Welcome to the KuppingerCole Analyst Chat. I'm your host. My name is Matthias Reinwarth. I'm an advisor and analyst with KuppingerCole Analysts. My guest today is the principal of KuppingerCole and one of the founders of KuppingerCole Analysts.
Welcome, Martin Kuppinger. Hi.
Welcome, Matthias. Pleasure to be back here. Great to have you back. And this is an episode around the topic of the identity fabric.
Of course, we've mentioned that in earlier episodes, we are running up to the Identity Fabric Impact Day in September in Munich. But we want to talk about a different angle on the Identity Fabric. First of all, the Identity Fabric is something that is around for quite a while. It started as visualization to help people better understand things. But currently, it's not only a conceptual model. It has turned into a foundational toolkit for designing, implementing, and operating modern IAM. Can you talk a bit about the history, how the Identity Fabric came into being? Yeah.
So, sure. We brought this concept up. I think it was around 2017, 2018 or so.
So, really a couple of years ago. And basically, I think it started all with stepping back and asking a simple question, which was, what is the purpose of identity management or identity and access management? And the purpose of identity and access management, at the end of the day, is to provide seamless yet secured access to what someone or something needs for everyone, for everything.
So, this is where it all started. So, which types of identities do we have? And when you look at the graphics of the Identity Fabric, left-hand side are all the identity types to the services and what is needed in between, so that everyone, everything, it's not just humans.
We're, from the very beginning, sort of beyond humans, even while there was no term such as machine identity or non-human identity around, to all services. And identity management is the enabler for this access, for a controlled access. And that was the starting point. And then from there, we thought about, what does it need in there? How to come there?
Also, in that time, I think what also was driving that entire thinking when I go back was, we saw consumer identity management emerging. We saw B2B identity management emerging and so on. And from the very beginning, I think, not only my, but also, for instance, you and others' perspectives, was, it doesn't make sense to have a separate identity management for every use case.
So, we need to think about how can we, at least from a conceptual perspective, bring things together and look at what are sort of capabilities that are needed for multiple use cases that can be reused. So that the complexity of the implementation of the tools landscape at the end of the day at least can be kept under control, even when there are new use cases.
So, this is where everything started. As of now, it is something that we, you and I, and then the team use in many initial workshops for just, yeah, for telling the story, for making our peers understand and get to the same wording when it comes to talking and thinking identity management from left to right by means of going through the block in the middle. This is something that we, there are lots of podcasts and videos around that.
So, that has been explained and we use it every time. It's really a useful tool for laying a foundation. And it's a powerful tool with all, I would say, positive and challenging aspects. True. Talking about the challenges, just recently you published a blog post where you proposed a simplified, a leaner version of the identity fabric. Why? Why did you do that? Why do we need a leaner version? Is it target audience? Is it the message? Why do we need to, or why do you suggest this leaner version?
So, I think what triggered this was basically work of our colleague, Jonathan Kerr, who started around the European Identity Conference working on identity security fabric. And he looked at our graphics and he came up with a much simpler, even simpler than that graphic. And that triggered me to go back to the very first incarnations of the identity fabric. And they were way, way simpler. And I think at the end of the day, the point is, it depends on the audience. If you want to at a high level explain the idea, you need a relatively simple model.
If you want to dig deeper into a concrete project in a workshop, you need a more sophisticated, more detailed model. If you look into the future, and that was what I talked about at my opening keynote at the European Identity Conference in Berlin this year in May, I talked about the identity fabrics for the 2040s, which then again is a different perspective.
So, the basic paradigm is always the same. Identity fabric as a paradigm, as a concept for creating a comprehensive view of identity management. Being both, and fabric in English has multiple meanings, and one is the mesh.
So, it connects everything. So, orchestration, things like that come into play. And it's fabric as in factory production, delivering the services.
So, this is the same for every version. But what I think is from, depending on with whom you talk, whom you explain this concept to, we need to fly at different levels above the ground.
So, sometimes it's more than whatever 30,000 feet perspective, sometimes it's very close to the ground perspective. And that was why I said all the same, but we can sort of zoom in. And I think what we need again, like in the early days, is sort of the 30,000 feet. Right. And you're absolutely right.
As I said, we use that quite often and quite heavily when it comes to workshops. But showing this picture, just as we are depicting it right now, this takes at least, say, 15 to 20 minutes, if you are really fast, to get people to understand it. And there is this, I don't like it, but there is this term of the elevator pitch.
So, you have two minutes to explain something to somebody who's probably not that technical, who's probably not even interested in all the details that are depicted here. Then we need a different means for storytelling. Yeah. And I think the elevator pitch starts with, good elevator pitch with 30 words. The paradigm for a holistic identity and access management across all types of identities and all services, something like that.
So, it is not easy to build such a picture, because as I said, it depends on whom you are talking to. And at the end of the day, the core things in that are, on the left-hand side, all types of identities, human and, call it non-human, all types of target systems. And we need to think from capabilities to services to tools.
So, we need to start thinking about which capabilities we need, how do we group them into services, and finally, which tools are needed. And that must, at the bottom, connect to the legacy IAM and legacy applications via connectors. To the upper right, it must support and manage digital services in SAS, also via connectors, via standards. But to the upper left, it also must expose an identity API layer where digital services can consume the services of the identity fabric.
That really becomes a factory of services where a service can ask whatever account to be created, a secret to be managed, access to be granted, or can consume information about potential anomalies. That's it.
So, I think below two minutes, but above 30 words. But also, by removing, by reducing it to the core, it really allows this strategic view on things. Not being overwhelmed by detail, but really getting back to what you just said, the strategic view, high-level, simplified, but easily graspable for everybody who is even not a too much technical person to involve all decision-makers, stakeholders, and maybe also C-level, right?
Yes, I think that's the point. It's a powerful concept that starts with a simple explanation and that could be describing what you need for seamless access of everyone, everything, to every service across capabilities, services, and tools to something that really becomes actionable in the sense of that we can use it in advisory to help organizations building their own incarnation of the identity fabric because the identity fabric is always somewhat different, depending on the legacy, depending on the identity type, depending on the applications, the maturity, and other aspects.
What I really often try to make sure that people understand that this is not our secret sauce. Of course, we created it.
Of course, we live it. We use it in every aspect of the work we do in identity, but this is something that is published. Your blog post is available right now on both pictures that I'm just showing here. They are available, and I've just talked to a prospective customer who said, yeah, we use that internally. I use that internally to tell the story to my team, to my management, that there's a reason behind that. There is this fabric, and we need to provide dynamic, agile services within an IAM portfolio rather than maintaining a silo.
This is something that everybody can take away from this podcast episode, from our website, to say, okay, even if I don't talk a word to KupingerCore, I can use this for storytelling. I think that is also the beauty because then people talk the same language. It's interesting to see how many organizations build on this concept. I see really quite a lot that say, okay, I use this. I use this in SlideX when I present to the management, when I work with the team. It has achieved really widespread recognition and adoption, which is a good thing. Absolutely.
I just talked to our colleague Alejandro about that, and he said, not even, vendors, especially vendors, pick up on that because they can easily show on that picture where they are, what is their capability set that they are providing, what are the services that they are providing, and what is their tool to the right, to say, okay, we fit into that. We know where we are, where we are a piece of that puzzle and provide services within the overall framework. I think that's really helpful. We highly encourage everybody just to pick up that model. You can talk to us.
You don't have to, but we're happy if you talk to us. If you visit us at Identity Fabric Impact Day, we encourage you to come there in Munich just to talk about the application, about the real-life operationalization of this thing. If you need to convey the message then to your management, to people who are usually limited in time, take the leaner version. I will try that as well, so it's one more arrow in the basket that we can use to convey the message.
Thank you, Martin, for explaining that to us. Any final word when it comes to simplifying that? Is it just simplifying or is it just reducing to the core? I think it's just another way of illustrating it so that a story can be easier told across several steps. I think it helps also developing the story and then going even further into the reference architecture. We have the advisory note on Identity Fabric and that reference architecture goes very deep into it. I think that is where it helps. I think it's just an easier entry to a complex scene.
You've mentioned that there are other versions, especially these forward-looking versions of the Identity Fabric. You've mentioned that regarding your opening keynote for EIC. An Identity Fabric for the 2040s, which seems far away, but it is not. This is something that people can also look into. Just catch up with your opening keynote and there's more about that also in your blog post. I highly recommend for everybody who finds this interesting to just jump over to our website. Blog posts, of course, are not somewhere hidden, but you just can find them easily.
I think we will link them in the show notes for this episode as well and then continue your journey into the Identity Fabric from there. Thank you very much, Martin, for being my guest today.
Questions, of course, always askable in the comment section of this video or just reach out to me or to Martin. We are happy to answer.
Thank you, Martin, for being my guest today.