WSO2Con2024 - Organization Management: The Revolution in B2B CIAM

wso2.org 252 views 25 slides May 09, 2024
Slide 1
Slide 1 of 25
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16
Slide 17
17
Slide 18
18
Slide 19
19
Slide 20
20
Slide 21
21
Slide 22
22
Slide 23
23
Slide 24
24
Slide 25
25

About This Presentation

WSO2Con2024 - Organization Management: The Revolution in B2B CIAM


Slide Content

Organization Management
The Revolution in B2B CIAM
Johann Dilantha Nallathamby
Head of Solutions Architecture for IAM
WSO2

B2B CIAM

B2B CIAM refers to a collection of
capabilities that helps you transform
how you secure and streamline users’
access to your B2B SaaS applications
effectively and efficiently from third
parties such as enterprise customers
and channel partners such as dealers,
distributors, resellers, vendors, etc.

2

3

4
Challenges in Securing Access to B2B SaaS Applications
1 Onboarding customers and partners
2 Reducing friction in customer access
3 Supporting diverse GTM models
4 Appointing designated custodians
5 Regulatory compliance
6 Reducing operational costs
7 Increasing developer productivity

Foundational Capabilities to Make Your
B2B SaaS Application a Winner

Digitally transform
processes
6
Empower
developers
Enhance customer
experiences

Empower Developers

Offering a “single sign-on”
experience for your consumers,
and a unified IAM development
experience for your developers
throughout your application
portfolio
8
Unified customer-centric
experiences
Application Application
Organization
Application-centric
Users
Groups

Roles

Policies

Connections

Users
Groups

Roles

Connections

Policies

Application Application
Organization
Organization-centric
Users

Groups

Roles

Roles

Roles

Policies

Policies

Policies

Connections

9
Hierarchical organization management
Built-in tenancy for logical compartmentalization
of each enterprise customer and/or partner for
customization and governance.
Reseller x
SaaS Provider
Reseller y
Customer e Customer f Customer gCustomer h
SaaS Provider
Customer a Customer b Customer d
Customer d - NA Customer d - EU
SaaS Provider
Customer a Customer b Customer c

10
Mandatory access delegation
Designate users and brokers to act on
behalf of customers through mandatory
access delegations.
Delegated
access

Mandatory
delegation

11
B2B Ecosystems
Build ecosystems where providers
and consumers can digitally
collaborate
Consume

Provider
Consumer
B2B
Ecosystem
Consumer
Resources
Provide

12
Tooling
Visual/low-code
editors, templated
workflows/integrations,
SDKs and CI/CD that
increase developer and
devops productivity

Enhance Customer
Experiences

14
Delegated user lifecycle
management
Onboard and manage their own
sub-tenants and users.
Platform Admin

DigiOps

create employee
account

Employees

Customer Care

SaaS Provider
user mgt
privileges

15
Platform Admin

Team lead

Employees

Customer Care

SaaS Provider
Admin privileges

assign role

DigiOps

entitlements
mgt privileges

Delegated entitlements
management
Manage their own users’
entitlements through roles for
applications and APIs.

16
Discretionary access delegation
Invite users to act on behalf of
customers.
Invite

Delegated
access

17
B2B collaboration
Collaborate with just the right
levels of access
Collaboration

Invite

18
B2B SaaS Provider
Employee

Customer
Admin

Enterprise SSO UN/PW Passwordless
Customized log-in
Variety of authentication
options for SSO, social
logins, and MFA, while
governing the “level of
assurance” for each
application
Employee

Customer
Admin

Employee

Customer
Admin

19
Branding
Shape the desired
appearance at every
consumer touchpoint,
including log-in,
registration, account
recovery, emails, and
URLs, with zero
development effort

Digitally transform
Processes

Customer
admin

SaaS Provider
Customer aCustomer b
Customer
Registration
Portal

Self-registration
CRM

Customer admin

Customer
SaaS Provider
Customer a Customer b
CRM

Registration
API

Account Manager

Sales-led
onboarding
Integrations
Transforming internal processes
by integrating with systems such
as CRM, subscription services,
marketing automation, and CDPs
21
Broker3rd-party
onboarding
client
SaaS Provider
Customer a Customer b
CRM

Registration API

Channels-led
onboarding
Customer admin

Customer

22
Customer bCustomer a
Customer
Admin

Employee

B2B SaaS Application
Customer
Admin

Employee

Customer c
Employee

Customer
Admin

Application subscriptions
Govern access to your
applications and API portfolio by
organizations.

23
Audits and Insights
Keep a bird’s eye view of all accesses
through audits and insights across all
your applications and customers from
a single place

PAM
24
IGA
B2C B2B B2E APIs
WAM
●Self-registration and
social-login
●Identity verification
●Account linking
●Progressive profiling
●Passwordless, OTP and
Adaptive MFA
●Consent-based
authorization
●Branding and
internationalization
●Login and registration
insights
●Distinct tenancies per
organization
●Flexible organizational
hierarchy design
●Enterprise login
●Customizable login
experiences for
organizations
●Delegated
administration
●B2B Collaboration
●User invites and bulk
onboarding
●BYO-directory/Virtual
directory
●Just-in-time access
provisioning
●Single sign-on
●X509, RSA, IWA and
Adaptive MFA
●Role-based authorization
●OAuth 2.0/OIDC
compliance
●Consent-, role- and
context-based
authorization
●Pre-integrated API
gateways
IAM Landscape
Access Management

Question Time!
25
Tags