All right, so thanks for joining and picking this session in your calendar and yeah this session title is maybe deserves a bit of a background before we go into a round of intro. The reason why you find three people on stage is because I had the pleasure to address this audience a couple of times before on the B2B subject. Two years ago there was no such a thing as a dedicated track on B2B, early days on having a better understanding on the relative importance of the subject. Now of course we do have that, we do have a dedicated compass, so things changed.
But what happened two years ago is that I had the pleasure to address an audience like this one and there was a gentleman in row number one with a lot of challenging questions coming my way during the session which I tried to address at best and that was an interesting experience. So I thought two things.
First, those are interesting stories. Second, my life is going to be easier if that gentleman is going to be on stage with me next time rather than challenging me on question during the session and that's why we have Olaf on stage and the same happened with Jerome which presented one year ago on B2B on stage during the keynote with such a great story. So we thought it would have been good for us to have a single session together to provide different perspective on a subject that we care about B2B in how to address B2B.
Also one more reason, I'm a vendor okay, but nobody cares about yet another vendor pitch. You probably like better to read your stories around adopters, so this is my chance to provide you along with them of course better insight. Now playing with stereotypes and then we go into the thing.
Of course I'm Italian as the accent and the name reveal, but all along in the preparation of this session and other before that were the pleasure to do before, Olaf is the one coming up with all sort of interesting ideas, hard to contain, very creative and also interestingly, very interesting for me showing up late at meetings, being late, now I'm Italian, you're stealing my role in the thing right, so I should be the one doing that hence the title that you now see in this session okay.
With that said maybe we do, oh my role in this presentation is probably to do the clicker and maybe to put some pieces together, but that's where my contribution is. With that we go through a quick round of self intro before moving into the subject. Olaf. So hi my name is Olaf and as you can tell my favourite past time is heckling Marco when he presents on BTV.
Also as you can tell from my accent, I live and work in Australia for one of the larger Australian banks and because we are the largest business bank in Australia, the B2B context is for us really important and it's actually an imperative from a commercial perspective to get that right because it is crucial to our customer relationship and the unlock for us was that we figured what do we need to meet from a regulatory perspective in order to achieve the outcome that we wanted to, which is a single sign on access to our business customer portal and the regulation was actually mute on it and even when sort of when we try to engage in that conversation we're like we're not interested, you have the regulation sort of stay within it and we made that happen.
Over to you Joe. Thanks, so I am Jerome, I'm a freelance consultant at the moment. I have a background in retail, so everything we're discussing here about B2B, I see the very messy part of that, so I do everything at scale, so that is going to be my contribution to this talk. So I would say as you can hear I'm from Denmark, so I'm a little heavy on accent but bear with me and yeah then it's over to you. Sure and Marco Benuti from Thales.
I indeed have been in the B2B space for the last few years even before this domain had a name and again I have the pleasure of course because of my role of having conversation with customers or system integrator across the globe in any vertical. But for the purpose of today we just go very quickly into a bit of level setting on what we mean of course with B2B because again there are a few aspects that we consistently find appropriate to recap which is of course is a single acronym but is actually addressed as different entities.
Of course here Jerome and Olaf represents the orange entity and organizations which has an ecosystem of either suppliers of course which are companies and depending as in this case in banking you have partners meaning intermediaries to reach customers and both of them are organizations meaning broker and aggregator or B2B customers. Slightly different in retail where Jerome belongs where retail by definition the customers are consumers so they are not a B2B entity in this in this space okay and different in nature as they will detail themselves in the next in the next slide.
So of course there are different categories the same domain slightly different problem depending on the level of assurance the level of level of delegating the life cycle that you want to leave those entity with.
With that there is a common denominator across those third-party entity in terms of expectation of user experience is a is exactly the same across the board they would like to be able to enroll their colleague or to manage part of the life cycle themselves to manage requests and approval of access and also to be able to do that without having IT skills involved but rather just business skill. This is what they would like to have but this is not what we're going to cover today. Today we cover primarily what belongs to the orange bubble which is where Olaf and Jerome live every day.
Yeah great so we have two vectors that we look at we have service sensitivity so how sensitive is the information in the system that we are giving the partner access to and we have the maturity of the partner so are is it a mom-and-pop shop with zero to a tiny amount of IEM capabilities or is it a full-blown enterprise who can cover everything themselves. We have up in the upper left corner we have where we definitely don't want to be we don't want to have an immature organization getting access to very sensitive company data.
I live in the lower left corner where I have a lot of should we say immature companies and partners accessing not so sensitive information. Olaf on the other hand is in the upper right corner and that's where we all kind of want to be and then yeah basically I am trying to move my partners from left to right and that's kind of my struggle in this. And if my wife was here she would certainly tell you that I live in the lower right of the picture as a mature partner but be that as it may.
So if you look at third-party integration then sort of as we heard from our previous presenters sort of one of the core elements of it is that you want to bring them in as easy as possible into your environment and yet another login is certainly not the story and for us sort of was a realization that we may want to improve the customer experience in that regard and so we started to look at what does that actually mean across a number of dimensions.
And as with everything in this world it all depends in the sense that even if it is a business customer portal that we are providing not all access to that portal is made equal in the sense that there are people who access it to authorize literally million dollar payrolls but there are also accounts receivable people who are just doing invoice reconciliation and we wanted to make sure that we can actually grant them access in a way that is commensurate with the sensitivity of the access.
Naturally even though Jerome suggested that we don't really have mutual partners but we have smaller mom-and-pop business customers as well and for them they wouldn't even know what IAM is.
Our larger corporate customers however very much do and we wanted to acknowledge that that is actually a part of our offering that we wanted to extend to them and we actually did have the intuition but it took one of our largest customers to come to us and go guys single sign-on is now 20 years old how about you get on the on the bandwagon and sort of coming back to our previous presenter a 365 day plan for this I think is highly ambitious so it took us about sort of 18 months to get to this point at a sort of very at what sort of was considered level one for single sign-on.
Part of this is evidently what kind of authentication does the partner provide to their employees and that was actually one of the more challenging conversations in the sense that we had our security team going oh yeah we just sort of need to know this this and this and this and sort of one look at it was that this was a straightforward copy of the third party assurance questionnaire that we normally provide to our suppliers and it was like we're talking about a customer here you can sort of ask these questions and lo and behold when we try to ask those questions they told us in no uncertain terms to get stuff so we sort of scaled that back to a point where we actually sort of maintain the level of assurance that we needed sort of without aggravating the customer and all of that in support of our regulatory requirements because they don't go away because you want to provide a great customer experience and so we sort of had to balance that a little bit.
The bit that sort of was for us an intent relatively early on was not to have sort of the straightforward single sign-on and let's do it the way everyone else does but we wanted to have this continuous assessment element in the sense that we were losing signals that came through our own login environment and the customer was losing signals in terms of also never had signals for all intents and purposes in terms of what was happening in our environment and sort of by putting in a shared signals framework set of rails this was something that sort of where we wanted to have sort of this mutual trust reinforced.
I'm not quite sure whether you noticed the little star next to my name but I'm a founding member of IDPro and sort of towards the end I will return back to sort of why that actually matters in this context but I'm now handing over to Jerome. Great, so I am going to make things a little more interesting because when you do B2B on scale we are actually looking at a lot of other areas as well. So if you have something like data residency where does your data live, what defines where your data lives and stuff like that.
We have a lot of Chinese vendors, we have a lot of US vendors and we have a lot of European vendors so that is suddenly three different areas that we need to take into account. We have given where we are located with stores, we do have different requirements for compliance in each country and brands that we do. So that also gives us some issues with regards to regulatory bodies and what they require of us. So who has access to what, how should that be logged, where should the data be stored, stuff like that. Then we have the authentication baseline.
So the interesting thing here is since we're dealing with everything from mom-and-pop shops we do have customers that has one email address that might be pointing to a shared mailbox. How do you ensure that whoever is accessing the systems through one shared mailbox is actually who they say they are. We have SAML and everything else for large enterprises and that works most of the time. And then lastly I would like to say that we have taken a very pragmatic approach to this. So we will actually try to meet our suppliers at where they are now.
So if it is a small mom-and-pop shop we will do one-time passwords then we will, given sensitivity of data and systems they have access to, we will kind of build out and we will help them on that journey to maturity. Right and you want this as well? Yeah I can take this one quickly. So basically the takeaway here is given geography, given diversity and the scale that we operate in, we have roughly around 10,000 partners at any given moment. And yes it is very vast the amount of mom-and-pop shops that we actually deal with and especially in Asian regions.
They do produce a lot for us and we do have the complexity of the whole delivery chain and we have a lot of third parties that work with us for doing brochures, commercials and stuff like that. Okay well thank you very much. By the way the timer is stuck so we don't know how we're doing on time. Okay so I have no clue how much time we have left. Five minutes. All right cool. So very concisely let me just maybe chime in and give you a bit of a perspective from a vendor standpoint of what we assisted.
A fairly abstract but still in my opinion a compelling way to describe what we see or what we saw lately is that most of our customers are trying to spin three cogs that are inevitably jamming one another. They cannot turn all at the same time because there's a continuous quest for the best fitting solutions for account for identity verification or for liveness detection if you need that or for your name depending on the level of assurance management and of course there's a continuous evolution of that.
At the same time you want to minimize the integration cost of picking yet another vendor and putting that into the context of the identity solutions you have in place and possibly reducing the vendor lock-in. So the three things are very nice or individually but are very hard to get at the same time. So the only redemption from that is to elevate in terms of approach from an individual tool focus to a different identity fabric inspired according to the to the Kupinger definition approach which is the only redemption from that otherwise over constrained approach.
I keep that concise and short even more so as we only have a few minutes left but this is maybe captured and represented in a couple of examples that I feel like sharing very very ten thousand feet level. Again if we look back again on the what B2B entails and we really define in the coarse grain what the traditional identity infrastructure looks like we're all familiar with the fact that you need to onboard users and B2E is HR inspiring, B2C is KYC and B2B is another thing.
Again you need to have form of authentication depending on the level of assurance you want to have and of course authorize them which can be in turn admin time or runtime authorization very different runtime being the way to go for the future and then some form of self-service meaning delivering access to application. This is a generic description not B2B specific. If we make it B2B specific there's a couple of things which are unique to B2B okay and those are the feather onboarding is now featuring the organization onboarding not just the user onboarding.
You need to first onboard a company and then the people into that company so it's a nested problem uniquely featured by the B2B domain and similarly in the self-service you have a notion of self-service which is again only featured within B2B which is the notion of delegation management. Everything else applies with different flavors also to B2C or B2E depending on the case. Now the question is okay how do I address them?
Well if you look at the first one the onboarding there's a lot of diversity again we saw that there are different kind of partner even within a single company and the company itself might belong to different verticals so there is a lot of diversity in terms of flows and requirement in what that means to onboard a company. It can be a lookup in a partner management system it might require approval from somebody okay it can be a self-register because of the first comma with a new email domain and off you go.
So there is no such a thing as a product that address that other than an orchestration solution that can be flexibly bent to model what is the reality like which by the way can be different within the same company for different types of B2B partner okay. Similarly the delegation piece I mean John mentioned correctly according to my experience that is indeed a very crucial requirement for involving appropriately humans which are most of the time not meant to be technical but rather business users and this is through a UI.
It is through a UI today and a UI that as a product vendor many of us including us are featuring specifically designed for B2B use cases but this is what is subject to a fierce evolution because of the agentic introduction so very often now the B2B part is no longer a human it's rather an agent which means two things first that is another user type that you need to have managed as we saw also from the colleague in the previous session but even the UI itself.
How long before and we see already some customer before customers are our customers are building on the fly or vibe coding the UI for the specific rendering of the use case that they need to deliver to their specific user population. What I'm saying with that is that the backbone of what an identity infrastructure requires there to stay the UI maybe not so much or maybe less than what we are familiar with which brings us to the last slide I believe to the session if you want to click it yourself as you own that. Thank you I thought you wanted to get your finger and work out.
Anyways I hope most of the people in the room realize how bad the situation actually is because this is an area that I in my mind has seriously been underestimated in terms of its impact from a customer perspective or even from a partner perspective so let's make sure that we go away from manual deliberation where we can where we sort of involve service desks and go to a world where all of those things happen more or less automatically.
Partner onboarding in my mind is a significant or even customer onboarding is a significant opportunity to streamline in the sense that you have most of your organizations will have things like Ariba. Why are the partner onboarding and the contract system not in any way shape or form connected there's room for improvement even but even in regulated environment like ours where we need to KYB not only the business but also the person who runs the million dollar payroll because that's what the regulation demand.
We can do this for personal customers or retail customers why can't we do this for business customers as part of the same flow. Authentication I don't think we need to talk about but the times where you hand an authentication to your customer is I hope and soon over.
Again standards wise but this seems for all I've seen highly bespoke in spite of the solutions being out there and what we saw in previous presentations there's a lot of room to actually go away from bespoke solutions towards standards and then really making this a standard pattern in your enterprise architecture is something that I wanted to encourage you to take forward.
A couple of takeaways from our perspective and from mine I just wanted to share a story with you where when we started this with one of our really really large customers and we started to talk about the intricacies of actually setting up the single sign-on and they were like what do you mean private George and sort of what do you mean Pixi we don't do this and it's like really is that sort of where you are and so through IDpro I was actually in touch with someone in an affiliated company and I managed to ring them up and he was like dude this is not right let me take care of it.
Two weeks later he comes back and says talk to this person and three weeks later the person that we worked with directly turned around and said if we have it sorted here's Pixi here's private George and everyone was happy. So it's the community organizations like IDpro are at times critically important to turn this into success. With that I hand over to Jerome. Yeah great so my key takeaways for you guys is basically try to segment your partners. Do you use the low level model I showed you before with severity and maturity then meet your partners where they are today.
If you try to enforce enterprise rules on mom and pop shop that is not going to happen and lastly just take it one step at a time you won't be able to to rest of everything in one go.
All right so from one side from my side the three takeaways are the first thing is is not about rip and replace it's about augmenting the value of what you already have in place if you need to add something that something might well be appropriate and orchestration solution to take the most of what you already adopted before which is in turn also extremely valuable for having a proper conversation with the budget allocation moment because it's not about replacing the big chunk of a solution but rather optimizing what you already acquired before and finally whichever solution you adopt of course mind the standards I think we call it out enough the way to go is runtime signal based authorization zero standing privilege and standard support if you're not going to be there you're going to be late very soon and with that we are zero we are very right on time which to me as my precise Italian matters a lot so thank you very much for your attention and of course glad to get question if any at all any questions well great thanks guys oh are you seeing any agentic AI or machine identity use cases in the CIM sorry yes we are so we have a lot of customers who or partners who are actually building AI agents to retrieve sales data how their different products do across countries stores regions stuff like that yeah maybe maybe just to add one point to this in so we've hammered the maturity element and not because all of us are mature enough but there is obviously a moment where this has run its course and as an organization you have as the two partnership on organizations in the partnership you reach a level of maturity where an API based integration is just a better approach and in that case in well in our case that would be something akin to open banking I guess in Jerome's case it would be sort of going in a similar direction and so my hypothesis would be that the agentic play is more on that side of the fence than really sort of where this slightly less mature delegation model sits okay well thanks we're on break I think the final sessions will be up on the C level starting at five thank you