Identity Access Management (IAM)

Identity and Access Management (IAM) is the discipline of controlling who can reach which systems inside an organization. It governs employees, contractors and increasingly machine identities — provisioning accounts, assigning entitlements, enforcing authentication, and removing access when someone leaves. It is a workforce security function, and it begins after identity has already been established somewhere else.

Scope Workforce and machine access to internal systems
Core functions Provisioning and deprovisioning, authentication, authorization, entitlement review, privileged access
Who creates accounts An administrator, following a hiring or contracting process
Identity source The HR system of record — not the IAM platform
Common standards SAML, OAuth 2.0, OpenID Connect, SCIM for provisioning
Governance layer Identity governance and administration — access reviews and certification
Distinct from CIAM CIAM handles consumers, who self-register at far greater scale
What it assumes That HR established who the person is before the account existed

IAM, CIAM and identity proofing

Three terms that overlap in conversation and answer different questions. Getting them apart is the useful content of this page.

IAM CIAM Identity proofing
Population Employees and contractors Consumers Anyone, at first contact
Account created by An administrator The user, unassisted —
Identity established by The hiring process, before the account Whatever registration checked — often an email Documentary and biometric evidence
Scale Thousands Millions Per person
Answers What may this account reach? Is this the same person as before? Who is this person?

The third row is the whole point. IAM does not establish identity; it inherits it. An employee’s identity was established during hiring — documents checked, right to work confirmed, references taken — and the IAM platform provisions access on the strength of that. Where the hiring check was weak, IAM manages access for an identity nobody verified, faithfully and indefinitely.

Where identity verification touches workforce identity

Two junctions, and both sit outside what an IAM platform does.

Onboarding. Remote hiring means nobody meets the new starter. The identity check is whatever the onboarding process performs, and in many organizations that is a document photographed and glanced at by someone in HR — precisely the check that digital tampering defeats. Where that fails, the result is a ghost employee with system access.

Help desk recovery. The most attacked path in workforce identity, and the one IAM platforms secure least. An attacker who cannot defeat a hardware key calls the service desk claiming to have lost it, and the desk re-establishes identity by recognizing a name, asking questions whose answers are on a professional network, or trusting a caller who sounds right — which synthetic voice now makes trivially achievable.

Re-establishing identity there with an authenticated document and a live biometric asks something an attacker cannot look up or clone. That is what identity document verification contributes to a workforce context, and it is a narrow contribution — it addresses hiring and recovery, not access governance. Employee verification is the applicable solution rather than anything resembling an IAM product.

What IAM can’t do

It does not establish identity. It manages access for identities created elsewhere, and inherits whatever the hiring process established.

Strong authentication does not fix weak onboarding. An account provisioned to a fabricated employee and protected with a hardware key is a well-defended fraudulent account.

It does not secure the help desk. Recovery is a human process sitting beside the platform, and it is where attackers concentrate precisely because it is designed to work for people who have lost their credentials.

Deprovisioning depends on being told. An IAM system removes access when a departure is recorded. Where that record is late or missing, access persists — which is the same failure that keeps terminated employees on payroll.

Frequently asked questions

What is identity and access management?

The discipline of controlling which people and systems can reach which resources inside an organization — provisioning accounts, assigning entitlements, enforcing authentication, reviewing access, and removing it when someone leaves. It covers employees, contractors and machine identities.

What is the difference between IAM and CIAM?

IAM covers the workforce, where accounts are provisioned by administrators following a hiring process and the population is in the thousands. CIAM covers consumers, who self-register unassisted at a scale of millions. The registration path, the scale and the consent obligations all differ.

Does IAM include identity verification?

No. IAM manages access for identities established elsewhere — for employees, during hiring. It inherits whatever that process confirmed, so where the hiring check was weak the platform manages access for someone nobody verified.

Where is workforce identity most often attacked?

The help desk. Account recovery has to work for someone who has actually lost their credentials, which is exactly what an attacker claims to be. Recognizing a name, asking questions answerable from a professional profile, or trusting a familiar-sounding voice are all now weak, the last especially so given synthetic audio.

Related reading

  • CIAM — the consumer counterpart, and why the registration path changes everything
  • Identity proofing — the step that establishes identity, which IAM assumes happened
  • Ghost employee — what a weak hiring check produces, with system access attached
  • Authentication — what IAM performs, and what it inherits from enrollment

Discover Our Solutions

Exploring our solutions is just a click away. Try our products or have a chat with one of our experts to delve deeper into what we offer.

Report
Mapping the Rise of AI-Powered Identity Fraud

AI didn't just make fraud faster. It made it a system. We analyzed millions of identity interactions to map how identity attacks are evolving across regions, attack types, and sophistication levels — and what organizations need to rethink to keep pace.

See the Data