IGA teams face a widening gap between what their tools were built for and what their environments demand. Access changes constantly, access reviewers are drowning in information, risk spans hybrid ERP and SaaS systems, and compliance now requires continuous assurance. At the same time, AI promises to simplify decisions, but without business context, it creates more noise than value.
Modern IGA platforms now combine cross-application correlation, continuous controls, and context-rich intelligence to overcome these limitations. When AI is enriched with process, policy, and risk metadata, it can guide access decisions, accelerate reviews, and eliminate blind spots across SAP, Oracle, Workday, PeopleSoft, and SaaS environments. This shifts IGA from reactive administration to real-time, proactive governance.
Patrick Teichmann, Lead Advisor at KuppingerCole, will outline why traditional IGA approaches are no longer sufficient, describe emerging IAM trends, and explain the concept of context-engineered identity intelligence. He will highlight the five core capabilities legacy tools cannot deliver and why they should matter to organizations.
Gerald West, Founder of CaroKahn and Principal Advisor, will share practical insights from decades of SAP and ERP security leadership. He will demonstrate how continuous controls reduce audit workload, how AI-guided decisions prevent over-entitlement, and how cross-application correlation eliminates hidden SoD risks. Gerald will also illustrate real examples from ERP-centric organizations modernizing their governance model.
Who Should Attend
IAM leaders, SAP/ERP security teams, auditors, architects, and IT professionals seeking practical guidance on modernizing IGA with AI, automation, and contextual analytics will benefit from this session.
Yeah, hello everyone, good morning, good afternoon, good evening all around the world wherever you are joining us from. And to our webinar today, Uplift IGA to the Next Level, How AI Can Deliver Value in Access Intelligence. We are going to discuss or, yeah, unwrap a buzzword that is around for quite some time and maybe has already, yeah, passed the hype. And we see already kind of a drop again of this hype. But we want to assess what does AI mean for IGA? What does it need to actually make it deliver value?
For this, I'm joined today by Gerald West from CaroKahn. Maybe, Gerald, introduce quickly yourself.
Hi, everybody. So, I'm Gerald West from CaroKahn. I founded CaroKahn two years ago. Prior to that, I had about 25 years as an end customer trying to make these IGA solutions work, working with business value and all of that.
So, what we're bringing, hopefully, is that operational practical element to this conversation about how we can take IGA to the next level. So, really pleased to be here. Thanks a lot.
Yeah, then maybe a short introduction of myself. My name is Patrick Teichmann. I'm working for Kupinger Coal as lead advisor. I'm advising customers on the right solutions for their IGA, IAM problems, challenges they have and to find the right solutions, but also to, yeah, find a strategic way forward in this, yeah, rapidly changing world.
Maybe, yeah, some housekeeping up front. So, you are muted centrally.
So, no need to mute yourself or unmute yourself. But you can ask questions anytime through the chat.
So, this is the opportunity you have and I highly encourage you to, yeah, ask questions and to share your insights with us also through the chat. We are running some polls through the webinar.
So, please make sure that you take part in them because we want to also see your view on this particular topic. So, I'm hoping to see a lot of answers.
And, yeah, finally, you get afterwards the link to the recording and the slides. So, yeah, if you want to use our material afterwards, this will be posted through our portal. And having said that, I will, yeah, jump directly to the agenda.
So, it's three-folded. I will start with my part with the analyst and advisor view from the practice, what we see here in terms of IGA and AI and what is actually needed to, yeah, get this boat floating.
And then, Ger will take over and show some practical insights, how you can do it with solutions and show, yeah, his practical insights. This is also the moment to, yeah, name our sponsor today.
So, we are joined here by Pathlog, who's sponsoring our webinar here today. So, let me jump in. When talking about, yeah, AI in the area of IAM and IGA, we can see it from two perspectives. From the internal view, we see it more or we can see it as an enabler, yeah, where we use it within IGA to improve the effectiveness and the efficiency of identity and access governance, where we actually support the users mainly to reduce manual efforts and to improve, like, the detection, for example, of anomalies and to augment human decision-making.
This is what we are going to focus on today, but, of course, it has also another view, where we see AI as an identity, where it becomes subject of IGA. So, where we are managing, yeah, agents within IGA and need to have capabilities to, yeah, govern their access and to have the appropriate measures.
So, but this is not part of the webinar today, so we are just focusing on AI as an enabler here. And this is the first question we want to ask you, yeah.
So, poll one, are you already using AI within access governance? And here I mean AI as an enabler.
Please, yeah, answer the poll and share your insights. The poll will remain open and I will jump then directly to the next slide.
So, please be sure to answer it. Yeah, to open, yeah, the topic, the stage, as I'm a big fan of metaphors, because I want to have something tangible within our, yeah, field of untanglable solutions and topics of IEM or cybersecurity.
Yeah, I was thinking about how I can transport the message what we are going today here, so that you can also communicate, for example, with your stakeholders or if you need to pitch your idea. And I came across the bridge. What it means in this particular regard, we will figure out and unwrap later on or throughout the presentation. But I will come with some parts of what characterizes, yeah, a bridge.
And, yeah, one of it is, so the general definition we have, yeah, a bridge is something that connects two separate sides that cannot be crossed safely or effectively on their own. So, if you don't have a bridge and there's, for example, water like in this picture, then you have to swim, for example. But a bridge, to make it work, well, we need to have a stable foundation. It rests on a stable foundation.
And, on the other hand, it needs to be designed to, yeah, or needs to be designed to carry the traffic, yeah, it's, yeah, going to carry. And, lastly, it makes the crossing of, for example, water simpler, faster, and safer.
So, keep this in mind when we are now going through the, yeah, to the presentation. Now, let's shift the look at IGA and where we are.
So, the so-called status quo. So, if you look at the nice promises the vendors and the system integrators give you, then you see a lot of things IGA should deliver.
So, it should reduce, of course, the operational effort and support the business agility. So, onboarding new applications should, yeah, work in minutes, not hours, not days, and should help you to get the insights in your compliance status as you need it, but also for the auditors.
And, lastly, it should improve your security. The reality looks a bit different. We have multiple tools, yeah, we have silos, fragmented islands that are running IEM individually, yeah, doing their IGA, their access governance individually, and we are missing the holistic view.
We have, on the other hand, not the right data to take the decisions. So, I intentionally use the term of data and not information because sometimes it's really just data and maybe sometimes even just characters that are showing to the users, to the end users, as descriptions of entitlements.
And, therefore, we have a risk spread across various systems and, lastly, we don't know the risk that is within the systems. Another consequence that we see is we have reports that have no meaning.
So, you see like, yeah, columns and rows filled with things like, yeah, orphaned accounts, yeah, you have a report which shows you the orphaned accounts, but what does it mean? What are the actions you should take? This is not recognizable from the report in a lot of cases.
So, you don't get the insights to trigger appropriate action. On the other hand, you have the access governance silos that are not interconnected, not changing, and, at the end, you're overwhelming the people who need to take the decisions when it comes, for example, to access certification. And this can lead to a situation that, if you have just an IGA, you could assume kind of security that you have and that might be, yeah, a false friend or something like this.
So, you cannot really, yeah, prove that you are safe. So, now look, let's have a look what is creating this gap between the promise and the reality.
And, here now, we get the first time, yeah, our bridge or the metaphor connected with the IGA topic. So, what you see is usually that you have, like, yeah, from the IT side, an IGA tool, yeah, implemented, and the business should use it.
So, the managers out there, the end users out there, they are obliged to use the tool, but it's not the speaking the language the business speaks. So, between the IT and the business, there lies the river of misunderstanding we have called it, and there within there lies the excess.
So, if you have this, you need to, or this river of understanding, you need to somehow cross it. And there, if you don't have any other opportunity, you are going to swim it. Swimming costs energy and is, yeah, ineffective, at least less effective than a bridge.
So, what you have to cope, the IT has individual requests, training sessions, tickets, by which it actually tries to overcome it and to meet the business. And the business has Excel sheets where it maintains information about what the excess means from a process perspective.
So, for example, meaning that entitlement ABC means approval of invoices, for example, yeah. You have IT coordinators within the departments which help, yeah, the end users to actually execute it.
So, this, but don't get me wrong, it does not mean that the issue lies with one on one or the other side. So, it's not the fault of the IT or of the business. We are not yet speaking the same language. And therefore, we come to the situation that how should a manager, how should the end user decide if he is asked, for example, during recertification for a decision if the information does not mean anything to him or her. And this brings me to the second point.
So, I want to know, does your IGA solution effectively support excess governance? So, the first answer is about that you're, yeah, doing it because you have the proof that this is happening. The second answer is that you have it partially delivering.
So, you have it implemented, but the effectiveness is limited. And the third answer is that you measure it, but you see the ineffectiveness.
And last, not sure because you don't have the appropriate KPIs, for example, at hand at the moment. So, let's jump to the next one. I then grabbed like two of the core issues we see in the practice, and you could name some more, but I want to make here a sample or showcase how AI would help or not help in this particular situation.
So, you see, we have the silo challenge. On the one hand, we have different islands that are somehow reviewed separately. We have SAR services that have individual implementation of IGA locally, for example, and this leads to a situation where we don't have a cross-application risk. On the other hand, by giving this all to the end users, to the managers, we are overloading them. We are overloading with data and not information here. We have too much data, and we have too little relevance, and at the end, no clear recommendation.
This leads to a situation where we see actually the failure of our measures, the excess reviews. We have lists of entitlements that don't mean anything to the users, and we have low quality of decisions because most of the time, then, the people who recertify if they can't answer if a user needs it, in the best case, they ask a question to the support desk, to the application owner, and the worst case, they just approve that everything remains as it is, and we have no changes triggered. If we are now adding, into this situation, artificial intelligence, then we just amplify the issue.
It might be that artificial intelligence is able to recognize some pattern, but the pattern has no meaning, so it's just analyzing how entitlements might be assigned to someone, but what is the business context of it? This is missing.
Now, let's have a look. How would this look like in our metaphor? We are adding a handrail without building the solid foundation. That means it is just changing the problem somehow. Instead of swimming, we now need to climb. Not the same issue, but somehow, it remains the same because we now might get the wrong conclusions, we get the wrong recommendations from AI, and then we have bad decisions because the user might feel safe because they think, ah, the tool recommended me this, so I will just approve it and might want to lean back.
So, what does AI need to actually work? On the one hand, you see now, artificial intelligence has moved to the bottom left because, first of all, we need an integrated platform, and then we need to feed this integrated platform with the context and AI so that the AI can actually use the artificial intelligence, or AI can use the context, sorry, and to support the decision-making of the human being.
So, at the end, AI is going to work because it gets the context, the business context, the process context of the access and, yeah, enables the user then to take the decisions and to speak the language of the user. So, by this, we can also then remove the silos, overcome the silos, yeah, with the integrated platform, we are able to provide them the holistic view.
Therefore, it means context is not just more data, context is the appropriate data that makes it information for the user or to the user and creates a meaning for the user. So, what is this context that we are talking about? We can talk about business context, where we are, yeah, assessing access or defining for the access, what role is executing this access or needs that we can combine it with the organizational unit, the employment types that are using it, or we can execute peer comparisons.
The process context, and then it's quite important here, really talks then about the day-to-day business of, yeah, the business units, of the managers, of the people who need to take the decisions. So, we are then actually in a situation that the user knows what it means to them, what can I do with this particular access and talks the language the user speaks. And last but not least, the policy and risk context pillar.
So, here we enhance the view with, for example, policy violations or risk ratings, can assign particular regulatory text, for example, show compensating rules that are in place already, and so on. We can also utilize risk signals that help us to understand what for a risk a particular access in the combination with others has.
So, we see context is not more dashboards, not longer entitlement lists, or just AI predictions. It's really creating a meaning for the user with access.
And now, I'm completing my picture, all the metaphors. So, you still have the river of misunderstanding, but we have an integrated platform of which IGA is one part of, or, yeah, one of the core components, and it helps you to cross, finally, the river of misunderstanding faster and much more effective, getting away from the individual request.
The context helps you then to make it better understand, yeah, and the AI stops you from falling out or falling, yeah, through the gaps the context might leave because AI, and, for example, implemented, for example, in a conversational way, the manager decision makers can ask questions about, yeah, what they see and makes it really tangible for them, yeah, and can ask the questions in their way. But this makes it also very clear what is needed for this.
To build a bridge from one side is very, yeah, very much work, yeah, so you need both sides that meet and build the bridge together so they can make it work together. How now would this journey look like? And as I already have mentioned, it starts with the data.
So, I need to gather the correct data, and then to engineer the context, I need to collect and aggregate information and correlate a risk out of this. I need to do this not only for single applications within my AGA tool, but I need to do it cross-applicational.
So, what does it mean when I see the access from the identity perspective cross-applicational? And then, if I understand the risk that is, yeah, existing because of assigned access and so on, I'm able to understand when I need to have a human intervening, and then I can trigger, for example, if a particular risk threshold is exceeded, reviews, yeah, so I get away from this once a year or twice a year reviews where I have to review hundreds of entitlements and go into a situation where I can, yeah, go with a risk-based approach and see what is, yeah, causing the biggest risk to my environment.
And then, when I have all of this enabled and you see that the baseline needs to be there, the foundation needs to be there, then I can add AI as decision support. I can then, yeah, take context or, yeah, bring up context-aware suggestions and deliver risk-based guidance that assists the human with, yeah, to take the right decision. But the human still takes the decision and can then benefit from this.
And then, you see it on the right. For just having insights, you get the action. You need the right data at the right moment and the right decision. And this is where modern IGA solutions are helping.
So, not only the right data we are supporting here then with the right moment and also the right decision. Now, let's bring it home. What are the key takeaways of what we for AI in this area?
So, we see IGA falling short at the moment when it comes to really decisions because it is not yet delivering the information in a lot of cases that is needed to take informed decisions. Therefore, we need to enhance IGA to have business context available and to create meaningful insights, meaningful descriptions, meaningful, yeah, decision processes to the users. And this means, yeah, AI without this context will not deliver its value.
So, I have to disappoint you if you thought AI will take away all the work you have. It can still support you, for example, with, like, creating proposals for descriptions but still based on a human input. At the end, AI should augment the decisions by delivering the right information at the right time.
So, for example, during access reviews, the right information is delivered to the user to reduce the cognitive load of the user and to reduce also the approval effort. And last but not least, it remains a very important perspective to have, yeah, the effectiveness measured.
So, this means put the right KPIs, the right measures in place to measure your success. And with this, we are going to have a look at the practical insights from Gerald, how you can implement this and how you can improve your IGA maturity with AI or what you need to can, yeah, actually add to make AI work.
Gerald, the stage is yours. Thanks, Patrick.
So, what I was going to go through was first, you know, talk about how this bridge looks like in practice. And I want to give a bit of context because I have actually been on both sides of the river that Patrick described. And I've stood on the IT bank trying to explain, you know, authorization concepts to business managers. But I've also stood on the business side trying to understand why an access request takes, you know, three weeks to come through.
So, in my time as an end customer, I've really been involved in making these solutions work. And so, that's really what I'd like to share with you. I've done a quick introduction. And what I will now move on to is to look at how this works in practice.
So, let's review what, you know, has just been covered. So, the idea of context being foundational.
You know, without that, AI just amplifies the noise. The river of misunderstanding, which is the core challenge that we face and we look to address. And the fact that governance is typically failing at that decision point.
So, you know, I want to try and paint a picture of what it looks like when we stop swimming and we start, you know, actually bringing operationalizing this context. So, what does decision ready actually look like is one of the things that we'll be covering as well. And I think one thing I've observed quite a lot is that, you know, quite often organizations are what I call infrastructure rich and process poor. They might be operating at a relatively low maturity level. But actually, they have capability that could take them a lot higher.
And it's just about, you know, the bridge materials exist, to use Patrick's analogy. The bridge materials exist, but they just haven't been assembled properly.
So, let's have a look at how a way of approaching thinking about this. So, we have a maturity model, which is a five level, familiar five level model from ad hoc to optimized.
And, you know, if we start at the lower levels one to two, what we see is that's basically swimming. It's scattered data, manual processes, segregation of duty checks in spreadsheets. To apply AI at this level is that amplification of noise problem, yeah.
So, the focus here has to be around getting the data in order first, yeah. Now, at this level, if we look at the maturity curve, as you move up the maturity levels, you get more value because you're executing processes more effectively and more efficiently and ultimately in a way that enables the business.
And so, we see the volume streams growing from initial risk reduction and compliance, which is what we're doing at the lower levels of maturity to efficiency gains as we move towards the mid-levels. And then ultimately, we're looking at agility, innovation, continuous improvement.
So, the AI focus really starts to add value around level three. Typically, it's what we see where you have that central repository, you know, the infrastructure that Patrick described.
You know, you have that foundation, you have automated SOD detection, and here AI can enrich the decision-making process. So, the focus here is really about enrich, you know, having that context at the decision point.
So, if we then look at the higher levels, and this is where AI can be truly transformational. So, what we are aiming to do here is to transform that bridge into something more sustainable.
So, if you look at level three, you know, we've basically built probably a footbridge, rickety footbridge. Whereas, as you move up to level four, it's more like a suspension bridge, and ultimately, probably a smart waterway crossing that river, yeah. And that's really what we're aiming at.
So, this model, it helps us understand where we are, and therefore, where AI can add value specifically. So, let's talk about the context, because context is how AI can deliver its value. And Patrick mentioned three types of context, the business context, the process context, and the risk context.
Now, we have a framework for operationalizing these layers. So, if we think about how AI can engage with the context that we provide in order to add value, well, there are three things that we need to do.
First, we need to discover what's going on, then we need to decide, and then we need to do something. So, those three levels are matched by, we have the analyze, which helps us discover, so it surfaces those unknown risks. And then we have the advice, which helps us make better decisions. And then ultimately, we can identify what can be automated.
Now, if we look at the analyze, what is it actually doing? Well, you would have some techniques like, I mean, baseline learning, what normal looks like, and then perhaps some anomaly detection, so spotting outliers. Advice would probably ask, what context does this approver need? Peer group analysis, compare with similar users, some sort of natural language processing for justification analysis. But really importantly, ideally, some sort of predictive risk scoring.
So, if I take this decision, what's the probability that something might go wrong? That's the sort of decision support you can get with advice.
And then, yeah, automating risk, you're asking, what should happen automatically? So, we're talking about intelligent routing, risk-based. Auto-remediation, perhaps of the lower risk items. Adaptive thresholds, where it learns from what's happening. The key is that the business context is feeding peer comparison. The process context will identify the patterns, unusual patterns, and then the risk context can drive recommendations.
So, I remember a number of years ago, we're looking at a concept we started off called user intelligence. And a scenario that we considered was, if you're looking at a piece of log information that says, and I guess, Patrick, you could call this data.
It says, G-West executed transaction VA01 in SAP system ABC at 5 a.m. on the 24th of January, 2026.
Now, that piece of information doesn't necessarily mean very much. It's not something that can drive any discovery or decision on its own. But once it gets enriched with a bit of context.
So, it turns out that G-West is Gerald West, and he's the head of application security for a particular organization based in Hong Kong. And it also turns out that he is part of this group that's working on a particular project. And there are a whole bunch of other things that are available about him.
And then, you also notice that the transaction that he executed, VA01, it's create sales order, which is part of the order to cash process. And you also, and has a certain level of risk, given what organizational information he used. You then have this event of G-West executing transaction VA01.
Now, is someone, a security guy in the IT department in Hong Kong, has now performed a business process in order to cash. And that generates a whole different level of meaning, a whole different level of context.
And then, add a little twist to this as well. This happened on the 24th of January.
Now, the context of that is, well, that's a Saturday, and it was out of hours. Now, as you drill into it, you may find additional context comes from the fact that he performed this activity as part of an elevated access, a firefighter session. And you were able to find the justification for that session. And it now ties back to the project that he's working on. All of this begins to give you some potential answers.
You may need to follow up, and this is where AI can help bridge those gaps that Patrick talked about, to be able to harvest this context and come up with the right recommendation of what to do about it. So, let's move on.
So, the next thing I would mention is, how does this evolve with maturity? And as we said, if we inject AI at the wrong level, when we're not ready, we end up amplifying the problem we have.
So, at level two, you're looking at that periodic SOD report. You're not really going to get the real benefit of AI until you start to have that centralized repository, and you are able to have the proper context provided.
So, we can see how the context gets enriched as we move up the maturity levels as well. So, at level two, periodic SOD report, static risk ratings, email notifications. By level four, we're looking at real-time monitoring, risk-based recommendations, just-in-time provisioning.
And then, at level five, you have that AI anomaly detection, AI-driven suggestions, and that ephemeral access. So, you have that consistent pattern, but the sophistication tends to scale. And ultimately, what we are looking at is moving from enrichment context to automation of actions, and then, ultimately, a level of autonomy is where AI will add the most value. Okay.
So, just a little word on bringing this to life in practice, because we talk about process maturity, and the way in which organizations get value is by performing processes more effectively and more efficiently. And there are typically five core processes around application access governance here, and we've actually used action verbs to illustrate that these are processes that pretty much all organizations perform, regardless of how they perform them. They might be doing it manually, or they might be using a sophisticated tool.
So, we've got analyze and monitor access, design and optimize access, request and provision access, review and certify access, elevate and control access. These are the key processes, and these all map to capabilities. And I've used PathLock as a great example of a modern IGA vendor, and has capabilities that allow these processes to be elevated.
So, for analyze and monitor access, there is access risk analysis, which does the SOD, the sensitive access, the critical access, et cetera. Design and optimize, you've got role management. Request and provision, you have compliant provisioning. Review and certify access, we've got the certifications module that does this. And then elevate and control, you've got the elevated access management tool.
Now, the key thing to note here is that at the higher levels, the cross-application coverage is really critical. Someone might have, you know, payment creation in one system and payment approval in another.
So, the cross-system SOD conflict needs to be handled. And, you know, having over 100 plus connectors means that the bridge that is shown will span the entire river.
So, it's not just a narrow bridge in one or two applications. It is a very comprehensive capability for doing that bridge, that river crossing.
So, this is a really great example. And, you know, in terms of the AI dimension, PathLog IQ is something you'll be hearing a lot more about, I'm sure, over the coming months. It's really key to remember that the maturity is what defines, you know, how good you are and what value you get. And the tooling, it's the use of the tooling to elevate the maturity in the process is the key thing. Right.
So, let's now look at some concrete examples. So, the first scenario that we'll look at is quite a familiar one, which is the orphaned account discovery.
So, imagine it's, you know, it's Tuesday morning and your security team runs a routine report and discovers 340 orphaned accounts. So, those are accounts that are linked to any active identity or owner.
So, now the question is this. How does it happen currently?
Well, what happens is you get a report. It says 340 orphaned accounts. You open a spreadsheet. You start referencing the HR data manually. You might send some emails asking, do you still need this access? And then you wait and you wait and you may get some responses, but then the audit happens and you hadn't managed to close everything out and the finding occurs again, appears again in the audit report. And that's swimming.
Yeah, we're still swimming. There is, you know, no context, no prioritization. It's basically just a list and a prayer.
So, you know, let's look at how this then can happen with context. So, in this scenario, the AI will tell you what matters. It will direct your attention to what matters. It will use activity pattern analysis.
So, three accounts actively used despite no linked identity. So, those you have to investigate immediately. Then you've got other things like you have business impact scoring is another thing.
So, 47 have elevated authority. That's a high priority. It might do some temporal risk analysis. 12 of these belong to levers, which left more than six months ago. That's a compliance exposure. Then it does some intelligent triage. It says there are 278 low risk. Those you can do a batch cleanup of those.
So, effectively, you don't have 340 problems. You have three urgent ones. You have 47 important ones, and 290 that can wait and be done as a batch. That's decision-ready information, and that's an illustration of how the bridge can work. Let's go to another example.
So, if we look at a privileged access request example, and here, you know, imagine a request for elevated SAP access lands in the approval queue. The justifications field, you know, says two words. It says project work.
So, in this scenario, you know, the approver sees, you know, this is a classic river of misunderstanding scenario. You just have a name. You have a technical role, and you have a cryptic justification.
So, there's no real context. You've got probably 50 other requests in your queue. You're probably under pressure. People are chasing you. You don't have visibility into, you know, the requester's history. You don't know what the risk level really is. You don't know what they've, you know, what the content of the role really does, but you're under pressure, and in the wrong scenario, you probably approve it. What else can they do? You may have checked with someone, and they said, yeah, it'll be fine.
So, then three weeks later, 50,000 customer records exported, and everyone asked, you know, who approved this. So, what could this look like?
Well, if we apply the context before the decision, then you could get some peer group analysis. You know, this is a first-time request.
You know, peers don't have it. That's unusual.
So, maybe just flag it, just in case. Yeah. Do an SOD simulation, a bit of risk analysis, and you can see what sort of risk might be created by this.
You know, for example, a conflict between, you know, two payment functions. The historical pattern, you know, similar requests have happened in the past. Three were approved, and two of them, you know, subsequently revoked. That's a bit of a signal.
You know, the end of the natural language processing the AI might do, we'll say, well, hang on, project work is a bit vague, and, you know, flag for more info. So, ultimately, it's going to give you some sort of recommendation, like request additional justification before approval. What it's not doing, as Patrick alluded to, it's not deciding on your behalf. It's equipping you, equipping the human to decide. One final example, and this is one that will probably be very familiar to many of you, is the access review element.
So, this is something we see a lot. The annual access review, some people do it quarterly, but I see a lot of annual. The manager receives a list of 200 entitlements for their, you know, 15 team members, perhaps, and it's due by Friday, and this is one of those proof of failure examples that I think Patrick mentioned.
So, if we look at what the manager actually receives, they get 200 line items, technical roles, role names they don't understand, no indication of what's unusual, no context, no risk context, no usage context, don't really have much of an insight into what to do, but they're under pressure. They need to complete this review.
So, they might, you know, in good faith, spend two hours scrolling through. They might ask for a bit of help, ask their IT friend, the IT coordinator, for help, and they're not really sure.
So, just to be safe, just leave it, because otherwise, you don't want to break the business process. So, in the end, they probably approve everything and submit.
Yeah, the good news is they've completed the cycle, but there are no changes. So, this is, I guess, what you would call compliance theater.
Now, if you were to enrich this with some AI context, then the manager would receive something that directs their attention and, you know, a bit of usage analytics. It says three of them haven't used the access in 12 months. It might do a bit of role position mapping.
You know, one transferred from finance still has payment authority. It would do a bit of risk analysis, yeah, and do it in the language of the business.
Yeah, so, actually explain what the risk actually is in language that the business could understand, and then propose some pre-populated actions. You know, we suggest you revoke unused access for these users, and we propose that you look at escalating any sort of role mismatch like this.
So, the principle is that it is harvesting a range of context and delivering actionable intelligence. So, 20 minutes instead of two hours, you know, eight actual changes rather than nothing.
So, that way, you move away from that compliance theater, and you start to deliver something that's a bit more like governance. Yeah, I think, you know, one thing to note is that at the higher levels, you know, if you get to level five, you would probably, you know, that annual review certainly becomes more of a triggered continuous micro-certification. That's the typical direction we see that happens.
Right, so, the next bit is about how do we measure these outcomes here, and a key takeaway I noted in Patrick's deck was that effective governance is measured by outcomes, not activity, and this is really very true, especially when we're looking at things like access reviews. So, the access review change rate, you know, where I see a lot of minimal changes because it's a tick box exercise effectively.
So, that's one of the indicators. The time to decision for privileged access, that's another one to keep an eye on. Approver confidence level, you know, it's much stronger if it's evidence-based and defensible. Audit evidence is really key. The SOD conflict status, you know, you're able to start managing and controlling your SOD scenarios, and then also just audit findings.
I always knew it's always better to discover issues first before the auditors do, and that's one of the things that you start to be able to do when you enable, you know, the context to then be acted upon by your tools like AI. So, the, you know, key point is that it's not really how many reviews that were completed, it's really how many resulted in change, yeah.
So, that's key. If your change rate is zero, you're not really governing, you're documenting effectively.
So, I think to finish off, I would just mention that, you know, if you are looking to challenge yourself and separate, you know, genuine agentic AI from dressed-up dashboards effectively, there are probably five questions that you should ask, you know, even whether you're on an AI initiative or your IGA vendor. So, the first question is, can your AI explain why the access is risky, yeah, because generic AI will typically say high risk, but you want that domain-specific AI that can explain the evidence, yeah, an explainable AI with traceable reasoning, not a black box score, yeah.
So, that's really, really key. The second is, does intelligence arrive before the decision point or is it something that's after the effect in some report, yeah. If it's an after the event thing, it's still a form of swimming and it's really important to try and bring this back to the decision point.
So, the third question would be, can recommendations be traced to evidence, yeah, because black box recommendations kill trust, that explainability, AI explainability is a very, very important topic here. And then the fourth is, do insights trigger workflows?
You know, if we go back to the three A's, yeah, and I actually have, I like the three D's. The three D's are, you know, discover, decide, and do, yeah. Are they resulting, are these insights triggering workflows? Are actions actually being triggered? Are we actually doing stuff as a result? And this is often where we see gaps where in AI pilots not being, because they may stop at the level of insight and being able to get beyond that, where you actually deliver some automation is really, really key.
So, and the fifth one is, where does your data go? So, this is more of a data privacy regulatory potential.
So, that's something to keep an eye on as well. So, finally, just to finish, I would just reiterate that the key point is, you know, the bridge doesn't always need new materials.
It, you know, sometimes it just needs better assembly. Yeah.
So, most organizations, you know, are infrastructure rich, but process poor. And, you know, one thing I've found is that even if there is this really strong case to upgrade your technology stack, you're going to have more credibility if you can demonstrate that you have made the most of what you have. And then that also guarantees that the same inertia is not going to be repeated with the new investment.
So, it's really important, even if you see that you are going to grab a new bit of technology to take you to the next level, make sure you're making the most of what you currently have, is one thing I would advise. So, ask yourself, are you getting full value from what you already have? And then the second is, your processes match your tools capabilities?
Yeah, that's a really key element. Again, looking at the maturity curve and where you are and what tooling will help you move from where you are to the next step in that cycle.
So, for example, if you go heavy on sophisticated AI capabilities when you're at level one or two, you're not going to get the value. You need to build that layer of infrastructure and context in order to be able to get the best out of AI. And then the final one is, is the context reaching the decision point or is it dying in reports? I think those are the three points.
So, I think Patrick made the case that context is the bridge and AI is the handrail. The river doesn't get crossed by IT alone or by business alone. It gets crossed when access decisions carry enough context that a business manager can act with confidence.
So, that's the shift from swimming to building and crossing a bridge. So, from compliance theater to real governance.
So, thank you. Happy to take questions. Yeah.
Thank you, Gerald, a lot for your insight and that you picked up the metaphor and so nicely transformed it into these real-life examples. That was really nice.
So, when I saw this offered account, yeah, like sending out the spreadsheet, and I know this so well, I always use the term pray and hope, yeah, that nothing happens in the meantime, yeah, and that at least someone answers, yeah, otherwise, because if no one answers with the offered account, you have the other side of the issue is you kill the account and might kill the production, yeah. So, you have to choose and there, yeah, by utilizing AI access governance, access intelligence capabilities, we might be able to shed a light here, yeah, and get better insights. Okay.
First of all, let's have a quick look at the polls. Very interesting results.
So, the first one was, are you already using AI with an access governance? So, the yes answers, no one answered.
So, no one is using AI so far in IGA. So, yeah, not the early adopters here in the webinar, but 75% say no, but we plan to and our tools support it.
So, we see modern solutions that support it already. I hope you're now equipped with some insights of what you might want to achieve with it and what you're promising and have filled a future requirements list. 30% each for the answers no, AI in access governance is not planned at all and no, we plan, but our tools are not yet capable.
So, this might be the point where you want to look, yeah, at the market. So, I can also refer you to our leadership conference, for example, to have a look or, yeah, one of the solutions we have seen here already with Pathlog and to look there for modernizing. The other one is, does your IGA solution effectively support access governance? And 50% answered, not sure, we lack appropriate KPIs to assess effectiveness.
So, I see, so what we are discussing a lot about, yeah, effective access governance. So, we are using at the moment a lot of the capabilities that the tools give us, but we are not measuring the success.
So, this will be, yeah, the next step and that is also what we see with a lot of organizations. More and more regulators ask, are you doing it effectively?
Yeah, what are you achieving? And so, we see a movement there and, yeah, I can also then just refer to our research. We have published a blog that I will share in the chat here, a link about this topic about KPIs and KRIs and their importance for IGA. 40% answered, partially governance intent exists, but effectiveness is limited. Changes occur, but not consistently or risk-driven.
And I think this is what we see then with, yeah, modern solutions that support here, yeah, with AI and can really also be enhanced with the context, can support them to track back why did someone decide like this, right? This is the case you made, Gerald, right, about the topic that you then can trace back, yeah.
I had a note also here in terms of this, so when we are talking about this, so not more of this implicit trust if someone sends a request, yeah, so when I saw your request and if someone approves it, they sometimes think about a person who's requesting, yeah, and I think this is a trustworthy person and approve it, yeah. I see, yeah, that you agree. This is also what you want to remove, right? 100%.
Yeah, great. Yeah, and only 10%, yes, we measured anti-effective access governance, so I see a lot of opportunity here for our audience, yeah, to improve here with on the one hand tool, but also on the governance. And I think this is a question we have here from the audience I would ask directly, maybe to you directly, Gerald, if IGA is not fulfilling the promises, is it the reluctance of using standards, a governance, not a technical problem? Do you have an idea on this?
So I don't know, not 100% a question, or at least about the reluctance of using standards, but do you have an, yeah, something about this, Gerald? So the reluctance to use the tooling?
Yeah, so, yeah, the tool, but there are no standards, so you could do it in one or the other way, but yeah, so not really achieving governance, however, would I say, yeah. Yeah, yeah, I mean, there are a number of factors, you know, you have some organizations, yeah, and this is what we see with maturity.
So if we look at the lowest maturity levels, there is this inertia that we observe, which is they would do the, you know, organizations would typically do the bare minimum, because they, you know, and that's where compliance is probably the only driver, reluctantly, that gets things moving in any way, shape, or form. There probably isn't that proactive risk management mindset either, and that might come a bit later, but we have to do it because of audit, and so we're being forced to do it.
We're very busy, we've got all these other IT projects, we've got so much, and now we have to do this compliance thing, and as you move up the maturity, you start to get a bit more of a risk management consciousness coming in, and people are starting to do things that are not necessarily audit related, but these are good risk management for the business, and that's another level, and then as you keep moving on, it becomes a little bit more aligned with the business strategy, and that's what we also see with the maturity progression, is that you move from compliance on the one hand, through risk management, into ultimately business enablement, and that probably fits the pattern that you were alluding to as well.
Yes, I totally agree, and I would also put it to that point, so you need to make your head, so you might have the technique, you have the tools capable of helping there, but you need to assess what you want to achieve, and then you need to start first with the capabilities, as you did Gerald, and highlight it, understand the capabilities, and what you want to achieve, then I can also derive the KPIs, and implement the correct measures in the systems, yeah, and make it work in the way as I, as an organization from risk effectiveness, want to do it.
If you, yeah, still need, or if you need more on that, yeah, reach out to us, we also advise here, Gerald is also here, we have the tools we have, but also the industry knowledge to help here, and this is, yeah, how would I, or how I close, yeah, it's not just about the tools again, yeah, it's about what do I want to achieve it, and start to understand it, and that's where I say thanks a lot for, yeah, your help, or your attendance, yeah, thank you a lot Gerald, for your insights, and I'm happy to hear from you, the question about the rating of the webinar, thanks, take care, thanks a lot, take care, bye.
See All Locations
See All Locations