IAM Reversibility
IAM reversibility is an organisation's ability to change or replace part of its identity stack without losing control of its data, configurations, policies and operating processes.
- Synonym
- IAM exit strategyIAM portability
Definition
IAM reversibility describes the ability to leave, replace or evolve a technology without losing control of what has been built: identity data, configurations, policies, connectors, workflows, role models, useful history, integrations and operating procedures. It matters particularly for SaaS services, but not only: a heavily customised on-premises platform can be just as hard to leave. Three levels are worth distinguishing. Data portability covers identities, accounts and relationships. Configuration portability covers rules, workflows and mappings. Functional portability is the ability to reproduce the delivered service on another technology. Exporting a CSV file is therefore not enough to call a platform reversible.
Why it matters
Reversibility determines how freely an IAM programme can evolve over a decade, far beyond the initial product choice.
The Ariovis perspective
Reversibility does not mean building an IAM without dependencies: every serious architecture has them. The real question is whether those dependencies are known, owned, documented and manageable. Fully using the differentiating capabilities of a technology is often reasonable. The problem appears when an organisation discovers, at migration time, that it can no longer tell its own IAM model apart from the proprietary behaviour of the tool.
Related services
Common pitfalls
- A common mistake is to equate data export with reversibility: the data comes out, but the role model, rules and workflows stay locked inside the tool.
Resources
Explore this category
These concepts matter most inside a real project.
The first conversation helps establish your context, the systems involved and the next useful decision.