* Novell helps to solve the identity mgmt. problems resulting from M&As
We sometimes think of identity products as point solutions for a problem, each having its own area where it can work its “magic.” But the real work gets done, and the real “wow!” moments really only occur when multiple identity products are used together to complement and reinforce each other. This was driven home to me last week in an extended demo that Novell Vice President and Linux General Manager David Litwack gave as part of two different keynote addresses at the company’s BrainShare conference last week.
You can watch the video replays of the two by visiting https://www.novell.com/brainshare/keynotes.html but be warned that you’ll have to listen to (or fast forward through) some droning on by Novell CEO Jack Messman, Utah Governor Jon Huntsman, Jr. and assorted other non-charismatic speakers.
What Litwack’s demo showed was how to integrate identity services following the merger of two banks. Before seeing this demo, I’d assumed that a 6-to-12 month project using electronic provisioning services with lots of manual labor would be necessary. Not so, according to Litwack. The secret is to kick off with identity federation services and follow up with some self-service provisioning and (at a more leisurely pace) some fine-tuning and tweaking of the system with traditional provisioning tools.
Because the two organizations that were merging are in the same business (banking), the roles defined in each bank’s identity management systems are similar. A little bit of work (days rather than months) allowed the consolidation of roles and the creation of broad-based new ones to cover most of the employees of each organization. Federation services allow an employee to authenticate to his own organization and be automatically mapped to a role in the merger partner’s organization.
A standard provisioning application is then used to create rules-based authorizations linked to the various roles defined in the original companies as well as in the new, merged entity. Once the employee logs in to his original organization and is mapped (through federation) to roles in the other, he is presented with a self-service provisioning screen. This is, essentially, a checklist of resources available to the roles that employee is filling. The employee picks the ones he believes he will need. Some are immediately provisioned while others are shunted to people with the authority to grant access on a case-by-case basis. Provided someone with authority is available, that whole process is automated and the employee is provisioned within moments, rather than days or weeks.
In this way, everyone can be productive even though the greater part of integrating the two organizations’ technology structures has only just begun. But as changes are made to create the architecture on the newly merged enterprise, standard provisioning tools can be used behind the scenes to redirect employees to the proper resources, to recreate rules and policies in a more structured, coherent and logical way, and to do the job right without the incessant pressure of having to have it all in place by “merger day.”
If you’re facing, contemplating or even at risk of having to merge two or more organizations you should take a look at Litwack’s demo. You may not choose the Novell tools, but you should consider the methodology.




