Identity & Access Management
What is IAM (Identity and Access Management)?
IAM (Identity and Access Management) is the framework of policies and technologies that ensures the right identities have the right access to the right resources at the right time. It covers how users are created, authenticated, authorized, and audited across an organization's applications and systems.
The core pillars of IAM
IAM is usually described in four pillars. Identity governance and administration manages the lifecycle of accounts: creating, updating, and deprovisioning them. Authentication proves who a user is. Authorization enforces what they can access, often via roles and policies. And auditing records who did what, for compliance and incident response.
Together these pillars answer a single question on every request: is this specific identity allowed to perform this specific action on this specific resource, right now? A mature IAM system makes that decision consistently across every app.
Workforce IAM vs. customer IAM (CIAM)
Traditional IAM secures an organization's own employees and systems, think Okta or Microsoft Entra managing staff access. Customer IAM (CIAM) instead secures the end users of an application you build and sell: sign-up, login, profile, and consent for potentially millions of external users.
The jobs differ. CIAM cares about sign-up, scale, branding, and privacy. Workforce IAM cares about governance, provisioning, and least privilege. Authdog is CIAM: identity for the people who use the product you ship.
Why IAM matters
Most breaches start with a stolen or reused password. IAM puts sign-in, least privilege, MFA, and an audit trail in one place. It also unblocks enterprise deals, where SSO and provisioning are not optional.
Frequently asked questions
- What are the four pillars of IAM?
- The four pillars are typically identity governance and administration (lifecycle management), authentication (verifying identity), authorization (enforcing access), and auditing/monitoring (recording activity for compliance).
- What is the difference between IdP and IAM?
- An identity provider (IdP) is one component that authenticates users and issues identity tokens. IAM is the broader discipline and framework that includes the IdP plus provisioning, authorization, governance, and auditing.
- What is the difference between IAM and CIAM?
- IAM secures an organization's internal workforce and systems. CIAM (Customer IAM) secures the external end users of an application you build, prioritizing scalable sign-up, login, branding, and privacy.
Done reading definitions?
Sign-in, SSO, MFA, roles, SCIM. The APIs are for you. The console is for everyone else.