Good morning, everybody. I'm Diego Galletti, and today we're going to talk about IAM with mAI friends. It's basically our experience with conversational IAM in a larger language and language-linguistic models in a large enterprise organization. So first of all, background and company. I'm an enterprise architect. I've been working for Quad for over 25 years. I have a lot of experience in cybersecurity, started with network security, and then the last 10 years spent all around identity access management. Quad is a global marketing experience company.
We basically have seven regions that we're covering. You probably cannot see the map for some reason, but 26 global facilities, 16 credit and content production apps. And with this, we're working with 16,000 employees internally. So we can cover globally all the clients and customers and offer services across the globe. How that started.
Basically, we started in 1971 when it was funded. It was really like a small company funded with a second mortgage on top of the first house in Pewaukee, Wisconsin. It then became a pretty large company in a 20 years range. And then at that point, it started basically growing in multiple phases. So the first one was what we call the foundational growth, when we started building a strong printing platform and infrastructure through eventually acquisition of other competitors or solutions that will make it more sense for the business. We then reached the other phase, which is the install phase.
That's where we started doing the industrial efficiencies. So acquire basically an extent print offering for efficiencies and offer more services for our customers. This is also around when we started to become a public company. So that was obviously a shift that also dictated all the IAM and access management requirements. The last phase will be basically when we started looking at the online one. This is where we move into the multi-channel solution, which is where we are today.
So we diversify basically our offering to basically support all the clients' needs from integrated omnichannel marketing services, agency solutions. And we basically have to do that, as you can see, through many acquisitions. You can see Rise. You can see Periscope. But at some point, we actually reached in 2022 $3 billion revenue. And then it keeps going, obviously, up. And we have more acquisitions coming soon.
So with all this background, last year we were thinking, what would make sense, you know, given how many conversations there are around AI, for us to explore and see if we can actually use it internally. So one thing we really wanted to do was, can large language models reshape the use of identity governance with a little bit of help of my friends?
And with that, we wanted to understand the potential of large language models applied to our systems, see if we can revolutionize with identity governance based with AI, and then really enhancing the user experience using natural language and conversational interfaces. Especially in a company like ours, we have people across the globe, so many different languages, and it would just make more sense. So our state, from an IAM perspective, is we've been using SailPoint from 2017. We have onboarded over 900 applications and connectors, so it's a pretty large deployment.
600 of these are all internal applications written by the developers many years ago. They are really custom or in some way also legacy, so a lot of complexity around these applications. And then we're managing a lifecycle of these 16,000 employees we were talking about before, so it's across the globe.
3,000 roles to manage, basically, for their access between IT and business roles. 120,000 entitlements to manage. That's quite a large catalog to basically manage. And we are conducting, out of these, because we're public, 100 quarterly access review. That is a lot of stress, obviously, and work for the managers and reviewers every quarter. So then we come up with what are the common challenges out of the current scenario.
Well, the first one is the challenge in requesting user access and permissions. The users are just going to the interface, try to look for something, entering keywords like you generally would do when you search something on the internet. Then you obtain your 200 results, and then it's like, now what? So that's a challenge. They really need to know what they need to look for, and it is really a struggle.
On the other side, you have managers that are struggling every day with this request because they're coming to them, but in the same way, they don't know if it's appropriate or not for the user. They have to do extra work outside the interface to understand exactly the reason behind that. The third case is auditors. Since we're public, we're facing, obviously, a lot of internal audit and external audit, and they're facing difficulties in extracting the report. It seems easy, but they ask different kinds of data, different kinds of questions every quarter.
So just keeping up with how they want to extract the data and the data they need, it's really complex. And the last one is project management, the case where the project management itself requires better third-party user oversight. We do have a lot of consultants and vendors in our company, and it's obviously pretty challenging to manage what they have. So basically, those are the objectives of the approach that we took last year.
So looking at the four ones that I described before, for business users, the goal is, can we eliminate the loss and destruction syndrome they're facing today and make that easier? For the business manager, we want to guide the manager through their proven review labyrinth because it is taking too much for them to understand if it's okay or not. Auditors and compliance users, obviously, facilitate extracting the reports that we just mentioned, but also check for policy evaluation. That's mostly what they do.
Then for project managers, can they effectively manage third-party account lifecycle with the approach of LLM? So the strategic approach was, let's employ natural language for user-friendly interaction. If we can consolidate identity data and events for temporary insights, then we can actually use it. Then adopting large-language models reasoning using natural language instruction can also help and facilitate the whole process. And then creating detailed glossaries to guide users through the process. All of these combine on the right, where you actually see how it works.
We have identity data events coming to identity graph database. And then we have on the right a set of instructions that can be description enrichment, but can also be just policy, risk policies. It can also be workflows of what you expect to do. It can also be just natural documents like glossaries or more data enrichment or SOW. All this is ingested, obviously, into the database, the identity graph database. And then the brain of Yamonis is actually using and connecting all the dots.
And then you have the users on the left that can just use their natural language and ask questions, and have the brain executing everything else. So looking back at our four cases that we wanted to solve last year. The first one, the business users, we want to remove the lost infrastructure syndrome. So the question was, you can see basically this is obviously a picture, but it's easy to do a demo. But the way we wanted to ask the question is, what permission do I need for managing legal contracts in Salesforce? That's a pretty easy question.
You could potentially ask or search for contracts Salesforce in our normal user interface in SailPoint, but it will give you a ton of items to potentially find. With these simple questions, what we're getting back right away is exactly a choice between the two. So it's giving me exactly what I want to know on the user side. And at this point, my only choice would be to decide if I need the European one or the United States one. And then just request it, just with natural language. So pretty easy, no reason to go through the old catalog. The second business case was the business manager.
How do we guide this manager through the proven review labyrinth? Well, first, the manager is able to actually request, to be honest, what does Diego Galletti do? And just obtain a lot of information, not just obviously the job title and department you can see over there, but also other comprehensive and rich information about what my job title eventually will be and what eventually my access in the system currently is. So he has a comprehensive view of exactly what the person is.
Today, without this, he will have to go outside the interface and find out this information in other ways. Then at this point, the manager can say, well, would it be correct to approve the Car View role for Diego Galletti? Car View is an internal system to approve, obviously, and order items. But the response is really, really what we were looking for. Because now you can actually see that it's going to give you all the background of why Diego will need that. It will also do a consistency check. So looking at my job title and looking at the department, it will make sense.
It's checking for policy violation. And then at the end, it's basically telling the manager that it would be appropriate to approve the role.
Now, once again, the manager can decide not to approve it, but this is really helpful to have a reason already. The third case was the auditor and compliance user. How we can facilitate extracting the reports and check for violation. Very easy case, nothing super here, but they just wanted to get this data of Diego sorted alphabetically, removing description where the role is either one or the two. Pretty easy to do, but doing a conversational way, you obtain the data right away. Whatever other customization in the tool today would require hours, sometimes days, to just build a new report.
So a very easy way to extract data. And then, easily, does Diego Galletti violate any policy? This is going to check, obviously, the policies that are defined and clearly state where I have a policy violation. So it's pretty easy to obtain the data right away in a few seconds. Last case was the project manager one. As you know, project managers generally have to work with statement of work. They are defined with vendors and consultants, and they are basically defining what the work is about, the duration of the work, the amount of spend, and what the vendor is going to work on.
If you ingest this into your monies, this data is then definitely available for later. So uploading these documents, integrating in our identity graph data, is actually helping. And then we can potentially use this data in asking questions and taking decisions. So in this case, I'm just asking about this. If we have any contract with Hector Gomez, which was in the statement of work before, and it's going to give you all consolidated data here.
But if I need to request access for this person, then it's going to give me more information about if it's appropriate or not, given the scope of the project. So that really helps, basically, the project manager.
Now, there are key challenges that we've been facing. Obviously, nothing is perfect, but, for example, the terminology. If you use different terminology, you can lead to confusion. A lot of people might be using access versus roles versus permissions. It's just keywords, but obviously you have to teach the model to make sure that it's clearly understandable. Users may also specify different keywords to identify a group of users. In our case, we have seen people asking for accounts versus cubes versus users.
In SailPoint, the concept of a cube is a container of users, so that creates a little bit of confusion. And the last one is obviously semantic enrichment that is essential at this point for communication. If you ask a SailPoint terminology like admin cube, you have to tell in the semantic that that means an administration-type cube. So a lot of people might be using their way to call things, but not necessarily working.
Now, this was a success, though, because people were able to use their natural language to ask questions and get exactly what they were looking for. Using this approach, we were able to accelerate finding the request by also extracting the data and generate the reports for the auditors.
And then, with external documents and all the data, we were able to actually improve the lifecycle for external users, too, because all the information is available there. As a takeaway, obviously, using natural language can streamline the user experience and find better. The identity access information now can be easily extracted without any complex encoding UI limitation that we used to have before.
And then, external documents enrichment process can really help fill in the gap. It is showing a lot of extra information, so that's really powerful. So with that, I just finished a few minutes before. Do you have any questions? Okay.
Yeah, it was very nice to see. It would have been great to see a demo also, but I might have multiple questions. So first thing is, is the whole process integrated in SailPoint, or where exactly the data is coming from? The data is coming from SailPoint, one identity gateway that goes to the Yamones solution. So it's push back and forward. It's just an identity gateway, basically, that's extracting the data. And the way this works is, you can use the website to basically do the website of Yamones to do all the interactions. In our case, we wanted to use an internal plugin.
So in the whole SailPoint interface, we also have the plugin that shows the interface of Yamones. So users can really pick between which one you like. You still want to go 20 years ago, interface style, trying to find what you need, or you want to use conversational approach. And what LLM are you using? The LLM I'm using, it's based on the Yamones solution.
Yamones, okay. Because I'm also trying to build something on MCP on similar lines. So maybe we can connect later. Sure.
Yeah, thank you for the very good presentation. One thing that I was interested in, does it work with different languages? It does. That was one of the plus that we were trying to find. And actually, it works pretty nice. I'm Italian, but other people are from Spain. We have people from South America. The headquarters is in the United States. We have people from Poland, Germany, France. So they can just switch, just between one question, just switch to other languages. And it really doesn't make any difference, because of the way that works.
So it's actually pretty nice, because they can use their own language, and there is no language barrier anymore. Okay, thank you. You're welcome. Thank you very much for your presentation. I would like to ask you, I'm here. Okay. Regarding the auditing use cases, report extraction use case, how did you build the trust within your auditing external team to actually trust the outputs of the LLMs, given that we know that they somehow, sometimes, tend to hallucinate? Correct. There has to be a lot of trust. You're right.
So the way that works is we show how this was working behind the scenes and extracting the data. And we have to prove out that the data that they're interested in is getting uploaded to the Identigraph database. So it is available there.
And then, eventually, what the distractions behind the scenes in Yamon is to obtain the data. Sometimes they want to see the instructions behind the scenes. So that's something they're asking, and that's the only way you can prove it.
Thank you, Diego. You're welcome. Thank you.