Okay, I'm starting. Ah, I don't see anything on the screen, but anyway.
Okay, so very warm welcome also from my side. You had heard it. This is the site on inclusivity in identity with women in identity. What is Women in Identity? This is a nonprofit organization run by volunteers like me, like Sylvia, like Kay is sitting there. And we have about 4,000 members and we are working on our vision, which is to have digital identity solutions built for everyone, built by everyone. And our mission is to drive the digital identity industry to build solutions with diverse teams.
And I have also, or we have also prepared and spread out some flyers where you can get more information on this organization. But today we want to show you various topics where we are working on. And I also want to take this opportunity here to thank KuppingerCole for their year-long support of Women in Identity, and for giving us the opportunity to talk about this organization and also to show what we are working on. So thank you very much.
And then we start with the first presentation, myself and my colleague Anna Phanesian on leveraging Gen AI, AI and automation for streamlined identity and access management in complex environments. And what does it mean? We want to show you how Gen AI, AI automation can really support use cases in identity and access management and make the life easier for stakeholders. Let's call it stakeholders for the moment. And what does that mean? There are many, many use cases in this environment.
And maybe you had experimented with some of the things around IAM, with AI, with Gen AI, also with automation. But what we have seen here, this is just the selection of possible use cases to give you an impression. But as I said, maybe you have experimented around it anyway. But what we have seen is that there are two main categories of use cases. One category of use case is to support human users in doing tasks around IAM. And the other category is using Gen AI, AI automation for operations in IAM.
And so this is a very rough categorization, but we think that most of the use cases fall under the one or the other. And you see here engagement and experience for end users, managers, auditors around that. And also in operation, ticket creation, validation, resolution, but also, and I will dig a little bit deeper into that application onboarding, what it means. And we will not only talk about theory on that. We will also talk about two examples. One is from the first category. One is from the first category to show you really how this can work and how this can really bring value.
And the second one, which I will then talk about, is about the application onboarding cycle to an IGA solution, which has many use cases in it. So with that said, I hand over to my colleague, Anna. I hope Anna is there. And to go through the first use case, the user experience.
Oh, Anna, your microphone is- Apologies, mine was muted. So thank you, Angelica. I appreciate this opportunity. So let's talk about, as those users that Angelica listed on the previous slide, there are so many channels to make a request for IAM, whether it's to request access or to do a, you know, how many applications or how many roles do I need to recertify?
How many, what other information do I need? And it's all fragmented. So you can go through ServiceNow or a similar ITSM or the application dashboard or through some other portals. So there's a lot of entry points for a user to request and they don't always have the correct information to fulfill a request. So the request comes in, it's lacking data. They don't know what role they really need to apply for. They may even not sure of what the application name is. And so there's so many queries that a user, whether it's the user themselves, it's a manager, an app owner or approver.
So there's just, and it creates number of delays. So it creates frustration. The requester cannot get to the information that they need or to perform a job or get a report or anything. So it creates numerous inefficiencies. So if we go to the next slide. So wouldn't it be great if we could have a simplified interface where the user is just asking a question, right?
Hey, I need to get access to the sales application so I can perform some business reporting on a region or a product or a service or anything along this line. But I don't exactly know what role I need because it's not well-defined and there's not a lot of information that is available. So the interface comes back and says, hello, I see who you are. I see what your role is. Is this the information that you're looking for? And it's a very simplified Q&A engagement. So there's more information that the requester could provide in what their intent.
And so if we go to the next slide, this is a sort of an architecture of how the Gen AI is incorporated into just this chatbot interface, which is purely the front end for the requester to begin this engagement. And it's, again, very simplified from their perspective, but in the back end, there is a tremendous amount of activity using Gen AI, connecting to all of the subsystems that are a part of this request. So what happens is that you create through using an agenic skillet, you create a number of skills, right?
These are use cases that perform functions and they are mapped together or graphed together so that they learn that there's a dependency of how a transaction is needed to be captured or information that needs to be captured to be able to perform this request. So through the skillet, you can group these use case skills to create a functional task of perhaps, again, requesting application access to the sales application to be a business advisor, to be able to create various reports.
And so I, as a user, I don't need to know every little detail. I can just say, this is what I want. These skills then are graphed together to create the tasks that need to be completed, the data that needs to be added to the request. And then once approved through that, again, that channel interface, we're using something like Teams or Slack or WebEx or even just a portal chat bot. Then you can go through the approver process to create a service ticket so that there's auditability of the change request. And then you can execute from there. So it becomes a more simplified.
There's no more delays of waiting for email exchanges or waiting for management approval and then go through that whole process. And again, making sure that you're getting the right information into the system at the right time and in a streamlined fashion so that there's no more troubleshooting, no more having to fix a mistake or remediation or what was the risk associated with creating an inaccurate transaction.
So this is the use case for a user using GenAI that can, again, using LLMs to collect the information, to gather out that information, using a graph TV to create the skills and the relatability between these skills. And then these skills can be grouped together. There could be a variety and various use cases. So the exchange is simple. It's engaging, it's satisfying for the user and ultimately for the operation. So you can reduce cost, reduce time and make the total experience better. So that is from the use case of using it from a human interface potential.
Next, I think then I will turn it back to Angelica who can play off of the same architecture for the automation. Okay, thank you. So what you have seen here now is really how the user can use that. And I do not want to do any advertisement. This is not just pictures. We have this built and it is downloadable. Who is interested into that can get back to me and I will tell you where you can download it and experiment with it then.
Okay, then let's go to the other use case. The application onboarding to an IGA, Identity Governance and Administration solution.
Many, many years I am working on these things to standardize that. To standardize that, I think I have started with that really in 2010 with my very first large IGA transformation program with the client. And we had standardized the process of application onboarding to an IGA solution for standardized in the sense of processes, templates, guidelines, everything is there and we really know how to do that. Nevertheless, it is always tedious. You have two really things or two things which you have to do. One is the technical connection.
Like, for example, if the access rights in the target applications are based on AD groups, you have to connect the active directory. This is what you need to do technically. What you also need is logical business information. Who can request what? Are there any rules behind it, business rules? And this means you need to talk to the business owner of that target application. And this is the person on the left here. And this is a process which is really time consuming, a lot of effort.
Many people don't like it, especially not the business owners because they are not familiar with all these things. So you have to do workshops and talk with them and explain it more than once and go through all these cycles.
So, and what I mean here, you see that there are some pieces which can be supported by AI or Gen AI. Gen AI usually only in the communication with a person. What Anna has also said as the communication with someone who's requesting access, you can have it as an analytics bot and you can have automation. But the main point is really this information you need to onboard that application. You need to collect that. And you have various sources for that.
One is, as I said, the application owner. Another one is the target application itself. You can get a lot of things out of the target application, even if you haven't connected the IGA solution to that. We have done that over the years always. You can get, if it is a CSV file, out of the target application with a lot of information on access rights, on rules and all these things. You can do that. And this all fills into this bucket with the information for that application to be onboarded. And other systems, CRM systems, ERP systems.
So you can fill this bucket of information with a lot of material automatically. This is not AI, but it is really important. But what you never can skip is the discussion with a business owner. And for that, we have developed, with all our experience, this application onboarding guide. This doesn't mean that not a person, a human, I would have to not talk to the business owner.
Still, I have to do that. But they can get back to that again and look into that. And this guide will talk here. You are missing that one and this one. And you can fill it in whenever you have the time. And these things on that one. So this is something which makes it easier for the application owner. What we also have developed, and this is independent. This is independent on the left from the IGA solution. And it is independent from the target application because it's a general process of what you need to know.
What we also have developed is, if you have an existing IGA solution, we have developed an analyst. And this is not, these are different agents. So it's an agentic solution then. One solution analyzes the existing rules in the current IGA solution. Another agent builds business-readable language. So a business owner can decide, yes, this rule is still valid.
Or no, this is old stuff. We do not need it anymore. This is dependent, of course, on the old solution, on the technology of the old solution. And what we also have developed to analyze and pipeline and onboarding pipeline and so on. So make this relatively smooth on that. We have even, but this is not AI. We have even developed some sort of automation, test framework automation to onboard specific applications. But they need to have a low complexity.
And this then in the cycle, if you put these things together, and even if you use one of them only, you will have a lot of increase in user experience and also less effort and efficiency. So to the entire cycle, if you want to have more information on that one, of course, you can talk with me afterwards, definitely. And then key takeaways. What I said, the pastor path, so using GenAI, AI, and automation in the right place for the right use case can really give you a faster path to compliance with risk reduction.
So for example, you can quicker onboard applications, or you can have quicker recertifications. You are reducing time and cost and higher stakeholder satisfaction. As I had said before, you always need to make the business stakeholder happy. With that said, I'm at the end of my presentation. And I think we have time for one question or so.
Yes, for sure. So are there any questions in the audience so far?
No, okay. Well, I'd like to say thank you for sharing the use cases of GenAI and Automation IAM. And please give a, I'm sorry.
Thank you, yes. Please give a warm thank you to Anna and Angelica. Thank you. Thank you.