Welcome to the KuppingerCole Analyst Chat. I'm your host. My name is Matthias Reinwarth. I'm an analyst and advisor with KuppingerCole Analysts. My guest today for a very topical reason is again Martin Kuppinger, one of the founders of KuppingerCole and the principal analyst.
Hi, Martin. Good to have you.
Hi, Matthias. Pleasure being back. Good to have you because we want to shed some light on a new four-letter acronym that has reached the space of identity and access management and that has gained a lot of visibility, pun intended, in social media, in publications. We want to talk about IVIP, IVIP. We want to talk about identity, visibility, and intelligence platforms. This is a solution, a capability, a set of products that come with a promise.
The promise is that it really aggregates and correlates IAM-related data from every source that is around, be it IGA, PAM, access management, ITDR, and everything else. It applies access analytics and supports continuous monitoring. In the end, it provides visibility into all things, identity, behavior, entitlements, how they are used, etc. This is the promise that it comes with. To continue this introduction even more, if we look at that from an identity fabric point of view, we introduced the new version in the beginning of this year.
It comes with the promise of being a new capability, so somewhere in column two, audit and risk and analytics. Of course, and that's I think the even more important part, it's a new set of products. It's a market segment. Your position, Martin, what is it really? Where does it come into play? Is it something new?
Yeah, I'm always a bit reluctant when a new acronym comes up and it's positioned as an entirely new set of products. I think there are four aspects which are worth to be discussed. The first thing, you elicit what it all aggregates. You didn't bring up big quotas, three letter in this case, NHI, which is another very important element. The first thing is, what is the focus? Is it everything around all identities or around some identities? The second thing to look at is platform. Platform is a huge, and the question is, is it a capability or is it a platform? Really a platform.
Platform for me is something which is a very fundamental element where I build things upon, which is really sort of at the very core of something to be discussed. And visibility, and I refer to a podcast which we recently did together with Felix Gatkins, where we have quite some interesting conversation about visibility versus observability. So the question of insight versus actions clearly comes up. So do I just know what is wrong or can I fix it? And how can I fix it? I think also worth to discuss today.
And then last and least, when we look at the identity fabric and for instance, what I talked about at European Identity Conference, at our keynote in May in Berlin, we talked about the modularity, building upon signals, more loosely coupled orchestrated solutions. And then the question clearly is, again, it goes back to capability versus platform. Do we need platforms or do we need additional capabilities that complement what we may already have?
If we look at exactly that question, many of the capabilities that are combined within this IVIP construct called a platform, at least for the time being, I would also be reluctant to call it a platform. These are capabilities that have been around for quite a while, but they now are restructured, recombined into this visibility mechanism. The question is, why hasn't it been done before? Most of the capabilities, if not all, have been around for quite a while.
It's access analytics, it's access intelligence, it's combining different types of identity information as a kind of relationship management. If we think back 10 years, there was this term of IRM, identity relationship management. This is built into that as well to understand how things work together. And of course, it all merges together through AI into a graph, a graph that gives this visibility slash observability. I would love to dig deeper into that. But as a thesis, I would say nothing new, just a new name for something that should have been done five years ago.
I would dare to say that the visualization via a graph is something which isn't entirely new, but which really has been added. But the term access intelligence is out for probably a decade. And building something on top, which helps analyzing entitlements across various sources, an entirely new idea.
It goes back to, I would say around 2008 or so, when the first access governance solutions came to the market, which by the way, were solutions that were sitting on top of other solutions, sort of gathering information about the current entitlement structure and providing visibility into that structure as a foundation for doing recertification for regulatory compliance when they started. And they weren't, at the beginning, they weren't actionable. So they told you what is wrong, but you couldn't easily fix it. So over time, this evolved.
And what I would say is, if we do it right, then there's a value. That would mean we have insights across all types of identities, especially also the relationships between different types of identities. So which brings us to something we discussed in a couple of podcasts already, when we talked about, for instance, non-human identity management, again in quotas. We looked at ownership aspects, et cetera. And these are things which then must be covered. But it must be also what is done with the entitlements.
So if we take really the usage information about which entitlements are used, et cetera, into that, then this really can provide valuable insights. Additionally, a broader and deeper and better level of visibility. And from that perspective, it clearly is not really new, but there are new facets in that. So I think this is how we should look at it. And then it can provide value, depending on which insights it really delivers.
And basically also what we can do is that I just recently talked to someone and they said, a lot of customers, whatever, thousand applications, it's very hard to really onboard them for IGA, for full provisioning, et cetera. But you can easily, that way, sort of gather the information about who has which entitlements across these applications. That on one hand is a view that is more focused on traditional sort of workload identities, maybe a bit beyond workload, a workforce identity, sorry, not workload, workforce identities. That's the one thing.
It's focused on more the traditional side of entitlements. And it leaves us with the challenge of, okay, if we spot issues, how do we handle them? So it still doesn't solve the issue of at the end of the day, really managing everything. And I think that that is probably also where we really need to look at. This is in some sort of visibility versus observability discussion already. Can we observability identify things that are wrong that may very rapidly result in major risks or attacks? And can we close this? Can we handle that in the proper manner?
And I think this is really the criteria that we should apply when looking at these solutions. As I said, they can provide additional insight, but insight itself is not enough. I want to be more critical because if we have this platform and everything that you described, I'm fully with you. It can be really this pane of glass that gives you more insight into all these types of identities, plus their usage across different applications, platform systems, and that really can help.
But in reality, I think it will be often just the highlighting of symptoms of identity architectures that have not yet been complete or well thought out or well implemented. And instead of looking at the root causes, you just highlight symptoms and then you say, okay, yeah, let's work on some parts of it because we need to start somewhere. This is far beyond or far before we get to a proper identity fabric because it's just, yeah, it's just looking at symptoms. Instead of designing IAM systems better overall, we add another layer, another tool.
Hey, let's buy another tool to get visibility for something that could have been done better earlier. And so it's really the increase of the problem of fragmented systems and adding to a tool sprawl instead of reducing tools for the benefit of having an integrated platform. That is at least a danger that I see for just providing these tools without thinking about a proper architecture.
Again, am I so wrong when I think of not so mature identity architectures? Hey, buy a new tool. I think it's very clear that these types of solutions will frequently be used when you need to, when you say, okay, I don't have enough visibility and I don't have enough insight. I need to do something and fixing the root cause would take me too long. It's honestly not very easy to properly fix the root cause. That would move us to other types of authorization models, helping us getting away from static entitlements.
A lot of conceptual work, also looking at how do the entitlement models at the application level look like? How can I improve that? Starting with documenting them, et cetera. There's a lot of work to be done, but yes, I think that it frequently will be something which says, okay, it helps me to better understand where my risks are. But that also brings us to, for instance, ITDR, Identity Threat Detection and Response. What is the promise of ITDR? Defying anomalies, risk, and acting on them. So I think when we look at it, we definitely also need to look at ITDR and how these play together.
Because there's a certain overlap, the one more in visibility, the other on the threat detection and response side, which mainly means threat detection. The response part there, it's where it's getting weaker on average.
So again, the actionable element, which is the bigger challenge. And I think we also need to look at what do we have and do we already utilize what we could do with, for instance, our existing IGA solutions, which when you look at all the vendors commonly come with a certain level of visibility, not as shiny as some of the crafts, et cetera, we see popping up, but also something which is already here. And there's a value in, when you don't have the proper solution in place, there's a value of having something which helps you at least mitigating the risks by delivering the visibility insight.
It's not that it's bad per se, but it doesn't solve the underlying challenge. That's where I'm fully with you.
And yes, if you want to set up whatever a new IGA platform, a modern one as part of your identity fabric, then this is a big project from a planning and execution perspective, even with the most modern solutions on the market, it takes you quite a while. And that's the time you may not have from a regulatory compliance, from a visibility, risk mitigation, et cetera standpoint. And then this platform can help you, but they are curing symptoms.
Yeah, right. I like the argument that in quotes is, should be built in. It should already be there. It should already be within the IGA system, should be within your access analytic solution anyway. That is the question. Why isn't it the standard feature? Why adding in 2025 after, I don't know, 20 or 30 years of IGA around, now adding a level, a new level of visibility. Why?
That's the part that I'm struggling with because it has been around, but to also give a counter position, there are still lots of organizations around that do not have an IGA, an IAM solution at all, who do that in a different way. And I've seen that with organizations just recently where they applied such an, call it IVIP at that time, it wasn't called IVIP, a solution that gave them insight into their tools, crawl into the AD, into the SAP directories and use that for prioritizing the first steps while moving into an IGA solution. And that was helpful.
It really helped them identify where are my main issues, which processes are broken, which policies are not well implemented or where do I don't have no policies at all. That would help. So it adds also in prioritizing and in understanding where to start first or where to take the next step. There I'm fully with you. The capabilities are really helpful. My only point is they should have been around for 10 years now.
Yeah, I think so. I think what has changed a bit is the ability. So we've made progress with the graphs, which are nothing really new, but we made progress in that area also with the visualization. The question is, is this always the right type of visualizing? I think underlying a graph makes sense from a visualization perspective. It looks wonderful in a demo. In practical usage, it may be very different because always walking through the graphs might not be the most efficient way to do things. So it depends on what we do based on the graph data.
And we are better in dealing with huge amounts of data that also makes a difference nowadays. So I think it's fair to say this can come in, but I think we also must not be naive with respect to how does the data come into these solutions. So there's a lot of data in different places, which means, and that goes back to, for instance, identify a breakpoint which is built around orchestration, APIs, around signals, et cetera. We need to be able to gather that data and we need to understand it.
And when you take entitlement models of complex applications, take SAP something and compare it with the entitlement models of just a good old Microsoft legacy Active Directory, then they are very different. So you need in some way to normalize information that could be single tiered, multi-tiered. You still have applications that don't have the interfaces that you can connect to that doesn't go away when you have this platform. So you still need ways to integrate that information.
So we know all the CSV import stuff we still do in access governance, which means some of these challenges don't go away. And there might be some over-promising here as well, where we should really carefully evaluate whether this is something new. But when I look at it as an analyst, I would be at that point, at least I would be reluctant saying there's a need for another leadership compass for something that covers an entirely new category. We have a leadership compass on IGA, which looks at the provisioning and the access governance side.
And we have one that is closely aligned with that, that really puts the emphasis on the access governance, the analytical intelligence visibility side. Maybe this is at some point renamed into IVIP or AWIP for access visibility and intelligence platforms or whatever. Don't know. But it's not that I would say there's this and the second one for IVIP. I don't see it. Because at the end, I see it more as a capability, as some innovation modernization around that, but not as a fundamental breakthrough innovation of any kind. And I think one argument could also be this is a rather new term.
It has been just published. It gained a lot of visibility. And for me, really surprising. But if you look at it, maybe not surprising. There were lots of vendors that immediately said, oh, we have IVIP solutions because they just repackaged their available capabilities and put on the new sticker IVIP because they do this. This is not that they don't have that, but it's been around for a while. And they now add this, repackage their capabilities, which provides a new market segment immediately because it has been around there, just a new label.
And for those who don't have an IVIP solution as a customer, it might be something like an artificially created buying urgency. Oh, I don't have that. I need that. Maybe you have and it's already in your platform. And chances are the more mature your identity fabric and your implementation of your overall process, just as you described, getting better in correlating data, the better you are, the more mature they are. Chances are you have it already.
Yeah, I think that's true. And there are also some interesting startups bringing in new ideas, new concepts. The point I really want to make also to summarize it a bit, it's not really entirely new. There are some new elements in that. You may have a lot of that already in place. Don't understand it as the final solution, but something that can help you to better solve an immediate issue if your current identity management is not yet there. I think this is the point. If you need it clearly, then there's also something underlying you need to improve over time more strategically.
And that is again where the identity fabric paradigm or these concepts help you more on the strategic path moving forward, but also be very cautious regarding what does it deliver and whatnot regarding the depth of insight, the visibility versus observability aspect, the coverage of identities and entitlements and other types of entities. So, how broad can it be? And how do you integrate what you have? And finally, what do you do with the visibility you gained?
Maybe, where can this term be helpful? If you are not yet there, if your maturity is not yet there, if you want to get through to the point that you just described, correlating data and making the next step to get to root causes, to improve, to respond, so to add the R from ITDR, then it might help you. Because it has traction, it has visibility, it's within all these shiny new documents. If it helps you to get the buy-in by your management here, fine, do it.
But in the end, it will be implementing the capabilities that should have been around for a while, adding maybe these additional features that you've mentioned, but recognize it for what it is. It's a rebranding of something that should have been there, plus the new technologies that help you in getting more insight.
So, I think that that might be helpful. Yeah, but at least us with the P in iWeb is definitely too big of a term. Right. In case you need a new platform for that, you've made something entirely wrong in the beginning.
So, you don't need another platform. You don't want to move data from A to B, add a new silo. You want to have a set of capabilities that help you improve your overall security. Let's phrase it that way. The platform is the identity fabric, or the identity fabric is your platform. That's where these things are added and built in.
Right, exactly. I would not say it's useless. I don't say it's nothing that you need. I don't say it's nothing new, because some capabilities, as you've mentioned, have been added, but it won't change the structure of the identity fabric. But if you look at this chain capability service tool, it adds new tools, but not because the tools are new. The branding of the tools are new.
So, that would be a good point. In the end, what is the good part? We're getting more visibility wherever it comes from.
So, that is helpful. This is something that we need to be better in anyway. I like this discussion, Martin. Thank you very much for being my guest today, for shedding some light on this new term that's been around. It won't entirely change the identity fabric.
So, analytics, visibility, access governance are in there already. The question is how you package that into tools, and that's the market side. That's the way how you build it into the overall landscape of tooling.
Again, thank you very much. Final words to add to this, maybe hinting at an event that we're doing in September? There's an identity fabric impact day in September, which you must not miss, in Munich, as I remember.
Right, exactly. If you want to meet the team in person, that's the right place. It will be nice, cozy, small, and very intense around how to leverage the identity fabric for creating real-life, mature identity platforms. And there we go again. With small being a relative term.
So, not so small. Small in comparison to EIC, but nice and cozy. It will be intense. Let's call it intense. Yes. Looking forward to that, for that intense day of identity fabric know-how exchange.
Thank you, Martin, for being my guest today. Looking forward to having you soon, and always a pleasure to discuss market trends with you. Thank you.