* 'Provisioning-on-demand' systems among the possibilites
Last week I moderated a panel at Kuppinger Cole’s virtual conference on identity, which talked about “Provisioning and Access Governance Trends” with Engiweb Security’s Cris Merritt and Deepak Taneja, founder of Aveksa. You can see a replay of the session by going here and clicking the “watch now” button.
We think of provisioning as the most mature of the IdM services (it’s been with us for more than 10 years) and we may think of it now as mostly “pipes” rather than “gold fixtures” (to refer to the plumbing analogy of computing) but there is still room for improvement.
Two areas were discussed for improvement. The first is a major change in the way provisioning is done. Currently, a “connector” between the provisioning engine and the application, service or data store being provisioned has to be created. While vendors have move to reusable connectors and some (notably Courion) have tried to commoditize them, Merritt suggested that they need to be abstracted into a service to be called on, as needed, by the applications or services needing the data. Further, we looked at creating “provisioning on demand” systems — where users could, via a self-service mechanism — do their own provisioning. Subject, of course, to access governance principles.
Taneja took us through the full panoply of access governance when I (tongue in cheek, I might add) suggested that access governance was simply provisioning on steroids. Of course that’s not true but it did lead us to a discussion of access policies and the need for both IT and business to collaborate to see that the right people get the right access at the right time. And only the right people do so.
I suggest that you also at least sample the sessions I wasn’t involved in, which were packed with useful information. But for those of you who prefer “in person” conferences, many of the same people will be gathered in Munich in early May for the European Identity Conference. There’s also, of course, the upcoming RSA conference in just a couple of weeks. So many conferences, so little time.




