So, hi everyone, a warm welcome. I am Devesh Kumar from Siddharth and Widas Group.
Today, we're going to talk about how third-party access and governance is playing a role, and how you can convert your third-party access and governance into a trusted partnership. Using that, how you can scale your business-to-business use cases or identities in a complex environment. Before we go into this, let's talk about the problem. What is actually the problem?
So, in all of our organizations, if we count the numbers, external identities outnumber the internal employees. So, they are 5X or 10X, and some part, whether it could be a partner, or it could be a supplier, contractor, anything else, but these are all external identities. If you look into the recent surveys, 70 percent of the breaches come from those third-party vendors, and these are a big headache for a B2B environment.
So, how do we tackle that? But we already have an IAM solution, why can't we tackle that there? If you look into that, so the whole traditional IAM was built around a single organization.
So, everything is one single identity, one single source of a whole human resource system. There is a clear path who joins, who moves, who leaves, and there is a standard catalog of roles, clear segregation of duties, and all of that. But when you talk about B2B use cases, we need more than that. We need partner onboarding. We need API-based onboarding. We need a trust between organization. How do we establish that trust? How do we delegate governance, so partners can manage their own users rather than we managing for them?
Then, how do you continuously evaluate and recertify those users whether they should still exist in your system? So, for that, if we achieve that, the life cycle from months to years or quarters turns into an event-driven system, and you can manage all of that in hours.
So, what is actually a third-party access and governance? So, in a simple term, it's just the identity layer extending the whole identity fabric and IGA principle beyond one single organization.
So, you are not talking or restricted to one single organization. You are talking about a trust between multiple organization, how you can authenticate, move, and all of that.
So, what we need to establish that? First, we need organizational identity. How do we say this is an organization? Whether do I trust that organization or not? How do I delegate governance? How do I get those events where I can recertify those organizations? How do I mitigate those risks? Maybe there is a contract change, the company is blocked, and how often all of that can be done manually? How do we handle that dynamically based on an event-driven architecture? These are the issues we talk about in organization, but these are legal requirements also coming.
The regulations, whether we talk about financial sector, whether we talk about critical infrastructure, whether we talk about EDAS-II, defense, all of them, they want the third-party system to be recertified every time they make a call. How do we do that?
So, to do that, first, we need to see who we are actually governing, what we want to govern. So, we want to govern our partner organization. We want to govern our partner users. Maybe they are running some workload in your infrastructure. They are managing something for you. We need to go on that also.
Nowadays, every partner has some AI agents doing something. You need to go on those also.
So, how do we build in all of that one model, which is fitting for all? So, if you look into, they all have the same primitives. What we need is a verification. We need delegation. We need short-lived access. Nobody should have access, okay, I get it, I have it. You have a short-lived access for a certain time, and the main part is everything should be auditable.
So, we have been working around those use cases. There is a maturity curve. How do we say where we are as an organization?
So, at level zero, this ad hoc scenario, I have a spreadsheet, maybe I have a user, all my colleagues are using my same user. I hope nobody does that here. Maybe they have separate users, onboarding it manually. That's also a very tedious task, how you manage it. We go one level up.
Now, we are in a federated system. I have an identity solution, my partner have an identity solution, they integrate their identity solution with us. They can log in, they can manage few users, or users can log in into your system, all of that.
But still, you need to decide the app level access, and how do you trust? The trust is still not established. How do you go on all those users? If a user is accessing your resources, how do you go on?
For that, you go one level up. That's like governance. You have delegated admins to manage this whole thing, you have recertification of users, you have audits, all of that in there.
Now, to reach the highest level where we can say, the organization is trusted, you need to have organization to organization's trust. There are multiple ways. You can have trustless, you can have KYB, you can have LAI, all mentioned there. All of that should be continuously evaluated. It should not be, okay, I trusted you, you are on-boarded, but next call you make, it could be a fraud. But how do we handle that? Every call you make should be re-evaluated, and trust should be established on every call. Then only we can say, you are into a trusted system.
I would say most of our organizations in today's day, they land on level one. How do we get from level one to level three, and how do we achieve that trust? So to establish trust, we already discussed, we need verified organization identity, we need delegation, we need short-lived credentials, we need everything to be built on standards. If I build something proprietary, maybe my partner is not compatible with me anymore. So everything should be built on open standards.
There should be a continuous policy evaluation, there should be a continuous recertification of everything organization is doing on you. Okay. So what's the solution? We have three products, Sadas, NIPS, and Clavik. We call it One Trust Plane, because every product enriches the other, and it manages the user journey throughout the integration.
So Sadas, the OpenID, OAuth2 compliance, FAPI2, DPOP, anything you have. It has a native support for organization as a model. You can delegate your partners as administration, so they can manage their part of users. All those open standards, token exchange, all of that hosted in Germany. But now the part comes, how do you onboard? How do you manage all of that lifecycle?
For that, we built NIPS. For NIPS, you can build onboarding flows, awarding flows, you can build all the orchestration, attestation flows. You can build an event bus connecting to your IGA layer where everything is recertified again and again. You can build lot of connections from one place to another place, verify all your business identities.
Now, when you're verifying, sometimes you need to hold cryptographic data. How do you hold that? You cannot just put in a file and save it somewhere. You need to save in a key management or a secret management solution.
For that, we have a key and secret management, where customer keys are held, all the short-lived tokens are held there, and then all the MTLS and DPOP keys are managed there. Let's talk about how do we currently onboard, and what will happen if we implement the whole organization trust. If we just ignore this for a second, how do we currently onboard a business? Somebody from our team or some organization team have a sales chat, they discuss something, and they design a contract. They sign a contract.
Contract is between two organization, but when you're onboarding a user, it's a partner user you're onboarding. You're not onboarding an organization.
Now, they need a few more men to work on your things. How do they do that? They open a ticket. Can you please onboard? How do I onboard? All of that takes a lot of time. We turn that around, and we say, we have a trusted relationship, and how we can make that whole process faster.
So, a sponsor in your organization takes the partnership, they decide. There is a contract signed, and we verify the company. There are several methods as we discussed, know your business, trust list, it has to all of that coming into. Once that organization is onboarded, now, the partner itself has a delegation admin rights. They can go on their own users. They can create the users, so you don't need to come to the organization, please create my users again and again. All of that you can manage, whole life cycle is managed there itself.
Now, if you're running a workload, that also needs to be managed. How do we manage that? When you create a workload identity in Sadas, you get a key saved in Clavic, all of that is managed. But the risk part is still open. If the organization is not trusted anymore, we need to recertify that. There the Clavic comes into the picture, where we get events, recertify. If something is broken, we block that organization, there is nothing opening for them. All of that, what we discussed, it's open standards. It's already available.
Few of them, I would say, still in draft phase, but they will be available soon. So ArcTest, there is a trust list, there is a KYB for user authentication. We already know you have OIDC, OAuth, and all of that. Then for delegation, there is already a draft. There is already a token exchange draft available for workload identity and access management. You already have the tools coming in, Spiffy, workload identity and management, and the dynamic client registration and all.
For keys, you have Clavic. But none of this is going to work in isolation. It needs to be built on open standards. If it is not built on open standards, the inter-portability doesn't work. I might be having the greatest system, but if the partner system cannot onboard it with our system, there's no use. Because eventually, we are talking about building a business-to-business use case. I want to say, this is the new topic coming everywhere. Any talk you go, you will find this, but that's the reality. Agents are also third parties.
Maybe sometimes they are operated by you, maybe sometimes they are operated by different organizations. They are your partners, suppliers. They need to be governed also. How do we do that?
We say, whose organization created this? Which user is a sponsor of that agent? Which task is allowed to perform? Whether it has the right scope, right audience? Whether the tokens are short-lived or not? Maybe you created a secret and forgot about it, but they need to be managed, and then they need to be life-cycled every time.
Now, there is already a precedence for all of this. The open banking, the PSD2, has already done all of that for us. The how you manage third party, how you manage the organizations, how do you ensure trust, this is already an open standard or open playbook for us. We just need to make sure we transform all of that in two different industries also. Whether it could be manufacturing, healthcare, or insurance and mobility, even in AI, all of that needs to be transferred into different sector also.
Now, let's talk about you learned something, you got to know business-to-business use cases, but how do you go and think about it? So let's take a pragmatic approach.
Let's say, if I go back on Monday, I see, let me actually find out how many external identities do I have. Do I even know how many we have? You find out, you categorize them, then you know how many businesses or partners you're talking, how many users are actually accessing your data.
Then, in next days, next time, next group, you make, okay, let's make it a standard, we follow the approach, the proper business-to-business delegation. We take a model, we put organization into a tenant model, we delegate the admin rights, let them manage the whole thing, and then move towards a trusted partnership, where organizations can be verified using digital signatures, a trust list, all of that, and all of those tokens, keys are managed properly. Same thing extended to AI agents also. So even your agents also needs to establish a trust, then only they can operate.
So I leave the floor with this small quote. Trusted third-party access is, I would say, a floor, but if you want to have a trusted relationship, it should become a ceiling, then only you can operate in a trust mode. Thank you.