Identity Access Management (IAM)
Identity and Access Management (IAM) is the discipline of controlling who can reach which systems inside an organization. It governs employees, contractors and increasingly machine identities — provisioning accounts, assigning entitlements, enforcing authentication, and removing access when someone leaves. It is a workforce security function, and it begins after identity has already been established somewhere else.
| Scope | Workforce and machine access to internal systems |
| Core functions | Provisioning and deprovisioning, authentication, authorization, entitlement review, privileged access |
| Who creates accounts | An administrator, following a hiring or contracting process |
| Identity source | The HR system of record — not the IAM platform |
| Common standards | SAML, OAuth 2.0, OpenID Connect, SCIM for provisioning |
| Governance layer | Identity governance and administration — access reviews and certification |
| Distinct from CIAM | CIAM handles consumers, who self-register at far greater scale |
| What it assumes | That HR established who the person is before the account existed |
IAM, CIAM and identity proofing
Three terms that overlap in conversation and answer different questions. Getting them apart is the useful content of this page.
| IAM | CIAM | Identity proofing | |
|---|---|---|---|
| Population | Employees and contractors | Consumers | Anyone, at first contact |
| Account created by | An administrator | The user, unassisted | — |
| Identity established by | The hiring process, before the account | Whatever registration checked — often an email | Documentary and biometric evidence |
| Scale | Thousands | Millions | Per person |
| Answers | What may this account reach? | Is this the same person as before? | Who is this person? |
The third row is the whole point. IAM does not establish identity; it inherits it. An employee’s identity was established during hiring — documents checked, right to work confirmed, references taken — and the IAM platform provisions access on the strength of that. Where the hiring check was weak, IAM manages access for an identity nobody verified, faithfully and indefinitely.
Where identity verification touches workforce identity
Two junctions, and both sit outside what an IAM platform does.
Onboarding. Remote hiring means nobody meets the new starter. The identity check is whatever the onboarding process performs, and in many organizations that is a document photographed and glanced at by someone in HR — precisely the check that digital tampering defeats. Where that fails, the result is a ghost employee with system access.
Help desk recovery. The most attacked path in workforce identity, and the one IAM platforms secure least. An attacker who cannot defeat a hardware key calls the service desk claiming to have lost it, and the desk re-establishes identity by recognizing a name, asking questions whose answers are on a professional network, or trusting a caller who sounds right — which synthetic voice now makes trivially achievable.
Re-establishing identity there with an authenticated document and a live biometric asks something an attacker cannot look up or clone. That is what identity document verification contributes to a workforce context, and it is a narrow contribution — it addresses hiring and recovery, not access governance. Employee verification is the applicable solution rather than anything resembling an IAM product.
What IAM can’t do
It does not establish identity. It manages access for identities created elsewhere, and inherits whatever the hiring process established.
Strong authentication does not fix weak onboarding. An account provisioned to a fabricated employee and protected with a hardware key is a well-defended fraudulent account.
It does not secure the help desk. Recovery is a human process sitting beside the platform, and it is where attackers concentrate precisely because it is designed to work for people who have lost their credentials.
Deprovisioning depends on being told. An IAM system removes access when a departure is recorded. Where that record is late or missing, access persists — which is the same failure that keeps terminated employees on payroll.
Frequently asked questions
What is identity and access management?
The discipline of controlling which people and systems can reach which resources inside an organization — provisioning accounts, assigning entitlements, enforcing authentication, reviewing access, and removing it when someone leaves. It covers employees, contractors and machine identities.
What is the difference between IAM and CIAM?
IAM covers the workforce, where accounts are provisioned by administrators following a hiring process and the population is in the thousands. CIAM covers consumers, who self-register unassisted at a scale of millions. The registration path, the scale and the consent obligations all differ.
Does IAM include identity verification?
No. IAM manages access for identities established elsewhere — for employees, during hiring. It inherits whatever that process confirmed, so where the hiring check was weak the platform manages access for someone nobody verified.
Where is workforce identity most often attacked?
The help desk. Account recovery has to work for someone who has actually lost their credentials, which is exactly what an attacker claims to be. Recognizing a name, asking questions answerable from a professional profile, or trusting a familiar-sounding voice are all now weak, the last especially so given synthetic audio.
Related reading
- CIAM — the consumer counterpart, and why the registration path changes everything
- Identity proofing — the step that establishes identity, which IAM assumes happened
- Ghost employee — what a weak hiring check produces, with system access attached
- Authentication — what IAM performs, and what it inherits from enrollment