical ideas for making sustainable IAM decisions that balance business enablement, risk, and long-term scalability.
Following the transformation from fragmented to centralised and to a cloud-native IAM foundation, Deutsche Bank is taking the next step toward standardized, role-based access.
This presentation introduces an enterprise Role Management capability built around three core components: a three-layer role model, data-driven role mining, and end-to-end role lifecycle governance. The session explains how business roles, IT-asset roles, and entitlements can be structured to align access with employees’ responsibilities while supporting need-to-know principles, segregation of duties, transparency, and accountability. It also presents the role-mining approach, which uses organizational attributes and configurable thresholds to identify scalable role structures and balance assignment coverage against ongoing maintenance effort. Finally, the presentation outlines how role management can be incorporated into Access Lifecycle Management.
Together, these capabilities establish a scalable and auditable foundation designed to simplify access management, strengthen governance, reduce individual access assignments, and enable more efficient access decisions across the organization.