Hello, everybody. How are you doing this evening? It's getting to evening. Lots of exciting topics. I am not going to be talking about AI. I'm going to be getting rather into the practicalities of IAM. I'm really going to be talking about stakeholders, which sounds so exciting. Until you think about how we've had a conversation over the last year or so about the chief identity officer, the Cheeto. I'll be getting into that. I want to sort out, like, who really cares about IAM and who should really own IAM.
But I warn you, this is going to be as much about Venn diagrams as about IAM, because I can't help myself. I've been preparing identity-related Venn diagrams since at least 2007. These are from my old blog. They're rather imperfect, but they're all designed to help us compare things. And since we've had so much change in the industry over time, it's useful to compare what we know, what ought to be. Had a little fun. There was an IIW. I don't even remember if it was IIW A or B in the year 2007, but we had a karaoke evening, so that's what that one was about.
What I want to talk about today is identity's jobs to be done. Anybody here familiar with the jobs to be done framework coming from product management? Yeah. It's about figuring out the higher purpose for which somebody wants to use your product. So the classic example is people don't want a quarter-inch drill. They want a quarter-inch hole in the wall. Or commuters don't want breakfast.
They want, some of them, healthy calories that they can hold in one hand while driving. So it's thinking beyond the apparent aspects of a product. And so I want to talk today about shared services that do identity jobs as a product. And for this, I use a four-part framework that I've actually shared here before briefly. I think it was the four Ps. That's so that I can remember them. Not Peter Piper picked the peck of pickled peppers, but protection, personalization, payment, and people. So protection, I think we're very familiar with the risk-facing aspects of identity.
That's where we all started, right? Think about SAML. It's called the Security Assertion Markup Language. It didn't have an I on it. This graph here is from a company that offers cyber insurance. Now 15 years ago, it was more like, oh, who offers cyber insurance? Does it make sense?
Like, we don't even know about this thing. And now it's de rigueur. The risk-facing aspects that we need to treat with identity are very well-known by now. Security risk, privacy risk, business risk. But there's more to the picture than where we started. There's also, I'm going to shorthand it as personalization. And by that, I mean everything market-facing. That can be cross-sell, up-sell. Here we're talking mostly about SIAM, true personalization of experiences, which can apply to any IAM.
Last year, when I talked about consent being dead, I shared this diagram, which comes from a now several years old Nestle investor deck, talking about how they want to grow the number of consumer records that they manage as a first party.
Fast forward to more recently, when their folks who own this function talked about having more than 100 data sources for the people that they're interacting with as customers and potential customers, and having four to five times engagement if they're first party custodians of the relationship than if they're just doing it the way that I talked about last year regarding identity resolution. So there's a whole world that cares about identity.
Third, payment. I don't even have to make the case about why payment and identity are kind of a binary star. And not only have we heard a lot about wallets that do both payment and identity today, but even looking at the slightly more traditional world of open banking where even the US has not even on a regulated basis but on an entirely discretionary basis has seen major growth in using these kind of rails, these APIs that enable payment and, by the way, have identity infused throughout them. The fourth P is people.
This is what is about what people really want, even if you didn't make them prove what age they are, prove they're old enough for something, prove that they work at a certain place. All those things are done to them. As I've often said, nobody wakes up and says, I think I'll log in today because it's so much fun. This is about what people naturally want, like sharing, maybe on a selective basis, like connecting with people online.
And like some of the really tough cases reflected in this LinkedIn post when we've had these circumstances when somebody passes away, and I will be on a panel about the death in the digital estate group tomorrow to talk a little bit more about this, but these are some of the really interesting use cases where people need to achieve something in a digital context and need help and support from the identity world in doing so. So to compare all these higher purposes of identity, we're going to want to look at a Venn diagram, but first I want to find all the math nerds in the audience.
I have a little bit of a lesson about Venn diagrams. You can't use circles to compare things when you're comparing four or more things. Any math nerds know what this kind of diagram is actually called? Euler diagram. It's not a Venn diagram. Why? You can't compare the thing that's only about A and C and the thing that's only about B and D. It's not possible with circles. They don't cross enough lines. If you could compare all the possible combinations, well, then I'd be naming this talk the icky guy of identity, because that's what this diagram does. I made up two names for the A, C.
What you're good at and what the world needs that isn't in the other two is your forced labor, and what you love and what you can be paid for but isn't the other two is your side hustle. So there you go. You're welcome. So what we're going to need to do to do this comparative exercise about identity's allies is something that looks a little bit more like this. That has all of the comparisons possible. So let's use this shape to get a sense of how you compare all these higher purposes of identity. Who cares about the risk-facing aspects, primarily legal and security?
They kind of own that function. Who cares about the personalization aspect? Completely different department. Marketing and security often do not talk directly, and they own completely different aspects.
Payment, well, finance has a hand, and depending on whether you're developing applications that are external-facing or internal-facing, you've got product and IT. Now these are very short-handed versions of who might be the owner in the picture, but it's who cares the most, who's given the responsibility for it. And then we get to people who don't actually have a C-suite person at the C-suite table really representing them, but HR does care, at least for employees, who's an employee today. So there's a little bit of a hole there.
So let's now get into some of the complicated cases of comparison. Well, if you're wanting to do privacy, you have somebody who owns privacy that is really looking at the intersection of protection and people, and they're advocating for people in that role.
Well, that's interesting. And of course, you've got product owners and application owners that are internal-facing as well that need to be responsible for that kind of protection, taking into account the impacts on people.
Now, when you get to that binary star of payment and identity, well, you think, oh, fraud. That's kind of between risk-facing and payment-facing, right? It's actually a little bit more subtle than that, because if you own fraud, fraud detection, fraud mitigation, fraud prevention, then you're kind of treating people as adversaries, and you kind of have to do adversarial personalization in order to do that fraud mitigation.
So yay, I got to have three sets in there. And then last, and unfortunately least, we get to the actual people in the equation. And I say users in quotes. They might not be using a service at any one moment. And I also say just humans generally, because even if you don't have a login at a particular application, you can bet that a large retail-facing company probably has a representation of you and knows you pretty precisely, even if you do not have an experience of managing that representation of you. So this is partly what makes these things complicated.
What does this complexity drive in terms of challenges? What do we experience?
Well, all right. I finally get to show the Cheeto guy. There's no obvious chief identity officer in this picture. I have been working with some companies where one financial services firm has kind of dithered for a couple of years now on exactly where the identity function should live. I once worked for a financial services firm where it was the fraud department that owned authentication but not the rest of the deal. So unless we know what in any one organization is being done and for whom and to whom and why, it's really hard to define a Cheeto job.
Second, you have to get really fine grained with your understanding of the use cases that you're trying to solve in your average organization. And just to give one really obvious example that's been sitting there this whole time that we haven't really talked about in our industry, provisioning accurate rapid provisioning, let's say, for employees of entitlements is something that the CIO is going to care a lot about. Pre-provisioning accurately and rapidly is what the CISO is going to care about.
Now, these are not separated into two different software packages, okay? So you've got a separation of concerns and you have to have a lot of coordination there. So speaking of coordination, thinking of video games, this is absolute boss level in terms of difficulty because you need to actually partner at extraordinary levels in your average organization in order to get these different higher purposes to align.
Finally, you've got blues notes. You've got notes that sort of fall into the cracks between the keys. Talking about death in the digital estate examples, hard delegation examples, identity relationship management examples where they're not considered traditionally part of what's delivered by a platform, and so they might be missed unless you catalog them carefully. So I want to give you two quick case studies of how this plays out.
Last year, yes, I spoke about consent being dead. That led to a lot of interesting conversations with the folks in marketing, the people who ran customer data platforms, the people who were in charge of the data lakes that serve marketing. And what I learned is we need to get on board with what each other needs to accomplish. And then we can start helping each other. So the identity we do is very direct and first party. The identity that marketing does starts as third party. The identity we do is frankly about little data. The average number of attributes in a Siam profile is about 20.
The average number of attributes in a marketing profile is about 200, sorry, 2,000, two orders of magnitude larger. And then there's the data monetization imperative that kind of squashes a lot of our most noble aims around privacy in particular, in some cases also security. It's hard to live up to the security and privacy promises we make as identity professionals given the fact that so much of the stuff that needs to happen happens off stage with respect to what we're responsible for.
However, we do have shared interests in progressive profiling, consent and preference management, of course, and then at least privacy compliance. And just to show you how this plays out, I found a wonderful customer data platform value framework developed by one of the wizards in the space, in the marketing space. And if you start looking at some of these things, I know it's a little bit small on the screen, but you start seeing ways that we could actually sit at that table and be part of that conversation. And I did the exercise of mapping to things that you could claim SIAM helps with.
And that's all the stuff that I just added there in the bold. So that includes a lot of direct risk facing stuff, a lot of branding stuff, a lot of great user journeys supporting both the aims of security and fraud protection and the aims of marketing. This is a way to empathize with folks who actually own quite a bit of the stuff that we often think is in our patch. And regarding consent specifically, I ended up writing a whole white paper called consent is dead after last year's talk. Got lots and lots of input.
And some of the things I found are ways to assess your organization's appetite to do more in digital consent and user powered permissions. This is now a white paper available through Venn factory. So that's one case study. And then on the other side of the world, when we get to purely kind of risk facing, I shouldn't ever say purely because of the comparatives that we're sharing here. Here's just a quick other case study. The identity security world, those two words put together. That's relatively new on the scene, even though we've been serving identity security for a long time.
This is where you find things like ITDR, like ISPM. And one of the things that I've been learning is there's some tensions that we need to talk about. And these are some conversations that I've been having with my clients. And so I've been learning about the tensions between, well, the SOC has a lot of data. It's got folks who are tooling it in order to get better visibility. But oftentimes they don't have visibility into the entire identity estate. Identity folks can help with this. Oftentimes they're not really in the proper mix to have those conversations. Sometimes they are.
And I learned through my conversations that according to one person, about 50% of identity teams in his experience are reporting in through security. So that's, you know, right there is a really interesting stat. The distribution of options is really quite wide. And of course the IT versus security imperatives exemplified by provisioning versus deprovisioning. The positive signs are really nice to see. The level of identity savvy that I'm experiencing in talking to CSOs these days, it's just rising and it's excellent and it's really good for working together.
The ease of integrating the IAM estate is actually increasing as well. The urgency of collaboration is all around us. Hearing the Zero Trust presentation previously and learning about all the AI vulnerabilities. There's a motivation to collaborate. And then the Zero Trust and Zero Standing Privilege ambitions that are being held by all of these folks in tandem is a spur to doing better together. So I just want to conclude with a little bit of advice reflecting on all of these comparatives here. First of all, you're going to have to plot your use cases and your stakeholders down to a fine grain.
Feel free to use the Venn if that's the way your brain works. Certainly the way mine works. You're going to have to build empathy for your fellow identity stakeholders and their imperatives. The SIAM versus marketing example is one that may be illustrative. What are the targets that they're trying to hit? Can you help them meet their targets? Probably.
Finally, be tolerant when the org chart doesn't currently reflect what you think is the reality of who ought to own what. Be collaborative. Reach out.
With that, I'll thank you for your very kind attention. Thank you so much, Eve.
As always, a pleasure to have you. We have a few questions here. What I wanted to ask you was, is the traditional security first lens for IAM still viable? Or is it something that we need to evolve in today's business and digital environments? I would start by asking what the audience is, because I think that that is natural for workforce-facing, and probably for non-human identities. But I do think we need to have better, bigger conversations with the consumer and customer-facing side, because I don't think they're not working very well. We've got a question from the audience here.
Is it important to identify identity data attributes and marketing data attributes, and is this a bone of contention for organisations? I think that marketing data attributes are often really completely off-stage from what we do in identity. I think there are a few touch points when it comes to consent and preferences. So right now, the twain are not meeting. I think it would be useful for identitarians to get a little bit of a wider view of what's going on in that world where things are more heuristic and more third-party. Great. Thank you. Another round of applause for Yves Maillard.