Welcome to the KuppingerCole Analyst Chat. I'm your host. My name is Matthias Reinwarth. I'm an analyst and advisor with KuppingerCole Analysts. My guest today is Alejandro Leal. He is a senior analyst with KuppingerCole Analysts.
Hi, Alejandro. Good to have you.
Hi, Matthias. Happy to be back. Great to have you back. Today is a funny situation because we want to talk about the identity fabric, the reference architecture, a concept that we at KuppingerCole have created.
Usually, I'm talking about that, but you are covering that as well. You are covering that from the analyst perspective, looking at the market, looking at vendors, providing solutions in that area. You've just written and provided research on the topic why identity fabric is so important in modern IAM and which role it plays. It is not only a theoretical paradigm or concept, very abstract, but it's really something for showtime, for real life. What are the drivers that you see that are behind the need for such a new amended approach to IAM? How does identity fabric fit in there?
Thank you, Matthias. Like you said, you know the topic very well. If I'm going to go over the definition and explain a little bit, hopefully, it's for the listeners and for those who maybe are not familiar with the topic. As you said, for the past months, I've been conducting research on access management, ITDR, and identity fabrics. One of the topics of conversation that I keep getting is the lack of visibility that many organizations face. I recently published a white paper on the topic entitled The Role of Identity Fabrics in Modern IAM.
For those who are interested in that and want to know more, check our website. To answer your question, the diversity of identity types, the varying levels of assurance, entitlements, life cycles, has made IAM a very complex endeavor. To make matters worse, traditional IAM approaches have proven insufficient. They often become outdated before providing real value. Fragmented tools like IGA, PAM, SIAM, ITDR, they continue to exist in silos, leading to gaps in visibility, operational inefficiencies, and security risks. IAM needs to adapt to this shift.
I think that modern identity management must evolve to support all types of identities and integrate the existing organization's capabilities into one model for ensuring consistent delivery of identity services. As a result, as you know, the concept of an identity fabric has emerged as a response to this reality. As you know, identity fabrics is not based on a single technology, tool, or service, but it's a paradigm for architecting IAM within enterprises. The services are provided as a combination of different tools and services.
As you have discussed in blogs and other episodes, we can understand identity fabric as a mesh of interconnected identity services and capabilities that provide consistent identity information across all systems and contexts within an organization. You could say that it connects existing systems and introduces coherence through orchestration. I think that organizations must evolve beyond these fragmented IAM deployments to this integrated, observable, and actionable platform.
We need to understand identity not only as a technical issue, but as a strategic dimension in the overall success of the business. The white paper that I mentioned earlier presents the identity fabric model exactly like that, as a strategic necessity, and explores how to move from this theoretical, conceptual understanding to practical implementation. Right. You've mentioned mesh, you've mentioned model, and that is, I think, also the important part when we look at identity fabric. Because when you look at the market, you usually end up, when you look at the product, in this siloed approach.
So you buy an IGA solution, you buy a PAM solution, you buy a CIAM solution, and not properly done, this will end up in the silo. So applying the proper architecture behind that, I think, is really what supports you in getting to a more holistic picture of all your identities, allowing every identity access to the systems that they need access to, and only to those. So I think that is also one of the major distinguishing points between a traditional IAM approach or identity model, and what we consider as the identity fabric.
So how can you describe, or are there other aspects when it comes to the identity fabric, where it differs from traditional IAM approaches, more siloed, more focused on an individual identity type? Yes. So identity fabrics is not a fixed architecture, right? It's a framework or a guideline that describes how a modern and adaptable IAM should work, and also describes the path towards achieving that. Martin Kupinger wrote a blog post last week on the different interpretations of an identity fabric and why we need them.
So again, for the listeners, make sure to check our website. It's also important to know that identity fabrics is not limited to workforce IAM or consumer IAM. It's supposed to cover all identities, employees, partners, contractors, consumers, citizens, service accounts, workloads, machine identities, you name it. They should account for the life cycle of all of these identities, the policies that govern their access, and the systems that must enforce the access. So I think integration is key.
You know that many organizations operate with hundreds or thousands of different systems where identity information resides, whether in SaaS services, cloud platforms, or legacy on-prem systems. It's important that identities be discovered, mapped, correlated, and governed. So I think that this requires deep integration capabilities. Identity fabrics is also defined by their flexibility and adaptability. So they allow organizations to future-proof their IAM model, especially if we understand technology, you know, how fast it's changing with decentralized identities, with agentic AI, et cetera.
I think identity fabrics provides a strong foundation in dealing with the changes that we see in the market. And finally, compared to traditional IAM architectures, the identity fabric model also supports business agility. So it can prepare your organization to respond much faster to new regulatory requirements, or if you decide to change your business model, or if the threat landscape keeps evolving, it can make friction minimal, and it can make you more agile if you look at it, let's say, long-term.
Right, and you've mentioned that term agility, and we are running up to the identity fabric impact day in September in Munich. I'm currently pondering upon my opening keynote and my idea behind that, and I really think that is something that the identity fabric really supports, is the shift of the identity architect, this role identity architect, moving towards a provider of identity service portfolios that are changing, that are changing very quickly, that provide the agility that is required for meeting business needs.
And if you take that approach, or really thinking of identity services, authentication, authorization, access governance, for each type of identity as a portfolio of services that you provide to your end users, which are the consumers of identity and access information, I think if you make that shift also within your own perception of the role identity architect, I think that also reflects the way how identity fabrics change the way we provide identity services towards our organization. You've mentioned in the beginning that their need for visibility, for observability, plays an important role.
Can you dig a bit deeper into that as well? Sure, and I look forward to your keynote at the upcoming event. But when it comes to observability, I think our first step, you could say, would be to take an inventory of all the software system services, including legacy systems, because this baseline will then enable you to identify what needs to be done, what needs to be improved, and to make sure what you don't need anymore, let's say. Once you have this inventory, practical response then begins with observability.
Achieving full visibility into identity data, entitlements, and access behavior is important. And then that can be followed by actionability. So how all of those insights drive remediation, governance workflows, and lifecycle management. And I think that this approach aligns well with identity fabric, because an identity fabric is a unified, intelligent layer that connects and coordinates different identity services across the organization. So I think that a successful identity fabric strategy should prioritize integration. So connectors must be available. The objective is time to visibility.
So how fast your organization can see the identity poster. Therefore, all the identity data that you collect must be correlated and normalized across all sources. So once this data is visible, it must go beyond just static reporting, but it must be continuously providing new insights, new actionable recommendations that reflect the true state of all the identities within the organization.
So this can include, let's say, identifying excessive or unused entitlements, orphan accounts, shadow identities, policy violations, or it can also mean uncovering critical gaps, like the lack of MFA for some users. Another point would be that the dashboard that the user interacts with, it must be flexible, it must be customizable, and it must support drill-down features. So usability is also an important component. If you want to have full visibility across your organization, it needs to be done in a way that will make it easier for the user to fully access this.
So yeah, like you said, observability adds a very important dimension. It's not enough to just know who has access to what, but organizations must understand how access is used in the first place, how it deviates from policies, and how it aligns with, let's say, the risk tolerance that your organization has.
So again, observability must involve continuous visibility into entitlements, behavioral patterns, and lifecycle inconsistencies. Right, so as you described, it's really a gradual approach for changing an architecture. So there is no need for a big bang, there is no need for replacement of any tool with some one-size-fits-all single IAM solution. This is the last thing that we're talking about. We are talking about making connections between existing systems and doing an inventory of services, systems, and identities.
So it's also about balance, about balance between the new capabilities that are added, the new perspective that you applied to your identity platform, but also to understand what is legacy, what needs to be there. Maybe you can talk about a bit more about that as well as a final thought. So how do we balance between the legacy systems that need to stay because they nurture existing applications, and in parallel, changing your overall architecture? And how do you do that?
Yeah, well, I think one option would be to construct the identity fabric on an API-first platform that employs open standards and provides legacy integration, and also offers adaptable implementation options. Every organization or most organizations have legacy software and systems, so when planning the incorporation of new digital services or new tools, there's a challenge, and the challenge becomes clear. How do they move forward at the required pace without breaking into the legacy environment, without disrupting businesses, processes, and practices?
But you have a lot of experience with advisory projects, so I know it's not my position to ask you questions. It's supposed to be the other way, but maybe you can also share some practical knowledge that you see, maybe from your experience.
Yeah, but as you mentioned, I think, first of all, your answer, thinking in APIs that are the glue between different components, be they legacy, be they more modern, be they more agile, is one key aspect. On the other hand, of course, it's a proper project approach when it comes to understanding where you are and a maturity assessment and assessment of your overall architecture, but also a risk-based approach when it comes to understanding how is my identity security posture in these different areas and where do I need to act first.
The beauty is that you can, in a properly designed identity fabric, you can start where it's required and then build upon that over time. So it's really a gradual approach, a modification of existing architectures from a status quo to a planned status in the future, and that can happen ideally without disrupting existing services, so keeping the balance, but allowing, for example, new service models and maybe providing the same service for more than one identity type.
So that's really a part where we're really looking into this operationalization, how we call it, how to operationalize the identity fabric. That is also one aspect that we covered at EIC, so if you're interested in that, there's a three-and-a-half-hour workshop recording that you can look into, or maybe better, there's an advisory note by Philip Messerschmidt and me that covers that topic as well, so how do you actually do it and what are the tools to use. So identity fabric really is a, it's just a paradigm, it's not really an architecture, it's a way of thinking.
If you need to describe a proper architecture, you need to drill down more, there you are at the reference architecture level and below, so finally drawing the lines between the individual technical components in the end, so you need to drill down, but that's the way to move forward, and identity fabric is the starting point, really understanding where you are.
When it comes to feedback and to the way how the vendors respond to this and the end users respond to it, that is what I see, there's a high level of interest on that, but vendors are also interested in the identity fabric concept, I understand.
Yeah, absolutely, and as I said in the beginning, many of my conversations with different vendors in different market segments, I get feedback from the identity fabric concept that they really like that and they want to align their solution with that whole strategy, because they are aware that many organizations have this visibility issue, so as you said, I think it's important that if you really want to implement this, you need to first understand your own business requirements, then you have to look at where you want to be long term, so you have to define your IAM concept and then slowly continue to build the identity service layer and keep acquiring, let's say, capabilities on top of that central service that you have, so it aligns well with the identity services that you already have, instead of having, let's say, isolated technical functions.
So, I was also going to bring up the paper that you wrote with Philip, I think it was published in January of this year by Serene Notes, so that's also a very helpful document that listeners can take a look at.
Right, thank you for highlighting that again, and if you have any questions, I'm really asking the audience, if you have any questions regarding the identity fabric, if you're watching this on YouTube, just leave a comment below that video, if you're listening or watching this on any other platform, please reach out to Alejandro, to me, just to Kupinger Coal, if you have any questions, we are eager to understand your questions and cover them in upcoming episodes of this or other formats, wherever it makes sense to support you in applying that.
This is no secret sauce, this is no hidden treasure of Kupinger Coal, this is widely available, it's openly available, please just use it as a common language. If you want to learn more about that, there are these advisory notes, there are these videos, there are webinars, recordings that you can watch with, for example, Philip and Martin Kupinger, where they explain the concept in much more detail than we could do in this episode, and your report, your white paper, is also available right now.
If you just can, again, mention the title, and of course, before we do that, I have to mention the Identity Fabric Impact Day on the 18th, I think, of September in Munich, so if you want to meet us there and talk about details and the nitty-gritty ways of actually implementing an Identity Fabric, then this is the place to go to in September. But then again, Alejandro, the title of your document, this is available at our website, right?
It is, and it's called The Role of Identity Fabrics in Modern IAM. Perfect, so thank you very much, Alejandro, for being my guest today, for highlighting the importance of the Identity Fabric and the reference architectures, also for the vendor perspective and for the actual provisioning of technical services as the counterpart to the actual concept that we're using. So thanks again for being my guest today. I'm really looking forward to having you again soon.
Thank you, Matthias. Thank you, bye-bye. Bye-bye.