Okay, welcome back to the second part of this workshop. Just a reminder, Phillip and I, we won't repeat the same part again, but we continue our story from this morning. So there will be more to come, but first, we had so much theory this morning, and now we want to talk about the identity fabric in action, and therefore we have two guests in that workshop. We have Kamy Ng, and we have Fabrice Deval, and they will present their experiences and their takeaways from how they implement the identity fabric. And then please raise your hand for Kamy and Fabrice.
Applause So, hi everyone, good morning. And it's my first time in the IEC today, so I'm really happy to meet fellow professional identity enthusiasts, let's call it this way.
Well, while superheroes save cities, I think we do something even more important in the digital world. We safeguard identities, right?
So, welcome to Identity Fabric in Action. Every great mission starts with a purpose, and I think we are all here today to really understand the concept around identity fabric and the framework around there, but also what it is and what is the purpose it is like to actually implement that in a real-world experience. And every good story comes in three parts.
First, we understand the profile, which is the beginning, and the middle part, it's about the playing field and how the battleground comes together and what strategies we need to apply. And finally, we gear up for battle day. We promise no one's going to get hurt, but this is where reality and real actions begin.
So, I'm Cami. I am the Global Identity Leader responsible at ABB, and together with me, Fabrice de Waal, Managing Director of Cornerstone Consulting.
So, over the past five years, we have been collaborating in various IM initiatives, professionally as well as a lot of exchanges. And through that, it helps us shape and refine our approach. And together, we forge something which is practical, lead with some real-life experiences and dialogues around how we want to, or we can actually implement identity fabric in a real-world experience.
So, let's start with the beginning part of the story, the profile. It's important to understand the context when it comes to applying the identity fabric to your kind of organization.
So, here, we're going to break it down to kind of our superheroes, and hopefully that relates to your organization. We start with Helen Pass, if you know Elastigirl.
So, she is, as a profile, she's always resourceful, and she's authentic and she's resourceful. As an organization profile, we see ElastiCorp where IT and business are truly partners, right?
So, they build a strong agility, strong backbone of trust and respect. So, in terms of the business profiles there, we say that both IT and business are strategically embedded. They have a very clear purpose-guided business goals, and IT are typically quite business-savvy. They can typically explain what are the business transformation is happening in the organization. And lastly, there is a real collaboration between business and IT, which is quite trust-led. We have gave her two stars in terms of difficulties, as every superheroes have certain challenges that need to overcome.
And the next is, if you recognize the brothers and sisters, Dash and Violet, and Violet's a little bit of an introvert, and Dash is a little bit of an extrovert, right? Together, they are actually, we call them the steady sidekicks.
Together, they bring both stability, agility, and innovation together. And as an organization profile, it is a business-supported organization. And what we meant here is that it's very structured focus. So they pay a lot of emphasis on process excellence.
Typically, most security programs are mandated. They are aligned in terms of business and IT, so business sets the direction, but they're not involved in the day-to-day decision-making or operations. And they really value consistency and trust. So they are talking about high performance, as well as they want to have a certain rhythm when things happen. And lastly, we come to, of course, Bob himself, Mr. Incredible. He is a strategic achiever, where it is a purely, what do you call that, no fuss, no BS kind of organization.
And IncrediTech here is a leading provider and go-to partner for business-seeking straightforwardness. So there's no fuss there. Straight to deliver best value to the customers. They want to cut through all the unnecessary complexity. And they really focus on accuracy and precision. And that is something about Bob. So I'm gonna hand it over to Fabrice here, who's gonna talk a little bit about the playing field. And at the end, you're gonna see how all that gelled together in terms of our experiences.
Fabrice, over to you. Thanks.
Hi, everyone. So we all come from different industries, I believe, right? So different companies, different industry vertical, different experiences, right? So what we wanted to try and do in this couple of minutes we have together is give you a panel of what your organization may look like.
Therefore, those different profiles that you've seen. They may not be inclusive of what you guys experience on a daily basis. And we'd like to hear from you. So if you have a different context, please come and talk to us. So what is the playing field? It aims at painting what we need to be concerned about as digital identity practitioner or leaders to bring value to our organization, right? IT does not stand on its feet just for that, right? It aims at serving a purpose within the organization it belongs to.
And we kind of develop four tenets that aim at guiding how you get your identity fabric to work, right? How you bring it to life. So the first one is to understand what is the shared value and vision for your organization, right? The second one is based on that context to articulate what the fabric shall look like in terms of the capabilities we've seen earlier this morning. The third one is looking at principle or principles that will help guide decision into where should I fit those capabilities and why, right?
And the very least one is, obviously all those capabilities are hosted or provided by technology. So we need to have our technology blueprint in check as well. So let's look at the first one. Like I said, it's not about us identity practitioner. It's about us serving a purpose, which is the objectives and the mission of our respective organization.
That's why understanding and factoring those different contexts, whether it is a business transformation ongoing, whether these are cost pressure, compliance pressures, whether it is merger, acquisition, or other, we need to take that into consideration when building or crafting an identity fabric. And that is something that every one of you has to do. This is not something that a third party company or a consulting firm would do for you. You're best positioned to do that as part of your organization. And because we're part of different organization, the definition of value differs, right?
So if I take the example of a manufacturing company, it's all about business enablement. I'm here to produce stuff, right? I'm here to commercialize my product, right? So I wanna make sure that my identity fabric enables the business in that mission, right? But I might also be concerned about cost efficiency, right? Because my margin are thin. And so I wanna make sure that as I build and as I craft my identity fabric, I do have that in mind, right? Another example could be resilience or cyber resilience or identity resilience, right? And the last is compliance.
In a way, in a different way, shape or form, we need to build in resilience in the service we provide. Our security practitioner or identity practitioners, right? And we need to be complying to regulations, needs to GDPR, others, right? But what we also need to take into consideration is that the size of those value bubbles differ if we're a bank or if you're a manufacturing company or if you are in a service industry or in the tech industry. Let me take an example real quick about a bank, you know?
A bank would probably emphasize much more on compliance because that's the basically token to operate, right? If they don't have that, well, they can't do their job, right? So compliance would probably go first. And then because there's so much exposed out there, they want to prioritize on cyber resilience, right? And they also want cost efficiency next, right? Because they need to make sure they remain profitable as a business, right? And often case, that would be at the cost of business enablement.
And what I mean by that, if they need to MFA into you, they would do it because that ensures their compliance and their resilience, right? So we need to see, and those are not exhaustive, right? So if you have many other value points or value proposition for your respective business, that makes sense, right? Understand those, right? And understand the size and the importance of those respective value or business objectives.
Next, we talk about principle, right? And how we use those principle to guide decision that we make when defining identity fabric. And principle are there to evaluate where to position those capabilities and why to position there, right? What we advise doing is pick principles that are stable, so your decision remain consistent over time. Because we know, many of you are in this business for a while, so you know identity project are not a point in time things, right? They are lengthy, they're difficult, they're sticky.
And so you wanna make sure that those principle or those guiding principles can be used over time and can be continuously helping you on your journey. So I've put here a couple of examples, right? I'll just focus on two. There are several dimension that you may wanna pick for defining your principle. One for me that is crucial is data, right? Because it all starts with data. And more than that, it starts with qualitative data and it starts with ownership on the data, right? Mattias talked about, and there was a question actually about that.
Mattias talked about how do we leverage or differentiate or enable ABAC or PBAC? Now those concept, they rely on attributes. If those attributes are not available, are not consistent, are not even present where you expect them to be, what can you do, right? You may have the best PBAC or ABAC technology, but it won't be of any help, right? So data is crucial. And for me, that's where you start your journey.
You know, that often goes with engaging with your data source owners, right? HR, for example, when it comes to IGA, to understand how they can support mutually, right? Reaching or achieving qualitative data, consistent data over time.
Again, something that is accomplished in a day. The other part is identity. Digital identity is a representation of a physical entity, a person, a machine, an organization, right? And as that entity leaves its life in an organization, the digital representation of it needs to be unique and needs to be immutable so you can have a trustability over time, right? But it also needs to be multi-constituent.
As we, in this conference, we'll hear a ton about human identity, different shape it has, but also about machine identity, right, NHI. It's important to have that identity and it's high. It's important to have that in mind very early on as you craft your fabric. You can't just focus on human and then three years into your journey, say, ooh, I need now to think about machine, right? So this needs to be in there from the get-go.
Now, you have a ton of different other elements such as the fabric, which often needs to be composable, consistent, and scalable, right? You wanna start at a given point in time, mature, and evolve over time. Happy to share this with you guys, and I think the slide will be shared, so any question over that, please come to us. The third element is about the, I call it, capability model. Our friends from Coupang are called, call it reference architecture, which is the same.
It's a conceptual illustration of how your fabric would look like in terms of the capability, the functionality, the integration, the constituent it actually serve, the target system or services it enables access to, and the different channels through which those items are being accessed, right? And we often get stuck with wanting to have the best possible fabric, but often case, perfection is the enemy of good. So we need to start somewhere, get to the best first candidate that we can, and evolve it over time, right?
So that's an example of an identity fabric that we've devised for one of our clients, okay? And as you read it, left to right, and top to bottom, it actually considers the identity constituencies I've been talking about, right? So you have human machines, you have different type of human identity that you could find out there, and different type of machine identity that you could find out there. On the right hand side, you have all the services that one may want access to. And at the top, you have the channels, physical channel, digital channel, et cetera, et cetera.
At the bottom, you have what I call the foundation piece. And for me, it kind of aligned with the principle in saying, what are the data source I need to provide my identity services, right? This could be your HR, this could be your non-employee system, this could be your IT asset management, this could be your supplier or vendor system, right? Then comes the integration, and we also had a question about that, right? For example, ITSM, that was also touched upon today, right? Since in many companies, ITSM technologies are the IT shop to get stuff, right?
To request access, request software, request machines or equipment. That's one of the thing you want to integrate with. There was also a question around agentic, right?
AI, RPA, you know, that's also something you want to factor into your fabric because there are more and more integration in this space. And then the intelligence and the analytics piece around access risk, around behavioral, analytic and so on. And as you can see, I won't kind of delve into all the blocks, but what I want you to remember is, if we go like two tenets up, right? The first one is about objectives and value within our respective organization. That's where you want to use those to say, what is it I need to get right first, right?
And for an organization that had a deprecating identity governance technology or system or process or capability, they probably want to fix that first, right? And these are a set of feature that you do want to have as part of your IGA, right? And as you move next, access management could be also something you look at, right? A lot of these things are industry or reference framework based. This is not rocket science. We have a fantastic example provided by Matthias and Philip. So use it to basically start, you know, and get value out of it, okay?
And the very last piece is about, is about plotting, you know, the technology or selecting the technology that would provide the capabilities we've just seen, right? And earlier on, we had a question around, how do I choose where to put some of those feature? Because some vendors would say, although I'm an IGA technology, I can also do X, Y, Z. So how do I devise where my capability would sit from a technology standpoint, right?
That's where you can use those principles to say, I want my fabric to be consistent, which means I may not want to allow duplication of features across different technology or set of technology. So I want this to be consistent, and I will make an educated decision to say, I'm not using technology A, but I'm concentrating that particular capability or those particular features in technology B, for example. What you also need to consider is, once this blueprint is matured and is developed, you want to make it known. You want to share it with the rest of your organizations.
Your stakeholders understand how you deliver or how you plan to deliver those different functionalities and features. We'll right now go into some real life feedback around what we've seen as challenge or as opportunity in the different contexts that Cami alluded to for those three companies. So I'll hand over to Cami for that.
Thank you, Fabrice. So, well, you hear the story about what makes a good story, the beginning, the middle, and the end. And to remind you, at the beginning, we talk about reflecting who your hero organization is. And Fabrice shared about what, in terms of the playing field and getting ready and the strategy. So let's talk about the ending. So to prepare for battle day, this is where we are bringing in some of our experiences and lessons learned when we are actually implementing identity fabrics in our organization. So let's start with ElastiCorp here.
If I can remind you, it's a business and IT integrated trust-led organization. So what's really important here to really optimize the value, given that it is a integrated IT and business culture, it's about timing. When you are rolling out or creating an identity fabric, it's super critical to hook that on to any business transformation that an organization is undertaking, whether it is modernizing your factory workflow workers, or actually simplifying the user access management or compliance processes around your organization.
So it's super critical to hook that on to maximize the impact, given that ElastiCorp has business and IT hand-in-hand. Next is, of course, co-shape the vision with a really mature understanding between IT and what IT understands about the business vision. It's also super critical to bring business along in your journey while you're crafting the identity fabric. So when the trust has been built, it's quite easy for the organization to start breeding and leaving identity. So they start caring about it. And that's why, if you remember, it was two stars difficulty. So why not capitalize on that?
And thirdly, this is also super resonating to the business where we bring in the persona concept. So think about if I am the factory manager and I want to onboard my externals because I have a contingent workforce, what would good look like? So bringing in the persona as I am a line manager and I like to onboard my new users with the right access to access the financial systems. And that speaks the language of the business. And lastly, to foster cross-functional ownership. And in my experience, we probably need to activate this ownership more than once.
The first time, perhaps you would reach out to the more functional owners and directors to shape the vision together. But ultimately, you'll start to realize that the discussion stays very high level. And you may want to actually go a level deeper to kind of talk to the application managers, the product owners, et cetera, et cetera. So if I look at Elasti Girl, Elasti Corp, she has stretchy legs and arms. And I think when we get into implementing an identity fabric, the stamina, it's also really critical.
And fostering cross-functional ownership, it's super important while you want to hook them on, but at the same time, you want them to help you scale across the organization. Next, the brothers and sisters. So as a reminder, a very process-oriented organization, very structured, very mandated. And what's important here, where the business is close, but not very close to IT, you have to be careful about the stakeholder gap. They are there at the start, mandating IT to take on the identity challenge, and they step away.
It's important to build informal sponsorship through the organization and keeping that relationship through the organization and keeping that relationship warm. And that means having champions within the HR organization and keeping him or her up to date in terms of what you are taking care of when you are rolling out your identity fabric. Although we have a mandate from the organization, it only goes a long way when people actually contribute into that. So always remember to co-create and don't impose that on them, saying that, hey, look, I've got a mandate, and the CIO says this.
You have to give me your requirements. And when they feel that they care about it, they actually work along with you to kind of solve this really difficult entanglement and legacy challenges that we have. And one of the technique that we have applied is really ranking the problem statement.
Typically, we always come up with one blanket problem statement. But if you try to drill down, you will understand that there are multiple layers of problems which the organization needs to solve. And when you talk to your stakeholders, some would care differently in terms of where the problems are ranked. Let me give you an example. One of the problems that we have experienced, or I've experienced, is that identity has a lot of issues around it because it is driven out of compliance reason.
I think many of you guys can resonate with that, that an identity program initiated because of solving and audit finding. But through the years and experience, you realize that that could be the major problem statement. But because of bad decisions that happened in the past, that resulted in other problems. Could be tooling, could be process, could be ownership. So when you rank them and co-create this problem statement and rank them, you get a little bit of a clarity in terms of where you need to focus first.
And of course, it's never about tooling and all of us here are really excited about chasing the new shiny tech technology, thinking that's gonna solve the problem. And I think Matias and Filip also already talk about it. It's never about the tooling.
And last, given the organization culture, balance, predictability, and progress is super important as well. While identity programs are typically long haul, it's a marathon, you need stamina. And how would you actually, once you have the hook, you have gotten the stakeholders, how do you actually balance that predictability and progress? So celebrate small wins, as small as getting rid of certain excels for a test station and really amplify that small win within your organization.
And I think in technology, especially in identity, I've experienced that our folks are very much heads down doing the work without really celebrating the success. And I think that is also our Achilles heel where we cannot profile ourselves as important. And one thing that I came to understand is that in IT, while we are renting a lot of our devices in networking, in laptops, devices, actually identities are the only thing that our organization owns. So think about that. And with that, I'm gonna hand over to Fabrice who's gonna talk about Mr. Incredible. Ready Tech, indeed.
So question is, how do you go about devising your fabric in an organization that is value-driven, meaning this has to produce tangible value for the organization? How do you do with a business that is time-strapped, that basically lacks attention to the topic or interest to the topic? How do you do with an organization that is innovation-led and always requests the best solution ever to IT?
Well, again, start with what's out there, what has been proven, what's been actually tested. So industry framework can help you. Coupling our call, again, we'll in a minute expand on their proposal of the identity fabric, see how that fits your need. See how you can tailor this to match your organization objective and to match your identity program objective. The second takeaway is to start with the first good candidate. Don't try to kind of over-engineer it. It's a conceptual model to start with. So having something that is good enough is often case good enough. So take that away.
The other element is this many different components in an identity fabric, going from identity governance and administration to access management, to privilege access management, to identity analytics, to identity threat detection and response. So that's many different things that you need to account for. So as we said, factor the objective and where the value lies of your organization helps you prioritize what you need to focus on first. But stay focused.
Once your identity fabric is good enough, when it's been shared, communicated, when it's been adhered to or endorsed, keep focused on building it as you go and evolve it as you go. And last, it's about demonstrating value.
So, you know, go with proof of concept or MVPs to quickly demonstrate what this particular capability does for your organization. Measure performance so that you can show value and then tell the story, right? Tell the outcome. So this was for Increditech company. So a couple of few takeaways here. So the mission, as we understand, is about protecting what's dear to our organization. And part of that is identities, right? Because they enable access to things in a digital world. And that's our mission. We also see that Rome was not built in a day. So we need to come with a plan, you know?
And a plan goes with having clarity about what your fabric should look like, why it should be that way, be able to defend that towards your stakeholders, you know, to get funding, to get team mobilize. Identity involve a various range of profile within an organization, from business to IT to maybe customer representative and stuff like that. So we need to make sure we are exciting people about it. So come with a plan. Practice early and often, you know?
We need to test different capabilities we're putting out, capture feedback, hear from the business, hear from our partners or our stakeholders, how they experience what we've developed, right? And then prepare mentally. Because we heard, you know, these are lengthy engagement or initiatives. And so sometimes it goes wrong, right? So we also need to be mindful of that and prepared for that. And last but not least is about resting, reflecting, and adjusting.
We also mentioned that we need to keep focused, but we also need to stay flexible and realize or recognize when batches are made and when we need to recalibrate a little bit our fabric or transform it as we go. It doesn't mean we just scrap it and start anew, but we need to adjust it to the reality of our respective business, you know? We hear now about the political and geopolitical tensions that are happening and the economy kind of going a bit ballistic these days. So these are consideration that may impact or influence the way we go about putting our fabric to life.
And as you see, there's a sixth bullet here intentionally left empty because we'd like to hear about takeaways you'd like to share with us if you've engaged into building your own identity fabric. So the question is now, what's this gonna be like for your organization, you know? Are you more of an Increditec type of organization? Are you more of a Spinovate type of organization or Elasticorp or whatever other profile?
So if you'd like to share some thoughts and talk to us about how your organization looks like and the challenge you see and the opportunities you see, just come and have a chat with us at the end of the session. As a closing, I'd like to leave that to you. As you start your day or your work Monday morning, trying to craft an identity fabric, remember that it's not just about technology, but it involves understanding the good timing, coming with a well-thought strategy and plan, but also achieving success with true collaboration because after all, that's the teamwork that we are all in here.
So thank you very much for your attention. That's it for us. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you very much, KB and Fabrice. Thank you very much. Sorry. Great that you added this additional aspect that we don't cover in our presentation, which is the soft facts, the business orientation, the project management part. Thank you very much. That was really great. Thank you. Good. So don't forget if you have any questions, we have this QR code. You can ask your questions online.
We will pick them up at the end of the session. And with that, we continue with our original presentation. What we just heard is the fourth chapter from Kami and Fabrice. And now we continue with the operationalization chapters. So chapter five would be around the SIAM reference architecture that is presented by Matthias. Thank you very much. So I think I had 30 minutes, but I go back to some 20, I think. This is okay.
Okay, as you can see, we have three aspects of operationalization. And I start with the actual, the reference architecture itself, how to operationalize that and drill down one level. I've hinted at that earlier. So the question is, how can we achieve that? And that is something that we're A, just working on and B, have done in various projects. So that is the outcome. So choosing an architecture based on the use case slash identity is the way to move down a level into the identity fabric and much more importantly, the reference architecture.
What we wanted to achieve is to establish a common blueprint. And that is what we've presented earlier today. That was the matrix, the columns, the rows. That was what we wanted to implement as the basis to have a common language, but then to allow special specialization so that we can build second level reference architectures or capability models. I don't fight about terms. That is really a way to look at things. The idea is to allow flexibility, keeping standardization. We've had that question earlier, how can we merge or reuse services if possible?
Yes, please. Let's create an overall architecture if it's possible, support incremental growth and a bit of analyst speak, but it remains true. Maintain future proof agility to make sure that the system overall is capable of growing within the boundaries that you have. Why CIM? Where do I present CIM? Because I think it's apart from employee, I am an area, a discipline that is close to many organizations and it has grown into an own discipline. It is no longer just using IAM for customers or for consumers. It's really something different. It has changed.
It has evolved and it is a strategic foundation for business just like IAM is, but it's different, but the same. So we want to have a system that is capable of providing the full user journey, providing data to downstream processes. And we want to do that for different kinds of CIM platforms. And you might even say, is it really the same for B2B and B2C? Open for discussion for that. And this blueprint that I'm showing right now, it will be quite all in one, but nevertheless, CIM, consumer identity and access management demands its own dedicated blueprint.
So what we did, and I want to just explain that briefly, is to keep, on the one hand, keep the structure, but exchange some of the capabilities. Some stay the same because you will need to have a data pot where you store the identity. So that won't go away, but there might be different other areas that you want to look at. So what stays the same from an analytical point of view? The semantic model of capabilities, functional columns and context rows, core privileged extended integrations API foundation. That will stay the same.
It's the same type of metrics, but we drill down a bit to get closer to what CIM demands for. And the question is that we stay still, oh no, it's not a question of factors. The tenet is that we still stay with capability-centric definitions, rather than saying, okay, take that tool for this and that, because that does not do the game. So we preserve the grid. We remove everything from IAM, which is IGA.
We introduce new CIM-specific capabilities and throw them onto the grid, hopefully where they belong to, and then realign some of the capabilities because privilege management in CIM is different than privilege management than it is in enterprise IAM, because you, for example, you delegate responsibilities to people who know better. And that means that you can then say, okay, let's have some kind of privileged access. And I've asked Philip to slightly indicate that it's a draft version. We ended up with this.
But if we have a closer look at that presentation, you can have, and it's really still draft. We're working on that. But if you look at that and you can take a photo, but you will have it also in the slide deck, I assume. Yes. Of course. Of course. The question is that I did a lot of, or we did a lot of changes regarding what is actually in there. Let's take just one block.
One block, audit and analytics. That is different in CIM than it is in enterprise IAM, needs to be in IJ. Because there you want to go closer to understanding your peer, your customer, your consumer, your partner. It's about progressive profiling. It's about profile enhancement. It's about really understanding what is the consent that has been given. Has this guy not paid three times in a row? Is this something that I should take into consideration? This is audit and analytics. You need to understand that this is past information.
Maybe from the periods of time, it's post event, but you throw it into your processes. So CIM looks different there. And it's much more important if you look at integrations. CIM is not a beast of its own as IJ is not, but it's different in many ways. So you will have, and I don't read them out. If you just fly over these and have a quick look at what all could be integrated in the different areas of the capability model slash reference architecture.
Could be, for example, third-party authentication services. Could be trust framework integration, but also making sure that you use session federation within brands, within your own organizations, but with different IDPs. So that could be something that could be achieved. So we end up, and that's maybe the main story, that we end up with the same structure, but the proper, hopefully proper, capabilities within this structure. A question then came up before the break was the question of APIs. And in the first picture, we had to be opaque.
We had just this one layer of API because we could not dig much deeper because it was difficult at that level just to say API is the glue. Very simple, but here you can see also along the lines of the four columns that we have different types of APIs. And this is far from being comprehensive. You end up with the types of APIs that make sense in that context and that it brings more flesh to the bone that you understand what are these APIs that I really want to leverage. This is integration.
And what's not on that layer right now is what are the APIs that you provide to the outside world as an CIM infrastructure. That is not on here because that you will define yourselves. It will be APIs that encapsulate some of the capabilities that are in this picture on the above. But what you actually expose to the world, it's up to you. So API layer, very important, will really show its value in here. And just to add, this is a conference exclusive because this is not online yet. This is the first time that we present that just to let you know.
This is the first second level reference architecture that we have drafted so far after we have released the high level, level one reference architecture in January. Right, and just one example more, if you look at identity lifecycle, of course, a consumer identity lifecycle is so much different from an employee lifecycle. It's registration, it's conversion, it's profiling over time and growing identities and maybe the activation or the request for deletion, all different processes. And they need to be covered fully as well in full lifecycle process definitions.
And then we are back to the principles that Fabrice mentioned, you really need to understand what are your requirements, what is the requirement regarding, for example, consent management for regarding being compliant to everything GDPR that you need to do. And that immediately then will be reflected in your lifecycle processes. And then you end up in customer lifecycle management somewhere on the left upper block over there. So that's the idea how you operationalize our reference architecture or capability model into a second level reference architecture for CIN.
As mentioned, this is one first throw, we are working on others for PAM for B2B right now. And as you can see, this is not a simple task, we're not doing that in our ivory tower, we're talking to people to understand what's actually happening out there. If you have contributions, reach out to me, please let me know. So that would be one refinement. Final step would be that was a question also before the break to say, how do we then if we have an IGA, if we have an CIM, if we have a PAM, how can we really get to a common picture? This is not out of the box right now.
And it won't be even if there are really nice blueprints for all areas that we're looking at right now. But the idea is that we gain a common structure, but allow this payload realization. So we go from the master IAM reference architecture, master or first level or however you call it, I'm happy to open for good names, master is bad, I know. We go down one level to B2B, to CIM, to PAM, and then need, and this is brain work, this is work, need to consolidate into a unified IAM service portfolio, most probably with separate owners for different areas.
And that makes things complicated to have different ownership, different service owners, different responsibilities and different stakeholders. The business usually does not care too much about IGA, but they care about CIM. Security will not really care about CIM, but they care about PAM. So the question is, how do you bring things together and how do you really slice and dice that into something that's not on that slide, a target operating model, the right responsible person that actually are doing that right now.
But that is intended to give you a picture of how that all plays together and how you get not to fragmentation, but real fragmentation, fragmentation, a unified picture of your identity landscape over time, whatever required. Sometimes they could even coexist, but I assume not. So that would be my short version on giving Philip more time for his parts. So that would be the second level architecture, how they play together, how they can be combined.
Still work, and that has been great, really explained by Kenny and Fabrice, how you actually do that from a project perspective, involving stakeholders, et cetera. And that's it for my part. I'm through now. Back to Philip and I can lay back. And thank you very much for your attention. So second chapter for operationalization, strategic development. So we had earlier the question, how do I use the identity fabric and reference architecture to do a strategy, to present that to my management, to move forward? This is exactly what I will explain now.
Before we come to that, I will show some examples. All of these are made up.
I just, I was very creative when I did that. So this is just to visualize that. These are no customer examples. Hope that's okay for everyone. And they might not be consistent. So that's also important. So if there is anything inconsistent, that was planned. So how do I get from a status quo analysis to a roadmap? That's the idea in five steps. So first step would be to have that maturity assessment to do the status quo analysis.
Second, think about the target state. Third is when I have both of them, the maturity assessment and the target state, define the gap in between. When I know the gap, I can go the next step and think about the action items to close that gap. And when I have the action items defined, I can put all of that on a timeline and that results, hopefully, in a roadmap. That's the high-level idea. So let's see how that combines.
Again, we start with the identity fabric and the reference architecture. So before I can start with all of what I've just shown, I need to make sure that I have a good framework, a good structure to approach that task. I don't know if you have ever done a maturity assessment, but without a good methodology and a good structure, that is a hell of a ride, to be honest. Pretty much impossible. So this is why we use the reference architecture for status quo assessments, maturity assessments. How do we do that?
Usually, we apply one of these two models. Either it is a five-level maturity assessment based on CMM, or we use a lighter version that is tailored to the reference architecture that has just the three levels on the right. It highly depends on how big you want this assessment to be and how good it needs to be structured. The idea is really to assess your landscape. So in the end, your landscape should look like that, or hopefully similar to that. The idea for an assessment is to understand each and every capability and discuss your very own maturity.
So what is your level of maturity for identity repositories? Matthias explained that earlier, what is behind that capability. And you can basically, for a status quo assessment, go through each and every capability and discuss that. Write maybe on paper, or if you're paperless, write it somewhere on a slide. What do you have there? And then you can assess your very own maturity level in terms of this capability. It can end up like that, and that makes it quite easy to identify certain areas where you are good, where you are not so good, where you need some improvements in the end.
But this gives you an idea of your current landscape. This is not talking about the target state yet. So this is important to mention. And when you do this exercise, you can easily also talk about the target state at the same time. But for the purpose of visualization, stick with the status quo only in the first iteration. In the second step, when you talk about the target state, you also need a target state for each and every capability. But that's not all. When we talk about the target state, we also need to think about the future. So it's not just now.
It's potentially also about what happens in five years, maybe even in 10 years, and we're talking about some of the IAM tooling that will be there also in 10 years. There are some trends, and you are on the right conference, obviously, to talk about trends and what comes next. I have displayed some topics here that we discussed, or we have discussed recently internally, just to show you what we are thinking could be some of the trends. When you do a roadmap, you want to have them in mind and also reflect that in your capabilities.
Even if you decide that it's not a topic for me, somebody else can do that, or my organization is not doing that at all, it is important to recognize that these trends exist and that they are part of your target state. Good. When you have done that, you get to the point that you have the assessment, the status quo, and you have, on the other hand, the target state. In between, there is usually a gap. So there are multiple methods to display that gap. One would be the scattergram to say, hey, this is the maturity that I have for the different capabilities.
And on the other side, I display the need for action or the priority and say, hey, I have a couple capabilities here in the right circle. I'm not sure if you can see that, but this is the upper left part there. This area is my high-priority stack where I have a low maturity but a high need for action. This is what I need to improve. On the other hand, I potentially have a stack down here in green that has a very high level of maturity, close to the 10 here, and a very low level of need for action. So that basically means I'm good there.
I don't want or don't need to move forward in these areas, but up there, these areas, that is my high-priority stack. This is where I need to move forward. And this is exactly where I need to apply these action items, where I need to find initiatives to move, to move forward, to get a higher level of maturity. And this is the fourth step, the action items. Action items are important. Why?
Simply, when you go to your management and say, hey, we have a problem in entitlement management, the first question would be, what is my problem? And what do you plan to do? So you better come prepared for that question or for those questions in that case. Action items are a good preparation also for projects.
So the idea, and I've, again, I displayed just one possibility to create action items is to think about the challenge that they solve, the goals that you have with that action item, what you need to do to realize that, and what happens if you don't do that, because for management, that is also important, to understand what happens if I simply ignore it. You can add more spices by effort, duration, the owner, the dependencies. So you're really free to add more information to it. Question is, if you should leave them out. So I've also seen action items that were basically a title.
I can tell you that's not enough. If you have all these action items, yeah? So we remember that scattergram, so you have a couple capabilities there. Now you design a couple action items out of them. And when you put these action items on a timeline that could look like that, again, that is just one possible way to visualize a roadmap that is very close to a Gantt chart. But the idea is really to say, how are these action items behaving when I put a time on them? How much time do I need to realize and implement these action items? Are there any dependencies to other action items?
As you can see, I have put the entitlement management phase, one action item that I've just designed, pretty much in the middle there, and some example projects, for example, action items everywhere else, just to show you how that can work. So that enables you to show how the action items that you came up with can be realized over time. And that makes them simply more operational. This is how you get to a roadmap, to a strategic roadmap that starts at the identity fabric and the reference architecture, and ends up pretty much here in a plan for your future.
And this one is for, I think, three years. You can do that same for five years, for one year, for, I don't know, whatever, 10 years, 15 years if you're good. Yeah?
So, and it's not limited. It is basically limited to the reference architecture that you use. As Matthias presented, you could do the same for the SIAM reference architecture that he just showed. So you are really flexible with that approach and can come up with whatever roadmap you need for your organization, for your purpose.
So, short conclusion takeaways for that chapter. You basically heard all of that because I explained that. IAM is a big and complex discipline, so make sure that you start with a structured approach into that exercise. Identity fabric reference architecture are examples for that. You could also use what Fabrice presented. You can have your own when you start with an identity fabric reference architecture for your organization. That's really up on you.
The trends help you to move toward a target state, so incorporate these trends that we have here on the conference to make sure that you cover everything for the future. Derive the gaps. They result from the target state and the assessment, as well as from the prioritization that you make. The action items, they are important for the roadmap and how to move forward. So the more details they have, the easier it is to derive projects and initiatives from them. Putting everything on a timeline is basically what your roadmap will look like in the end and will display your future strategy.
And all of that is supported by our frameworks, or if you adapt them by your frameworks. That depends upon you. This was the second part of operationalization on a strategic level now. We had the question in the first half, yes, that all of that is great and super strategic. How could I use that when I am really into the bytes and bits, an operational, everyday engineer that has no clue or no intention to go into strategic questions or challenges?
Of course, we have something prepared for that. We call it operational development. It's just the title. The idea is pretty simple. What happens when I'm struggling with my day-to-day business? I have a process inefficiency. So in that case, I chose a joiner mover lever inefficiency just to give you something that you can have in hands. Idea is we have observed a lack of automation, media disruptions in our joiner process, inconsistent identity data, lots of manual tasks. Whatever you can come up with can be discussed here.
So how do I approach that with the identity fabric and the reference architecture? The idea first is to get a good idea of what I'm looking at.
So now, within this challenge, we are talking about a joiner process. So what is a joiner process? This is the first step. You need to understand what you are talking about. If that is your daily work, you are obviously familiar with that. So I don't need to explain it to you.
However, I brought up a slide to explain the joiner very briefly. So the definition here, a joiner process describes the structured onboarding of an identity, ensuring they receive the appropriate identity and access rights. So for everyone that was not familiar with the joiner process, now you are. The rest for now is not super important, but if you feel that you want to read it, this is also on the slide deck so you can read it later. Diving deeper into the joiner process, the important part is really here on the right side.
The left side is, again, a little bit more details on what we are talking about. The idea of the joiner is to onboard somebody. So to make sure that a new employee is onboarded, gets an identity proofing, gets an identity verification, potentially gets the right access rights to start right away. In our setup, in our challenge, we have talked about it. So the challenge really is the identity data, the process itself, media disruption, automation, and so on. So identity proofing, the birthright, the provisioning, all of that is somehow not working.
So what can I do with the identity fabric and the reference architecture to handle that? Again, we start at the very high level, which is strategic. I'm not discussing that. That's not an operational vision or not an operational framework, but it helps you to structure your challenge. You start high level and you think, the first thing that you think about is what kind of identity type am I talking about? A joiner process could potentially be everything. So I need to make sure that I talk about the right identity type before I can identify the capabilities that I need.
In this case, I've just assumed that this is an internal employee. So we are basically talking about a B2E workforce identity type. With that in mind, I can go into the reference architecture that displays the capabilities for this kind of identity. Good thing is that we can display that with our level one reference architecture. What a surprise. And moving on with that approach, I know that the identity type is a workforce identity. In the next step, I want to make sure that I understand which capabilities are an issue or are a challenge based on my observations.
So when I lack automation, when I lack data, or the data is not on the level I need it, when I need a more automated process, what do I need to look at? What is the problem when I cannot assign birthrights, for example? So I have highlighted here three different capabilities. Matthias explained all of them earlier, so I will not repeat that. But I have the slides here. So if you take a closer look later, you can check that here. The important part now, when you try to dive deeper into the capabilities, is you need to ask the right questions.
So when I have an issue with my joiner mover lever and automation or the processes behind that, I take all of the capabilities and I need to ask the right questions or identify the challenges. In this case, this is the first column. As an example, is the identity information automatically provided by HR? And I need to assess the status quo. So I need to know where I am today. This is the least that you need to know as an operational expert. You can probably simply answer that in a minute.
If not, well. The next step, when I have that, and I feel that I have the right questions asked, I go into the benchmarking part. The benchmarking here, in that sense, is the vision, more or less. What do I need? What would be the best possible implementation or the best possible solution for my problem? So when I think about, for example, here taking again the first one, is identity information automatically provided by HR? The best possible state that I was able to come up with is a full event-based integration. So whenever I get a new identity in HR, that is synced directly to my IGA. Right?
That would be a benchmark. And I have more examples here, so you can see other examples as well. The benchmark is not always the right next step for most organizations, as it is potentially a vision. In this case, that does not seem too far away, but there are other areas, especially when we're talking about birthrights, where the vision could be a new identity gets all of its excess rights that are required from day one based on a job profile. That would be a nice vision, but I can tell you from my experience, 99% of the organizations are not able to do that.
Not even in the next three years, or five years, potentially. So the benchmark could be very far away, depending on your challenge. This is what the organization-specific target state is about. So for operational experts, it's usually important to identify the very next step. It does not help to know how something should look in five years. That doesn't help you. The step is simply too far to get there in one jump, probably, not even in one step. So this is exactly where you need to find the step, the right step that you are able to take as an organization.
So what is the one next step that you are able to do? And this is what you need to have here. And this is actually, and I'm not sure if you can see that here because of the chairs, but this is the gap that you are trying to close. It's not the gap here to the benchmark that you are trying to close in your operational daily business. It's really about the next step. Maybe about the next two steps, if you want. Because it doesn't depend how many small steps you make. In the end, it becomes the big step. But it's much easier to handle if you go smaller steps.
So, why do I have more capabilities over there, not just one? Because most of the daily challenges are not just within a single capability. So when we are talking about a joiner, there are more capabilities for a joiner than just one. It's probably not even just the three, depending on your challenge. So these might be multi-dimensional in terms of the capabilities. And you just need to ask the right questions or identify the right questions, think about where you are today, where you want to go in the future with your next step.
And if you bring all of that together, then you can handle operational challenges, starting, again, with the identity fabric and the reference architecture. And that connects the strategic layer and the operational layer also for the operational experts. The good thing about that approach is it works for pretty much everything. A process improvement, a tool selection, a technology optimization, whatever you can come up with. The good thing is, from the identity fabric, you can always drill down into the reference architecture into your problem. It doesn't matter what it is. Pretty much.
Or I would say, challenge me after the session. So, short conclusion. Most importantly, you need to understand your challenge first before you go and drill deeper into your issue.
But then, the structure that we provide, the identity fabric and the reference architecture help you to do that. Don't choose the benchmark as your next step. I've explained why. It is potentially too far away for you to reach it, at least not in the near future. Define tiny steps, because one tiny or multiple tiny steps are a big step for you as an organization. And that feeds into the big picture in the end. And maybe you are able to reach that benchmark at some point. And for me, most importantly, this approach is not limited to a process improvement.
So, you can basically use it for everything. You can basically use it for every kind of challenge that you have. The identity fabric and reference architecture is always a starting point. The structure supports you with pretty much every challenge. And that brings us to the wrap-up and closing. And that is done by Matthias. Wrap-up and closing. First of all, I think we should start with questions, shouldn't we?
No, we do the closing first and then we can. Closing first and then, okay. For the takeaways, yes. Okay. What we wanted to achieve is to, as I said in the beginning, we want to give you a common language. You will use your own language within your own organization, of course. There will be a glossary translating from A to B and B to A, which is necessary. But we want to have a language and two levels of framework to give you, to use as a scalable foundation for a future ready IA. As a scalable foundation for a future ready IA. That is the first starting point.
We wanted to give you a first glimpse on second level reference architectures and happy to have your input. This is a workshop. Although we've been talking all the time, we hope that you took something A away and B, willing and able and ready to provide us feedback, especially when it comes to other reference architectures at second level. Philip showed that, and I hope I showed that as well, that a modular service design, as we've shown, also with different service owners, encapsulating more than one capability, are key for this efficient operationalization.
What Philip explained, what I explained, so really it's not only talking about technology. We are analysts. We love to talk about technology, but it's about solutions. It's about real life. It's about real life. And that is where we need to operationalize first. We are flexible in the selection of architectures and that makes sure that we can really align. And that is, of course, hand-in-hand with what Kemi said when it comes to this different types of organizations.
That is the flexibility that you need to adapt the frameworks that you use, but also the project management approach as shown to the different organizational strategies and the digital transformation goals. A bank is different from a retailer, full stop. That's the difference. That's the difference. And finally, if you don't improve, you get left behind. And that is especially true within IAM and IGA and PAM and CIAM. So continuous improvement is essential, not only to get better for yourself, but also to stay ahead of threats, of market developments, et cetera.
And then it makes sense to go back to what EIC is a bit about also looking at trends and all this shiny stuff out there and how that fits into your overall picture because there is a match between both. And these shiny technologies help you in these architectures. That was mainly my main takeaway. So I don't read that out. That's a really long sentence, but it's really the summary of what we just talked about. It's really about, I take the last part, shaping your organization's digital future.
Because when I started 20 years ago and I'm old enough, IAM was just efficiency and making accounts work faster. We are no longer there. IAM is really a foundation of all of your business strategy. And this is also true for employee IAM. And that needs to be taken into account. I think that is really where we are right now. And this is understood. That's the good thing about that. And now the takeaways are done. Our other takeaways are over and now we can do the questions. Do we want to invite Kami up to the stage again for a few questions? Because there are some for you as well.
I hope this is not too surprising. Oh, damn it. Christopher just left. He knew the question. The CISO question. Very right.
Okay, thank you. So we start with a question to Kami, to ABB. Are you considering consumer identities in your capability model?
If not, if no, why not? If yes, how did you engage with the different stakeholders? So when it comes to CIAM and ABB, we are actually early days. I have to say that. So there's not too much that I can share in terms of where we are on the journey. But like any organization, we are experiencing like fragmented tooling there. So there's CIAM sitting in all different business areas. And we are actually trying to consolidate that into one kind of one enterprise CIAM solution. So it's a journey which is interesting to undertake.
And actually I'm gonna apply what both Fabrice and myself shared in our CIAM journey. So thanks for the question. From your experience, you're working with other clients. How important is CIAM in that area? Does it show up?
Yes, it does. And that's because we live in a hyper-connected world. Whether we're a bank or a manufacturing company, there's a desire to be closer to customer, right? To generate new business and new value stream and new revenue streams. And that's where you see customer identity and access management play a role, right? Because it facilitates acquisition, building trust, building loyalty, providing ease of access, but also profiling your agents as they go and use your platforms and your portals. So that's a crucial element of the Fabric.
And we see an acceleration in leveraging such capabilities in the business right now. Yeah. And the stakeholders you interact with, that was the second part of the question. Who would be the persons who know customer requirements? So that's a good question. And that's a question we receive often. There's different schools, right? But usually Siam sits with your sales marketing department because that's those that are heading your portals or your customer relationship management part.
But it's also heavily connected with your developer organization, which actually produces the tools for an app, for a portal, for whatever. Those external identity used to consume your product or services. So I wouldn't say that there's a specific place or specific stakeholders. I like to think about a constellation of stakeholders, which obviously includes your developer organization and sales and marketing, and obviously your CISO organization where identity sits often case.
Okay, thank you. Cheers. And that was a perfect transition to the next question. That is for us. But interestingly, you basically picked it up. What is the role of the CISO in the context identity fabric?
Yeah, we should hand that over to our CISO. There's a microphone. I knew that that kind of question comes up.
Basically, I didn't join the previous part you shared, but the role of the CISO is really depending on the organization who is responsible for doing the, or building the identity fabric at the end. Initially, the CISO is responsible for defining rules, for governance, for stuff like saying, we need to have a proper join and move a lever processes. We need to know our suppliers and so on, based on the standards you do, but whether it's a regulated BaFin, Kritis, or even an ISO certification, that is the starting point. And then it really depends on your organization.
In the best case, the CISO is responsible for driving the identity fabric. That's what we usually try to start within the organization. So the CISO is the starting point for building the identity fabric with the specific teams to have a proper framework like Matthias and Philipp and the two others shared today. But there are, maybe you know from your organization, also companies that do it differently. And sometimes it works, sometimes it is not working. So that is the starting point or building the identity fabric. The popular answer Matthias likes to give it, it depends.
Yeah, thank you. So that was our CISO, Christopher SchĂĽtze, with the answer to that question. Let's move on. So next question. Why are you considering conditional authentication as part of authorization? We have a little bit more information here. So it's talking about the location as a context information. So why do we do that? That is a very simple answer. The very simple answer is that the borders between authorization and authentication are getting thinner when we talk about signals. We can use these signals not just for authentication, but in the future also for authorization.
This is why we can use also something like location or any other condition for, not just for authentication anymore, but also for authorization. Good. Thank you. So. So we have time for two more questions. I think the end-user experience, did we have that? Good. How much of end-user experience important when we consider the KC framework?
Yeah, that's an interesting question. The question is when you do such a maturity assessment, for example, the question is, who are the stakeholders that you talk to when it comes to user lifecycle management, when it comes to self-services, but also when it comes to the day-to-day practice of authentication and authorizing, the question is whether you can bring in some friendly or much better unfriendly end-users that can provide feedback from the end of the food chain that really need to work with the system and that they can provide their feedback.
And if this is possible, we usually ask for that. Now we're really in the role of an advisor and we ask for that, but not every organization wants to do that, just depending on how the organization is structured. But then of course, user feedback and user experience plays an important role when it comes to, for example, how do I order a role and how long is the list to choose from? Do I understand what that role means? So this is something that we try to also factor in these results, but it's not always possible, but end-user experience is important, at least for me.
Question is, maybe also getting back to Fabrice or Cami, how important are your end-users for you and when providing IAM services? Well, I think a lot of the vision that we have crafted in various identity program always talks about seamless access, right? So I think it's a given that it is super important. But in order to allow for seamless access, there are a lot of background work or homework that needs to get there. So what Philip mentioned, to get to the end state in benchmarking, maybe you need to take two, three step approach before you get there.
So while you're painting that, there's the vision that we want to enable, but you also need to be realistic towards your stakeholder, whether this will really drastically improve CX or UX, given the maturity in terms of where we are right now. So I think that's also something which is really pragmatic to think about. And if I may have had just one more very concrete example, we've talked about self-service in the first part of this workshop. And the fact that ITSM tools are often used as IT shop to offer those services and order those services.
I think what's important when you address a node genesis to provide visibility into the way your process are organized and the different steps they include. For example, imagine I'm a user, I'll just go on my ITSM tool to request an access. Regardless of the application. The only thing I could see, right, is when I submit the request and when it's completed. If I would be able to see the different steps, for example, where the request is qualified, the request is in process or in progress and the request is completed, that's a great help as a hand user.
Because I don't get frustrated because I see that my request has been processed, it's been treated, right? And I know many organizations struggle with providing that visibility. And in the end, the IAM team takes the hit because they are the frontline of people looking at them saying, where are my access? Why are you not doing your job? So I think providing visibility back to your audience in various different use case that you may face is of great help to also support your IAM team in their job.
Great, great, thank you. Good point. Good. We are running out of time. We have two minutes left. So I will not pick up another question. We have a couple of different questions. We will follow up on that later, probably by a podcast episode, making sure that they get answered. So sorry for not picking them up, but we will take care of them. Marketing block, don't forget to pick up your identity fabric. They are over there. And that leaves me with just one thing. Thank you for your attendance. Thank you for presenting the content. Thank you. And I wish you a very good conference. Thank you.
Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you.