Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Customer and partner IAM: what external identity teams should rethink


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15817
Topic starter  

TL;DR: Gartner’s Innovation Insight for Customer and Partner IAM argues that more than half of organisations still rely on homegrown CIAM or no solution at all, according to Descope’s reading of the report, while external identity demands are becoming more dynamic and security-sensitive. The governance problem is no longer authentication alone but whether identity architecture can support transient users, partner ecosystems, and modern protocols without overloading workforce IAM assumptions.

NHIMG editorial — based on content published by Descope: Reflections on the 2025 Gartner® Innovation Insight for Customer and Partner IAM Auth Thoughts

By the numbers:

Questions worth separating out

Q: How should security teams govern customer identity differently from workforce IAM?

A: Security teams should govern CIAM as a customer journey problem first and an access-control problem second.

Q: When does in-house CIAM become a governance risk rather than a cost-saving choice?

A: It becomes a governance risk when the organisation cannot keep pace with modern authentication, consent, risk, and orchestration requirements without creating brittle custom code.

Q: What do teams get wrong when they treat B2C and B2B as separate identity programmes?

A: They usually over-separate the business model and under-separate the control model.

Practitioner guidance

  • Separate external identity from workforce IAM governance Inventory where customer and partner access is still being handled by employee IAM controls.
  • Map external identity journeys end to end Trace onboarding, authentication, consent, risk checks, and downstream orchestration for each external constituency.
  • Test whether your platform supports mixed constituencies Check whether the same identity stack can express different controls for individuals, businesses, and partners while maintaining consistent policy.

What's in the full article

Descope's full article covers the practical detail this post intentionally leaves at the strategy layer:

  • How Descope frames the build versus buy decision for CIAM and PIAM across external identity programmes
  • Examples of external identity journeys that benefit from custom orchestration, adaptive risk, and multi-portal support
  • The specific requirements Descope says it sees in organisations moving away from workforce IAM for external users
  • Gartner citation context and how the vendor interprets the report for CIAM and PIAM planning

👉 Read Descope’s reflections on Gartner’s CIAM and PIAM innovation insight →

Customer and partner IAM: what external identity teams should rethink?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15402
 

CIAM and PIAM are becoming governance disciplines, not just authentication projects. The article reflects a broader market shift: external identity now has to balance user experience, risk, privacy, and lifecycle control at the same time. That is a different problem from workforce IAM because stakeholder churn, federation complexity, and business-to-business relationships create more varied control states. Practitioners should treat external identity as a governed programme with its own operating assumptions.

A few things that frame the scale:

  • 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to Ultimate Guide to NHIs.
  • 91.6% of secrets remain valid five days after the targeted organisation is notified, showing how slowly governance gaps can close once exposure exists.

A question worth separating out:

Q: How do you know if external identity architecture is actually working?

A: Look for fewer one-off authentication paths, consistent policy across portals, and clear lifecycle handling when users move between customer, partner, and admin roles. If every new use case requires bespoke code or a separate toolchain, the architecture is not yet governing external identity effectively.

👉 Read our full editorial: Customer and partner IAM is moving beyond workforce IAM assumptions



   
ReplyQuote
Share: