Okay, so good morning. I think we got many languages, not all of them, but it's wonderful to have you here. I am going to, as we get started, I'm going to ask of you one favor. If you're slightly hungover, we will keep this favor easy for you, but I'm gonna ask you one favor, please. Please stand up, please stand up, thank you.
Now, if you're in these front rows, do nothing. If you're in these back rows, please do come forward to the front section of the room, and then we will get started.
Wonderful, thank you so much for indulging, appreciate. So, welcome to our workshop. This is our mighty community opportunity to come together to discuss IDPro. We'll do a bit of a retrospective, see what has changed over the last 10 years. Can you believe that the organization is 10 years now in operation?
So, we'll share some of those aspects of what's transpired over time, and then we do have opportunity to have a bit of undiscussion, so some interactive discussion with this room to take in your feedback and bring your perspectives into the front of the room. So, that'll be a bit of our agenda for today. I see a lot of familiar faces, but is somebody new to IDPro that has never joined before?
Okay, that's awesome. Some of you are lying, some of you are liars, but that's okay, please make friends.
So, since you've lied, it makes it hard, but if you saw someone raise a hand that it seems to be new, please make a friend with them. That would be wonderful.
Okay, so a little bit about IDPro. So, 10 years ago, Ian Glazer, hi, Ian, gave a talk about the future of our industry, of identity management and access management and all these words we love to describe it.
So, our space for who we are and what we do and considering that, and I was privileged to be a part of some of those early discussions. I think a lot of the focus came out of recognition that we didn't necessarily have a curriculum, a track, a school of where we were learning the arts of practice, be they technical policy, business angles, and quite often, our space, identity management, is kind of a part of another space. Maybe it's human-computer interaction, maybe it's cyber.
So, we tended to fall as a part of other strategic or other operational segments within an organization, that identity management stuff, and not necessarily what these capabilities do as a horizontal across an organization, what they enable and what they empower, in addition to what they protect.
So, as an organization and as a community of practice, to be strategic enablers, we are all challenged to how do we contribute and demonstrate top-line growth within organizations, how can we decrease the cost that organizations face, and how can we, in our practices, increase customer, client, and service satisfaction. So, it's all about value delivery, and I'm incredibly keen to listen to you and work with you on what your perspectives are on the order of priority and what value delivery looks like in this new ecosystem that we're in.
And, in the early days, Ian and this community argued for professionalizing this industry, making sure that we know who we are collectively, that we have an opportunity to recognize each other, to build expertise, to build camaraderie, to talk about the problems that we're trying to solve within our organizations, and the strategies that we're taking that are actually working within our organizations as well.
So, just having that sense of community, being able to recognize each other, and I would put forward as well, we still have even more room to grow in terms of recognizing others who may not necessarily even consider themselves to be identity practitioners. In fact, I think there are a lot more out there of us than they might realize.
And, in that line, identity is, of course, part of a broader community, from privacy, security, business growth, enablement, and more. So, it's the leg of the stool that is keeping the stool ahead and keeping us moving.
So, did I go past my slide? No. Okay. I didn't make it. It's still recording.
Okay, this has imagery. So, this is the IDPro was born slide.
So, out of those discussions around what would be the future of IAM, would it survive, who would be the people and organizations that would work together to not only take up that mantle, but grow that ecosystem further, came the IDPro. And so, there is imagery here, a birthing of sorts, of a community, a community that is woven together with diversity, with a lot of different interdisciplinary skill sets.
So, at EIC, the organization was born. So, it's very apropos that we are here at EIC again together. And the mission was to globally foster ethics and excellence in the practice and profession of digital identity. And I would argue that we've done so there. And primarily, how are we delivering?
Well, we're helping to curate each of our peers and our friends in this ecosystem and industry, supporting them as they're developing their, we have conference talk mentoring. So, not only the skill sets of delivering insights into audiences to draw that knowledge further, but how do we refine our ideas? And how do we test our ideas for their validity? And I know that many of us are constantly pitching each other on what our thoughts are and which direction we think that this space needs to go. Supporting speakers bureaus.
So, again, it's about getting the message out there, telling our story, and seeing what of our story, I think really important as well, seeing what of our stories resonate. I know for sure that in some of my experiences, when I'm saying, a customer will say, well, I need to be able to talk to 10 people and browse the web at the same time.
Okay, you have this thing, this will do it. Oh, no, no, I don't want that thing. I want this thing over here.
So, it's really that exchange of information. What information are we working to get across to support our mission, to support our industry? And then what's resonating back? And are we meeting in the middle?
Now, really, really key here is the body of knowledge. So, if you're a part of IDPro, you're aware of the body of knowledge. Some of you have contributed to the body of knowledge. If you're not a part of IDPro, go and peruse the body of knowledge. It is a living resource to help you learn more on the practices, the profession, the lessons learned. It is something that continues to grow and evolve as our space continues to grow and evolve, as the technology practices grow and evolve.
And we're always looking for what types of articles we need to curate and what is that knowledge that's going to help our community on the way forward as basically an industry-driven curriculum. And then, of course, the vendor-neutral certification, so the SIDPro.
So, do we have SIDPro folks in the room who've gone through? Yes, yes, yes, amazing.
So, if you have not, have a look at the SIDPro. It is the leading certification program for identity management professionals in the space. We encourage you to go through the certification. If you're a company, we encourage you to become a member, join the organization, offer the certification through your community, because not only is this about supporting our community as a profession, it's supporting matching into those vendor opportunities and building up those expertise within enterprise, within organizations as well.
So, SIDPro is also a growing and evolving offering that we would love you to take advantage of as well. So, now, this is a small group of values and benefits. We have a very active community value, community sharing information and value through our Slack. We have the IDPro meetups.
So, there are lots of different channels. And as we go forward, and I'll hand off to our fantastic new ED, Elizabeth, who many of you know, we are always looking to how this organization can and must evolve, because if we're not changing, we're moving backward, and I think that stands for everyone.
So, that stands for IDPro as well. So, you know, and I'm chronically bad. If you don't know me, my name is Joni Brennan. I always forget to introduce myself when I have a microphone in my hand.
So, if you don't know me, I'm Joni Brennan. I'm the current, honored to be the current board of the chair of the organization, taking over from the amazing Miki.
And yeah, I've been in the identity management space for 25 years or more. And so, it was a real pleasure and honor to see this organization take shape.
And so, I am, as I plug the importance of evolution and what comes next, I am selfishly listening to the conversations through this conference, through the channels of Slack, through our discussions as to where and how IDPro is supporting our community, what is working, and where and how we can evolve and add and grow and add more support for this community, because we're all evolving along with a world that is changing pace. And I promised I wouldn't draw AI in too much, but let's face it, these technologies are really changing the shape of what we do as well.
So, all right, with that, I am going to hand over to Elizabeth, thanks Elizabeth. Thank you, Joni.
So, with that, look back at where IDPro began and the value proposition that we started with. We're gonna talk about how stuff has kind of changed in the last 10 years. Have you noticed things have changed?
Oh, really? Yeah, I think so. We went from Twitter to X and chaos ensued. We went from cubicles to working from home to having to go back to work. We went from selfies to AI headshots. We went from Google to LLMs. And apparently, this is okay now. Have you tried it? Apparently, it's good, you can do it, it's allowed. And a lot has changed in our industry as well. We went from malware to ransomware as a service in terms of the threat landscape. We went from basic phishing emails to deep fakes and everything that came with it. We went from OTP to passkey.
And then I got bored of finding pictures, so I just made this huge list. We went from our back to policy as code, panfalls to ephemeral creds, static entitlements to just in time, access reviews to continuous governance, federated to decentralized identity, token expiration to continuous auth, service accounts to specific spire, workload identity to agentic identity. All sorts of things have changed and you guys could probably come up with more or better or argue my language here. That's fine, you may. Importantly, we went from computer scientists to prompt engineer as well.
Our skills survey, which we've been running now since 2018, suggests some things are changing and some things are staying the same. In 2019, identity as a service and cloud-based systems were our top trending. These are things my business is actively learning about and looking to do. Strong Auth was up there. Customer Identity and Access Management was up there.
PAM, Lifecycle Management. Now we're hearing, and that should say top five in 2025, by the way. We have our 2026 survey live now and I would love for you all to take it. But in our last year's survey, authorization bubbled to the top. Strong Auth was still up there. Governance, IGA, was rising. PAM was still there. And then risk-based and continuous authorization or authentication was a top issue. There are some new things showing up in the verbatim comments. Things like, how are we gonna manage identity for AI agents?
How do I prepare for the impact that VCs might have in the next five to 10 years? What am I supposed to be doing with that now as an enterprise? But then other things are staying the same. People are still telling IDPro that they need mentorship. They are still telling IDPro that they are desperate for peer-to-peer mentoring opportunities. And vendor-neutral training materials is still really, really important to people.
They are constantly in our survey asking the question, how do we work together to make this talent pool, to build the talent pool in the first place and to help people continue developing as our industry changes faster every single year? And then we often get questions from people who are new to the field of like, how do I even start? You have to have years of experience before anyone will hire you in this field to do anything. So where do I even start? We're hearing that just as much today as we were 10 years ago when the organization was founded.
We are also seeing a growing crisis of confidence among professionals, especially the newer-to-field professionals. The red and the blue, those are earlier in their career. But this is the percentage of people who say that they don't feel proficient. That number is growing, and it's growing among every single group, albeit not the middle list of managers. They seem to be doing fine. They feel fully proficient. But everybody else, that gap is widening. People are saying it takes longer and longer to feel like I really know what I'm doing, and actually, there's some big stuff happening out there.
I'm looking forward to getting that statistic this year in our survey. And so now, with everything that has been changing, you guys have been along for the ride, all of you, and if anybody else wants to hop on up here in this panel, I think you'd be welcome, especially if you've been a board member. We're gonna do a little bit of a Q&A. I might pop up this list of stuff that's changed again.
Oh, there it is. All right. We do need to use the microphones in case there are people listening online, so please make sure your microphones are on and that you have one. And then let's just go down the line and introduce ourselves.
Joni, chair of the board, you've already introduced yourself, but you can say more if you want. Joni, chair of the board, I've already introduced myself.
Oh, I'm also the president of the Digital ID and Authentication Council of Canada, which I also forgot. I'm bad at this.
And yeah, that's me. I'm Bertrand. I've been doing identity consulting for more than 20 years now. I was there 10 years ago, and probably the reason I'm still in the industry is that the community exists, and I witnessed that 10 years ago, so thanks a few of you that are in the room. Thanks to everyone in the room, because you're building and you're making this community alive, and I'm happy to be here in 20 years, just before I retire. Anyway. I'm Miki Bronsler. I'm a senior product manager at the National Australia Bank in Australia, but also former, what is it, chair of IDPRO.
Very delighted to be here, and I'm probably a newbie in terms of IDPRO because I didn't know that existed until Alan Foster came to Australia maybe three or four years ago. Olaf was there, dragged me into this meeting, and I went, oh my God, there is an organization for professionals, so that was my introduction, and yeah, great to be here. Thank you. So we'll go down the line again, or we won't go necessarily in order. Anyone can start. What do you think, from where you sat, have been some of the most fundamental shifts in the industry, or you can name one if you like.
What has been one big shift in the last 10 years that has mattered to you in your work? There's a big cheat sheet behind you.
Yeah, no, I mean, I think that there's lots of big shifts, and I mean, look, I came from a time of Liberty Alliance, where I was a program manager of software engineers, many of whom are luminaries in the space at the frontier, to Contour Initiative, to lead Contour Initiative, to DIAC, and in that time, I think that the, if I was picking some very, very fundamental changes that have made a real difference, I think it's kind of the centralization versus decentralization.
I think that's kind of arguably the largest paradigm shift, and all of the policy implementations and responsibilization of the assumptions about end users' ability, desire, to be able to manage credentials. So I think decentralization versus centralization, which also then gives rise to wallets and credentials, which is largely what this conference is going to end up being about, so yeah. Mm. I would agree with decentralization.
I would say that we went from on-prem to first generation of cloud identity, and now we are in some kind of second or third generation of this, so this is a major shift. And another thing is about how we are perceived in the enterprise. Our identity is, I think, finally perceived as central or essential to cybersecurity. It probably was not the case 10 years ago.
It was, yeah, sometimes identity, someone thought about identity to do secure things, and I think now in every use cases around the enterprise, identity is known as to be one of the key, if not the key to secure things. Cool, the thing about being last is I can say, all of the above.
I think, yes, the decentralization and things, but also the federation that's coming in, and especially in the sort of the financial area that I'm in, also bringing in new technologies and things like that, especially for the common people who rely on not just digital assets and things, but we have to think about what we do with the people who are not digital, and that makes it really difficult. But at the same time, we have to move ahead with the time, so we're trying to bring in PASCs and things, which has been a big thing for a while.
And of course, there's AI coming in now, and that's gonna make it a lot harder for us as well. So yeah, all those things have come in.
Oh, the other thing is, like a few years ago, it was all about authentication. And then the last couple of years in the conferences and things, it's been about authorization. So it's always moving, I think, from one thing to the other. Can I add something? No.
I mean, yes. I'm going to anyway. So with those two pieces, I think in a sense, I would love to say that identity is being, my own experience that I see identity being recognized more as a part of the essential ingredient to moving an initiative project forward, service forward. I do think that I see identity present in everything that is in front of me. I don't know that the party on the other side is necessarily calling that identity. So it's good to see it there. Is it being called that?
And then the last thing, and I'll toss to you Bertrand, I did go to Money 2020 this year, and the entire conference was about identity, but it was about identity proofing, identity verification. They weren't calling it that, but they were doing all kinds of services, pulling all kinds of data together. We won't talk about privacy respecting or not, but everyone was trying to figure out how they could pinpoint who that customer is with assurance. And so it was the topic at Money 2020.
Sorry, go ahead. No, I was just going to say that, yeah, probably we are biased because we've been doing identity for some time. So we know identity is everywhere and we're convinced of this, but I think that the conversation gets easier now than it was five or 10 years ago. And people, I think, outside of identity are interested and understand that we can help. And we have better discussions now than we had before we had to convince. Now we have to design, and it's a different conversation, I think.
Yeah, I was going to suggest we do that, but Miki wanted to say one thing. So I think if anything came out of COVID was that people became aware that, they need to kind of be able to identify themselves as bad as it was, but also kind of, now that's my train of thought. While you pick it up, if you want, I know that for me, I was working in financial services at the time at the beginning of COVID, and it was a wake-up call for the bank that I worked in because the small business department had no way of verifying who was signing their docu-signs, right? So it was a major wake-up call.
Yeah, and I think more people in general are understanding about identity. Like a decade ago, when people talked about government identities and things, it was like, oh, no, big brother, we don't want that. But now it's becoming more important because they need to show who they are. And I would tack onto that change over time. Something that I wasn't prepared or didn't see coming was that the term digital ID would get dragged into the grand conspiracy theory of the world and the effects that that would have, especially for us in Canada.
Government programs were completely scrapped because the word digital ID was attached to them. So it was not good. Didn't see that coming. But now I think that we're on this alternate swing of AI driving the public from saying, hey, we cannot tell what is real and what is not anymore. So I think we're sort of getting a little bit of the answer to that pendulum swing toward this digital ID thing is scary and bad and terrible to, oh, gosh, I can't tell if that's my mom or the bank or anything anymore. So I think we'll be more in demand for that purpose as well, yeah.
We were about to poll the audience. Did we wanna ask what the biggest change is that's affecting your professional lives? Related to identity, please. We all feel the inflation, sorry. So one thing I found is that tools like Cloud and ChatGPT are making a lot of people think that they're identity experts now.
Yeah, and now I have to go on this program wearing another hat of making sure that we've optimized the OpenID website to actually be consumed properly by LLM. So continuing with Justin's theme, Cloud, ChatGPT, the LLM are also creating lots of opportunities to implement bad identity systems. I see a lot of just copy your cookies from the browser, just copy this access token, and these patterns are getting repeated again and again and again. And we're all gonna get wrecked by that.
We're all gonna get owned at some point because of these bad patterns that are coming because people who are not traditionally developers or haven't been exposed to that realm are now suddenly developers with, and pardon my Americanism here, but we gave people a foot gun to shoot themselves with. We literally gave them something, a loaded gun without instructions they can shoot themselves with. And that's unfortunate. For anyone for whom English is not their first language, the idiomatic expression that Dean is referencing is to shoot oneself in the foot. Okay. I would just say the brokenness.
I mean, I spend between an hour and two hours a week logging in. And none of those logins are particularly, like I'm like, eh, that could be fake. And it's just like two hours a week I'm spending logging in. I've already spoken to my credit card company twice because I've traveled like not very far from my home. It's insane. Yes. I feel that. I feel that so deeply in my bones. I love it when there's a login experience where you've forgotten your password and it's actually quick. It's amazing.
I think, oh, here we go. I think we've been doing identity for a long, long time now and we're still not very good at it because we still keep blaming the average Joe because they're not doing the right thing. Our job is to make it so that it just works for them. And I think as an industry, we've still got quite a long way to go to make it so my mom doesn't have to worry about identity. Agreed.
Okay, George, I'm coming, I'm coming. I'm getting my steps in. Thank you. So I love what you said, Alan. I'm just not sure that there's a business model to do that. And so how do we make doing identity so that it just works right for the normal user a valuable business model? And until that happens in our capitalistic world environment, it's really hard to accomplish that. That's what we're talking about, end users. I wanna add to this list. We went from writing down a password in a notebook to printing out your one password keys and sticking it in a notebook. Sorry.
I was just gonna add into Alan and George's comment. I think there are ways to make it work just right and super simple easy, but they don't necessarily work in cultures that are democratic and have privacy protections. Like we should be fair to ourselves. We probably could do it really easily in a very surveillance driven and non-friendly way, but we're trying to not do that. Anyone else?
Oh, nope, that's not a hand. Okay. All right. How about...
Oh, wait, there is a hand. Mike Jones has raised a hand. To the brokenness point, there's an article in a publication called The Onion whose title is 97% of average Americans today spent retrieving six digit codes. The fact that that's even an article that's funny is very telling. We have a lot to answer for. We have a lot to answer for. So has the way that you've navigated your careers, we'll start again with the board and probably open it up. Has the way you've navigated your careers or your development over the last 10 years changed at all as things have been picking up pace?
Well, definitely because I was very siloed into, I was working at Australia Post when I started in identity and I just looked at one simple thing, how do I identify people at the postal office counter and things like that, and then scanning documents and all that. But now it's gone so fast and even every day, things are changing, especially with AI coming in that I have to kind of upscale myself quite often. And I can't go in too deep into anything because there's just so many things to be aware of, but to at least keep abreast of what's happening in the world is really important.
And I think that's where things like IDPro is very important, yeah. I think things changed for me. 10 years ago, I was Googling for how OIDC works and I stumbled after minutes of research on Brian Campbell's slides from Cloud IoT Summit or here in EIC. And now I just have to ask someone on Slack, can someone explain to me the details of this or that? Does anyone know why we made a choice in the standards to do things? I really think what changed for me is the IDPro community is really something very useful for me, for end user companies as well.
They have direct access to people who write the standards and that's a game changer, rather than having to lurk around the internet or go to a conference to get that access. That's a game changer for me every day. Awesome.
So for me, I'll start with something that has not changed. I will out myself every year when I do the skills survey and I think one of the last questions is, are you an expert or do you have the tools you need or something like that? Do you feel proficient? Do you feel proficient? Yeah. That's the question. I put no every single year because every single year, I feel there is just a mountain of knowledge to learn. So whatever it was in that year that I answered, it could be something completely different in the next year.
So I think that feeling of this is a vast, vast space and demands time and attention, demands a community that we can work with to help us figure out what those skill sets are. That stays constant every year. I think that's something for me and my career that has changed is when I started in this industry, I started very much to save puppy dogs and cats and kids and protect people from surveillance capitalism and privacy protection and data.
Over time, I've now look at this much more as an ecosystem with multiple use cases that simultaneously exist and I do the serenity prayer daily for which of those use cases we actually have an ability to affect change on and then try to recognize which ones of those we might not have the ability to affect change on. And even that line is subjective and kind of changes year over year. Now over to you guys. Has anything changed in the way that you navigate your careers as things have progressed in the last 10 years? Andre.
For the last 20 years, I've been an expert and I could answer every question about identity and access. Mostly about access. I like access more than identity. But the last six months, I'm at a loss. So before that last 20 years, everything was more or less the same.
So we had, well, 20 years ago, we had OAuth, we had loss of identity. It's all 20 years ago.
20 years, it started a business and then we had a spike of information and a lot of stuff happening and I managed to follow that. And so that's, I would say, that level of knowledge stayed the same. Nothing happened. We had feedback. Nothing special. So that was it. And now the last six months, we have all those things popping up. I have to know Spiffy and Spire. It's too much now. Before that, I could manage everything myself. I could answer every question, have an opinion about everything. And now since the last six months, I'm at a loss. So this has definitely changed.
I'm not an expert anymore. You're still an expert. You still have value.
George, I feel like I've heard you talking about that. Or at least the amount, the volume of stuff that you need to get through. You wanna say anything? You don't have to.
No, I agree. The amount of new things that are coming out is just crazy.
I mean, you can look at it in a very small microsystem at just the number of individual drafts going into the IETF, just like one standards organization going into the IETF that are touching on, effectively gaps in standards, pretty much approached from a very usually narrow perspective to solve their particular thing. But there's just an explosion of them and they keep coming out of the woodwork. You can ask the robots to try and go find it, but they won't find it all. I was sort of representing identity at a National Science Foundation event back in April.
And somebody came up to me and I was like, oh yeah, I'm a professor from Ohio State University and have you heard of this? And I'm like, no. And here's the paper on how we're processing intent and turning into slices and blah, blah, blah, blah, blah. And then this morning, someone else was like, oh, I got this great thing and dropped the link to it on one of my LinkedIn posts. And it's impossible to sort of try and keep up with all of that, nor do I think we have a good rubric by which we can evaluate these things.
To sort of like say, how does that fit into some sort of structure for processing the information to sort of rate them? Ian? So I think it's important for the people in the room that have less experience in this industry to listen to what just happened, right? So you have Ante D'Cruz, who knows more about access than I've possibly ever could. And George, who's a living deity of standards. And for them to say there is too much to know that is important for two reasons.
One, it points to the emotions you may or may not be having, which says, oh my God, I can't keep up. Guess what? You're in phenomenal, phenomenal company.
And two, the only option here that is provable to not bite you later is not to defer to Claude and be like, hey, what am I supposed to do here? And the response is like, well, just put your personal access token in. It's all good. What could go right? The only thing to do is to rely on a larger community because essentially you have to outsource this to people who have essentially self-nominated to be willing to help. Because there is no way, full stop, to keep it all in your head right now. And that is not going to change.
So it is very important if you are in the room, if you are listening online, if you are newer or if you are more seasoned to hear what just happened because it points to the thing that I think we all feel. Joni, it's good to know you are among the 10 to be 26-ish percent of people that respond to the skill survey as I do that say I still do not feel proficient because it's not possible in my opinion to do so. So you're in good company. So to add onto that, I think it's telling that a lot of the seasoned experts are the ones that are saying there's too much to understand.
And going back to my previous point, the people new to the field armed with an LLM don't know that they're not experts because they've been told that they're doing a great job. And yeah.
Justin, that's exactly the kind of response that we're looking for in this room. Dean, I've heard you talk about this too. So I have to agree with the last three gentlemen.
Yes, things are moving too fast. Joni, unlike you, I have marked as yes, I feel fairly proficient for the past couple of years. I no longer feel proficient. Things are absolutely moving so fast right now. And I have changed roles. So I had been in a role where I was doing a lot of standards work the past five years. Now I'm in a more of a corporate role where I'm not doing as much standards work and trying to keep up with what is happening and IETF and FIDO and OIDF and all of the other places where people are discussing things is madness. It is absolutely impossible.
And I have to really begin to narrow my focus on what I learn, what I understand and what I let go and learn dynamically because I just can't keep up with it all right now. And that's really changing how I interact with the world of identity and the world of standards. And I figure it's going to continue changing for the rest of my career.
It's not gonna stop, but I'm gonna have to approach how I learn, how I do things in a very different way and continue to lean more on my community here in IDPro to ensure that I know that Andre is the expert in access and George is the expert in all things OIDC and OAuth and others like that and lean on those people when I can't or don't have the time to do the primary research and understanding myself. That's a fantastic point, Dino.
And I just wanna also draw some context around that as well, which is, I've done a lot of work with governments and corporations as well, but let's look at governments for a moment. One thing that is kind of well-known in that space is the work that a minister does, a minister's ability to be effective is highly dependent on the chain that's reporting to that minister above.
And so I think that part of this community as well is doing that serenity prayer, recognizing things are changing, looking at who we can lean in on particular subject matters within this multidisciplinary space, but also then making sure that the next crew that's coming in has that ability to brief us up as well. Like we don't have to know everything and we never will. So that next generation being able to brief up is such an important part of every ecosystem as well. And IDPro is here for that too. Yeah.
Another thing that I think is important is that there's all this new things coming in all the time and yes, we have to keep up with it, but the other thing that we need to do is to be able to translate it for the general public. And so, you can get a lot of information, knowledge and things, but then if you're not able to make it so that it's facilitating it for the general public to keep up with all that's happening around them is very important. And I think that's something that we need to look at as well. Did you just raise your hand?
No, you did. Okay. I'm gonna ask the room if you have any questions for our board or one another in a second. But first I will hand the mic to Grace.
Yeah, so I'm kind of new in the industry, but I think there's been, to what the guys were saying over there about depending on one another, I'm definitely sensing that there's more of a movement towards collaboration and that a lot of the organizations, I mean, we all have like our favorite protocol and a particular line in that protocol that has to be an exact certain way. And I think people have been more and more willing recently to say, okay, I'm willing to compromise because we're seeing that the fragmentation is so damaging to the industry.
And I think the main thing to keep in mind is there really is enough identity work for all of us. And a lot of the organizations that are doing the work and a lot of the organizations that have been kind of trying to elbow one another out, I think we're starting to see like, okay, we really are gonna have to hold hands because this is getting too complicated and there's too many, like the stakes are really high. It's people's privacy, it's people's security, it's control of everything that people do. And so I've been really impressed by like, not everybody, right?
There's still people who are very competitive in their mindset, but I've been impressed by the collaboration that we've seen across like a lot of these different organizations that used to be very separate and how many times I'm invited in to speak to the steering committees of other standards bodies. And yeah, there's just been a much higher level of willingness to like, okay, maybe we can compromise about my favorite protocol or whatever it is. It's a great- My favorite protocol. Okay.
Oh, George. So I have a question because I feel like we're entering an era of increased fragmentation and I don't see any way to get out of that.
Just, you know, the push to deliver is so great that people are just going to go do stuff, whether it's good or not. And I guess my question is, is like, what is our best path through that period of fragmentation to help in the best way we can at some point in the future when things start to fall apart or recognition that it is too fragmented and we need to collapse?
For me, the fragmentation is a given. So how do we best manage that going forward? Industry legend and former AD of ID Pro, Heather Flanagan is ready to jump in. But there's no pressure. It's interesting to think about when you are asked, do you feel proficient? I answer yes, because for me, proficiency means I don't know the thing, I know where to find it, I know who to ask.
You know, that's actually all I need to feel proficient. I don't necessarily know how to install it or run it or which boxes to tick or, you know, I'm a librarian at the end of the day. And that's actually been enough. So am I an expert on anything?
No, but I'm proficient because I know where to find it and who to ask. And where do you go?
Well, I'm gonna say Slack for a bit because there's like 20 different Slack instances that I'm on to ask about. Two with the W3C and IETF one, the ID Pro one, the OpenID one, right? So Slack is a thing. Mastodon is a great thing for certain types of questions. Blue Sky is good for a whole different type of questions, you know, knowing your audience and who's there. If I didn't know, I would go to the ID Pro Slack and I would DM Heather Flanagan. She knows. It's recursive, yes.
Just coming back to the question of what changed, I just wanted to reflect on the fact that not only did we progress as a community, but we lost also some of the giants on which shoulders this community stands, be it Kim, be it Andrew and others. But I think it was great to see sort of how this community comes together to allow us to celebrate them and move on and keep the thought of them alive.
Hear, hear to that. Yes, and in addition, I think that what we're looking at here is always also for the purpose of display, it's false dichotomies, right? We're always somewhere in between the poles.
It's like, you know, Samuel still lives and things like that. So things are still, you know, we're never- Sam will never die. Sam will never die, so it's never die. Until the post-quantum apocalypse. Until the post-quantum apocalypse comes and then who cares, you know? So I find that refreshing and positive.
And, you know, maybe to George's point, you know, like, didn't Nat Sakamora give a talk like two years ago or? Once everything becomes completely decentralized, we're all centralized again. So don't worry, you know, there is a light at the end of the tunnel. We will get there. But I think you asked a really hard question, George, about centralization or about the fragmentation, you know, and I think that is a continuance but like galaxy-wise, we're always kind of spreading apart and always moving.
So I've been thinking about bits of that a lot and something I'm kind of noodling on is we do a lot of talk on technical problems and I'm trying to enumerate a set of business problems, like, which comes back to your point, Miki, about, you know, when we talk to people, if we go in and we'll say, well, do you know the difference between Spiffy and Spire? Like, they have no idea, right? But what business problem? Let me talk to you in the job you're trying to get done and then we'll translate it into the right tool in the toolbox.
I think, was it Alan or someone back over there? Illustrious industry demigod, Alan Foster, would like to make a statement. It's just Alan. Responding to George's statement, I wonder if it's not just the natural point of where we are in our industry that we feel uncomfortable with this fragmentation because, you know, we've been through this before. I remember every single phone having a different cable to charge it up or, at some point, there were actually multiple kinds of computers that didn't work together.
And as an industry, we kind of moved forward and the business needs got us to the point where it all, the winners won and then that fragmentation kind of fell away. And I'm wondering if it just makes us really uncomfortable feeling that fragmentation now until we have some winners.
Well, you can thank the EU for the cable thing. I mean. I feel like I need to do this shameless plug to about my talk on fragmentation tomorrow, right before lunch. I will shameless plug my talk at 4.40 on ingredients to moving identity forward without mandate. First of all, I have the same problem as you, Johnny, with answering the question about the proficiency and always said, no, no, no, no. What I usually do when I do have a new problem to solve or to understand is trying to find a model, a layout of abstraction to do that.
And the cable situation was a good one because we invented the ISO layouts and that. And there's an even more perfect model for chemistry, the periodic table. So what would happen if we, as a profession, would find a model where we just can say, okay, here's a new element. We can drop it here to help understand what it is doing and to have an idea, how does it work together? You don't have it? Can you do the first draft, please?
I can do, yeah. Wait, I have it.
All right, perfect. We tried that several times. Kim tried the laws of identity. We had the IRM work group where we tried to explain the elements, the models for that. And there were several more, but we do not adopt it. We just forget about it. And I think this is something we need to change. It's an important point about, there are the laws and IRM. I think it's an important part of this community as well is that we help not to forget those pieces. Sometimes it's our responsibility to dig into the history and pull it back up to the top and to recontextualize it to what has changed.
I think it's a good opportunity to go back and read the laws again. Does sovereignty fall into the laws? I don't know. But I think it's a good refresh opportunity, yeah. One thing. IRM is a good example. Has anyone tried to download the document in the past month? It's not available anymore.
No, it's gone. Okay, we'll take that note. We'll go find it and pull it back up for you. It's power of community. I'm gonna let you have one more opportunity to ask the board and one another a question. Then we're gonna hear a story from Ian Glazer. I have a couple more slides. And then I think we're gonna break into small groups and talk about what IDPro can do to help us navigate these challenges. I wanna make sure we leave some time for that. Does anyone have any other questions for our panel or one another before we hear a story from Ian Glazer? Yeah.
No, okay, story time. Gather around.
So, many people don't know why Germany is so particularly important for IDPro. Which is, well, Joni is instrumental in getting IDPro created because of a very, very long, late into the morning conversation at RSA. Olaf has a very particular role in all of this. Back when I was, I guess, still at Gartner, I was concerned about the problem of how long it took to build an identity practitioner.
Now, I'm still concerned about that. But I happened to be visiting customers in Frankfurt. And I happened to have the opportunity to be kindly invited by Olaf to talk to his financial institution. And I got the opportunity to ask the question, how do you learn this gig? How do you learn this practice? And the answer was an amount of time that I think back, say, 13 years ago was maybe okay. That amount of time is now not an acceptable amount of time.
And so, that is really the meeting that began to crystallize on my head this realization that says, we've got to find a way to help one another accelerate the time to at least being usefully dangerous with identity. So, it warms my heart that Olaf is here, has taken the journey through the earth, through the center of the earth to come and visit us. Because here and at EIC, really formative moments for the organization.
So, I appreciate that opportunity. Yay! Yay! Yay! Yay! Is that a hand or just a dramatic hair waving moment?
Okay, did you guys have any final thoughts before we do a couple more slides and then break into groups? No?
Okay, that's fine. No more final thoughts.
Good, okay. So, we're moving through these again.
So, we've been, stuff has changed, right? And we have been thinking a lot as a board and a leadership group about does IDPro need to reflect on its mission, its vision, and as it moves forward into this future?
So, we have been updated and drafting our mission statement. And we're interested in your feedback on it, either now or later. I think maybe we'll do the feedback later unless you feel really compelled because I wanna break into these groups. But this is, we've updated it to say we offer global professional community to ensure that identity professionals are recognized, connected, and equipped to advance secure, trustworthy digital services. We are hopeful that this kind of, there is a perception out there that IDPro is a little bit more limited in its scope.
And so, we were trying to make it more expansive as we did this. Do you guys wanna say anything more about why the board ultimately drafted it this way? I think that we, we're in that, a little bit in that trying to work through that equation of what is an identity professional?
Is it, and I'll speak for myself. Are they a software engineer? Are they a policymaker? Are they a business enabler? They're all of those things. And is identity the goal?
Well, quite often, identity in this collection of things is what we use to enable access to something, trusted services, something to get done, some resources. So, we wanted to put that, the goal in this ecosystem is to support trusted digital services. Then what's the goal of IDPro? Is to help all of us become more recognized, connected, and equipped.
So, this was kind of our thought process on keeping us tightly focused on the profession while not trying to define the profession within the mission itself and give a, tell a story like Ian in our mission statement. So, I'm gonna, I'll put in some like town hall meetings and stuff where we can talk about this stuff in more detail as members. And I'm gonna hand it over to Mickey to talk a little bit about the SIDPro. She's done some great slides for us.
And then let's break out into groups and talk about what is like, what are the next generation of things that IDPro should be focusing on to better equip, connect, and enable you all to do your work in these challenging times? Oh, you have a mic. I don't need to hand it to you. You're good. I'll take the clicker though. You can have it.
So, I won't talk much because I think a lot of you know about SIDPro and some of you have done that already. So, just for those who don't know much about SIDPro, I just made a few slides so that you can see. It's a vendor neutral practitioner built.
So, a lot of questions and things were brought to us by the practitioners. And it's grounded on the body of knowledge that we have, but we also have resources so that you can look up other areas that you can look for information. And we give you sort of a study guide for it. And these five things here are the main areas that you need to understand.
And so, on the top you can see we have a whole bunch of questions. Not all of them are on the same test, but you have three hours to do it. And it's a proctored online test.
So, you can do it at some, sometimes like we do it at Identiverse. We have a dedicated room that you can do it, or you can also book yourself in to do it online.
So, yeah, so you have the body of knowledge, you have the references. We also have a practice exam that you can try things out on and then a lot of it is also based on your experience.
So, it's based on two or two plus years of knowledge, but it's also not that you have to have all that knowledge. You can also use the exam as a way of judging where you are in the knowledge of things.
So, that I think we need to kind of keep expanding on the SIDPRO as well, because like we said, things are changing a lot. But it does give you a sort of a marker to see where you are at in terms of your knowledge, but it's also another way for employers to kind of see where you're at as well.
So, it's a good way of finding out where you stand in terms of how much you don't know about things. So, yeah, that's probably all I need to say about that, I think. If you have any questions around the SIDPRO, please come and ask me, or do look online at the idpro.org, because there's also a nice video there that Heather and Kevin Strader has put on, which is a webinar about SIDPRO.
Cool, great. All right, so I think now I would like to keep the conversation flowing as we break into small groups and talk about what are some of the things that IDPRO can be focusing our time and energy on, either as volunteers or me as staff, to better equip, connect, and enable our ID professionals.
So, this is the let's hear from you slide. Notice how young Bertrand looks on it.
Also, John. Still?
Yes, oh, yes, yes. And compare it to now, he hasn't changed a bit.
All right, so this is just the QR code for if you wanna go to IDPRO. So, we're gonna hear from you now. Let's break into groups. Let's each take a small group. Yeah. Position yourself in a location, and then pick your favorite person. Or pick your least favorite person. Or pick the person you wanna have a fight with. And let's talk about what IDPRO could be doing.
Oh, so being very specific, what IDPRO could be doing to better support you in your career. Yes, yes. We have half an hour in this room.