Showing posts with label user centric. Show all posts
Showing posts with label user centric. Show all posts

Tuesday, August 26

A few interesting Identity findings

User-Centric vs. Enterprise Identity

Dave Kearns offers a concise explanation of the core difference between user-centric identity and enterprise identity. His summary:
Enterprise-centric identity management is really all about tying together all the activities and attributes of a single entity into a readily accessible (and reportable and auditable) form. User-centric identity is about keeping various parts of your online life totally separated so that they aren’t accessible and no report can be drawn.
I like the simplicity of this explanation. I think it really captures the essence of the difference in an understandable way.


Management Profile

In this article from ComputerWorld, the Director of IS, strategy and architecture at Universal Service Administrative Co. is profiled. He talks about his current project:
An IAM framework will allow for customer information of applicants and contributors to remain consistent across IT platforms while spanning new and legacy systems and applications. My goal is to have one authoritative repository for contributors' and applicants' access information that will be used in managing a secure access control infrastructure. I believe that identity and access management will become an underpinning technology that IT leaders need to address.
He goes on to say that Identity Management is the most critical technology of the year. It's nothing earth shattering, but I always give priority to real customer insights.


Interesting Service Offering

I've discussed the idea of outsourcing identity and managed identity services, but CoreBlox, a company founded by ex-Netegrity folks, have this posted in their service offerings:

Dedicated CA SiteMinder Support Professional

It's an interesting twist on managed identity services and one that I think would resonate with customers. I've known a number of companies who would've liked to just outsource the identity support role to someone who knows what they're doing -- without having to hire and without having to pay for a full-time resource who sits around waiting for something to go wrong. One of the things I like about this is that CoreBlox isn't trying to provide a support professional for any identity system. They're focused on the technologies that they know.

So, if you had a provisioning solution from Courion or SAP and Siteminder for Web Access, you might need to go to two different people or companies to get the right support. BUT - that focus on core expertise is a recipe for success (especially in a support role). And likely still more cost effective than hiring, training, and retaining someone to support these complex systems.

Saturday, April 19

User Centricity in the Enterprise (Cont.)

I've blogged on this before. But I was oh so young and naive back in December of 07.

OK, I'm not 100% convinced yet, but I'm beginning to see the light. I think part of the problem is that I have an internal tendency to want to understand things in mathematical terms and what I'm finding is that I almost need to think of this issue through an artist's lens. And that's a tough metaphor to make because I know it could be misunderstood - I wasn't trying to make the issue black & white or say that there would never be a case for x, y or z. But as a philosophy, I was thinking that user-centric identity is about individual control which seems at odds with the goals of enterprise security. Just because the technology could be used to enforce control on both sides doesn't mean the philosophy of a user-centric approach works within the enterprise walls. I was able to fit B2B transactions into the equation (like an insurance rep interacting with multiple carriers). But, that again isn't really contained within the walls of an enterprise. I was trying to build a chart of some kind in my mind to map out the scenarios.

But then I had a few good discussions with folks like Kaliya Hamlin, Dale Olds, Michael Barrett of PayPal, Andrew Jaquith of Yankee Group, and others. And then I read this (thanks Pamela) and this (thanks Dale) and I watched the video from Brainshare that Dale linked to.

I'm not quite ready to start professing the faith of user-centric in the enterprise and I certainly haven't mapped it out in my head, but I'm beginning to recognize that I'm on the dark side of this and that Kim Cameron, Kaliya, Dale and Pamela are in the light.

Thursday, December 13

Great Answer

I asked for a useful scenario for OpenID in the enterprise. Johannes Ernst delivered.

I do think though that while this sounds like a good use-case for some of the underlying technology, it may not contradict what I was thinking. What I was referring to, regarding user-centricity in the enterprise, was the authentication and user information management model that enables people to manage their own information rather than have that information managed by the application owner (think eBay, Amazon, iTunes, etc.). Rather than have each of those companies store information about me, I can own that information and perhaps store it at an identity provider that I choose. This is the model that I believe, while providing tremendous value in the consumer world, may not often translate to the enterprise.

And I agree with Pamela Dingle who wrote:
My advice to Enterprise decision-makers is simple: take the tools and find out if there is a story that those tools can tell that brings value to the organization. If the story is there, adopt the tool. If the story isn’t there, walk away. Whether or not the marketing term applies is, to me, utterly inconsequential.
But as a technologist, I want to understand all the creative uses of technology so that I can recommend the right approach when I speak to companies who are looking to improve their operations. And as an employee of a company that deals with identity audit, I want to get ahead of the curve. If there will be a need to audit the use of technologies in a user-centric model, I want to know what that means.

I'm not trying to make any statements here about what OpenID should or should not be. I'm just trying to understand what the value-proposition would be that would lead an organization to internally adopt a user-centric model.

And a more secure un-spam-able messaging environment sounds like a good start.

Tuesday, December 11

User-Centricity in the Enterprise

Most of the on-line discussions about Identity Management over the past few years seem to have been about consumer authentication. The industry has developed solutions for user-centric authentication models. I'm not going to go into detail here or try to define those models. But, now that OpenID and other technologies has brought the user-centric model to reality, I'm beginning to see more chatter about user-centricity in the enterprise.

Patrick Harding doesn't seem to think that the enterprise is the right place for a user-centric model. I agree. I also agree with Pamela Dingle who noted that user-centric technology may be useful in an enterprise for the purpose of users keeping some information up-to-date.
I would qualify that, though, by saying that it's only going to be the information that the enterprise decides is unimportant enough to leave in users' hands. Companies never allow employees to update critical information on their own -- job title, pay grade, SSN, email address, etc.. Nor do they allow employees to decide what information they choose to share with the company's HR department. Companies require forms to be filled out completely. And if there are blank spaces, there's often warning that it could be just cause to rescind the employment offer.

Nishant Kaushik doesn't seem to think that the user-centric model is right for an enterprise environment. And Johannes Ernst disagrees.

I've been thinking about this for a while and I'm with Patrick and Nishaunt on this one. The goal of user-centricity is to give control of their identity information to the end users. That's great in the consumer world. Enterprises, however, have been spending millions on Identity Management specifically so that they (the enterprises) can control identity information more effectively. In the consumer world, it makes sense for people at home to want control over their information as it travels across the Internet. But, in a corporate environment (or government or education) employees and associates don't have rights over their identity information. Since Johannes is the one I've seen to recently claim otherwise, I'll look at his comments.

First, he talks about potential customers. For most enterprises, potential customers are anonymous or simply contact info and notes about whatever the enterprise can learn about their interest in the company's product. He talks about current customers and their desire to use user-centricity when interacting with the enterprise. OK, I can see that point, but that's not really enterprise. To me, that's still a consumer solution.

He then talks about affiliates. This is the typical use-case for Federation. Since this is about business transactions, the most important component of the federation model seems to be the non-technical stuff -- business agreements, contracts, terms of use, processes, etc.. It's not a scenario where you want one business partner to decide to withhold information from the other for the purposes of privacy or information control. Affiliates don't tend to share personal information, but business account information and transactional information that are both critical to the transaction in process.

Finally, he mentions user-centricity within an enterprise's own internal systems. Specifically, he gives the example of a personal cell phone number. To me, that's not enterprise data -- you can manage sharing your personal contact information with friends and close co-workers through social networking sites. Company-sponsored cell phones and IM addresses should be part of the corporate identity management infrastructure. Employees may be allowed to keep information up-to-date, but they're not allowed to decide which managers can view their information and which can't. The company makes the decisions about information use.

I don't know if I'm "defining away the issue of user-centric identity in the enterprise", but I don't see any major value or realistic adoption of a user centric model within an enterprise. The examples presented in the argument for it seem to be consumer scenarios and not enterprise scenarios. If you're expected to be available at 2am, then it's the enterprise who controls where your cell phone number is posted for anyone who needs to find you.

Let me be clear. I'm not bashing Mr. Ernst or trying to minimize his argument. He's obviously an intelligent guy and has contributed a great deal to the industry. But I'm challenging him and others to give me better examples of where the user-centric model may be useful within the enterprise. Because right now, I don't see it.