IAM programme and roadmap

IAM Operating Model

An IAM operating model defines the responsibilities that make identity and access management work durably across an organisation.

Synonym
IAM governance modelidentity operating model

Definition

An IAM operating model organises who does what around identities and access. It answers questions such as who owns identities, who owns the data, who defines the rules, who owns roles, who owns applications, who approves, who controls, who operates the platform, who handles incidents, and who decides on changes. It also clarifies how responsibility is shared between security, IT, HR, business lines, and the IAM team itself. A workable operating model documents decision rights and escalation paths, and stays proportionate: enough structure to make access decisions traceable, not so much that every request becomes an administrative process.

Why it matters

An IAM operating model is what allows access decisions to remain owned by the right people once the project team has moved on.

The Ariovis perspective

IAM is a sociotechnical system. A technically excellent platform will never durably compensate for responsibilities that do not exist. Governance should not turn into IAM bureaucracy either: the operating model has to let business teams take the decisions that belong to them, while giving IAM the means to apply those decisions reliably, securely, and traceably. This is one of the clearest illustrations of the Security Meets Business approach.

Common pitfalls

  • Expecting an IAM platform to compensate for undefined ownership of data, roles, or applications is a durable source of failure.

These concepts matter most inside a real project.

The first conversation helps establish your context, the systems involved and the next useful decision.