Welcome, everyone, to this videocast, where we're going to have a quick, hitting conversation on the topic of the Identity Fabric. I'm Matthew Gardiner, fellow analyst here at KuppingerCole, and I'm joined here with Bhanot Singh from Cross Identity.
Bhanot, please give a quick introduction and say hello. Hi.
Hello, everybody. This is Bhanot here. So obviously, the first question that we're going to get into, since the topic is the Identity Fabric is, well, what is the Identity Fabric? It's a topic that KuppingerCole has been hitting on for a number of years now. But to set the stage, basically, we think of it as an architecture, an operating model, a framework, use whatever term makes sense to you. It's specifically not intended to be a single product.
Another way to think about it, and actually, I'll put up a very detailed graphic, which we won't go into any great depth, but just to give you a sense that there's a lot of complexity underlying the Identity Fabric. You could think of it as connecting some of the subdomains of Identity Management, like Identity Governance, Access Management, Identity Threat Detection and Response, directories, et cetera.
But basically, tying it into a fabric that an organization can, over time, in a modular fashion, pull out, expand, improve, and tie together the various components that make up an Identity Fabric. So I want to hand it over to Bhanot and talk a little bit about how does he handle, how does his organization handle the conversation about platform and fabric and Identity Management with your customers? Sure. So I'd have to date myself back to almost quarter century. We have been into the Identity and Access Management for almost 25 years, at least.
I've been a practitioner in that area for that long now. And in the initial years, when we saw that we were system integrators in the U.S. doing more than 450-odd projects, and we saw the genesis of the problems that led to a solution like Identity Fabric. We saw technologies being broken, and not because they were broken by design, but it was a part of the evolution. As we all know, initially, we had provisioning coming in, the single sign-on and access management came in a few years later, and that followed by privileged access management, and so on and so forth.
Till today, we see Identity and Access Management domain having grown into more than nine different components, if you start looking at all kinds of identity. And so it was a problem which was supposed to be inevitable, because in the earlier times, I saw that we did not have the need of integration so much, and you could still exist as islands, but with all the changes that have occurred in technology and the demands that it has brought, it has become important to exist as one single technology. Right. And it seems like it's a recurring theme in IT.
We don't know we're building Frankenstein leg by leg, and arm by arm, and head by head, and then we turn around years later and realize we have Frankenstein. I don't know if that's a good analogy or not, I just came up with it. So are we sort of abstracting the architecture now to build Frankenstein into a more attractive human being? Maybe that's a way of modeling it. Very true. So now that we have a little sense of what it is, and sort of the next stage or fraction of the identity management problem, the next question is, well, why should I pair?
Why should I architect using the identity traffic approach? I think we sort of hit on it in that the complexity has now become so high, because back in the ancient time, 20 years ago, when you're mostly on-premises and the world of the web was just brand new.
But now, of course, we have SaaS and cloud, and we have M&A happens with IT systems coming and going inside an ecosystem. So you have massive heterogeneity. And then you have the conversation around the classic architect that's centralized versus federated. And I think the natural inclination in the early days is to think centralized, but then you realize with all the complexity and heterogeneity that the federated model is really what's necessary.
And that's where the identity fabric comes in, because it's all really about APIs and independent systems interoperating with overarching orchestration. So when you're having conversations with your customers and prospects, how do you get them from the old school identity management siloed approach to the fabric approach? How do you handle that conversation? Right. So it depends on the type of customers.
And if I have to really segment the market, I would say customers who have been there, who are very large enterprises and have been in business for a long time, as opposed to enterprise, which has been in business for, which has grown very fast over the last just about eight to 10 years. And then we also cannot ignore today the mid-market and the SMBs who suddenly seem to be needing as much of identity and access management and all of it as anybody else.
So when it comes to the first type, which is legacy organizations, which, as you said, have got all kinds of, they've got both the legacy applications and enterprise, as well as cloud embracement over the last few years. There, they have no choice. Obviously they have invested in identity in a big way. They already have in all probability for some IGA tool. They're using something for access management. For sure they have PIM, but then what they're looking for is now all of it to be put together in a way that they would be able to orchestrate services out of it.
Because look, one issue that we have in our industry is that the solutions, the way they come, they're not coming the way problems are to be solved in the sense that traditionally solutions have come in modules, various modules like access management and all that. But if you look at a solution to be solved, it runs across the modules and therefore it requires some sort of orchestration mechanism, workflows to be created for which you need to bring these identities, management modules together. That actually staggered perfectly to the next topic. Go ahead.
It's a little easier for the large organizations, the enterprises who are more recent in nature, and they have gone for a little bit of more convergence from the very beginning, because they have been dealing with issues like cloud and all right since their inception. So for these two, there is no option usually, but to build a fabric as we all talk about. There is another option that companies like us are beginning to provide.
We have a converged fabric, natively converged fabric, which offers a layer of foundation, a foundational layer on which you can not only create newer modules, but your existing modules would also very easily come together. And I think a combination of all that is required for large enterprises, but when it comes to the SMBs and the mid-market customers who have not yet invested much in identity management, I think they can very seriously look at natively converged IAM solutions, which are beginning to appear in the market. And trust identity, by the way, is a good example of that.
Basically, what I hear you saying is that depending on where you are in your identity management journey, whether you're a long-standing one and have lots of heterogeneity or have that Frankenstein that I was referring to, or whether you're newer or fresher with less heterogeneity, you can get a solution that takes a bigger bite out of the identity fabric and one recognizing that there's no one solution that covers everything. So you still need to get down to the how does it interoperate with the other components that you already have so you don't have to lift and shift them.
So you get down to, when you're federating, you need to have APIs so that the components can interoperate with each other. But you also need to have essentially a workflow or an orchestration that goes across the multiple layers so that you get a logical flow across by leveraging the APIs that federate into an identity fabric. So I think that's more or less what you were talking about. Does that make sense to you?
Yes, it does. What I always say is that one problem that you end up solving through APIs creates another problem. We are all talking about the identity bloat. We are talking about the fact that the security break happens more at the seams when we are trying to put two things together. So that's another problem to worry about. And from that point of view, for the converged solutions that are beginning to appear, they do offer, at least for the smaller organizations, that solution whereby you don't have any API bloat.
You don't have what we call zero millisecond revocations because typically when you put multiple modules through APIs, it gets slower. And in orchestration, when you're trying to pass a signal to make the action in another module, it takes time to do that. At that time, it could be fairly damaging in today's world because the hacker would have done his job in that. It also derives the need for standards. You don't want to have all these custom APIs. I think the industry has done some good work in standardizing the handoffs between one domain and another domain.
But clearly, a lot of work still needs to be done to standardize the APIs to make the identity fabric really work as well as it should. Very true. And we have seen lots of it. Thanks to analysts like communities like yours, you put in a lot of effort. You're promoting that, we can see. And it's very, very needed at this point in time. I think one needs to look at it from different angles. There are no perfect solutions out here. The standardization takes time. And in the meanwhile, people need solution.
So it's a combination of looking at some of the available fabrics that are there like ours, and also looking at how much of convergence you can go in from the beginning. There's one important starting point. Starting with the framework. You have to have the architecture in mind and build towards it. That's right. One very important issue I'd like to talk about is this whole convergence is obviously taking time. And the solutions are required by most of the organizations given the security situation. They need solutions now.
So how do you really balance between what you need now and what you need to have over a period of time where the technology is still evolving is another challenge that we see customers dealing with all the time. As an organization, since we dealt with services before, which is quite uncommon in the industry, the services vendor getting it to build products. We saw those issues of the past and we went on to develop something. But we can see the challenges because people are moving from one generation literally to the third generation. And they're really grappling with what you said.
But yes, standards are emerging. Companies like us are embracing those. We try to make the problem a little simpler, at least for the smaller organizations, by building a solution which is all in one and doesn't have to necessarily deal with the problems of integration. So basically, if you're a green field, you can leverage the fact that you have a cleaner slate than the Frankenstein 20-year-old implementations. So to make matters more complicated, there's the identity type explosion, which we're sort of in the midst of experiencing and how that fits into the identity fabric.
In my early days of identity management, we dealt with employees, customers, partners, human beings, basically. But in the meantime, over the last 15 years or so, there's been an explosion of non-human identities. You can't really get out of this conversation without talking about AI agents becoming the hottest new non-human identity. Fortunately, the identity fabric does address that. If you go back to the diagram, which I won't do right here, non-human identities and human identities are all part of the equation.
So in your experience, when non-human identities, whether they're service accounts or the new age of AI agents come into the picture, how does organizations you work with handle them? Where are they? How do they manage them? Where are they in priority? What are they doing differently to manage the identities of these machines and these AI agents? As you rightly said, I think non-human identities are very last five, seven years phenomena. And it has, in terms of numbers, completely overpassed the human identities, including consumer identities.
Especially if you look at things like AI, I think that's making things even more complex because the technology itself is evolving, if you look at AI. And what it was six months ago is different from what it is today. So it's kind of becoming that way, more complicated for technology providers and IAM like us, because we got to keep track of what's really going on, for example, in AI and continue developing things which will be appropriate to the changes that are occurring now and also taking care of the changes that we anticipate coming in tomorrow.
One short-term thing I see a lot of organizations doing is they have the AI agents basically inherit the permissions of the person that it's an agent for. So if you assume an AI agent is an agent on behalf of somebody, the going in idea is that they inherit all the entitlements and account access that that person has. So I don't know if that works in all cases, but literally if it's my agent, then in theory it should be able to do the things I can do and no more.
But I'm not sure what happens with these system agents that are working on behalf of the whole company, like how do you not grant it infinite privileges in the environment and thus obviously if it went rogue, it'd do bad things. Yeah, you're right.
You see, we have been grappling with this as well with a large number of customers and then we came to our conclusion that there's got to be a way to combine different kinds of identities into one repository. Eventually, if you don't do that, then you're trying to deal with multiple repositories and that's even more of a complication. So we decided to put everything in one repository, way to manage all of it, and we can see many organizations moving towards that. So I think it all begins with trying to treat both human and non-human identities in a way from a way that... Exactly.
So with the back to the identity fabric, and we didn't mention the question also asked about zero trust. I think my general takeaway is that zero trust is, again, another philosophy, architecture, approach, framework, that sort of thing.
Similarly, identity fabric in that way, where you can't do zero trust if you haven't managed the identity effectively, but ultimately that's a key input into whether the service or the person to get access to the system or data, to trust them essentially, to verify who they are and what their act level should be. So fundamentally, identity fabric is an enabler of zero trust. I assume you agree with that. That's very true. Very well said.
In fact, talking on zero trust, we have recently been talking about the name it should perhaps itself should change to something like managed trust. Because if you remember, eight, nine years ago, when zero trust began, the technology did not offer much options but to go either to a zero or a one, to disconnect or let it be there. But today there are so many options. You can manage the risk appropriately. Depending on the risk, you can take actions and it has become more of a continuous scale rather than a discrete scale of zeros and ones. But that said, I think you're absolutely right.
Zero trust becoming so essential for organizations, identity fabric is the only way to take care of it because convergence of all the technologies into one singular fabric is the need of the hour. One of the issues that I see our customers struggling with, who have a lot of legacy solutions, they cannot get away from it because it's doing a lot of good work. It's been implemented over a period of time. It's not easy to get rid of anything in our kind of an industry. So they have to live with it and they have to do further work on it.
The integration costs, what I call integration tax, that is burdening. Besides the technology part, the service element is becoming more and more challenging. That's another thing that customers we see struggling with today. Makes sense. So the final question is, how do we get from, help organizations get from wherever they are to this Mount Olympus identity fabric, everything works well together, federated, API orchestrated world?
Obviously, it's not something we're going to do in one step. For example, I worry about some of the legacy systems that you just mentioned, specifically in my work with Active Directory and its cousin, Entry ID.
The base, the core systems on which a lot of the identity management ends aren't necessarily very well maintained or very clean. And so, if you're built on a foundation that's a little bit weak, obviously the structure you build on top of it isn't going to be that great. But the basic question is, how do you, as a practitioner, help organizations get from wherever they are to directions towards the identity fabric? Any insights you can provide would be really helpful.
Well, we truly believe that this has to be addressed through, there is not a single silver bullet for everybody. It depends a lot on where you are in your identity journey. There are a lot of organizations who have done investments 10, 12 years ago.
Anyway, they also started believing that it's time for them to take a look at maybe doing one level of changes, if not completely replace the technology, at least look at some replacement elements. So, the technology per se has also to undergo some changes because you cannot stitch beyond a certain point something which is 15 years old.
So, that extent to which they can make a change, if they have to make a change, is something that we recommend. We try to make it minimal because it's not very advisable, in our opinion, for large customers to make drastic changes in their technology, even though they're not highly satisfactory. You don't want to cost a lot of money and not get a lot of return. That's the classic challenge. You can't spend too much on architecture because then the business leaders are like, what did we get out of that expense?
But at the same time, a moment comes when the cost of staying with the technology and doing band-aiding becomes much more than making a change. And the change has to be gradual, obviously, in an IAM kind of a situation.
So, we recommend that when we look at an organization, we put the problems into multiple categories. One, technologies that have reached a point that it needs a change, and you don't have any other way but to do that.
Two, technologies which need some amount of amendments, not truly a migration to something completely different. And three, certain elements that need to be brought in fresh.
Now, what is going to be the proportion of these three is not easy to really decide. How do you find the IT and security people that are on that mission? How do they sell it outside of their organizations? Whatever you're talking about will cost time and money. And a lot of people with the money don't really understand this identity fabric and the need for it. Any hints you can give people on how they sell it, how best selling it, outside of the IT and security groups?
Yeah, I can tell you the way we are looking at it, and I look at it, rather than talking about concepts like identity fabric, which many customers don't understand, we talk about their problems. For example, I was talking about how do problems really come today? Any solution requires three or four different modules. If you look at orphan account management, typically we see you need access management, you need portions of IGA for sure. If you're talking about orphan accounts in the cloud, you need CIEM. Anything requires today risk management, so IRM is required.
Now, if four different modules are required to solve one problem apart from account management, then how do you do that? Because you cannot do it with four different pieces of software that you have procured. So you need to do some stitch, or you've got to look at a singular technology that can integrate all of it, like the converged technologies are beginning to become available, as I said.
So we go from the solution angle rather than technology angle, because concepts like fabric are still, as you rightly said, are not so well known, even in organizations who have been there with IEM for a long time. Yeah, we certainly can't expect the business leaders to know anything about it.
But yeah, it's an ongoing challenge. How do you invest from an IT and security perspective such that you're ready for when the next business initiative hits, or you're ready when the explosion of AI agents comes on the scene. And getting ahead of that curve, I guess, really is what the Identity Fabric is all about. Laying the groundwork, laying down the architecture, laying down the approach such that when the next thing comes, you can essentially plug it in without a huge level of investment and change.
Well, any final comments before we sign off and give the listeners back some more time? My advice as a practitioner for 25 years of this domain is that times have never been more challenging than now. And any investment a customer thinks of making has to do it very carefully. A lot of things are blurring at this point in time. On one side, you've got solution providers who have been there for years together, and they have a lot of stability in their solution. But on the other side, you also have newer players who are offering solutions which are very agile, but they're not yet proven.
The crux of the matter is to be able to study. The customer has had to never study more than what they need to do today. You cannot just go and start acquiring technologies because you've got to look at your situation, where you stand today. You've got to look at what options are available and where things are moving. I think identity fabric is one thing that every single organization, whether it's an SMB with 100 odd people or it's a large corporate enterprise with 50,000 people, everybody has to look at it seriously. That's my last message.
Yeah, I agree. It's all about the architecture, the plan, and having the 6, 12, 18-month plan so that you're moving from where you are to where you need to be, at least closer to the identity fabric vision. My final comment is, that's why we're here. That's why Kubernetes Full Analyst exists. That's why the European Identity Cloud Conference exists, where the topic of identity fabric and how to make practical investments to get from where you are to the vision of the identity fabric is going to be all over this conference.
My final word and suggestion is that if you've never attended this event, please do. If you have attended in the past, please come again. Check us out on the web. Please join us for other events, live and virtual. Thanks very much, Vinod, for your insights. Thank you to the listeners for listening to us chat about the identity fabric for the last few minutes. All the best. Thank you so much, Mathieu.