Welcome to the KuppingerCole Analyst Chat. I'm your host. My name is Matthias Reinwarth. I'm analyst and advisor with KuppingerCole Analysts. I guess today is Martin Kuppinger and we want to continue a discussion we started in September last year. But first of all, hi, Martin. Good to have you.
Hi, Matthias. Pleasure being here. Great to have you. And as I said, we continue a discussion that we started in September 2025 when a fellow analyst company came up with a new four-letter acronym. And we discussed way back then whether this is useful, this is necessary, whether that fits or bridges the gap that we have functionality-wise or capability-wise. So we talked about, now I have to look it up, identity, visibility, and intelligence platform. Is this something that we needed?
And the verdict that we came up with last time and that you continued in an advisory note was it's not really a new platform, it's a set of capabilities. Does this still hold up? I am with my position from back in 2025. So IVIP is a set of capabilities. A lot of these capabilities have been here. In some areas we see improvements, but it's definitely not a platform. I think a platform is, for me, a platform, and this term is overused in vendor marketing and sometimes in acronyms. A platform is something where a lot of capabilities come together to form a very comprehensive solution.
So platforms are in tendency relatively rare because we don't need many, but we need a lot of capabilities, power provided by tools. And this is what IVIP delivers sometimes, capabilities delivered as tools that add potentially to what you have, which then still raises the question, are these capabilities needed and by whom and when? Right. So this is the technology or the vendor perspective. What has happened on the market in the meantime? The fact that you produced an advisory note around the topic hints at vendors have taken up that?
What we see is that a lot of vendors position themselves under the IVIP term. Most of these vendors have been around for long in the broader IGA space mainly, so Identity Governance Administration. So it's not that I would say we have seen a huge number of sort of IVIP startups emerge. It's more that existing vendors from different areas, some of them coming from other parts of the market, try to position themselves under the IVIP term or at least say, oh, we deliver to IVIP, we deliver IVIP. So usually they don't say we deliver to IVIP, but they say we deliver IVIP.
Even while they maybe only add some again, specific capabilities. But it's, for instance, in contrast to AIH discovery or in contrast to AI MCP server level authorization. And for both, we could question is this really the thing we need the way it's delivered now? But in both areas, we see a huge number of startups emerging, bringing sometimes also really new ideas, sometimes very overlapping and common solutions. But for IVIP, it was mostly, I would say sometimes adding capabilities, in many cases, mostly relabeling.
And the question that we have on the table for today's episode and catching up on what we did last time is whether, and this, of course, is a bit provocative to say, could AI, the way we use it in IGA, for example, or in PAM already make IVIP more or less obsolete faster than it ever becomes a mature category? Before we dig deeper, what's your gut reaction to that? Can AI already solve many of the questions that IVIP tried to answer?
AI, at least, is very impactful on the way IVIP solutions are and should be delivered. So the promise of IVIP only will become a sort of reality, only will hold when the potential of AI is used. I think that that is the minimum my gut reaction. Provocatively, we clearly could say we can do so many things with AI that we don't need IVIP, but that would mean we are doing a lot of own construction work. We are talking about tools, about building instead of solutions, and that is anyway the wrong way. So I think currently we are working way too much on the base level when we use AI.
So the fact that we need to learn how to use whatever cloud optimally after we switched over from whatever chat GPT, that reminds me of the early days of the web when everyone had to learn HTML and do the things really at this level. I think we need solutions that utilize AI and everyone trying to build everything itself because that ends up in the usual mess of no one maintains it. It's not fully done. It's not properly done, etc. So at the end, the first reaction saying, okay, this can be easily done with AI, which is not always true.
So the MVP or the mini MVP can frequently be done very well, doing it at scale, manageable in a way that we really have a solution, not just a set of homegrown tools. That is a different story. You've mentioned HTML. I think when it comes to analytics, the case is even worse. We go back to text-based exchange formats, not to say CSV files.
And that was some kind of criticism that you also raised in your advisory note to say, okay, in the end, either can do a lot of great things, but the question is how do we get the data in there and how do we make them normalized and how do we make them comparable? Is this something where AI actually can help creating faster connectors, understanding data better when it comes to applying the IVIP capabilities to this data? Absolutely, yes. And I think this is one of the playing fields for AI. When you look at what some vendors did, they massively improved their ability to build connectors.
They massively reduced the time it needs to build a connector. So understanding the APIs, the interfaces, the data formats.
Also, to a certain extent, understanding the potential customization of data in a target system. So in many cases, the fields aren't always used the same way. So everyone who has dealt with application integration to IGA knows that there's a lot of custom use of different fields, etc., etc. And helping to analyze this is clearly a strength. Building a connector, automatically supporting this is something where AI can help. So it potentially helps in moving away from CSV level or other type of very old school integration into more integration.
And obviously, in that situation, you can address one of the biggest shortcomings, the biggest challenges of IGA. That is the non-kept promise of application integration. So a typical IGA project starts big and says, oh, we will have hundreds of applications on board in the first year. And then you end up with five which are a bit integrated or something like that because it's more complex. This is a complexity you can massively reduce. So you can do more with the same effort at the same time and have more applications integrated. It still means you need to map that information properly.
This is where, again, to an extent, AI may help in better understanding. It's still something where you need to have the right model in place, which I think this is where the human comes into play again. So building these data models, understanding these data models, that is still something which requires, I think, a lot of conceptual thinking where tools, some of these tools really have a lot of this built in already. And so that helps them to do that. So AI simplifies that.
And with that, you have more of the potential of having more current data to analyze, maybe also deeper data to analyze, and you can deliver better results with Ivy. And that's, again, why I said AI plays a very important role for any Ivy vendor, because the Ivy vendors must utilize this potential so that they really can fully deliver on this promise. You still can argue that this is nothing else than what IJ promised all the time, having all that information there. So when I go back to the initial days of access governance, it was the SS versus 2B state comparison of entitlements.
That was 20 plus years ago. And basically, we end up there with better analytics, with a better analysis. And then still it's, humans are needed sometimes to understand where does this stem from? What is the reason? Because AI is good in spotting anomalies. AI is not so good in reasoning and understanding why is this the case? Is this relevant or not? Exactly.
So now that is a perfect segue to my next question to say, okay, now that we have the data in there, and hinting back at our earlier episode in September last year, my point was that many of the capabilities are already there, but they're scattered across different tool categories in IGA and PAM, in ITDR. Now AI helps in supporting these capabilities. So this is something where AI can, I think, really drastically improve the results of these capabilities. The question is, where will they be then?
And do we actually care if it's ITDR, if it's IVIP, if it's IGA, when it's a whole fabric built together, consuming and using these capabilities? Is IVIP then something that really delivers additional value? Does it move up one level? Or does it the same thing that ITDR was expected to do two years ago? So I think first, and that's something I stated a couple of times, new acronyms are of very limited value. Let's phrase it like that.
So if there's not a real fundamentally new category behind that has a sort of a right to exist of its own, where you say this is a new field we are tackling, then we should be careful and distinguish between what is really a new category and what is a set of capabilities that is needed. I think the same for ITDR. ITDR does analytics more at a technical level. So it's really more the anomaly detection and understanding it as a threat. So it comes from a threat response more from a security perspective, while IVIP comes from a governance perspective.
But in some, obviously they are very closely related because also from a governance perspective, you need to understand where are the outliers. So it's not that you can draw a very sharp line between these two sets of capabilities. And both are needed in a modern identity fabric. So I think it's way, way more meaningful to start with the fabric and then look at which capability sets do you need in addition maybe to the core pieces that build your platform. And then things will change over time.
So what we already see is that obviously vendors at both ends look at and then another at least one or two categories of tools come into play. Obviously it's not sufficient to look at the human accounts and entitlements in IVIP or in ITDR. It's looking at all types of identities. And then we have the workload identities, like service accounts used in the cloud, like maybe another identity. Alexei wrote a great piece on that just recently.
We, for instance, have the API keys and other stuff, which are most types of secrets, but something happens with them. And we also need to understand not only who, but also what could access, which also comes a higher level, the traditional service accounts, you have the same. And then you have the agents. And at the end of the day, all these technologies, IVIP, ITDR, and the entire identity fabric, and this was built in the identity fabric from day one. We didn't talk about AI agents because there were no AI agents when we started this identity fabric, but we already had workload identities.
We had identities of things and all the stuff, the traditional service accounts. And so this, that means you have even more capability sets like the NHI management, like a lot of stuff in AI security, and all they are related to each other. And we need to understand across everything, KIEM, we could bring up, and that's a popular acronym, Cloud Infrastructure Entitlement Management, which basically is about the entitlements of service accounts to the use of cloud resources. So at the end, all that is there, all that plays a role and we need to weave it together.
And this is where the fabric comes into play. For all of these things, AI is helpful. I fully agree. And I think one other aspect that I want to highlight is if we compare just the acronyms, IVIP and ITDR, the V stands for visibility. So analytics, looking at things, is something wrong with something? Do I need to do something? The R in ITDR stands for response. So actually to act upon the information that is available. And I think that is something that we see in other tool categories, call it access management, call it, I don't know, dynamic authorization capabilities.
The just-in-time privilege assignment is something that is the action part that is currently being added. So really moving the access management decision, the decision-making process closer to the signals, closer to the information that is available at runtime. And I think that is something where IVIP, provocative again, falls a bit short. If you know what happened, you know what went wrong, but you don't act upon that and other tools do that. Am I right?
I think the term IVIP at least suggests that it's about visibility less than observability, which I have from the very beginning said is a misconception. We need to be able to act upon that. I think we are anyway, from a vendor perspective, moving into how can we address it. If you look at it from a fabric or also a broader IGA perspective, then this is to an extent definitely in the concept, but we definitely need to look at it always from, can we really solve the challenges? Can we act upon this? Absolutely no doubt that we need to make progress here and always look at it.
But I think the governance element as I've said is important. So we need, so to speak, a technical level, we need an observability. And the more dynamic the accesses, the more dynamic the identities are, the more we need sort of an automation also at this level. But we also need across everything a proper governance layer that helps us understanding where our biggest risk, where do we need to act upon, et cetera, et cetera.
I think the fact that IVIP really rang a bell with buyers and with vendors, the reason for that was that there was a need for such a kind of dedicated aggregation layer that wasn't there before. If you think the fabric properly, that would be something that is in there, but delivering that as a product that consolidates information from PAM, IGA, access management at runtime into a single interface, that I think was the beauty. And you've described that already, the AI can massively support in there.
The question is what would be a next step if you were theoretically to advise an IVIP vendor today? Where should they focus and how would they, would you say how to use AI strategically to contribute to the fabric and to stay available as a product category? Yeah. So I think one of the areas obviously is using AI to speed up application integration and have a higher level and current mass of information that comes into the system. So really shifting away from CSV and at the end of the delivering on the non-cap promise of IGA when it comes to application integration. That would be one thing.
I would clearly look at a lot of automation when it comes to the newer type, or they are not so acceptive agents, they are not new. So the workload has been around. But expanding into the others, that requires more automation because these things happen not at human speed but at machine speed. That would be obviously one of the areas.
Analytics, I think, is very straightforward. So shifting into observability and marrying this technology with ITDR to have a more comprehensive coverage would be straightforward and logical. Right. So there is no simple answer to our initial question that we started that episode with. Is AI an enabler or a killer for iVID? And the question is, what will decide that answer? Would it be the buyer's maturity to understand how to build that into their own fabric or the vendor to provide the capabilities that are actually needed and fit in the delta that other tools just do not provide?
What would be your point here? What do you expect for the future of iVID, say, for the next two years? Will it be around? I am not sure whether the iVID category survives. I think there is a logical merge between IGA and iVID and ITDR to an extent. So I think we will probably see some sort of modernization. Which password at the end is used? I do not know. Maybe more. Maybe it consolidates back again. But I think it is all part of a journey into modernization and expansion of what historically had been called IGA with the extension a bit of ITDR and other things.
But all of them basically play in a field where it is about delivering on that initial promise we had in this space in a changing world. And AI is then an enabling technology. At the end, anyway, the market decides. So vendors will bring up new capabilities and they are either picked up by the customers or not. I think that the huge advantage here is that you can utilize this to modernize a lot of your existing IGA in a leaner manner by redoing your entire IGA project. And you have a huge capability to finally deliver on the promises of IGA, which I think is super important for this market.
Right. And I think nobody should be going out to the market and say, I want to buy an IVIP product. But you should always, and this is our tenet when it comes to creating infrastructure, creating your own fabric slash platform slash infrastructure to look at what you actually need as capabilities and then identify the right tooling to implement that, be it IVIP, ITDR, IGA, PAM or whatever, and then combine these building blocks into your actual solution that fits your needs. But the IVIP market should be something that will expand based on AI. From our discussion, I get that.
Anything that anybody who has listened to our episode just right now should learn for their next decisions, purchasing or architectural decisions? I think there are two elements. The one is when you struggle with your current IGA, think thoroughly about where this needs to be in a couple of years from now, beyond sort of the traditional IGA focus. That will help you make the right decisions of what you need to add or what you need to replace or whatever else.
The other thing is, look at it always from the fabric perspective because this is very helpful to describe a state you potentially want to achieve and the way forward. And that also helps you then to understand what are elements you can keep, which ones do you need to replace at a certain time? Where are your gaps from a capability perspective? Which capabilities you may not need at all? That might be also quite a lot of these, etc.
And how to bring these things together, how to orchestrate different capabilities, which is today, technology-wise, so much easier than it was just a couple of years ago. So, look at it from these two angles and then work strategically with a good plan and not by just hopping on the next hype tool.
Thank you, Martin. That was the great final summary of our conversation. I think that is the way that we should look at the market, really. Maybe IVIP does fit a gap or fill a gap, or maybe it is just another overhyped term. It depends on what you need and what your capability requirements are.
So, yeah, thanks again, Martin, for being my guest today, for shedding some light on this emerging market, on the role that AI plays for IVIP and it does disrupt this quite heavily right now. So, let's monitor these markets. This is what we're here for. This is the analyst's work that we're doing.
So, looking forward to having you soon on the next episode, Martin. Thank you. And I thank a little bit of Edward because you didn't do it. If you want to learn more about how to do things right, don't miss our Identity Fabric Impact Day in September and all the other impact days because this is where we really will dive into the details of a lot of these subjects. How could I forget this?
Of course, especially don't miss the opening keynote by Martin. Don't miss the closing keynote by me.
So, have a lot of good information and some fun in Cologne for the Identity Fabric Impact Day on the 9th of September. Thank you very much, Martin, for reminding me and looking forward to seeing you there. Thank you. Bye. Bye-bye. Bye-bye.