One area where I did see, let's call it, lots of room for improvement is around the know your business side, though. Again, if you think about maybe a different kind of supply chain where you've got businesses and individuals that need fairly short-term access, how do you go about vetting organizations that you might only do business with a few times?
You know, if you've got a thousand different organizational entities, you probably have hundreds of thousands of individual users. So delegated administration is absolutely essential because the one person at the prime has no idea about these hundreds of thousands or millions of individual identities. Good old-fashioned RBAC is just really insufficient to be able to provide the level of granularity and of control over the very sensitive resources that might have to be shared in complex B2B IM solutions. Welcome to the KuppingerCole Analyst Chat. I'm your host. My name is Matthias Reinwarth.
I'm an analyst and advisor at KuppingerCole Analysts. Today we want to cover a topic which we actually haven't yet covered. Not in that form. Maybe included in other topics as well. And for this new topic, I have invited my colleague, John Tolbert. He is the analyst researching that not yet mentioned topic that we want to cover.
Hi, John. Hello, Matthias. Good to see you again. Good to see you. It's been a while. We want to talk about a topic that is called B2B IAM. You have been covering that area together with another topic that was CIAM, so Consumer Identity and Access Management. And B2B IAM is slightly different. So first of all, why do we do that? Is this really an emerging market? Is it really differentiating from traditional CIAM? Is it a thing as of today?
Yes, I believe it is an emerging field sort of in between, you know, customer or consumer identity and access management and traditional or workforce identity and access management. You know, obviously, workforce has been around for a long time. Consumer has been around for 12, 15 years, depending on how you look at it. Consumer looks at masses of accounts with probably not as much need for fine-grained authorization, but really an emphasis on scale and how do you go about signing up or registering for accounts, which, again, is different from workforce.
Workforce accounts are probably most likely provisioned by your human resources department. Consumer accounts need self-registration and social login options. So how you get started and what you do with it are quite different. And now many companies find themselves in fairly complex relationships with other companies. So simply saying IAM does not necessarily work in those situations because you have to be represent organizations maybe as the primary unit with many users nested under them.
So, you know, self-registration might not work in many cases in business to business. And we find that through the course of our research for the last several years, many companies in the CIM market have said their largest segment is actually B2B IAM. So that's why we decided to let's take a closer look at what the differences are. What are the use cases? What are the technologies that are involved in making these things happen? And then evaluate them separately.
Right, and I've seen that in advisory as well. We had customers. We're exactly asking for that. They are customers. Their peers were larger organizations with all the structure that comes with it, with really different, even different companies within one group that needed access under one contract in quotes, and they needed to assign them with different levels of access. So a whole separate structure that needed to be integrated that does not work well with CIM. And they tried to build it with CIM because way back then there was nothing else.
So there were lots of bespoke developments and it did not really work. So that actually solves that issue. So really representing organizational hierarchies and then hanging people into that tree and allowing them to do things within a system that is not owned by them and where administration is handed over. I think that is, I've seen that earlier and I really was struggling in finding the right solution with the customers together. And now we see that this is really an emerging market. And I've talked about this delegation administration part of things.
So I think at least I would expect that one key capability is delegated administration. So allow somebody from the customer organization, maintain data in the systems of the provider of services, of goods, et cetera. So really handing that over. Since I had a look at that earlier, how mature are they actually? How good are they? I think you find a wide range of capabilities and I'm sure most of it's driven by the customers of these B2B IAM solution providers and what they have requested.
So yeah, you know, you're right. I think it's difficult to actually pin down one, two, or even three different kinds of models, because if you think about all the different kinds of B2B interactions that are out there, you may have, let's start with the most complex one, a big supply chain where you have, let's say, I'll call it a prime with many suppliers and then also many customers and maybe different kinds of contractors that work.
So you could have hundreds or in some cases, even thousands of organizational entities that need to be provisioned with identities so that those identities can then be assigned entitlements, permissions to be able to get into shared workspaces of different kinds. So you think about even in that statement, you've got suppliers, customers, partners, contractors, and obviously they're not going to need the same kind of access. But then there's also where are they coming from? How do you do authentication?
You need massive federation capability if you've got hundreds or even thousands of organizational level entities that you need to interact with on a regular basis. And then if you've got a thousand different organizational entities, you probably have hundreds of thousands of individual users. So like you said, delegated administration is absolutely essential because the one person at the prime has no idea about these hundreds of thousands or millions of individual identities and what they need to be able to do.
So delegated administration is pushing that decision-making capability to responsible individuals in the line level units and all of these other organizations. So that, of course, implies trust. How do you vet the trust? How do you do not only identity verification of individuals in these organizations, but how do you vet the organizations themselves? There's just so many questions that revolve around trust and figuring out how to right size trust between the individual users and the many different kinds of organizations that are out there. Right.
And I've even seen it, absolutely, I've seen that you said, so scoping and making sure that one department does not administer the other. And so this is all relevant. But we've seen that also with that specific use case I've been in, that even executing some kind of operations in the remote systems required a training certificate and some qualification that needed to be proven in a reliable manner or just a commercial role within the organization that you are allowed to sign a check, something like that.
All of this requires this level of trust that you've mentioned to say, okay, I can prove it. I'm allowed to assign this access, right? I have the proper proof as a document, as hopefully in the future, a verifiable credential that actually proves what this person actually is allowed to do so that the actual transaction is valid also from a commercial perspective and from a legal perspective. I think this is really an interesting aspect. And that's why I'm asking, I ask for good.
The question is how flexible, how trustworthy, how scalable these mechanisms are to cater for very large consumer or customer organizations, especially, for example, in the pharmaceutical industry where there are lots of these really complex interdependencies between organizations. Sometimes they are the customer. Sometimes they are the provider.
That is, it can be weird as well. Another part that I've seen in that scenario was the question, do I trust my customer organization in a level that I federate identities into my systems and then allow this delegated administration based on existing identities that are inherited, federated from somewhere and then allow the access?
So that's, I think that is also a new perspective that has not happened before with traditional CIM. It happens at IGA sometimes in larger organizations, but usually not external IDPs that are federated. So how do these B2B IAM solutions handle that challenge? This is also third-party risk management, isn't it?
Yeah, I think you can see how quickly it becomes very, very complicated and risky to manage it all. And I want to go back to something you said a minute ago about training and certification. I think the situations like that, that traditional role-based access control certainly falls down here.
I mean, you can't just do authorization based on roles. How do you represent training and certification status? Because that's important in many different industries. Typically what I found is most of these vendors have extensible schemas. And if you're willing to get in and do the work and define things like that, you know, let's say certification, yes or no, even. And then you can also configure, well, where do you go look for up-to-date information on that? Because it's probably not in your LDAP directory.
You can do these things with quite a few of these vendors, but yes, it's going to take some customization in order to make that happen. Often these certificates, they expire, they need to be renewed. This is a process that needs to be checked as well. A decision that was valid yesterday might be invalid today. So this is really a complex topic. So the deeper you look into that, the more specific requirements there are.
And, you know, really this is about instantiating legal trust and how do you offload? How do you verify? I think there's definitely a legal component as well as a technical component here. And being able to keep those aligned is very important. Right. And from the federation part, this is something that they deal properly with, that these solutions typically can handle so that they understand the federation assurance level and what they do with the identities then?
Yeah, I'd say that's one of the more well-developed parts. Most everybody, you know, except SAML and OIDC, that's pretty well built out across the industry. And then being able to add in attributes as necessary or do authoritative attribute lookups as necessary. I think that's all fairly configurable in most of the solutions that we see out there. Right. It's good to hear that. So we have a reliable way of getting trusted identities into the provider system. But as you said, there needs to be a trust also in the processes that are happening on the other side.
So that if somebody is off-boarded in the consumer organization or customer organization, they need to be deprovisioned or defederated in a timely manner so that they are no longer able to act on behalf of the customer organization. I think that's also very important. And you need to understand their processes.
Yeah, IGA and lifecycle management is definitely a big part of B2B IAM. And I think that works well in many cases, because what you just said, you know, let's say you're, again, the prime organization and one of your contractor organizations hires and fires people, I guess, as they need to, when they remove access at the contractor organization, you know, it should also remove access at the prime organization because of that relationship. One area where I did see, let's call it lots of room for improvement is around the know your business side, though.
Again, if you think about the maybe a different kind of supply chain where you've got businesses and individuals that need fairly short-term access, how do you go about vetting organizations that you might only do business with a few times? You know, to a degree, you need to be able to name and watch list screening, sanction screening, look up to see if the company is legitimate. It's not on any kind of list of fraudulent companies or things like that. And that's where I think a lot of B2B IAM solutions could use some help.
Still, some of them do a pretty good job with that. Others allow you to configure those kinds of lookups as needed. But I think that's an area for improvement, broadly speaking. And also this needs to be renewed on a regular basis because the trustworthiness of a partner organization can change over time, to be polite, and that needs to be tracked as well. Even when a company is taken over and just is rebranded or just merged into another organization, then all this information actually is lost or outdated. So that could be an issue.
So we've talked about the actual onboarding, either via manual maintenance or via protocols like SCIM or something like that. On the other hand, we talked about federation. When it really comes to the usual mechanisms like SAML or OIDC. And we talked about the authorization within the system to make sure, can we understand the actual hierarchy of the customer organization? But the next step is actually authorization within the target system.
So once they are in, you need to make sure that you have the proper access according to the customer organization to the systems that are related to the hierarchy. That can get as complex as IGA and actually much more complex because of talent structures and organizational subdivisions and everything like that. Can you tell a bit more about that? How does that work?
Yeah, authorization always does seem to be the most difficult part. We understand authentication. We have good processes around identity verification, but authorization.
Yeah, I think, you know, in many cases, you need to leave it up to the asset owners, you know, the business people who, again, maybe you've got a complex supply chain with hundreds of different individuals that might have access from dozens of different companies. But it's the person or the team that builds the resources often that has the best understanding of what are the characteristics of people who might need to get access to this data, who might need to get access to a particular application, and then might need granular rights even within that.
Who should be able to be allowed to update data records in a database? Who should be able to merely read them? I think that's where it's really imperative to have good policy building mechanisms such that you can define the attributes that you're looking for and then have that enforced at the data object or application level. That is definitely the most difficult part of this whole thing.
And I think that's why we see attribute-based access control, policy-based access control, and now relationship-based access control really coming to the fore here because we find that good old-fashioned RBAC is just really insufficient to be able to provide the level of granularity of control over, you know, very sensitive resources that might have to be B2B, IAM solutions. Right, so you've taken away that question from me. How do you authorize? And is it modern authorization or is it something that is more traditional?
But I think we see the same tendencies that we see in IGA or in access management in general. We're moving away, not fully, but partially away from traditional roles and groups, and we're moving towards fine-grained authorization with CDA, with OPA, and these technologies that actually are much more scalable and can deal with this amount of information and these different vast number of customer organization members. So that would be an interesting part to dig deeper in, but this is really, really complex. But we have the first checkmark.
So modern authorization is one of the main topics that we see a lot. No podcast episode without AI and no podcast episode without agentic identity. This is something that is showing up there as well. So agents acting on behalf of customer organization members or even the full organization. This is nothing new, right? I'm sure it's happening, but I don't think that everyone's quite ready for that.
You know, I did ask questions about that during the surveys. I think that there are a few solutions that have pretty well thought out capabilities that are there for dealing with agentic AI. I think in many cases, it's going to take a lot more work for the IAM system to be able to understand when it's being managed by or an AI agent is attempting to do something rather than the human they may be responsible for. I think there's still a lot more work that needs to be done there.
On the use of AI and generic side, I think many and many have for years used machine learning detection algorithms to do user behavioral analysis or maybe role mining or things like that. So that's a pretty well-established use of AI technology. I also now see a few vendors that are trying to make the policy building easier by providing a natural language interface. I think that's a good development, but still, I would not say that that is widespread amongst the solutions set out there. Right.
Yeah, but that's interesting that we have both sides of AI again. So on the one hand, agents running around and having the need for somebody being responsible, liable, accountable for that agent. So this ownership management on the one hand, and on the other hand, AI really supporting the day-to-day business within the platform to get to more functionality and where it can help. We talked before this episode and I thought my question to you was, is this only SaaS?
Is this something that sits somewhere in the cloud and then deals with these different systems with a federated client or as the customer on the one hand and the provider of services on the other hand? Because that is clearly closely related to compliance, to data residency. Am I really willing to hand over my customer data to a platform that is not owned by me just for compliance reasons or just for security reasons? When it comes to this topic, and of course, then also regulations like GDPR and everything like that, how are these services delivered and from where are they delivered?
So we're talking about, on the one hand, about regionalities or where is it, and on the other hand, really the option to run the system completely autonomously on your own platform, on your own cloud to make sure that this is fulfilling your own requirements or your sector's requirements. How does this look like in this area?
Yeah, very interested in that because these are questions that are raised to me all the time. Well, I will say by and large, the preference of these solution vendors is for customers to consume it as SaaS. And for that, they have both multi-tenant and single-tenant options available.
There are, I think, probably less than half offer their solutions in some sort of on-premises deployable form. And just thinking back over work on IAM and CIM over the last several years, fewer and fewer of them tend to want to offer on-prem options today. There are some that do, but it is becoming less and less common.
As to where it gets deployed, most of these have data centers in various places, North America and Europe, for example, and many of them allow a degree of granularity on where the customer data can be stored so that it can help comply with data residency and even sovereignty requirements. We do have a number of European-hosted vendors specifically that operate fully within the bounds of the EU.
So, customer organizations in those areas might want to take a look at those first if they're concerned about data residency and data sovereignty. Okay, but usually you will find solutions that can be catered to the requirements of the individual organization.
So, if you look at the full market, all options available from SaaS to on-prem, self-hosted to everything like that, although they are not that fully available in all options. When we reach the end, I want to go back to one topic that you've mentioned briefly already when it comes to the topic of the onboarding of an organization, identity verification of people and the due diligence of onboarding organizations. You looked into sanctions lists and something like that for organizations and proofing how if an employee is actually an employee and has the right certificates available.
Can we dig a bit more deeper? Because this is much more than I just hinted at. There are more aspects to look into.
Yeah, I mean, if you think again about how employee accounts are created in workforce IAM systems, in general, we're depending on our HR departments to do whatever due diligence is necessary before those accounts get created. When we do identity verification for consumer situations, there's sort of a wide range of identity verification technologies that can lead to different identity assurance levels. And that's often quite customizable for the customer organization.
On the B2B side, again, thinking of a supply chain where you have a company that's doing business with another company, you effectively have to trust whatever their HR processes are unless you, if you consider a different kind of B2B scenario where maybe you're a large organization and you're hiring a bunch of freelancers. So then you need to do something that may look a little bit more like consumer grade IDV. And you may also have other organizations that you're dealing with that you have to depend on their HR processes.
Yeah, I think this really shows there's another level of difficulty, if you will, having to understand what the different risks are, how do you mitigate those risks with either identity verification or maybe using HR background checking services in the case of freelancers. You know, that's kind of closely related to something I did want to mention too. If you think about, we often think of employee relationships as long term or even some contractor relationships are long term.
But in the course of this research, I found that there are many organizations that sometimes hire a freelancer to do a specific task, which may last less than a day. So one of the really interesting requirements that I saw was the ability to set very stringent limits on what different kinds of accounts can be created. And then to enforce that lifecycle management very, very strictly, even to the point of, you know, a matter of hours.
So, yeah, I'm just trying to illustrate the variety of requirements that we need in B2B IAM systems and how that really exposes the need for different kinds of solutions than our traditional workforce solutions of old and even our high scale CIM solutions of the last 10 years. Right. I've seen that as an example for help desk employees and four weeks before Christmas, they are scaled up and five days after Christmas, they can go.
And this is something that I've seen and similar requirements, not in an hour or within hours perspective, but maybe for the onboarding, yes, and very limited access to systems. And that was really just to scale up, scale down very, very quickly. That was something that I've seen as well. And so these long term relationships, if they exist, they are with their parent company, not with the customer or with the service provider company in the end. So that was interesting to see.
Yeah, good to see that from your perspective. This is the first edition of this research that you do and that you did. So it's a leadership compass. It's out now. It's out for quite some weeks now. So it's available for anybody who's interested into looking into that. Really highly recommended. I've went through it because I have to, from the advisory perspective, very important to have recent research here. Do you expect that market to evolve? Will there be a rerun of that leadership compass? Do you see any hurdles in the way?
I don't, but I just want to make sure. Yeah, based on everything I've been told, the growth of this particular market, yes, I expect I'll be redoing it again next year. And likely there will be more vendors that are positioning themselves to address this ever increasing market.
So, yeah, stay tuned. I think we'll have a lot to say about this in the years ahead.
OK, great. Thank you. And usually my final sentence at the end of the episode, if you have any questions that we have not covered and that you do not find answered in the report that John has created, please reach out to us. John is available by mail. Easy to find out. We are on LinkedIn. You can find us there. If you want to ask a question regarding this episode just right now, after we close down and say goodbye, leave a comment in the YouTube section, send us a mail from any other platform that you consume this podcast that we will answer. We promise.
So if you have any questions or if you want to continue this conversation, say, let's have a look at this specific aspect of this research. Maybe we do another episode on that. Having said that, thank you very much, John, for sharing these insights. This is very close to me, this topic. And we've talked about that a lot, a lot of times. And it's finally there. We have this news market segment B2B IAM. And I think it's good to have it and to monitor it. Thank you very much for the research. I think it's a massive amount of work, but the results really pay off.
It's a really nice piece of work and really helpful. So thank you very much, John.
Thanks, Matthias. Looking forward to having you sooner again. See you. Bye-bye. Sounds good. Thank you. Bye-bye.