TL;DR: C1.ai says Gartner has named Identity Visibility and Intelligence Platforms as a new category built around rapid IAM data integration, unified identity views, and advanced analytics, while identity sprawl, non-human identities, and AI agents keep outpacing legacy tools. Complete visibility is becoming the baseline for action, because without it identity security remains guesswork.
Editorial analysis by NHI Mgmt Group, based on content published by C1.ai: “Meet IVIP: A New Era of Identity Visibility”.
By the numbers:
- Gartner predicts it will take more than 10 years to reach full maturity.
Key questions
Q: How should security teams respond when identity data is fragmented across too many systems?
A: Treat fragmentation as an operating risk, not just a tooling inconvenience.
Q: Why do non-human identities complicate traditional IAM programmes?
A: Non-human identities complicate IAM because they often outnumber human identities, hold broad permissions, and operate outside normal joiner-mover-leaver processes.
Q: How do you know if identity visibility is actually good enough for governance?
A: You know it is working when reviewers and control systems can consistently see current entitlements, identity relationships, recent activity, and configuration without manual reconciliation.
Practitioner guidance
- Map identity data silos Identify where identity, entitlement, posture, and activity data live separately across IAM, cloud, and SaaS systems, then document which controls depend on each source.
- Classify non-human identities separately Split service accounts, API keys, machine identities, and certificates into distinct inventories so lifecycle, ownership, and review can be measured by identity class.
- Test whether access reviews have enough context Check whether reviewers can see current entitlements, relationships, and recent activity for each identity before certification decisions are made.
Bottom line: Identity visibility has shifted from a reporting preference to a prerequisite for governing complex identity estates.
What's in the full article
C1.ai's full blog post covers the operational detail this post intentionally leaves for the source:
- The exact IVIP feature set C1 associates with identity visibility, intelligence, and unified control
- The vendor's discussion of multi-agent identity management across human, machine, and AI identities
- Implementation detail on its connector model, unified data model, and graph-based relationship mapping
- The roadmap items C1 says it plans to add later in the year, including dashboards and security insights
👉 Read C1.ai's analysis of Gartner's IVIP category and identity visibility →
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Identity visibility is becoming the gating control for modern identity governance. Without a unified view of identities, entitlements, relationships, and posture, every downstream control starts from partial data. That is true for human IAM, but it becomes more acute when service accounts and AI-driven workflows expand the number of identities that must be observed. The practitioner conclusion is straightforward: visibility is no longer a reporting layer, it is the prerequisite for control.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
- 96% of security operations teams report critical blind spots, most commonly in cloud infrastructure (74%) and identity and access behaviour (67%).
A question worth separating out:
Q: What is the difference between visibility and protection in identity governance?
A: Visibility tells you which identities exist, what they can access, and where risk is concentrated. Protection goes further by using that visibility to enforce policy, restrict access, and create auditable control actions. In practice, visibility is the prerequisite for response, while protection is the operational outcome that reduces exposure across the enterprise.
👉 Read our full editorial: Identity visibility and intelligence platforms: what IVIP changes