IAM programme and roadmap

IAM Reversibility

IAM reversibility is an organisation's ability to change or replace part of its identity stack without losing control of its data, configurations, policies and operating processes.

Synonym
IAM exit strategyIAM portability

Definition

IAM reversibility describes the ability to leave, replace or evolve a technology without losing control of what has been built: identity data, configurations, policies, connectors, workflows, role models, useful history, integrations and operating procedures. It matters particularly for SaaS services, but not only: a heavily customised on-premises platform can be just as hard to leave. Three levels are worth distinguishing. Data portability covers identities, accounts and relationships. Configuration portability covers rules, workflows and mappings. Functional portability is the ability to reproduce the delivered service on another technology. Exporting a CSV file is therefore not enough to call a platform reversible.

Why it matters

Reversibility determines how freely an IAM programme can evolve over a decade, far beyond the initial product choice.

The Ariovis perspective

Reversibility does not mean building an IAM without dependencies: every serious architecture has them. The real question is whether those dependencies are known, owned, documented and manageable. Fully using the differentiating capabilities of a technology is often reasonable. The problem appears when an organisation discovers, at migration time, that it can no longer tell its own IAM model apart from the proprietary behaviour of the tool.

Common pitfalls

  • A common mistake is to equate data export with reversibility: the data comes out, but the role model, rules and workflows stay locked inside the tool.

These concepts matter most inside a real project.

The first conversation helps establish your context, the systems involved and the next useful decision.