Perfect. Good morning and welcome to the European Identity and Cloud Conference 2026. Instead of deciding for joining Beautiful Coffee in Berlin, you decided for this more valuable workshop about the identity fabric, the reference architecture, the maturity assessment. So happy for having you all of you here and also welcome to the online audience for those of you who are aware with KuppingerCole workshops. We have the opportunity to ask questions for sure. I will explain on a later slide, but this will be handled remotely again. So we have two 90 minutes blocks this morning, a tough timeline.
We will start for sure with a general introduction. That is what we are doing right now. Then for those of you who are not aware of the identity fabric, we will explain the updates since last year, what happens and then how to operationalize all that stuff. Then for sure, we are an analyst company. We will talk about trends as well. So for sure, agendic AI will be used as a word in this session and we will cover also some rough ideas how to handle that. Then the most interesting part is for you seeing that in practice.
We have a speaker here sharing experiences of how to implement that, how to rate the maturity and then we will do the workshop thing, talk to you interactively again and see, okay, what is the level of maturity in maybe your organization or some organization you know built together for one capability for one building block? How does this work?
Yeah, and that is basically, then it's lunchtime and almost time for the opening keynote. That's the plan for today. And with that, I would like to start to introduce first of all, Dr. Lisa Zimmermann. Maybe she introduces herself.
Sure, okay, this works. Hi, glad to be here. My name is Lisa Zimmermann. I'm heading the IAM team at Fresnaf MaxiZoo, biggest European pet retailer. So maybe if you have pets, you might know us.
And yeah, I'm very, very happy in the second part to share our experience with rating the IAM maturity at Fresnaf and showing you how we did this and why we did it and what some of the results were for us. Then we have Rainer.
Yeah, good morning also from my side. My name is Rainer Mertens. I'm a lead advisor at Kumpinger Coal. I will do the practical part here today and the interactive maturity assessment together with Christopher. And I'm very happy to have you all in the room here. Thank you very much. Perfect. And Philipp.
Yeah, also a warm welcome from me. My name is Philipp Messerschmidt. I'm a lead advisor for Kumpinger Coal and I will explain the identity fabric, the reference architecture and how the maturity model works. So that's the idea. And then last but not least. Back to Christopher. Christopher, that's me. I'm leading the advisory team with Kumpinger Coal and also responsible for our internal information security. And today here with my colleagues to share knowledge and experience.
First of all, for those of you who don't know Kumpinger Coal, first of all, we are doing things like this small conference here in Berlin. We have also other conferences this year in Munich, in Frankfurt and somewhere else. I think it's the Cologne area, something that we do, but a bit smaller than this conference. Besides that, we are doing exactly things like that for customers, workshops, usually not with, I don't know, 80 to 100 people. It's more like five to 15 of the bigger groups helping organizations to implement identity fabric, reference architecture.
And for sure, as an analyst company, we are doing also research, focusing on trends, challenges, things, how to solve future readiness within your organization. What are the goals for today? First of all, the idea of giving you, again, maybe some recap for those of you who are aware of the identity fabric, how does this concept work? How is this related to the reference architecture? And then not leaving you alone with, okay, that's the concept. Also help you to rate your maturity, how to implement it.
That is what we want to share with you today, that you are ready at the end of the day to take the framework and analyze by yourself, okay, what is going on? What is my level of maturity? Can I improve that? Then for sure the real world example, and yeah, that's it. And for those of you who are at the side here, also free seat, so feel free to join. No need to stand at the side. Here are two, one, two, two, feel free. And now the interactive moment starts. You will find in this session and in all other sessions at this EIC some QR code. I would ask you all to scan that.
You will be forwarded to Slido. That's the tool we use today. And whenever we have a specific question, I can enable this on the tablet, and then we can see the results live here as well. So everyone scanned? Take your time. Perfect. And with that, I would like to hand over to Philipp. Okay. So we start with the identity fabric and reference architecture fundamentals, and we can right away check if the scanned QR code works, because I am starting with a question to you.
So the question is, who is familiar with the Kupinger core frameworks, the identity fabric and reference architecture, and who uses them in their own organization? That is the question. So is everyone or anybody here already familiar with the frameworks? And this is interesting because I would like to see who is having a basic idea and who is deepening the understanding. There are five options that you can answer, but let's see how the results are. So can we already switch to the results? So we have a mixed mixture of attendees. So some are already familiar with it. Almost the half is not.
That's good, because you are able to see the frameworks for the first time then. We leave the poll open, so we can see who is familiar with the Kupinger core frameworks. We leave the poll open, switch back to the other slides, and come to the frameworks. So the identity fabric is one of the major frameworks for Kupinger core. It is quite big, but I will walk you through in a couple minutes. The idea of the identity fabrics is that this is a strategic framework that we use to structure IAM for pretty much everyone. What we can see here is on the left side the different identity types.
By the way, all the slides will be available online, so you can download it if you like. And also we have some giveaways with the identity fabric over here. So if you want to have some for your pocket, that's also possible. So on the left side, you see the different identity types. We have split them in two categories, the human identities and the non-human identities. And every category consists of a couple of types. So we have the workforce, we have the B2B, we have the B2C identities, and we have a couple non-human identities in there.
The list is not exhaustive, so currently you find agent and bots, but not agentic AI. But in general, these lists can be continued as long as you have new and different identity types to add there. That is not a problem for the concept itself. On the right side here, you find the target systems. So the idea is the identities try to access certain target systems. And these are on the right side. You can come up with pretty much everything that you can think of. Applications, NAS services, back-end services, legacy IT, OT, whatever you find.
Again, you can add whatever you can come up with. The idea stays the same. In the end, our duty as identity and access management experts is to enable these different identities and identity types to access all the services on the right side. And how do we do that? We do that based on capabilities. Pretty much everything that is in between these both sides. The capabilities are the functional and technical features that we require to enable that access. We bundle that into services and we implement that based on different kinds of tools.
On the upper and lower end of that graphic, we have the connectors. So since we are operating in a world that is usually not a green field, we already have stuff in there. We have systems, we have connections, we have services there, and we need to connect our tools from an IAM perspective to everything else. And that's why we need interfaces, we need connectors to make or to integrate these capabilities and tools that we use to enable the access. But in the end, it's everything about enabling the access for the identities to the services. That is the idea.
The good thing about the identity fabric, it's a high-level strategic framework. So it's quite flexible. When we are talking about one of the identity types, we can pretty much freely adapt to the capabilities that we need. So in other words, a workforce identity needs different capabilities or has different requirements than a B2B identity, than an agent, than a B2C identity, a consumer. So these have different requirements and that's why we need different capabilities to ensure that the access is possible.
And since we need different capabilities, we need to design different services and implement that based on different tools. So this is how you more or less use the identity fabric to navigate the IAM landscape. You decide first which identity type am I talking about and then what application or what service, which target system is accessed. And then we can figure out what capabilities are required, how do I plan my services and how do I implement them. This way you put the tool at the last point in your decision tree, not on the first position. Good.
What you probably already noticed, when we are talking about tools, we don't have vendors on that framework. So that means we are completely vendor agnostic. We are talking about capabilities and tools, but from a general perspective. That makes it also quite valuable as a strategic tool. So identity fabric, that's a nice framework, but very high level. That's true, but it can not be connected to the operational level. That's why we have the reference architecture, the second big framework.
And the reference architecture in general, and it will show that bigger, so you don't need to try to read that at the moment. It's just as an indication where the reference architecture sits. The reference architecture in general lists all the capabilities that you require for certain identity types. So as you can see, it covers the capability part and goes more into detail on that. So we move away from the big strategic framework and go more into details for the different identity types.
The important thing about that, and that's what I'm trying to explain here, is depending on the identity type, these identity fabrics, the identity fabric and the reference architecture will change. As said, when I'm talking about a workforce identity, different capabilities are required from an agent or a bot. A bot will require, again, different stuff than a consumer. And that changes also the reference architecture. So when we are talking now about the reference architecture, this is the level one reference architecture and the level one identity fabric.
So nobody stops you from creating your own identity fabric and your own reference architecture for your own organization. So both frameworks are adaptable to your situation. These are just the templates that you can start with. And they are quite comprehensive, I would say. The idea of the second level reference architectures especially is that we can focus the different identity types. So the level one is a good overview that we usually start with when we don't know what we are facing. But when we look into a special identity type, we use the specific reference architecture for that.
So last year in this workshop, we have shown and released the reference architecture for consumer identity. No, for partners and for B2B in general. So not for consumers, for B2B. And we have that reference architecture also online. I will not show it today. But with that example, you can see how we use different reference architectures to navigate different identity types. So what we will do today in a second is diving deeper into the reference architecture to understand how we get from that strategic level to a more operational level.
So the idea right now is to have another poll before we get to the reference architecture to find out what your favorite reference architecture would be. So I'm interested in knowing which identity types are interesting for you, which reference architectures would be interesting for you. And here you have multiple options. And we start with the classic level one version. That's the one that I will show in a minute. But you can also say, okay, I am not that interested in the level one.
I'm more interested in a special specific reference architecture like NHI, agentic AI, or consumers, the IGA part, the pump part, or something else whenever you have something else. Good. I think the question is understood. Let's switch to the results while you are voting. So I think the numbers don't really make sense, right?
Oh, we have multiple choice. That's why. Good.
Yeah, you know that. I'm aware of that. It was just for me. So as we can see, agentic AI is on the first place. IGA is right behind that. NHI also quite high percentage. So the classic level one version is not that interesting. Good. That makes it much easier for me to present exactly that in a minute if nobody is interested in that. Yeah. Good. Then we switch back and check the level one version. But no problem. I come prepared. I have IGA at least partially in there. So at least some of you get more info here. The reference architecture.
Again, quite a big framework. We have put it on a slide. The idea and how you read that is that this is a matrix. And in the columns, you can see the four A's. This is a classic approach to structure IAM into administration, analytics, and risk authentication and authorization. And in the rows, you have, I would say, an abstraction level. So the most important part of the rows is the core area. So this is the part where we as IAM experts are responsible for IAM that is right in our teams. The more we move away from the core area, we get to extend it in integration.
So this is the area that we have something to do with. We exchange data. We are sometimes responsible for it, but not always. But this is, yeah, that's stupid to say, but it's not the core area, right? So it's not always our responsibility. It's usually more of an integrated exchange level. Then we have privileged in there. We have API and foundation in there.
As I said, this is an overview over different identity types. So we cover a little bit of privileged access management here. The API layer is very important because one of the benefits of the identity fabric is that you can freely connect different systems and tools to ensure that the identity landscape works as a whole. And then we have the foundation layer that combines a couple, well, let's say non-exclusive IAM capabilities that are still important and bring in some organizational aspects despite the functional and technical level.
So the interesting thing is that we have structured it a lot. So when you are trying to navigate the IAM landscape, you can very good, you can use these capabilities to get an overview. So more specific than what we see in the identity fabric, but not yet on an operational level. And you can dive into each of these capabilities. And that's what we will do in a minute. So you can say, hey, for this identity and this target system, I need these capabilities. And you can basically mark them and cross them off. That is what you then can investigate later.
And that's also what we will do in the second half, checking what is your maturity level on these capabilities when we were able to understand them. At the moment, we just see the headlines. So what the capabilities are on a very high level. But there's also a description. There are also key aspects for each and every of these capabilities.
As said, we will get there in a minute. But before we get there, I would like to highlight how we use that coming from the identity fabric. So some of you voted for IGA, for example. So I was aware of that somehow. So I marked every capability that belongs more or less to an IGA here in red. So when you are trying to find your IGA capabilities, you basically then start with identity repository, get a better understanding of it, and then move forward to identity information, quality management, to identity lifecycle, the entitlement management, the access governance.
And all these capabilities together form then a service. And that is implemented based on a tool. This is how the identity fabric works. And this is how you build, based on the reference architecture, your services. And then you look for a tool. That's how it works. Not the other way around. Not looking for a tool and afterwards designing a service. So that's the wrong way. So I promised that we'd go deeper into the details. That's what we will do now.
As said, every capability is not just a box in here and not just a title. But there are also a couple of details. So in this case, we have the identity lifecycle. And the identity lifecycle has a one-sentence definition, a detailed description. We have the key aspects. And we have a couple examples. Sometimes also use cases. That depends a little bit on the capability. Important is, when you go through the reference architecture and through these details, that you understand what the capability is and that you are able to discuss the different aspects.
So for identity lifecycle, just as an example, it's important to understand that most of it is join, or move, or leave, or but not all of it. So there are a couple processes, right and left. But it is mainly join, or move, or leave, or understanding how identities join your organization, what happens when they move, what do I need to do, especially in my IGA, for example, and what happens when somebody leaves? How do I need to react to that? And there are some key aspects here as well. User context lifecycle, user data lifecycle.
But again, this is just to give you a rough idea. There's certainly more when it comes to identity lifecycle management.
However, we use these descriptions and these details in pretty much every workshop with our customers to start from a very high level with the identity fabric and explain that, as I just did. Explain them the reference architecture to get more into the details and still have an overview where to navigate, understand which capabilities are important. And then when it comes to assessing the maturity or talking about the different tools, we dive into the details here.
And that's where we can discuss with the operational experts certain challenges or whatever is important for them, for tools, requirements, challenges, whatever you can come up with. That is how you link the strategic level with the operational level. Good. I have brought two more, two capabilities more. So the rest is available. You will hear that later, how you get to that. Access governance is important for us today because in the second half, we will use access governance to go through a maturity assessment with you because it is a quite detailed assessment.
We have just this one capability prepared. It will take some time, but you will see what access governance is, how it works, and hopefully where you stand when it comes to access governance. We will explain that later, but I will already start with the explanation here. So access governance is basically covering the key elements like the access request, access approvals, the recertification process, parts of SOD certainly. So this is what you usually have in an IGA.
As said, the key aspects reflect what I just said. Auditing and reporting is also part of that. So overall, the idea of access governance is to get an overview, to ensure compliance, and to mitigate risks in the end. So we will dive deeper into that when we come to the maturity assessment. The last one that I brought is strong authentication and passwordless, just to give you another idea of how the capabilities work.
And again, you can see we have a short sentence definition, a detailed description in the key aspects. Strong authentication, or we know it as MFA usually, and passwordless, that is the thing where you don't need the password obviously, is something where we develop towards.
Again, you can see here key aspects, authentication factors, MFA, and pass keys is usually something that you could also consider here important. Two factors, which is pretty much MFA, but not always. This is something that you would discuss with your experts when you come to this capability. But this is the first capability that's not part of an IGA, so I guess you noticed that. And this is, again, to summarize my talk, this is how you use the identity fabric and the reference architecture, and how you navigate the capabilities to get from the capabilities ultimately to the tools.
And how we will use that and operationalize that a little bit more, that will be explained by Reiner. Okay, so first thank you very much, Philipp.
Yeah, first maybe some organizational parts. So for those standing in the back, now is a good chance to go all the way here, because on the right side here, I see still quite a few open spaces here. Not just in the front row, but also there in the middle area. If you go just here, that's the easiest pass, then you can take a seat and do not need to stand around there. We have the time. We're a bit faster than expected, so you want to stay there, that's fine.
Yeah, leaning on the wall is kind of cool. Okay, so we will start again with a poll. And so I ask you to go back to the application or to Sli.do again and open up the next poll there. I'd like to understand in which situation is your organizational company at the moment? So when we come as advisors to companies and helping them with their strategic alignment, doing a maturity assessment or something like this, we frequently find one of these situations you see here. So we find situations where we have a simple lack of usability. Some are looking for benchmarking.
So how do we do compared to our competitors? Maybe they have a misaligned understanding in the room.
Trust me, I've seen that. I have worked in companies of my own, seeing that every time we have a misaligned understanding, that everybody talks about identity or users, but they have completely different understanding what that actually means or is. Maybe you are working on a target architecture which is simply unclear. You are running a modernization project. You're simply starting your first EIM initiative or you're challenging the agentic challenges which we all see at the moment, or a lot of us probably simply trying to close audit and compliance gaps.
So maybe we can then also switch to the results then and see where people are. I need to turn back now a little bit to see the screen.
Oh, it's interesting to see that a lot of you are starting a new EIM initiative here and also addressing emerging challenges such as agentic AI, of course. Audit and compliance is in the middle. Lack of EM usability.
Okay, you're probably not here. And modernization without a starting point is not too much.
Okay, thank you very much. You have a question?
Yeah, it is multiple choice, right? Isn't it on the in Slido? No?
Oh, yeah, maybe. Maybe, maybe, yeah.
Okay, so yeah, what is it now what the identity fabric and also the reference architecture provides you? So in my experience with all the advisory projects I have done and what my colleagues have done, there are three main benefits you gain from this. So one is structure. The second is the common blueprint and you gain clarity from that. And the structure has already been explained a little bit by Philipp. It separates the what from the how in a very well way.
For architecture, that's an important discussion point that helps also with stakeholder discussions or when you talk to the more operational level. You also have this capability areas which helps you to structure things a little bit better. The common blueprint is exactly about these terms and the definition of what you're actually talking about. And then overall, it helps you with clarity. And I will come to that a little later.
It helps you to define your status quo, to do a maturity assessment, to actually find out what capabilities are implemented in my company, what identities I'm actually already managing, or what identities I have on the table but I'm not actively managing here. And yeah, just to give you a reminder here, the identity fabric helps you to exactly find this out. So as you can see on the left-hand side, the identities again, you can see, okay, what kind of identities do I'm already managing? What kinds do I have to manage? You have your capabilities, those map usually to some services and tools.
And what we see frequently is that we start in an engagement to first find out, okay, what are the service and tools in place? What kind of identities do they manage? And then try to map them to capabilities. When you start on more on the green field, you can also do that the other way around, but practical, that works quite well. And with stakeholders, you frequently then more have a discussion on the level, okay, what is it what we need to do? And that is then on the capability level here. I need some water.
So yeah, without further ado, yeah, let's take a look what kind of customer journals you can go through and what kind of things you can do with the identity fabric and the reference architecture. And I've created together with my colleagues, this nice pie chart, which explains that for us, the identity fabric and the reference architecture is really more or less at the heart of everything which we are doing. We all the time come back to that.
So we jump from the identity fabric and the reference architecture out to any of those topics you see there, and we go back there, but you can also read this kind of clockwise. So you start on the upper right with the status quo here. You go maybe through a maturity assessment. You maybe want to do some benchmarking. Stakeholder management is important. You do a gap analysis, defining your target architectures, and finally then come up with an identity and access management roadmap. You can always pick any of those things and just go back to it.
And depending where you are with your initiative, you can start at any point in this circle here and then come back. Some companies also do this all the time again over and over again. So they start with the maturity assessment. They define the gaps. They close the gaps and then come back to another status quo assessment to see where they are and if they have approved. So I want to go to some detail and give you some examples how the results could look like, how that actually really looks like in practice.
First, some disclaimer here. So all the numbers you see are not from actual maturity assessments we've done. So Philip and I, we were very creative here and just put some numbers on the table here. I don't know, freaking out to put some numbers there and make it just usable. It's really just to show you how the methodology works and how the results could look like just from the visual aspects. There are usually then five steps which you go through if you want to define an ERM roadmap.
And whether you are just starting an initiative, if you're modernizing, if you are closing some gaps, usually you need this roadmap. You need a plan for one, three, and five years. So the typical short, midterm, and long-term plans. And this is how you can come to this. And this is what we often do together with our customers. So you start with a status quo and a maturity assessment. And depending on how much time and effort you want to spend, that could be simply first trying to understand what identities, what tools and services do I have, what kind of capabilities I'm working on.
You can do that on a three-level maturity assessment, which is kind of ample style, just like red, yellow, green. Or you can do a full-blown maturity assessment with five levels and 12 categories, which we will do together with you in the second half of this workshop here. Once you have that done, you need to talk about the target state then. And the target state obviously is also then just, I mean, it could be just the maturity you want to reach. Say you say, OK, all the capabilities we decided to have implemented, we want them at least on level three, for example.
But it is usually also trends and upcoming security challenges you are facing here. So you want to make sure that you have, I don't know, past keys on your table. You're looking into the gigantic challenges here. And you want to put this kind of trends on your roadmap and incorporate in your planning. What you do then is a gap analysis. So what is in between your status quo and your target state, which then defines the activities and initiatives you need to implement, which you then put on a roadmap.
I mean, that is not rocket science. Once you have defined your initiatives and activities, the roadmap is then basically the easier part. The discussion with your management when you do that and if you get the funding, that's a different story then. But also with that, I think the reference architecture and the identity fabric is quite helpful. And we will give you some hints in a couple of minutes. So this is one of the results which we just put together here. And I don't know if you can see that. Just double checking.
Yes, it is readable. That's quite good. So what you can do is based on the maturity you evaluated, you can put little small pie charts on each capability to get an indication whether you are there on initial state or if you're quite mature on managing already. So between the levels one and five. If you just do this ample style, they are very simply just red, green and yellow. And because of the different areas, you already see in which areas you are quite good and in which areas you may need improvement.
And what we frequently see is that companies are good in authentication, maybe fairly good in authorization, but then when it comes to the analytics and risk or to the administration part, things get worse. That's what we see quite a lot. And now maybe you want to do some benchmarking, then you need a different visual concept behind that and just want to give an example how that could look like.
So if you want to do a benchmark to either your target state in terms of maturity, or maybe to your peers, maybe to our opinion as experts, then you can use this kind of spider charts where the dark line is your actual maturity. And then some other dotted lines indicate the maturity of your peers, may indicate your target maturity of whatever you want to use to compare your maturity.
This is, I think, as it also reflects the area. So each quadrant you see here is one of the areas from the reference architecture. And it also helps to get a quite quick visual understanding where you're already good and where you have room for improvement. When you then look at trends, you may want to look at the trend or topic radar like we have from Kumpinga Kohl from last year. And of course, you probably look into the ones which are mature and also evolving. You maybe want not to look so much into the areas where you have this decline.
Watch still topics which are growing but not mature at the moment. That is something which you then probably watch. But the ones which are already mature and are growing, these are the ones which you need to keep in mind. And then at some point, you need to then bring the capability, maturity, and your amtrams and the need for action. So a priority, you need to bring that together to decide then what you are doing first. Because we all know you cannot do everything at the same time and you will never get the funding for everything at the same time.
So in front of your management, you need to really explain why you are doing what and what is the first thing, the second thing, and then maybe the third thing which needs to wait a little bit. And this kind of scattergram, that helps exactly with that. And what you see here is on the one hand on the x-axis, you see the maturity. And then on the y-axis, you see the priority or the need for action. And if you bring that together, nice things happen because three areas then appear. That is the first, the red area, which is here on the top left.
That is the one where you have the highest pressure because you have a high need for action but a low maturity in that area. These are the capabilities where you should start working on. And that is also then easy to explain to your management. The second then is where you have a high need for action but also acquired maturity or that is what I would call maybe the quick wins. So you see a high need for action, you're already quite good at this so you can, I don't know, pick some benefits in that area.
And then the last one down below here, these are the ones where you don't see a high need of action but already very mature in that area. That is something where you're probably fine for now. Maybe look into that in three years or watch it. When it then comes to define your actions and initiatives, I think the reference architecture really helps because of the focus is put on certain capabilities. It's not just that you say we need to improve access governance and nobody understands what that really means.
It is really looking into each capability, understanding some challenges and questions you have there. Have your status quo there and you define your organization specific target state or do a benchmark and based on that we can then really derive concrete actions initiatives. Not just saying something generic as I explained, improve access governance. You really talk, I need to improve identity information quality management and that is the action and that is the initiative we need to set up to get that done.
I think that really helps then to close the gaps and not just have kind of generic initiatives running. We are quite uncertain what then the final result will be in the end. Once you define that, I think then this is kind of a project charter which is then the easy part. So you have your challenges, you define your project goals, you have specific actions not just general things going on here and important for your management usually is then what is the impact if that is not done. I mean all that is not specific to how to say to identity access management.
I think that's good project management practice but having those capabilities and the focus to the exact capability really helps you to make this unique and precise and not too generic. And once you have done all that together then the final step is to in a discussion put that on the roadmap.
That might be again the hard part because then you go to discussions with your management like funding, when can we do what, do we have other initiatives running in our companies which are maybe more important, how to assign the resources but you can then do all these discussions because you have your project charter, you know exactly what you need to do and you exactly understand what you lose if you don't do that. And with that let me wrap it up what I explained over the last 50 minutes.
So what I want you to really take away from how you can use that within companies is first establish this common blueprint. So you have your terms, you have your definition and you speak the same language and then second you get structure and clarity. You have a clear picture of where you are with your identity access management at the moment right now in time. It's not confusing, it's not yeah I don't know if we manage NHI or not you have a clear understanding of what's going on there.
Then target operating model I've not discussed about that too much but that is something which is coming up over and over again and by the way my colleague Patrick will have a speech on that on Friday I think. On Friday very interesting recommended to go there talking about the target operating model and that is also what Philip explained. So how make we this thing going live, how do we assign the responsibilities, who is doing what in my company and if you do that based on our target operating model and the underlying identity fabric and reference architecture that really helps.
And then for the architects of course you can look at current architectures or define new architectures based on that and then again I mean every architect knows if I'm talking to separate the what from the how everybody knows what I'm talking about. And I'm yeah more or less I started my career as an architect and I like this the most on this from this identity fabric and reference architecture that I can separate the concerns here very easily. Yeah with that I would like to hand over to Christopher I think talking about trends if I'm correct. Yeah perfect thank you Rainer.
And before we jump into the next section, short hint the QR code is also related to a Q&A session. So if you have any question to us it is planned that we have 10 to 15 minutes before the break really to discuss with you things around capabilities whether you understood the framework or have different views on that. So feel free to use that we can see then the questions here on the tablet we have and then discuss this in the group. Trends. So we are an analyst company and before I jump into the slide of last year's EIC for a short recap.
In the rating you ask for what was this the second level reference architecture you talked about something like a genetic AI. So I highly recommend to join the keynote later on just a short hint. These trends here are from last year so it's EIC 25. Pretty sure we will have another slide end of this week or maybe starting by next of week next week but you see many topics around it. So we always have some different views from advisory perspective we work with customers we have everyday topics.
When you are an regulated organization you are usually a bit more behind than a non-regulated organization especially organizations that now have to deal with NIS2. That's new for some of them they have challenges and this is why this trend section is really interesting because sometimes reality what we talk about a genetic AI I'm pretty sure all of you in your organization have that issue or NHI stuff but on a different level and the preconditions for dealing with things like that is really different.
Some of you don't might maybe you are all good in class might not even have a good repository of what kind of tools do I have rather than the taking care of identities at all. So this is really the different levels and we will see later in the maturity assessment part where we dive into potentially that's my expectation how different the levels are at the end. So last year NHI was the biggest topic there are different figures around like every human identity has up to 40 80 non-human identities plus those you don't know and how to deal with them is a big thing.
The identity fabric as Philip explained covers non-human identities but doesn't exclude you from taking organizational aspects around that I mean basically from the foundational idea and non-human identities also something that needs an owner that needs some kind of life cycle with a little thing that a non-human device even if you take something like a fire detector or smoke detector or other things the lifetime of those things is pretty fast we are not talking about a human that joins a company is there for I don't know four months up to 10 years or longer we are talking about sometimes seconds or minutes so the typical processes we know from humans do not work and also the tools classic life cycle provisioning have challenges but it is related somehow.
Then the proving of the identity was a thing and then for sure this will be also a topic a bit more mature this year agendic AI.
So last year it was like okay I have jet gpts I have something from Claude I'm trying something to figure something out the reality is I'm pretty sure all of you also in the security departments tried and played around with that to defense the organization to automate processes not on a workflow level so really on a level of AI so not an automation thing here and doing things and the challenge for sure is and that is what we all realize in our everyday business we have not that level of control of what these agents are doing and even worse agents can duplicate and create another one that one is doing something and we need to have something like guardrails and a clear understanding and limitation.
Basically we should be that restrictive to agendic AIs as we are for humans and the reality is ah play a bit around with Claude oh cool I can connect it to some CRM tool oh cool it's checking time sheets and what happens in the background 10 agents started doing things and security is trying to defense somehow and preventing from IT perspective doesn't solve the issue also topic that was what Philip mentioned evolving of the identity fabric so the CM reference architecture identity fabric was announced last year we improved or worked on their normal identity for identity access management as well yeah I think basically Philip anything to add from the trends perspective yeah for me outstanding is the the modern authorization models so what we can see on what we have seen last year is the trend towards dynamic authorization especially with agentic AI and and all the real-time actions that they are doing this is becoming much more important I will have a talk on Friday about that more from an authorization model perspective but what we can currently see is that authorization models especially the real-time authorization models are becoming much more important so we have seen that obviously already last EIC but we are now one year further and and it's becoming more and more important so we I cannot stop repeating that to be honest and this is also something then when we have figured that out for the for the agents we can also apply that to human identities obviously so I expect to be honest I expect that authorization models will drive our authorization landscape and and the maturity of the authorization landscape for all identity types a lot in the next couple of probably months or years next two or three or years next two or three years what we have seen with DORA is also B2B trust framework so securing your supply chain that's also an important piece we have learned based on the agents that not just your your own organization is a threat to you but insider threat and and inside insider threat in terms of the supply chain is also very important so you need to have an idea how suppliers are organized how secure they are and which kind of B2B identities you have within your organization but also how your suppliers are organized and secured so the B2B trust framework one word that is important with that is a federation approach for example what is it what you need there yeah and the last one on the list decentralized identity that has been yeah not a buzzword but but a trend for a couple years already this is still a thing but to be honest agentic is much more important right now and still decentralized identity is not going away so when we are talking about wallets about the UID this is this is still somewhere being developed and on the radar good these were the trends for 2025 meanwhile we have used the time to research on that a little bit and that is what we are sharing now and first of all before we jump into what we share right now also short recap on what Rainer explained why these trends are important so maybe I jump back as we have the time today it is the where's the trend slides this one right we changed it cool okay so it's potentially this one basically the idea of the identity fabric is to build a framework for those of you who joined last year's EHC there was the opening keynote by Martin talking about 2040s identity fabric which was what was the calculation two years of planning and one of these identity and access management capabilities so one of these things three years of building implementation typical IGA thing and then 10 years of use which means decisions we make today we have to deal with within the next 14 years not right now but 15 years at least that's the current state of the art it changes for sure it changes but that is something you need to deal which means I need some kind of architecture and plan that also have thoughts about trends to be open and flexible and adjustable that's the main thing of the identity fabric or all the other fabrics and that is the cool thing by okay we see there is a genetic AI there is NHI there is DID and all that stuff relevant we are open for that and the truth is as an analyst and advisor I can tell you we don't know what happens in 10 years but we can make assumption and I really love that recap that we created here seeing what was announced last year and if you have a look at EICs five years ten years ago many things happened not 100 percent and not in the speed of the same speed in all organizations that's what I meant was like whether you're regulated or not and at the end already saw we have a good question related to that what is the benefit of doing this how can I pay explain my management from identity or cybersecurity perspective that I want to invest money into something specific like okay I want to do that when you're in retail company you want to sell products and invoice that's the thing first of all not a good idea by the way but that's the idea behind okay again the the hint if you have questions use the QR code we have some time today and then jumping into the key research findings Philip will support me here for sure what we found can we zoom in a bit for me please my eye is a bit dry so otherwise I need to look in that direction which is not very nice perfect thank you so this is basically what happened in the last 12 months maybe 14 months in our research and statements to non-human identities in the past we had multiple workshops we also had an impact day around that and non-human identities was have been the big topic last year at EIC and over the year agentic AI is now more or less part of that or not depends on how you define it but NHI identity management is maturing more or less there are specific frameworks around that especially for authorization also syndication covering the speed that I mentioned that the normal life cycle stuff the normal IGA solutions you can use are not working anymore the second one I spoiled it already that's what I said it's something like human identity has related 40 to 80 or depending on which study you take non-human identities plus the ones you don't know and the challenge with the NHI stuff is even on a governance level or you need a governance level that if you are not good in IGA or classic identity and access management how would you be good in NHI it's related you need some kind of responsible person or department in the worst case and having those things whether it's an agent whether it's an OT and workflow without a governance layer is this thing allowed is are the permissions the entitlements that are assigned still valid is this thing still needed or not is really relevant because on the other hand if an attacker joins an organization joins attacks an organization in the first place they are looking for especially those technical stuff and jump from step by step to privilege to even more privileges in that case especially around the 2040s identity fabric the part like what was the calculation two years of planning and four years uh three years of implementation for today's needed speed especially around agentic AI that's too slow and that is also covering the opening keynote last year covering the opening keynote last year the fully mesh we haven't prepared that for for today but it's accessible on the research site where you really also go into towards something like dev sec ops for the identity fabric so there is a need for a small new capability maybe as part of lifecycle whatever for NHI things and then you add it as a service-oriented organization layer to that small thing and then it usually should not take longer from idea to testing to go live than two weeks four weeks something like that and not like five years and a lot of budget and planning and things like that at least for the smaller things but that's not part for today's thing session yeah basically that's from my end maybe philip wants to add something as well not not much to be honest um when we think about the scale um i have a couple different numbers but as christopher said it depends highly depends on which source you have um my numbers are mere one normal personal normal identity and on the other hand we have 150 agents already so that's 150 agents already so this number is growing very quickly i heard growth rates from about 10 per month at the moment um because everyone is trying agents and they are popping up right and left so this is definitely that that number is definitely increasing so 40 is probably from the beginning of the year maybe um this is something we need to be aware of but when it comes to the questions as christopher explained we we really have the same questions for agents as we have for human identities who are you what what are you trying to do and how do i govern that so in the in the end we need to answer the basic questions the only thing is that agents are doing that much faster at the moment than we can work with it so what we have right now is we have agentic ai that is behaving like a human so they are doing it at the same speed or even faster most of the time faster um but our current landscape is built for pretty much static slow a slower approach this is why we see the the trend towards dynamic authorization because every time we put a human in the loop we lose the advantage of speed that an agent has so think about agents being used for for audit capabilities trying to defend something against attackers so the attacker will not wait for the agent or for the for the human in the loop to say yeah you are allowed to block that session that is probably too late so we need to ensure that the authorizations that an agent gets are in real time and as you can see from the points here from the top to the bottom there's a storyline behind that right we still we need to know what agents we have well guess what that's a familiar question because we also need to know that for humans right so that's the same for agents um we need to ensure that we are protecting the risky areas with our defensive measures that's the same for humans that's the same for for bots and agents the only thing is the capabilities are more advanced that's the thing so what we are doing right now is we are trying to figure out what is the governance that we need for that what are the life cycles that we are the life cycle stuff that we need for that and then we need to know who is trying to do that first vendors are trying to come up with solutions for that as we speak more or less um you will see that outside that pretty much most of the vendors have that on their radar they are trying to come up with solutions if they don't have a solution yet they will have it on the roadmap in the next six months probably or you should change your vendor um but but that is that is important right everyone is working on that i think that is an important takeaway good then we move on um we have said 2025 um identity fabric was an important topic it still is an important topic these frameworks provide structure they provide an overview that enables you to navigate iam that has not changed these frameworks are flexible we are updating them regularly and we will keep doing that with the second level reference architectures we are coming up with new perspectives for new identity types for new challenges that you may have that is what is happening so as i said we have the second level for scion published that also covers b2b and all the c identities so this offers a new identity type a new vision towards iam so who is whoever is interested in that that is on our website you can find that there if you don't let me know then i can help you um so second thing here on the slide is what we have also seen in the polls is that agentic ai and nhi in general is a very important topic to everyone i would say we know that we are aware of that we have a draft for a second level for nhi and especially agentic ai but we feel that this is not ready for publication yet because the topic is still so much developing there are so many changes we are learning new stuff by every week basically um so this is why we have not published it yet but we are working on different um capabilities on on the second level reference architecture and i hope that we can publish it soon but right now the takeaway is we are working on that so third thing um privileged access management we have not talked much about privileged access management so far um from the poll i know it's it's not so interesting for most of you um you might want to reconsider that because agents agents and especially agentic ai often has privileged access so this is one of the important defensive measures that you have right now and that's basically what is written here privileged access management is changing right now as we speak we are moving away from just password vaulting and simple human session management towards agentic ai control features so it becomes more and more important to ensure that especially the high privileged agents are secured that is what pam is currently evolving towards i say it evolving not everyone every vendor is already doing that but what we can expect especially for agentic ai and the solutions that we see in that space that pam is an important component of that from a capability perspective there is quite an overlap so last point on this slide um and that's the one i was looking forward to the most is that i'm allowed to announce that we will update the identity fabric and reference architecture um in the first quarter of the next year that is our plan so we after eic we will sit down and start the the update process this is usually a lot of discussion with all of the members of coping a co more or less because we have different perspectives we have martin in the discussions we have jonathan in the discussions we have christopher in the discussions we have our experience we have our perspective and that's what we are trying to bring to the new version plan is to publish that this by 2027 so stay tuned and i hope we can announce that by the beginning of next year like we did last year but we have one more announcement and that is do you want to i want to so then i will go for it this is our announcement for today um as we are talking about the identity fabric and reference architecture so much and we figured out in the past that just a report or a research paper on our website is not enough to to keep everyone covered especially since it was behind the paywall we moved it and changed the visuals a little bit so we have pretty much released it i think friday on our website that the identity fabric and reference architecture is now freely available for everyone on our website again you can click on the capabilities and you will get all the information that you have just seen on the slide so every capability is explained on the website you can use it and if you have questions we are there for you and that's our announcement the qr code will directly bring you to the website good that is basically what we have for the first half we have received a couple questions we will answer them but before we do that i can already explain what we are doing in the second half so we have triggered we have teased it a little bit already and you have seen the description but what we will do in the second half is really walk you through the coping a cold maturity assessment we explain what the five levels maturity assessment is what the criteria the 12th criteria are that we use for a maturity assessment per capability and we will show how that works as a process then we have lisa she will present how it worked out for fresno and then in the second half of the second half we will do that with you for the capability access governance so we will walk you through we'll explain what the capability is what the criteria are and how the criteria unfold we will again do that interactive so you can vote and see how the maturity is for everyone and see where you stand that's the idea for the second half so now to the questions perfect and as i have the tablet i can ask philip the question no we do a mixture maybe also ryan i want to join um first of all thank you very much uh really good questions um while we are asking still the opportunity to ask more we have brought about 20 minutes or maybe 15 if you want to jump into the oh we can see that that's perfect okay so it is changing by rating let's start with the first one how do we refer capabilities which one is this uh refer capabilities to risk and value elements the management is not going to buy in improving erm quality without tangible benefits or risks do you have such typical mappings philip is this a question for you or rhino because i would have an answer i mean i can go for that um this is an interesting question because it links benefits to what we do with the reference architecture usually i start my presentations with a different slide the drivers for i am because it's important to understand what we are doing and i am why that is important for organizations so the three drivers that you can always come up with from a general perspective when you're talking about iam is something like business value or operational efficiency so you get better faster less expensive usually and can react quicker the second one is security so obviously i am still a security topic even though some people some managers don't believe that so it's our duty to protect the organization so every benefit even though it is somehow a theoretical thing is that we reduce risk risk measure measurement is the thing yeah but when we reduce risk that is also a benefit and the third thing is and that is always forgotten we need to handle certain regulations so in the end dora is two when the auditors come and say you are not good enough that means money is blocked in the end so you need to secure the risks um so coming back to the questions do we have such a mapping not as a template but when you are doing a maturity assessment you get very quickly to the point that you see where you are and what your challenges are and this enables you also very quickly to say dear manager this is our challenge right now this is what we are not good at and that means the following risk with that risk the benefit to improve on on this or that capability would mean this and that we become faster less expensive we become more secure we are able to pass a dora audit there there are possibilities um it's it's hard to to to say that on a um on a framework level though yes of course we can say identity life cycle management if you don't have a good mover um overprivileged identities are a consequence yes but your manager will not buy that so you need to become more specific as an as an entry i i would recommend to have something like a maturity assessment but that's again what we will show in the second half and an important point because i think that is about um how to get the funding and there are two important other business drivers to that there's not just only risk and i've seen the company who was i worked for them um purely driven by risk and that is not the whole story about identity access management there is also the business value and there is compliance um in there um and um i think that's also important to also put that then on the table because risk is really hard to judge so because um you need to understand then what is the um sorry probably probability yes so what is the probability for a certain risk um that it really happens and behind that what is then the impact to the company what does it really cost you if this security risk happens to you and that makes things quite hard and that is why i then recommend also talk about the business value of identity access management the innovation behind it and also talk about um the compliance and audit topics which also drive identities and assessment and now i can add a business value as well um seeing the opportunities so management um i mentioned this is an example about retail they want to sell their products and if you can speed up that's what philip said the efficiency um and all that stuff maybe with less expenses at the end because you're faster you bring additional business value you are the business enabler as identity and access management then you can convince managers as well so really one thing that's three four five six years ago identity and access management should not be an it department topic that's in compliance topic at minimum on the best level it is um that organized as an orthogonal layer like enabling the organization in being in delivering value to customers internally external audit stuff okay so i think if i click that there was an interesting one that was interesting about isn't that too academic i wanted to yeah yeah that's the next one okay i want to follow also the questions from the rated person so the next one more is are the identities of business partners positioned with a museum or through a specific b2b tool now everyone is running away i'm about to answer yeah i want to answer another question so okay then philip um yeah identities of business partners within siam or through a specific b2b tool that's an interesting question one that i struggled also in the past years with um when we see our i mean i'm referring to our research when we see that we have the siam leadership compass um in there you find the capabilities that are covered by that the interesting thing in the past was that we had just this one document but for both disciplines that means that in the report there was the spider graph and for most of the vendors it was either or so either they were covering the the c identities the classic c identities or they were covering the business partners that made the spider graphs looking quite interesting because they were always filled 50 depending on the focus of the vendor so we have changed that now we have two leadership compresses for that one focusing on the c identities and one on the business partners so the question then is quickly answered um c identities as explained in the identity fabric have different requirements than business partners that means you need different capabilities then you need a different reference architecture you need different services and a different tool most of the time when you try to handle your c identities with your b2b tool or the other way around that will not work because b2b identities are much closer to workforce identities why is that the thing and that's a thing because consumers usually don't have access to critical data or critical applications obviously that means that partners that are accessing these applications have a much higher requirement when it comes to authorization depth obviously and that makes them much more comparable to workforce identities than towards the c identities that's also a thing that vendors learned in the past and that's why there are specific tools for b2b identities however some of the iga vendors also have modules that enable you to do that so everyone that is working with guest accounts and entra knows what i'm talking about but that's that's just the tip of the iceberg so real b2b identity management modules and tools can do much more than that good and i think that answers the question okay then uh it's changing again it's changing again uh nh i are all over yet you see leading iga product products not supporting for instance group managed service accounts in ad or managed identities or agents agent i the gentic ideas in entra why is this from your perspective and how can we influence so the death road yeah autocorrect is the cool thing here hopefully no influence yeah um also an interesting question that we asked ourselves um what we can currently see is that the vendors are also developing as we speak i've said that earlier we see that also for the iga vendors um one thing that i said earlier is that dynamic authorization is becoming a thing most iga vendors are not yeah not capable is a little bit hard but they have their challenges when it comes to real-time evaluations and managing therefore managing agentic ai but i think to answer that questions there are two things important to understand um the first thing is agentic ai is probably just three to four percent of your landscape at the moment i know it is increasing i said that by myself a couple minutes ago but at the moment you still have 90 percent of your landscape working the old old way this is still there agent don't make other identities go away they still need to be secured so ij will not go away um the other thing is that as said we need modern authorization for agents so that means dynamic authorization at real time fine-grained again i will talk about that on friday so what does that mean the ij vendors are also talking to us obviously and they are aware of that challenge so as that most of the ij vendors have a roadmap agentic eye is on that so save point i think they they announced that they have such a module like two weeks ago yeah and and others have that on the roadmap question is on the roadmap is not there yet so are we insecure well you need to talk about that with your vendors but we see a move in the market so the vendors are aware of that they are moving towards that the important question is for the ij products do we see a major shift in the market now i personally would say yes we see a shift here um the the other thing that's important to understand about the market there is not just an ij market in the authorization space there are also vendors that are doing real-time authorizations already but that works a little bit different that's that's why it is a different market but interesting to draw that i can also add to that um because it was also about the non-human identities there and philip explained that also in the beginning that non-human identities also have a stronger relation to privileged access management so because non-human identities often have privileged access and that is why um yeah not only we as analysts see their relation because also the non-human identities need kind of a different access to identity information which is a little bit more comparable to what privileged access management tools provide and that is why then also i see that privileged access management tools are also jumping into the direction of the non-human identities so i'm not sure where the market will actually really go there but that's what i observed that privileged access management different uh definitely is also yeah a tool or an area of tools a market looking into the non-human identity management um topics here um maybe christopher if i can catch the question which is no longer here because i find it so interesting it was mainly about it was no i do it anyway right so it was something like okay isn't that a little bit too academic year and 12 criteria and five levels of thing and do we lose context here in the end and the question is i think the comment is fair so the thing is maybe slightly a little bit um academic so when i started using that i think it is already now five or even more years ago way before i joined kumpinga coal um and i was asking myself is that a little bit too much and in practice the good thing is it has a very good flexibility and we also have the three levels which is the ample style which really helps then to tailor this to your needs onto what you actually want to do based on that and there i think and there's good reason sometimes to really deep dive into this um five levels but sometimes you want to stay on this um on this upper level so as i don't remember the rest of the question i'll leave it with that perfect um so it is always important to have a plan b by the way that's the tablet in that case so you need now to trust me that the next one is the most rated one as authorization becomes more dynamic and real-time and cross-cutting do we need a neutral policy layer rather than more point features inside identity and access management and api products this sounds like something for philip short please as we have two more shot yeah yeah i will combine it with one of the questions that is still in there and i was talking about zero trust so when we are talking about dynamic authorization and however the question was phrased but it all gets back to to zero trust so we need to ensure that we have more checkpoints so policy enforcement points in the way and we regular check the access especially when we think about real-time decision making we will need these decision points or the enforcement points and the decision points somewhere to answer the question do we need a neutral policy layer that's something that we currently discuss as well and we will certainly need something like that if that needs to be central um there are different opinions on that it it will certainly help to have that centralized the question is how manageable is that in the future and if you can do that in a centralized manner what we certainly will need is a couple repositories that we concentrate on when it comes to policies if we can do the same thing with policies than we did with um with the iga and with roles that is something that we will figure out in the future yeah and the interesting thing is we are talking in the same track on friday exactly about that topic and i will especially touch the last point you say in my speech talking about okay if you have this policy layer who the hell will write the policies if you want the answer come to the call or to the presentation isn't the answer ai is this not the answer oh we could give it a try yeah let's control the idea i'm sorry for spoiling again that might become some kind of this topic future then i don't know if i want that so next question maybe i also take time to answer the last one do you think ai will eventually govern nhi maybe we do a voting first who thinks think that's a good idea raises the hand um no one did you understand the end of the question it was not a trip yeah i think uh interesting question and not that far away i mean what is the challenge the the best thing uh of having an ai it can detect uncommon behavior for instance it can detect unused things um so deprovisioning whatever um turning or disabling nhi things in that case or um supporting and creating maybe inventories like detecting what is going on there something like that but normal governance like okay um is this thing allowed these days needs usually also from a regulatory requirement a responsible person and an ai is i would say not a responsible person even if you delegate it uh to some one um so that is the main issue you need to deal with and uh in that case i would agree to most of the people that didn't raise their hand it's not the best idea right now anything to add one minute i can add stuff i would ask with the counter question um are we able to to do it without any without hai um that's the most the more important question from my perspective um because the human in the loop is probably not the answer i said that earlier when we are attacked we need to react in in milliseconds probably yeah um that's not nothing that the human in the loop can do um however in the end i mean we will need ai at at some point to govern all of that but we need to be careful how we do that otherwise that will be a disaster we have seen ai doing stuff that we didn't anticipate in the past terminating sessions would be one of the things that i would expect when we have a wrong setup here for example and you know how how happy users are if you are terminating 50 of their sessions and that's the thing that we need to be very careful with um and that's basically the thing you need some kind of um guardrail or you would need some kind of guardrails of what does this mean one minute left so 10 second question you're referring to the fact that that basically exactly means uh like okay what is this kind of agent allowed to do and when and why and pretty sure at the end these days you need some human person who then verifies this decision at the end or what happened okay but it is for sure as philip said in this you agreed much faster than something else okay and that's what i mean with the setup so in the end we need to ensure that that doesn't happen in the end perfect okay just in time finished um we will continue at 11 o'clock and uh would be happy if you join the second part as well have a good uh not lunch break coffee break and in 30 minutes yeah and we have here the giveaway so grab your identity fabric over here and some stickers if you like thank you