The Importance of Stakeholder Engagement for IAM Success in Your Company
The success of Identity and Access Management (IAM) depends on many factors, and one of the most important is the value of stakeholder engagement. Let’s say, for example, that your company has acquired an IAM product that’s a great fit, and your IAM team is doing excellent work on the technical management side of the product.
In that case, you can certainly talk about IAM’s success from a technical standpoint. However, IAM is really a centralized identity and access management function. Because of that, it sits at the center of the company and needs to interact with many different teams. So what does the IAM team need to do to succeed in that central role?
This is where one of the most important factors for IAM success comes in: stakeholder engagement. Say, for example, you’re planning to bring a new application’s authorization management infrastructure into IAM. This is exactly where stakeholder engagement comes into play. Products usually have a technical lead from IT and a Product Owner from the business unit. In that case, for the application you’re onboarding into IAM, it’s essential that the process of bringing the product’s IAM infrastructure in line is run well on the technical side with the technical lead, and that communication stays clear. For example, if it’s a migration project, it’s very important to take the previously used authorization matrices from the technical side and, together with the product’s Product Owner or analyst, make sure the authorization infrastructure is managed correctly according to the business units’ needs. When building the authorization matrix, you need to get input not only on the business units’ needs but also the opinions of the business unit managers, in order to produce a correct authorization matrix.

Let’s assume you’ve successfully cleared this stage. Does IAM’s job end here? No, we keep going. When we, as the IAM team, start defining the authorization matrix for the product we’re onboarding, we need to check whether there are any authorization conflicts that violate the “Segregation of Duties” principle. Doing this check requires getting approvals from HR or Internal Audit teams based on the SOD matrix, or getting sign-off from the relevant stakeholders. If there are people on the IT teams in production who need access, evaluating those requests in coordination with Information Security is another part of the job.
In the end, if we want to successfully implement an IAM product at our company and make proper use of all its functions, all stakeholders — together with the IAM team — need to respond to the requirements with the same commitment and dedication.