All right, it has worked. Okay, two disclaimers first before we dive into our conversation, because this topic pretty much stemmed from a conversation that Matthias and me had.
The title, this is obviously, frankly, a JetGPT title. I'm not a native English speaker, so the translation is a bit odd, overlooked.
In fact, it was meant to be a bit catchy. We meant it in the sense that we can ignore it. Let's pick this apart, because I think that's quite important to note before we start. This is not a vendor bashing, or this is not putting anyone on the spot. It doesn't mean that there are trends that are not important. They are. We need to take care about all these things that we see in the vendor compasses. We need to take care of all the hypes and the important topics and issues and challenges that we currently face. It doesn't mean that you, at the point where you are, urgently have to.
It also doesn't mean that your company does not have to face these things or solve them in any way. It does not necessarily mean that you, as an IAM-responsible person, does need to do that. Because what we see is, I mean, we had yesterday, in case you were not in the Identity Fabric session, yesterday we learned that if Kuping or Co. does an assessment of where does a company stand in their IAM maturity, usually the companies, they stand between two and four, with somewhat leaning toward two or two.
So, our talk is for the guys who rank somewhere between two or three who say, well, Agentica AI, that's nice, but I still face difficulties in joining a mover lever. I'm struggling with rolling out recertification to my whole company.
So, this is for you, and we want to get a conversation going that we think is not happening publicly enough, because in all the other topics we see Agentica AI. Second disclaimer, we had to hand in these slides a couple of days and weeks ago, and we already have one day behind us after all the conversations I had yesterday. We just would put up one slide that said, Agentica AI, and then a question mark.
So, what are you doing there? How do you do this? This would also be a great talk, because we really would like to learn how you do this, how you get so far along, or if it's just a topic that you know there is, but in fact, you're not actively working on it.
So, we picked two trends that we see. They are a bit hidden within the slides. This is AI for identity, and it's identity for AI, and the topics that stem from there, and all the effort that we need to put in there. Before we dive into that, my name is Tim. I'm a consultant. I occasionally work together with Matthias, and we talk a lot together. We also love to talk a lot and opinionate, and we thought that, well, we put our conversation to the bigger stage.
Thank you, Tim. Yes, we like to talk, and we agreed that we make some slideshows, but we will not do the slideshow.
So, we make it quite spontaneously, and I'm Matthias. I learned all the things I know from Deutsche Bank for 10 years, and then I decided, okay, I want to change something, and it would be not possible.
So, I went to GLS, and now I have the heritage of 20 years unstructured identity access management topics there, and we have to solve it. Keep it simple, stupid.
So, you see people who work with me together, like Robert from Netherlands, and Sonny from Dijkstra Centraal. We want to make you aware that all the things you are seeing here on this fair might feel you, oh, I don't have this. I don't have this. I'm not in this shape to doing this, but make your basics right before you want to introduce all those fancy things you are learning here. If you don't have good data quality, if you do not have processes, if you have no accountability, AI will not solve the issues. And this is my takeaway for you or our takeaway for you.
Keep it simple, and then we go to the first slide. We see all those numbers, and Tim will walk you through those numbers, and then I will share some insights of the company I work for, what we are doing there, what challenges we have. And I will tell you, for example, we have 20 HR systems. Not 20 SAP HR systems, though, no, 20 different HR systems, because we are purchasing every year two to three companies. And we are earning them the AD, the Entra ID, the Octa, the Key Cloak, the Alt Zero. They are there. They are working with those things. And we have to integrate them.
So, ISPM or AI might be an option, but not right now, and not in my plan for the next five years. Yeah, I see.
So, that's an opinion from our side, right? If you say this topic is important, but if we take a look at the number, it's quite obvious, right? The GDP in Germany, it's stagnating at somewhat around zero between one, depends on what source you have.
However, the projection for the market growth, and this should not be a percentage, it's 2030, are the market growth of IAM that is projected at 18% growth. It means all these new features, this new platform, we just have seen yet another vendor compass that we have.
And this, of course, is driving the market. And the issue here is that the market is evolving faster than the budgets and all the money that we earn, that we then can respend, that they are accelerating at different levels here. And in addition, there just was a recent survey where we figured out that four out of 10 German industrial companies, they all actually want to let go of people, they want to reduce staff. And if we take a look at, well, who has good perspectives on the job market?
Well, it's these eagerly sought identity or IT security professionals, right? Every company has a lack of this workforce and they have objections. And if companies now want to reduce workforce and they are offering packages, guess who might take them first? So we see that there is an issue rising. And in addition to that, yes, we see this new vendor compass, right? The scope increases drastically, right? We started with access management, then we had IGA, okay, we put some workflows behind that, visibility, transparency, and governance.
And now we are massively increasing on the supposed scope of identities and entities that we should manage. And we are moving towards policy-based access. We are moving towards real-time authentication and authorization. Who's going to do all that stuff? And I had a very heartfelt conversation on the identity on Monday where a guy in one of these industrial companies told me, well, I'm frightened. What if we can't do all of this stuff? And our key takeaways before we... We might not be able to finish our slides, right? We love to talk.
The takeaways that we want you to take away right now, they're on the first slide already. All these AI topics, they will not solve your own problems, right? They will not help you along with explaining to users what you actually do, fixing the data quality. They also will not massively increase, for example, system performance. It's okay to sit some things out, right? You don't need to jump on the AI hype train right away and load all these agent identities into your system.
You can let your company figure out first what they actually want to do, establish some basic guidelines, but not over-inflate your systems. Some guy asked me, well, if we talk about machine identities and also they have access rights in the sense of operational security, do I put all my production machines now into my IGA system because they have network connections? You might kill your license scope there. And don't be a hero in that sense, right? Don't try to figure out, well, there are all these new topics and me, I alone, I have to face all of these all alone.
We put all of this into the IAM team. Shout and let the help management out there. So my line manager went a couple of weeks to Bucharest to the IT days and came back with a lot of ideas and says, Matthias, can you do now at CIAM? Can you please do the integration of the agencies in Spain and also the French and Italian and then please do also the third-party depots in Poland? But by the way, the certification campaign is also overdue since two years. And can we simplify the access assignment based on policies and rules?
Yes, of course, I would like to do this. But to be honest, it's not possible. It's not possible because recertification means the end user, the line manager must be aware how to perform a recertification. Revoked decision means access is gone. If you are not acting, force revoke, access is gone. You have to request it again. Not complaining. Data quality. When the HR data is no good and we have, for example, 20 HR systems, as mentioned, and for those we have already onboarded, we have one big country, we have for 10,000 employees 1,200 job titles.
I mean, we are shipping parcels from A to B. We are not flying to the moon. So why do I need 1,000 job titles? How can I build policy-based access on those data quality? HR system writing all names, uppercase. And then they're complaining about, oh, my name is displayed in teams, uppercase.
No, shit in, shit out. So we have to do the things from beginning and when those things are done, we can make the next step. So when you cannot walk, you will not run. And this we must learn from those sessions here. Nice ideas, really cool topics, and the level of agility is quite high here on this fair. But the real life is we are doing I&M and IGA for the business. So we are a business enabler and we are securing the business and driving this change. But we must know that people sometimes overload other work and they do not have the capacity to learn how to use all those nice things.
Recommendations on access you need based on bias information, wrongly assigned. And I can tell you we've done some investigation in the previous company of a big application with 60,000 accounts and thousands of access rights over two years. All the decision then was access right used in the last two years. And I can tell you 30% of the access right assigned to people was used in two years time. So this means the other 70% was wrongly assigned or not needed. When I make now those recommendations based on I can see you, you and you, you have access, you're not.
There are 60%, yeah, you need also. No, it's wrong. And then we are assigning access rights, higher risk, license costs, yeah. So we are not working for hyperscalers where cost doesn't care. We have to be cost sensitive. So licenses are money we have to spend. We have to ship more parcels. So we must be very careful about access reassigning. The conversation we had has also recertification is actually a trending topic at the moment because many, many people now surprisingly fall under NIST two.
And what NIST two doesn't directly say do recertification, but they say establish some proper means of identity or IT security and have processes in place that keep your data in shape. And this you can't do without recertification.
So many, many companies be it because they migrate away from an old solution that did not have this feature. Hello to the SAP IDM folks. Or people that say, oh, I did not want to do it, but now I'm supposed to. So we have a lot of recertification projects at our clients at the moment and they face the same issue.
Well, recertification, I'm looking at all my accounts and I see that Matthias here, thank you. It's getting cozy.
It's good, right? So, no, thank you. And if I look at Matthias in his IGA system, he has probably some hundred AD groups, a couple of dozens SAP roles. And he has a manager and this manager has also 10 other employees. So he gets a recertification campaign at the end of the year where it's not stressful enough with a couple of hundred questions he has to answer. And some of these questions, they are confusing. So this is a pain point. This has been a pain point in IGA all along.
And when people go ahead and say, well, we have AI now and we have this amazing pattern recognition where we say, I can give you a little nudge, right? This is Matthias. I can see where Matthias has his access right all along. And we have all these colleagues. They have completely different jobs, right? But somehow they sneaked all their AD groups in there and say, hey, Matthias is alike his colleagues. Let's keep all these AD groups. And the first problem was management did not want to click through a hundred questions. So control A and save.
And now they say, oh, it's justified because AI told me that I need to do this. And not sure if some guys, I mean, every one of you, you work with JetGPT and such. The results it produces are sometimes confusing. And by definition, they optimized on pattern recognition. So they make everyone alike. And I think that is not a key concept of what recertification and what access governance is supposed to do. So not only does it not solve the solution, but it might actually go into a different direction.
If I look at Matthias, he said, well, Tim, I actually do not want that people keep their access rights. The second topic, all these recommendations, they can also go into the access request process.
Matthias, I see your colleague has all this nice little AD group. Oh, co-pilot license. You might want that as well. And manager, hey, co-pilot license. You might want that as well. And the fact is, GLS as a logistics company, it's very, very cost sensitive. So we actually do not want that all these people have all these amazing access rights. So are you going to use AI for your upcoming recertification features? No. No.
I mean, a couple of weeks back, my CEO came to me and said, Matthias, we have to save money. We have to save money and we have to get rid of Atlassian access rights and Udemy and all those things which are costly effective.
Like, can we not change the Microsoft E-license to a F3 license? Because it's saving a lot of money. And then we are doing this and then it makes bang and then people cannot work because limit of storage or you are losing your complete access to conference pages. You are having an issue. But we don't want to perform a review campaign only for, let's do a review campaign because we have been told to perform a review campaign and then we are all clicking on maintain, maintain, maintain, maintain. And then to be honest, sometimes the access rights are described like, access right is called ABCD.
The explanation is, this is access right ABCD. Have fun line manager, review this access rights. Do you need this access? And you ask your employee, do you need the access right? I have no clue what this access is doing. I can work.
Yes, I need it. And then we are maintaining, maintaining, maintaining. And we all know the story from the trainee who is passing a lot of departments and after three years time, he has access to everything. And then it's exactly those people who get targeted and then they get privileged. And what's happening? We have this issue that people ask, can you please install remote control? I'm your agent supporting you on your issue to get there. No problem. External contact possible via Teams. It makes it easy, but also a risk.
And that's the reason why we should really be careful what we're rolling out, what tool we are using, because on the end AI, everything comes out. You are using it. Nobody has forced you to use. You are accountable. And then we make recommendations based on wrong data. What comes out? Wrong recommendations. So if you're at a point, we talked about this. If you're at a point where you need to decide do I need a more expensive solution because it has all this massive, new, shiny AI features, you might at the point where you are, you might actually not need it at this point in time.
We have other topics, right? AI generated reports. If your management is not interested in those reports and it's not looking at those, why is this feature actually here? Why do you need this? Where it can help is we have on the second side, what helps is data quality. AI needs data quality. You need a data quality all along. If you have tools to be employed, use them to improve on your data quality. Get patterns out there where you say, OK, these are outliers. This data is malformed or we have attributes missing. Helps steer this process.
This might get you forward, but you don't need to put a feature in there where it says, well, it's AI and by that, it is automatically better. That's usually not the case. We are running out of time, so I'm going to do the same thing as the previous speaker did. I'm going to tease other topics you can talk to us about. After that, I like to reserve some time for questions because you might have some or might want an opinion on something or share an opinion, which I would very much cherish. Platform scope is the second thing. Identity for AI. What are we going to need to put in there?
Are our old solutions working for the new world? I think we have a couple of opinions. We heard some of them already from Martin Kuping.
I said, well, the platforms are also not prepared right away. We can talk that through as well. And by that, one and a half minutes for questions or shared opinions. Thank you very much. Are there any questions from your side so far? Then maybe a show of hands what we just opinionated on with whom this topic resonates a bit where they say, well, I'm also not quite there yet. Don't be shy. So you're not alone.
That's the reason why we've done this presentation to ensure you are not the only company struggling with all those things you are seeing here because AI is good and we are also using AI like Microsoft Copilot we are using here and people are still struggling for a correct prompt which data they are able to upload. Step by step and then you will have success. Thank you very much for listening in. See you around.
Thank you, guys. Thank you.