Field notes on IAM
Short pieces from our consultants, drawn from real assignments: what fails, what holds, and how we decide when the manuals stop being enough.
- Expert insight
Why IAM programmes fail before the tool is even installed
Across information systems built over decades, the missing piece is almost never the platform. It is the operating rules nobody has bothered to write down.
Read - Expert insight — Identity Governance & Administration (IGA)
What if we stopped manufacturing roles?
On most of the IGA programmes we have led since the post-Covid period, the question is no longer how many roles to build. It is what the organisation is already producing on its own, and where human attention actually deserves to be spent.
Read - Expert insight — Identity Governance & Administration (IGA)
An identity is almost never described by a single source
Across the large information systems we work with, no programme has ever begun with a single repository that perfectly described every person. The programmes that succeed are not the ones that find that source; they are the ones that accept it does not exist.
Read - Expert insight — Active Directory & Identity Security
Privileges always tell a story
An Active Directory audit that begins with "who is a Domain Admin?" misses the point. The privileges that actually matter in a living information system are almost never where you first look for them.
Read - Expert insight — Access Management and CIAM
We are not trying to know everything about a customer
We are trying to reach enough confidence to authorise an action without opening the door to fraud. A senior Ariovis IAM architect walks through two very concrete situations: a consumer who has lost their phone, and a business customer asking for thirty-day payment terms at the counter of a construction-materials store.
Read - Expert insight — IAM architecture and Fine-Grained Authorization
An authorization engine does not know your business
What fine-grained authorization demonstrations do not always show. A readable policy only becomes an operational control once the surrounding architecture knows, in time, where to find the business data and how to enforce the answer. This piece is about human identities — employees, agents, contractors, partners and external users known to the organisation.
Read - Expert insight — AI agent security and Fine-Grained Authorization
An administrator role is not a security policy for an AI agent
Why Identity Governance, the Secret Vault and Runtime Authorization have to work together. An Autonomous AI Agent must not inherit the power attached to the technical role the application forces us to assign it; it must only be granted the ability to perform the action it was created for.
Read - Expert insight — AI agent security and fine-grained authorization
OAuth issues a token. AuthZEN asks whether the action is allowed.
Why autonomous AI agents need an authorization standard, not just new OAuth scopes. Field notes from an IAM architect who runs autonomous agents inside Ariovis' own operations and helps clients govern identities, secrets, APIs and runtime decisions.
Read - Expert insight — Netwrix Identity Manager Production Operations
IAM automation must also know when to stop
Safety Thresholds, Simulation Mode, Rollback, Restore Points and controlled deployments in Netwrix Identity Manager Production Operations. A senior Ariovis architect and RUN lead walks through a major anonymised incident and several recurring situations we face on platforms deployed on-premises and in SaaS.
Read - Expert insight — Access Management, CIAM and Fine-Grained Authorization
Your business team did not deploy Keycloak to rebuild your SSO
It needed to decide what the user was allowed to do after signing in. Field notes from a senior Ariovis IAM architect on the Keycloaks, OAuth servers and local entitlement stores that appear next to enterprise SSO — not to condemn them, but to understand the authorization need they reveal.
Read