Field notes on IAM
Short pieces from our consultants, drawn from real assignments: what fails, what holds, and how we decide when the manuals stop being enough.
Our director looks back on what our consultants see on assignments, and on what those observations bring to teams running an IAM project.
- Expert insight
Why IAM programmes fail before the tool is even installed
Across information systems built over decades, the missing piece is almost never the platform. It is the operating rules nobody has bothered to write down.
Read - Expert insight — Identity Governance & Administration (IGA)
What if we stopped manufacturing roles?
On most of the IGA programmes we have led since the post-Covid period, the question is no longer how many roles to build. It is what the organisation is already producing on its own, and where human attention actually deserves to be spent.
Read - Expert insight — Identity Governance & Administration (IGA)
An identity is almost never described by a single source
Across the large information systems we work with, no programme has ever begun with a single repository that perfectly described every person. The programmes that succeed are not the ones that find that source; they are the ones that accept it does not exist.
Read - Expert insight — Active Directory & Identity Security
Privileges always tell a story
An Active Directory audit that begins with "who is a Domain Admin?" misses the point. The privileges that actually matter in a living information system are almost never where you first look for them.
Read - Expert insight — Access Management and CIAM
We are not trying to know everything about a customer
We are trying to reach enough confidence to authorise an action without opening the door to fraud. A senior Ariovis IAM architect walks through two very concrete situations: a consumer who has lost their phone, and a business customer asking for thirty-day payment terms at the counter of a construction-materials store.
Read - Expert insight — IAM architecture and Fine-Grained Authorization
An authorization engine does not know your business
What fine-grained authorization demonstrations do not always show. A readable policy only becomes an operational control once the surrounding architecture knows, in time, where to find the business data and how to enforce the answer. This piece is about human identities — employees, agents, contractors, partners and external users known to the organisation.
Read - Expert insight — AI agent security and Fine-Grained Authorization
An administrator role is not a security policy for an AI agent
Why Identity Governance, the Secret Vault and Runtime Authorization have to work together. An Autonomous AI Agent must not inherit the power attached to the technical role the application forces us to assign it; it must only be granted the ability to perform the action it was created for.
Read - Expert insight — AI agent security and fine-grained authorization
OAuth issues a token. AuthZEN asks whether the action is allowed.
Why autonomous AI agents need an authorization standard, not just new OAuth scopes. Field notes from an IAM architect who runs autonomous agents inside Ariovis' own operations and helps clients govern identities, secrets, APIs and runtime decisions.
Read - Expert insight — Netwrix Identity Manager Production Operations
IAM automation must also know when to stop
Safety Thresholds, Simulation Mode, Rollback, Restore Points and controlled deployments in Netwrix Identity Manager Production Operations. A senior Ariovis architect and RUN lead walks through a major anonymised incident and several recurring situations we face on platforms deployed on-premises and in SaaS.
Read - Expert insight — Access Management, CIAM and Fine-Grained Authorization
Your business team did not deploy Keycloak to rebuild your SSO
It needed to decide what the user was allowed to do after signing in. Field notes from a senior Ariovis IAM architect on the Keycloaks, OAuth servers and local entitlement stores that appear next to enterprise SSO — not to condemn them, but to understand the authorization need they reveal.
Read - Expert insight — CIAM, multi-tenancy and AI products
CorgiBOX only wanted to add login. It ended up building a CIAM.
When CorgiBOX launched, identity was not a strategic topic. CorgiBOX is a fictional AI-backed platform built around the canine ecosystem: individuals initially use it to organise and share content, while AI helps classify, retrieve and use that information.
Read - Expert insight — Fine-grained, dynamic authorization
How do you spot an attacker reading too much data?
Least privilege is not always enough: sometimes you have to decide whether each access is still legitimate at the moment it happens.
Read - Expert insight
ReBAC vs PBAC: should you model relationships or query the right data?
ReBAC is appealing because it makes authorization readable: Alice belongs to the team that owns this document, so Alice can read it. PBAC starts elsewhere: the decision is computed from context data, at the moment it is requested. The real issue is not picking a side, but understanding which question your application is actually asking.
Read - Expert insight
NIS2 survival: secure your Active Directory in 90 days
NIS2 is not an Active Directory standard. But AD sits underneath enough critical mechanisms — identities, privileges, delegations, administration paths — to be the best place to start when you want evidence rather than a “NIS2 ready” badge.
Read - Expert insight — AI agent security
Deploying Hermes in an Enterprise Environment: Best Practices
An agent able to chain actions across your information system is not first a model question, but a question of identity, mandate and authorization.
Read - Field notes — Netwrix Identity Manager
An IGA programme does not start with a connector
Netwrix Identity Manager — formerly Usercube — industrialises the governance of identities, roles and entitlements. We use it to turn real IAM processes into an operable system: HR sources, lifecycles, roles, provisioning, reconciliation, certifications, audit evidence, migration and run.
Read