Hello, everyone. This is my pleasure to be here. This is five years in a row already, and this is my pleasure for sure bringing the sun from Madrid to here, to Berlin, because it is quite convenient in terms of weather, especially yesterday. And I'm going to talk today about how we are evolving our IGA solution in Holcim, which has been in place for a year in order to make it the Pillar of our Identity Fabric. So the speed, try to be as much practical as possible.
So I'm going to transparently share how we are doing the things, not only just show some ideas here, but evidence how we are implementing and developing the technology. So instead of a key message that I would like to start sharing with you, so I'm quite convinced that some of you who has been on the Identity Governance and Administration for a year has struggled a bit in order to connect your application to the system, right? It is something that is not happening from one day to another, and sometimes requires associated significant effort and engagement with different things.
So the good news here is that it could still be leveraged on your Identity Fabric, so the work that you did in the past, it is something that you will continue using, and I'm going to try to explain here how. So first thing is to explain a little bit or go through the agenda. So I have four items for today.
First thing is briefly explain who we are in Holcim, key concepts that you need to understand in order to move forward with the thing that I'm going to explain, share about our IGA evolution, and for sure give some message or some takeaway that I'm expecting that you guys will be able to get from here. So regarding Holcim, just one slide.
So Holcim is a company which has been in the building material for years, so we started with cement, ready-mix and aggregate, and now we are evolving to more sustainable construction in order to make the life better for the society in general through more greener theater and through more sustainable construction. So we are more than 40 000 employees worldwide, and in our digital identity management team we are trying to put in place the right technology to manage the access to the application. So first thing that I would like to share with you as key concepts is what is the Identity Fabric.
So I fully understand that the quality and the details of the picture is not the same as the one shared by Martin yesterday, but I think it explained quite well some of the components that we have in the Identity Fabric, and for sure it has to be integrated, it has to be federated, it has to be protected and need to have a life cycle. So we are going to explain here how we can put these pieces together and how we can liberate in an integration with the IGA solution, which is in the middle as you could realize here.
So about the IGA solution, it is also important to understand or to summarize here what are the main capabilities. So what we have been developing in our IGA solution for the year, what is still there and how we can bring to our Identity Fabric. So first thing is identity life cycle management, so everything around the joiner, mover and lever, so it is something that all the IGA solution have and for sure a necessary piece in the Identity Fabric. And titles and role management, so again it is something that we have been doing for year and now it is something that we have there.
Approval workflows, so any single IGA solution provide approval workflows in order to allow the user decide the access granted. Access certification, again part of the IGA solution, something that has been there for year, maybe in not so friendly manner, so it is true that it is there but not all the legacy IGA solution are put in freely enough for the end user. Segregation of duties, in some cases mainly linked to the ERP, in other cases not always providing the level of granularity that may be required but it is something out of the box included in the in the IGA solution.
Auditing, so it is one of the main things or main functionality in the in the IGA solution, be compliant and ready. Identity intelligence, so it is I would say a bit more modern capability that used to be there and for sure analytics and reporting, so the data is in a repository in a database normal and it could be extracted and it could be reported. So those are the capabilities that I would say all the IGA solutions have but now let us go through the one that not all the IGA solution are having and we are expecting to provide to the business as part of our identity fabric.
So I'm going to cover five from this presentation because as you know it's 20 minutes, so it is the time that I have, so I will start with the first one. It is approval recommendations, so we say that the certification are there but the recommendation in terms of approval for certification or for other requests is not always in the IGA solution, especially in the legacy one. The next one is about cloud infrastructure and title management, so the IGA solution are not always providing this capability, so we will see how to integrate it.
Next one is ITDR, so it is in everyone's mouth, it is something that is constantly repeated during this session and here I'm going to explain how we integrate the ITDR with the IGA solution in order to take decision in the IGA solution coming from the ITDR signals.
Access management assistant, so it is something that we internally developed that I'm going to share with you, so the process to request access in the IGA solution is not always so easy or so user-friendly as our business expects, but we could customize and we could tailor it in order to do it in a bit more simple manner for our user. And the last one, it is mainly a bit specific in our case, but I'm going to explain how we monitor the task for the IGA solution but outside of the IGA solution in order to have a proper reporting. So how we are doing it?
So the first thing that we do in order to make our legacy IGA solution, our main component in the identity forward is to extend the API. And how? What process we follow with here? So first one is the use case definition, so first thing is to identify what you want to do, so how you want to extend your API. Second is extend the IGA platform API to support the use cases, so first define it after extend. Once you have the API ready, you need to modify the different applications or the different components in the identity fabric that are going to consume this API.
And last but not least, it has to be tested, it has to be used, and for sure it has to be socialized with the internal stakeholder in order to make them aware about the functionality. So basically, and this is also summarizing a little bit what I previously explained, the idea here is convert the API capabilities that sole legacy IGA solution are already providing from out-of-the-box solution to something customized enough in order to support the necessary use cases, define it as part of the integration with your identity fabric.
So I'm going to translate it a little bit more in a technical way, and I'll be providing here some example about the extension of the APIs that we have already defined. So as you can see here, those are a sample of endpoint, of API endpoints. In some cases, they are executed through pods. In other cases, there is just to get information, and here you have information about what the APIs endpoint are doing and the use cases that we have behind those. So for example, and starting from top to bottom, we have one which allows us to make the sign-off of the certification.
I will explain later with a video, but we have an interface, a solution which is giving recommendation to the user about the decision that they need to take in the approval review process, but it is not just enough to provide this recommendation and after request the user to go to the legacy IGA solution in order to take the decision. No, the idea is to take the decision also in the same interface, and it has to be translated to the IGA solution, so you need to have an API for that.
Another one that we also need to customize is the process to create a request in order to inform all the items that are included in the other request. Next one is something which allows to fetch depending on approval. So we created a chatbot and a system which is executed for different places integrated with the messaging and collaboration tool, and the most common thing that the users are doing in relation to the interaction with the identity governance administration platform is hey, tell me what I have to approve and then I will be able to take the decision.
For sure, it is also necessary to be able to calculate the segregation of duties conflict, so if the IGA solution is integrated with the GRC solution, if it is able to provide segregation of duties capabilities for the ERP and crosswise with other applications, we also need to have an endpoint in order to retrieve the segregation of duties conflict that it will be associated with another request if we decide to move forward.
And the last one, just to share with you another example here, I understand you could get it here, so when you integrate the ITDR solution with the IGA solution, one of the things that you need to do is to block or to lock the user, so if you get a threat and you are confident enough about this threat, so you need to trigger an action, an action which is normally disable or lock the user in the target application, not only in the one where the compromise is coming, but also in all the applications where the identity might have access in order to avoid the possible spreading as soon as possible.
So once we have explained the use cases, once I explained how we extended the API, so this is now the time to see the use case in action. The five use cases that I was explaining before, so I'm going to share to you guys how we are doing the things here. The third one that I have here is related to the approval recommendation, so let me check, could you please help me to play the video, because it is supposed to play automatically, perfect, really good.
So you see here there is a target as a review, it is asking if it has to be certified all the user or just one, so it is doing the calculation, it is showing here all the items that we have in the certification, and it is providing some recommendation, it is providing a level of confidence based on manager, based on position, and it is also allowed to see the details of any of the items that we have here.
So if we click the detail, it is informing to the user, but in really easy language, so it says okay this permission is assigned to this user, but not to this other user, and this is based on the position, and this is based on the manager. Here it is also possible to say okay, give me the best action, so based on the scoring that you have, based on the level of confidence, recommend me the action, recommend where to approve, where to reject, and where I will need to see more details in order to be able to take a bit more informed decision.
And once it has been executed, once all the actions have been selected, we simply have a button here to sign off the certification. When we click the button, as you can imagine, we are consuming the API endpoint that I was showing before in order to transmit the decision to the AGA solution. This is the first use case that I would like to share with you today, and the next one is about KIEN.
So you know that not all the AGA solutions are nowadays able to provide full visibility about the cloud infrastructure and title management, and it is also quite common in the organization to have security tools around the public cloud management. It is quite common to have cloud security posture management, and basically this cloud security posture management are collecting parameters about how is the security running in the cloud, but also a lot of information about the user entitlement in the cloud, and also about the risk that these users are having there.
So those cloud security posture management solutions are also exposing an API, so it is possible to integrate in the AGA solution in order to fetch this information, in order to aggregate this information, and based on this information it is possible to take actions, such as trigger certification, and for sure also take decision back in the cloud solution in order to mitigate the risk through permission removal or through any other action which might be convenient in any of the cases.
I'm rushing a bit just to be aligned with the time, so the next one that I would like to explain today, the next use case that I was summarizing before is about ITDR integration, identity threat detection and response.
And it is quite common nowadays because there is still a margin to improve in the ITDR product, not to have just one, so there are ITDR solutions which are more focused on legacy directories, putting the focus in things such as active directory, there are other ITDR solutions putting the focus in the software as a service solution, so there are applications which fall in the SaaS security posture management, we are offering ITDR capabilities and the cloud security posture management solution are also offering ITDR capabilities, so there are Banot tools providing ITDR capabilities, some of them dedicated mainly to this use case, others providing this as an add-on, but it is, I would say, quite common to have more than one.
So on this threat which are detected by the ITDR solution, when we detect a threat and we have a level of confidence, so it has to be communicated to the AGI platform and it has to be communicated to the AGI platform through the API that I was explaining before, then the AGI platform will be able to take action not only over the account which has been detected by the ITDR solution, but also over the rest of the account which are linked with the identity, and this is something which allows us to move a little bit further in the real-time decision that Sean Collett has been speaking before.
The next case that I would like to share with you is about the Azure Management Assistant, this time it's playing the video automatically, really good, so as you can see here this is chatbot mode, so the users are interacting with it, so first thing it is asking if you want to request access for you or for any other colleague, how do you want to identify your access based on my position, based on my peer, just after it is asking for what application do you want to have access, and then it is making a comparison between the roles already assigned to the user and the other one which are not assigned to the user but the other colleague has, then it is doing an SOD calculation, and last but not least, when everything is clear, when it has been selected, it is creating the access request, and it is everything performing, leveraging the API endpoints that I have been explaining before, and here other use cases is just to check the pending approval, so what is pending for me to approve, so basically you can click here and it is informing in a really easy way what it is pending to take a decision, and it is something that every single user is able to understand in a fairly easy manner, and the last one for today, this is about task and job monitoring, so all the legacy AJA solution are aggregating data, it is part of the connector that we have been developing for years, and we need to be able to react if something is not working, or if something is not aggregated at the specter, so we need to have a way to monitor if these tasks are working, and also being able to have a way to monitor them out of the AJA platform, and to cover this gap, to cover this need, basically what we developed is some logic, some code inserted on some lambda function running on AWS, in our case we use Python, but basically with this function we ask the API about the status of the task, and generate alert if the task has not been finished as we expect, and for sure create a ticket in our ATSM tool, so next step, what we are going to do next, so as part of this journey, what are the things to call, so the next thing that we are working on already is the logs intelligence, so we are recording everything happening in our API, all the logs, and we have already assigned some agents in order to read this log, and to understand them, in order to suggest us the way forward, we are also integrating our API development in the CICD process, in order to be more agile with deployment, and for sure we want to expand further the API in order to cover additional use cases, but always maximizing the business values, always prioritizing what the business needs, and just to conclude in the last minute that I have, so I would like to ensure that you guys get from here some takeaways, something that you bring with you home, so for one, is that the AGI is the core component of the identity fabric, so the thing that you have been developing for years is still there, and will be there still many years, so continue using it, the integration with the rest of the AI platform must be prioritized, it is something that it is not only me saying today, so the Kupinger analyst has mentioned that it is the time to take action, the customization or the extension has to always be adapted to the business needs, and last but not least, start today better than tomorrow, not postpone no more the decision, so this is the time to act, and that's it, so here if there is no time for questions, you have my LinkedIn, you can approach me outside, again my pleasure, thank you so much.
10 seconds, 10 seconds, perfect, and I add 30 seconds because I have one question with a short answer please, this is impressive, how is the user acceptance, how is the user experience, is it taken over from the audience very well? It has helped to improve the user experience, so some functionalities that we have developed such as the certification recommendation, or the request chatbot, it is something which has highly contributed to improve the user experience.
I guess so, because everybody's now used to these chat interfaces, and when they actually do some reasonable good work, then they're used to it. They love it, they love it.
Yeah, okay, thank you very much. Thank you.