Glossary

What is customer identity and access management (CIAM)?

Customer identity and access management (CIAM) is a system that manages sign in and access for customers. A business uses CIAM to register, sign in, and protect its users. CIAM handles large numbers of external users, not internal staff.

On this page
  1. What does CIAM do?
  2. How is CIAM different from workforce identity?
  3. What features does CIAM need?
  4. How does SenseCrypt support CIAM?
  5. Frequently asked questions

What does CIAM do?

Customer identity and access management (CIAM) is a system that manages sign-in and access for customers rather than staff. It covers registration, sign-in, account security, and the consent and retention duties that come with holding consumer data.

The population is what makes this a separate discipline. Customers are numerous, unmanaged, and free to leave. Every point of friction you add is measured directly in abandoned registrations.

Registration at public scale

Sign-up is open to anyone, so the system absorbs traffic spikes and hostile automation at the same time as a genuine new customer.

Security that does not cost conversions

Account takeover protection has to work without asking a customer to configure anything. Anything optional is skipped by the people most at risk.

Privacy duties attached

Consent, data subject requests, and retention rules apply to customer records in most jurisdictions, and the identity system is where most of that data lives.

The account is part of the product

Sign-in is often the first screen a customer sees. It is a product surface with a conversion rate, not an internal utility.

How is CIAM different from workforce identity?

Workforce identity and CIAM look similar on a feature list and behave nothing alike in production. The difference is leverage. You can require an employee to enroll a device and finish a training module. You cannot require that of a customer.

Scale runs the other way. A workforce directory holds thousands of records with high assurance requirements. A customer directory can hold millions, with a hard ceiling on how much you may ask of each one.

Who the users are

Workforce identity serves staff and contractors you employ and can support directly. CIAM serves external customers you cannot train and cannot instruct.

What you can demand

An employee can be told to use a managed device. A customer abandons the flow instead, so the secure path has to be the default path.

How it is sized and billed

Workforce systems are sized on headcount. Customer systems are sized on traffic and usually billed on monthly active users, because most registered accounts are dormant in any given month.

What features does CIAM need?

The checklist below is where most CIAM evaluations end up, and the tension inside it is real. Security and ease of use pull against each other for every method that asks a customer to do more work.

That tension is the argument for removing the credential instead of adding steps to protect it. A method with nothing to type is both the faster path and the safer one, which is the only way out of the trade.

  • A sign-in that finishes in seconds on a phone.
  • Phishing-resistant authentication that is on by default, not opt-in.
  • Standards support: OIDC, OAuth 2.0 with PKCE and PAR, and SAML 2.0 for partners.
  • A recovery path that does not become the weakest link.
  • Audit logs, access control, and support for consent and retention rules.

How does SenseCrypt support CIAM?

SenseCrypt is a passwordless identity provider (IdP) for CIAM. A customer enrolls from a photo already on file and then signs in by face on their own device. The match runs there, and the server stores no face image and no face template.

For customer identity the list price is one dollar per monthly active user with a 20-seat minimum, and volume discounts apply. That is not the whole bill: non-exportable signing-key custody adds twenty dollars per key per month, and each tenant or custom domain past the first three costs ten dollars per month. The 30-day trial takes no card.

Nothing for a customer to remember

There is no password to set, forget, or reuse, and no shared code at sign-in. Support load moves away from resets entirely.

Certified liveness on ordinary phones

Liveness holds iBeta ISO 30107-3 certification at Level 1 and Level 2, from a standard 2D RGB camera with no depth sensor.

Recognition is evaluated, not certified

Face recognition entered the NIST evaluation in 2021, which was then FRVT and later split into FRTE and FATE, and is maintained through our latest submissions. We do not call that certification, because NIST does not certify.

Tenants, roles, and logs included

Multi-tenant isolation, role-based access control, and audit logs come with the platform, which is what a privacy program needs to answer questions about customer data.

Frequently asked questions

What is customer identity and access management (CIAM)?

Customer identity and access management (CIAM) is a system that manages sign in and access for customers. A business uses CIAM to register, sign in, and protect its users.

What is the difference between CIAM and IAM?

CIAM manages external customers. Traditional IAM manages internal employees. CIAM must scale to public traffic and value an easy sign in.

Does CIAM help with data privacy?

Yes. CIAM gives you control over customer data. SenseCrypt adds audit logs and access control. This helps you meet privacy rules.

How does SenseCrypt support CIAM?

SenseCrypt gives passwordless face login for customers. Face matching runs on-device, and SenseCrypt stores no face image and no face template. For external CIAM, it lists at one dollar per monthly active user, with a 20-seat minimum.

Related

Retire the password, keep the person

Stand up a passwordless identity provider for your workforce and customers. Free for 30 days, no credit card needed.