How Governance Around Identity and Access Is Changing in 2026
For decades, enterprise identity management was primarily viewed as a perimeter issue. The main objective was to verify that an employee or customer was who they claimed to be at the initial point of entry, issue a password or single sign-on (SSO) token, and grant access accordingly. Enterprise security was grounded in a foundational question: “Who are you, and what systems are you allowed to access?”
By 2026, this approach has become obsolete, and the traditional questions are no longer adequate for effective identity governance.
The proliferation of distributed multi-cloud architectures, non-human identities, and autonomous AI agents capable of executing thousands of actions per minute has created an unprecedented paradigm shift for security leaders. As a result, traditional Identity Governance and Administration (IGA) is rapidly evolving into Identity, Authorization, and Runtime Governance.

The following analysis examines how governance surrounding identity and access is undergoing fundamental transformation.
1. From Access Governance to Action Governance
Traditional IGA models governed static access paths (e.g., Jane, a Finance Manager, has access to Salesforce, Workday).
In 2026, security teams are required to govern actions rather than merely access. When an AI agent leverages delegated authority to interact with an API or update numerous accounts, the critical question extends beyond system access to whether the agent is authorized to perform specific actions on behalf of a human. As highlighted in NIST’s 2026 guidance, reliance on extensive human-in-the-loop controls or the sharing of broad credentials introduces significant risks within agentic systems.
2. Managing the Explosion of AI Agents and Non-Human Identities
Whereas previous governance models focused primarily on employees, contractors, and partners, contemporary enterprises now manage an expanding ecosystem that includes service accounts, APIs, cloud workloads, and AI agents.
Modern enterprises are no longer comprised solely of human workers. In many cloud environments, autonomous AI agents, service accounts, APIs, and automated pipelines now outnumber human users.
Traditional Identity and Access Management (IAM) tools were designed to manage human login lifecycles, resulting in significant governance gaps for non-human entities. By 2026, organizations must address the reality that AI agents or automated scripts with broad permissions can execute high-impact actions at machine speed. As a result, governance frameworks have expanded to treat non-human actors as first-class entities, requiring explicit lifecycle oversight, verifiable lineage, and stringent runtime boundaries.
In contrast to traditional service accounts that execute predefined scripts, AI agents interpret objectives, select tools, make decisions, and delegate tasks to sub-agents. In alignment with NIST’s 2026 AI Agent Standards Initiative, governance of non-human identities is becoming a core enterprise requirement, necessitating:
- A verifiable, unique identity and defined purpose
- An accountable human owner
- Clear traceability through a delegation chain
- Defined lifecycle management (from creation to retirement)
3. Moving Beyond the Front Door: The Rise of Rigorous Proofing (IAL2)
The proliferation of deepfakes, synthetic data, and automated credential stuffing has rendered basic logins increasingly untrustworthy. Consequently, organizations are raising their upfront verification standards. Frameworks such as NIST’s Identity Assurance Level 2 (IAL2) are transitioning from federal mandates to mainstream enterprise requirements.
Contemporary governance frameworks now distinguish between identity proofing (“Who are you in the real world?”) and authentication (“Do you control this digital credential?”). Organizations are implementing multi-pathway proofing processes that integrate government-issued photo validation, biometric liveness checks, and authoritative database cross-checks. These measures ensure that every high-risk digital interaction or privileged onboarding is anchored in verifiable trust prior to the issuance of any token.
4. Transitioning to Dynamic, Contextual Authorization
Static Role-Based Access Control (RBAC) and once-per-session checks are no longer sufficient to protect dynamic cloud architectures. Modern frameworks are adopting models that emphasize Just-in-Time, Just Enough Access, and action-specific authorization to address the demands of real-time environments.
Authorization engines now incorporate real-time context and risk, evaluating variables such as user behavior, device state, agent intent, environmental factors, and continuous risk scores prior to granting transaction-level privileges.
Current market trends emphasize continuous authorization and Zero Standing Privilege (ZSP). Identity governance systems now evaluate context in real time by analyzing device health, network anomalies, behavioral baselines, and runtime risk scores. If an entity’s risk profile changes during a session, governance platforms can automatically increase verification requirements, restrict permissions, or terminate access immediately.
5. Moving from Periodic Reviews to Continuous Governance
Quarterly access reviews and annual certifications are insufficient for environments operating at machine speed. Governance is transitioning from periodic audits to continuous, real-time, and event-driven monitoring. If an agent’s behavior becomes anomalous, policies can trigger immediate automated interventions to reduce privileges.
6. Convergence Into an “Identity Control Plane” and The Shift Toward the “AI Identity Fabric”
Historically, technologies such as IGA, Privileged Access Management (PAM), Security Information and Event Management (SIEM), and User and Entity Behavior Analytics (UEBA) operated in isolated silos. The emergence of AI is driving the convergence of these technologies into a unified Identity Control Plane, which serves as a centralized framework for organizations to discover, assess, authorize, and govern all digital actions across multicloud and SaaS environments.
To integrate these components, enterprise architecture is evolving toward an AI Identity Fabric.
Future IAM platforms will extend beyond managing human users to governing the complex relationships among humans, AI agents, tools, data, and autonomous actions. Each automated workflow must maintain a clear and traceable chain of delegation, linking every autonomous action to an accountable human sponsor.
What This Means for Identity Leaders
For Chief Information Security Officers (CISOs) and Chief Information Officers (CIOs), the operational mindset is experiencing a fundamental transformation:
- Old Priority: “Who has access?” → New Priority: “Who or what can act?”
- Old Priority: Access certifications → New Priority: Continuous authorization
- Old Priority: Human identities → New Priority: Human, machine, and AI identities
- Old Priority: Audit access → New Priority: Audit identity, authority, and action
Conclusion
Enterprises in 2026 differ fundamentally from those for which traditional IGA was designed. The transformation of identity governance extends well beyond a product update; it signifies a shift from managing access to managing authority. Identity is increasingly serving as the mechanism by which enterprises govern digital actions.
By establishing identity as the core control plane for autonomous enterprises, organizations can securely leverage AI while ensuring that every human, machine, and autonomous agent operates with verifiable intent and accountability. Organizations that persist in treating identity as an isolated login mechanism will face challenges from automated threats and stringent compliance audits. Success will favor those who adopt identity as an observable, programmable, and deeply integrated infrastructure fabric.
Identity Is No Longer a Login Problem. It’s an Infrastructure Problem
For decades, enterprise identity was all about one simple question: “Who are you, and can we let you log in?” Fast forward to today, and that model is rapidly becoming obsolete. Modern enterprises are no longer just made up of employees logging into applications; they are complex ecosystems of humans, applications, APIs, service accounts, workloads, and AI agents.
Identity has fundamentally outgrown the front door. It is no longer just an authentication service it is evolving into an enterprise control plane and a critical infrastructure layer.

The Catalyst: Agentic AI and Non-Human Identities (NHIs)
The most significant driver of this transformation is the rise of agentic AI. Unlike traditional software that follows predetermined instructions, AI agents can receive a goal, reason about it, select tools, call APIs, and execute actions on our behalf. According to Okta’s 2026 Businesses at Work research, 91% of organizations are already using AI agents, yet only 10% have a well-developed strategy for managing them.
This creates a massive governance challenge. When an AI agent executes a transaction across a SaaS application, a database, and a downstream payment system, who is ultimately responsible? Traditional Identity and Access Management (IAM) struggles here because it often compresses multiple actors into a single credential. The future of identity must preserve the entire chain of authority—from the human sponsor to the agent, the delegated tools, and the final action.
From Directory to Identity Graph
To manage this complexity, identity architecture is shifting from a static directory (User → Groups → Applications) to a dynamic Identity Graph. This graph maps the complex relationships connecting human identities, machine identities, AI agents, delegated permissions, APIs, and data.
Non-Human Identities (NHIs) such as API keys, service accounts, and automated pipelines—are scaling rapidly, often dwarfing human users. An enterprise identity fabric must treat these NHIs as first-class citizens with strict lifecycles, clear ownership, and defined time boundaries. Every production agent should have a verifiable identity, an accountable human owner, a clear purpose, and a controlled retirement process.
Authorization Over Authentication
While authentication proves who the actor is, authorization determines what they are allowed to do. In an agentic enterprise, authorization must be dynamic, contextual, and time-bound.
Privileged Access Management (PAM) is also moving into the autonomous era. AI agents should operate on Zero Standing Privilege (ZSP)—requesting Just-In-Time (JIT) and least-privilege access only when needed, and immediately losing that privilege when the task is complete. Identity infrastructure must evolve to evaluate real-time trust, analyzing behavioral baselines and context before granting access.
The New Identity Security Fabric
As protocols like Model Context Protocol (MCP) and Agent-to-Agent (A2A) communication become standard, delegation must be explicit and verifiable across organizational boundaries. Identity determines who can access data, and data context determines what an identity should be allowed to access.
To prepare for this shift, organizations must:
- Build a comprehensive identity inventory covering every human, machine, workload, and AI agent.
- Give every AI agent a first-class identity with explicit human accountability and sponsorship.
- Move toward dynamic, risk-based authorization rather than relying solely on static Role-Based Access Control (RBAC).
- Create an agent activity ledger to track the entire trajectory of an automated action for compliance, forensics, and accountability.
Conclusion: Trustworthy Autonomy
Identity is no longer just answering “Can you log in?” It is now answering, “Can this actor perform this action, on this resource, under this context, with this authority and can we prove why?”
The winning enterprise architectures will treat identity as the operating system for digital trust a unified security fabric that makes the autonomous enterprise possible, observable, and deeply secure.
Important Takeaways for the Modern architecture:
- Identity is becoming a control plane, not simply an authentication layer.
- AI agents are creating a new category of first-class non-human identities.
- Authorization is becoming more important than authentication.
- PAM must evolve toward Zero Standing Privilege for autonomous actors.
- Identity governance must move from periodic review to continuous, automated enforcement.
- Identity graphs will increasingly replace isolated directories as the foundation for understanding digital relationships and authority.
- Agent identity must preserve the chain of accountability from human sponsor → agent → delegation → tool → resource → action.
- Identity, data, behavioral analytics, PAM and AI security are converging.
- The winning enterprise identity architecture will be a unified Identity Security Fabric spanning humans, machines, workloads and AI agents.
- The ultimate goal is not merely secure access. It is trustworthy autonomy.
Rethinking PAM: How AI Changes Privileged Access Management

For decades, Privileged Access Management (PAM) has operated under a straightforward assumption: there is a human behind the privilege. System administrators request access, security engineers elevate privileges, and employees perform sensitive administrative actions. We have spent years mitigating this human-centric risk using password vaults, multi-factor authentication (MFA), session monitoring, Just-in-Time (JIT) access, and Zero Standing Privilege.
Enter autonomous AI agents.
Unlike traditional service accounts that execute rigid, predefined workflows, an AI agent can reason, decide, delegate, execute, adapt, and act continuously at machine speed. It doesn’t just use privileged access; it makes autonomous decisions about how and when to use it.
This shifts the foundational security question from “Who has the password?” to: “Who or what is making the decision to use the privilege?”
Why the Privilege Problem Explodes With AI
Giving an AI agent administrative access to critical infrastructure introduces unprecedented risk. While a human administrator might make a single mistake, an autonomous agent can execute hundreds of complex, high-consequence decisions in minutes.
The threat is no longer theoretical. Recent investigations highlight how multiple AI agents can engage in coordinated activity—such as attempts to expand autonomy or manipulate environments underscoring that capability without strict privilege boundaries creates unacceptable enterprise risk.
When faced with risks like prompt injection, compromised credentials, or hallucinated objectives, traditional static PAM models fall short. We cannot simply trust an AI agent. Instead, we must build a security architecture where trust is continuously evaluated, privilege is dynamically granted, actions are constrained, and every decision is attributable and reversible.
The New PAM Framework: 5 Core Principles for Agentic Privilege
To safely embrace autonomous agents without exposing the enterprise to catastrophic blast radiuses, security leaders must modernize their PAM strategies around five foundational pillars:
1. Give Every Agent a Real Identity
No production AI agent should be anonymous. Every agent requires a unique, verifiable identity that can be authenticated, authorized, monitored, governed, rotated, revoked, and attributed. Beyond a simple name, this identity must bind together the owner, purpose, environment, underlying model, tools, risk level, and authorization scope.
2. Eliminate Standing Privilege
Leaving permanent administrator keys with an autonomous agent is the AI equivalent of leaving the data center keys on the front desk. Just-in-Time access, Zero Standing Privilege, and ephemeral tokens must be extended to AI workloads. An agent should only receive temporary, time-bound credentials precisely when a task demands it—and those permissions should automatically dissolve the moment the task is complete.
3. Authorize the Action, Not Just the Identity
Traditional authorization asks whether an identity is allowed to access a system. AI-native authorization must ask a deeper question: Is this identity allowed to perform this specific action, under these circumstances, right now? An infrastructure agent may legitimately need to read logs or restart non-critical services, but that does not mean it should have permission to delete databases, modify IAM policies, or disable security controls.
4. Treat Agent Behavior as a PAM Signal
Traditional PAM monitors static privileged sessions, but AI-native PAM must monitor behavioral intent and execution patterns. If an agent that normally interacts with a couple of databases suddenly begins querying dozens of systems, requesting new privileges, or communicating with unfamiliar agents, the PAM platform must dynamically catch the anomaly, re-evaluate risk, and scale back or revoke privileges.
5. Build a Human Accountability Chain
“We don’t know, the AI did it” is never an acceptable security posture. Every privileged action taken by an agent must maintain non-repudiation tracing cleanly from the human who initiated the workflow, through the agent’s intent and policy bounds, down to the exact system changes made.
The Ultimate Question
The future of PAM isn’t about securing humans from AI; it’s about securing the enterprise from what AI can do with privilege.
The winners in this new agentic era won’t be the organizations that give AI the most access. They will be the ones that master how to give AI the right access, at the right time, for the right reason—and revoke it the exact second that reason disappears.
So, can we trust AI agents with privileged access?
Yes, but only because we don’t trust the AI; we trust the deterministic controls wrapped tightly around it.
Why Your Product Organization Is Stalling (and the 3Ps to Fix It)

As organizations scale, a frustrating paradox often emerges: the more people you hire and the more “Agile ceremonies” you implement, the slower you seem to deliver. Innovation begins to stall, and the overhead of coordination outweighs the output of the teams. This is the “Scaling Trap”a state where increased complexity leads to organizational friction, high “Process Waste,” and a fatal disconnect from customer value.
To break this cycle, product leaders must look beyond individual features or meeting schedules and focus on the organizational system as a whole. The 3P Framework (Product, People, and Process) is the antidote to this friction. However, these pillars are not silos; they are an interdependent system.
If you optimize them independently, you fail.
- Focus on Technology alone: You build elegant solutions that nobody needs.
- Focus on Business goals alone: You optimize revenue while destroying the customer experience.
- Focus on Customer requests alone: You build a disjointed product that lacks a cohesive strategy.
When aligned, the 3Ps act as a “force multiplier,” allowing your organization to scale value without scaling complexity.
1. Stop Building What Customers Ask For
A defining characteristic of high-performing product organizations is the ability to distinguish between what customers ask for and what they actually need. Fulfilling every request leads directly to Product Waste: building features that don’t solve core problems or drive business value.
Consider a customer requesting “another dashboard.” A weak product organization adds it to the backlog immediately. A strategic product organization asks: “What decision are you trying to make that the current product isn’t helping you make?” This shift from feature thinking to problem thinking is the hallmark of professional product management.
“Product Management exists to create value at the intersection of three dimensions: Customer Value (solving an important problem), Business Value (revenue, retention, or strategy), and Technology Value (sustainable execution).”
2. Success Is Measured by Change, Not Shipping
Sustainable product excellence requires a fundamental shift from measuring outputs to owning outcomes. It is the difference between measuring what was shipped and measuring what changed because it was shipped.
The Executive Challenge: Look at your current plan. Is your roadmap a list of promises to ship, or a list of promises to improve the business?
| The Output Roadmap (Features Shipped) | The Outcome Roadmap (Metrics Moved) |
|---|---|
| Build a new dashboard | Reduce customer onboarding time by 30% |
| Launch a public API | Increase user adoption by 20% |
| Add a new workflow tool | Reduce support cases by 15% |
| Release a mobile experience | Increase conversion by 10% |
In a healthy organization, a team is not celebrated for hitting a deadline; they are celebrated for moving the target metric. Success is value creation, not just delivery.
3. The Process Paradox: Clarity Over Control
Process has a poor reputation because most organizations use it to create bureaucracy, approval gates, and documentation—the definition of Process Waste. However, the right process actually makes organizations faster by reducing cognitive load and providing the “operating mechanisms” for efficient execution.
Instead of a set of rules, think of your process as an Innovation Flywheel: Problem (Product) → Idea (People) → Experiment (Process) → Data → Learning → Scale.
The goal of this flywheel is to answer fundamental questions: How do we prioritize? Who makes the decision? How do we measure success? When these are clear, you eliminate the need for endless “alignment meetings.”
“The purpose of process is not control. The purpose of process is clarity.”
4. Healthy Disagreement Is an Innovation Mechanism
The “People” pillar is where most organizations fail by confusing “collaboration” with “consensus.” This leads to People Waste, where talented people spend their time on low-value coordination rather than high-value decision-making.
Strategic leaders must establish a critical distinction: Collaborative decision-making does not mean shared accountability. While teams should collaborate broadly, a clearly identified owner must be accountable for the final decision and its outcome.
To achieve this, move your culture away from the “Agree → Execute → Discover Failure” model. Instead, adopt a model built on “Constructive Challenge”:
The Behavioral Model: Disagree → Debate → Decide → Commit → Learn
Innovation requires the safety to challenge assumptions. If teams are afraid to say, “I don’t think this will work,” your organization has developed decision-making blindness. Healthy disagreement is not friction; it is your primary mechanism for stress-testing ideas before you commit capital.
5. AI Increases the Premium on Human Judgment
In the AI era, the cost of building software is plummeting. AI can accelerate research, generate requirements, and prototype at lightning speed. However, as execution becomes a commodity, the value of Product Judgment skyrockets.
AI increases your capacity to build, but it cannot decide what is worth building. To stay competitive, product leaders must double down on the skills AI cannot replicate:
- Strategic Prioritization: Determining where to place bets in a crowded market.
- AI Governance & Risk Management: Navigating the ethical and security implications of automated systems.
- Human-Centered Design: Ensuring that AI-accelerated delivery actually solves a human problem.
- Outcome Measurement: Validating that the speed of AI is resulting in actual business value, not just faster “Product Waste.”
The Synergy: Unlocking Enterprise Innovation through Product Management
The true power of the 3Ps lies in their intersection.
When your Product strategy is compelling, your People are trusted and empowered, and your Process is frictionless, something remarkable happens. Efficiency naturally rises because waste is eliminated. Productivity increases because teams spend less time fighting tools or politics and more time building. And innovation thrives because a safe, structured environment encourages bold experimentation.
Leading product management through the lens of Product, People, and Process ensures that your organization doesn’t just keep up with the market—it sets the pace.
Product: Define Value and Direction
The “Product” pillar is your north star. It encompasses vision, strategy, problem validation, and the roadmap. Too many organizations treat the product as a static backlog of tasks rather than a dynamic solution to customer problems.
- The Why: Without a razor-sharp product focus, teams fall into the trap of output over outcome. They ship code rapidly, but fail to move business metrics or delight customers because the underlying value proposition is muddy.
- The How:
- Tie strategy to customer pain: Ground every roadmap item in rigorous discovery and validated user insights rather than internal opinions.
- Obsess over the problem space: Give product teams the autonomy to fall in love with the user’s problem, ensuring that what you build actually matters.
- The Impact on Efficiency & Innovation: When the product vision is clear, engineering hours aren’t wasted building the wrong things. Clarity breeds focus, which is the prerequisite for disruptive innovation.
People: Cultivating Ownership and Culture
You can have the best market strategy in the world, but execution relies entirely on people—designers, engineers, stakeholders, and product managers.
- The Why: Product management is a role of influence without authority. If cross-functional trust is low and psychological safety is absent, collaboration breaks down into territorial silos and bureaucratic friction.
- The How:
- Empower cross-functional triads: Pair product managers, tech leads, and designers closely, giving them shared ownership over outcomes rather than just output.
- Foster psychological safety: Encourage teams to run experiments, challenge assumptions, and talk openly about failures without fear of blame.
- The Impact on Productivity: Highly aligned, trusted teams move with velocity. When people feel a genuine sense of ownership, decision-making decentralizes, bottlenecks disappear, and daily productivity spikes.
Process: Designing the Rhythm of Execution
Process is the scaffolding that turns chaos into repeatable momentum. However, bad process feels like heavy-handed micromanagement, while great process feels like invisible infrastructure.
- The Why: Without lightweight, transparent processes, communication collapses, handoffs become black holes, and delivery timelines become unpredictable. Conversely, over-engineered processes crush morale and stifle creative problem-solving.
- The How:
- Streamline discovery-to-delivery loops: Implement cadence-based planning (like agile Sprints or dual-track agile) that balances continuous user research with steady engineering execution.
- Automate governance: Build compliance, security reviews, and metrics tracking directly into the workflow so they act as guardrails rather than speed bumps.
- The Impact on Efficiency: A clean, optimized process eliminates cognitive load, reduces context-switching, and ensures that brilliant ideas move seamlessly from a whiteboard to production.
Conclusion: Building the System, Not Just the Part
To build a high-performing organization, you must stop optimizing the 3Ps in isolation. You are building an interdependent system where:
- Product creates the “Why” (Direction)
- People create the “Who” (Capability)
- Process creates the “How” (Scale)
When these are misaligned, you generate waste: unneeded features (Product Waste), talented people doing administrative work (People Waste), and bureaucratic bottlenecks (Process Waste). When they are aligned, they create a system that turns problems into validated outcomes with unprecedented speed.
“Product gives the organization direction. People give it capability. Process gives it scale.”
Review your last quarter: Which of the 3Ps is currently the weakest link and therefore the primary source of waste in your organization?
MCP + A2A: The Connectivity Layer for the Agentic Enterprise
A single intelligent agent will not define the next phase of enterprise AI.
Networks of specialized agents working together will define it.
A customer-service agent may need to ask a billing agent to investigate an invoice. A security agent may need to ask an identity agent to validate a user’s risk. A procurement agent may need to collaborate with a finance agent before approving a purchase.
And those agents may be built by different teams, run on different platforms, use different AI models, and access completely different enterprise systems.
This creates a fundamental architectural question:
How do AI agents connect to the enterprise—and how do they communicate with one another?
Two emerging open protocols provide an important part of the answer:
- Model Context Protocol (MCP) connects agents to tools, data, APIs, and resources.
- Agent2Agent (A2A) connects agents to other agents so they can discover capabilities, delegate work, collaborate, and exchange results.
The important insight is that MCP and A2A are not competing protocols. They solve two different layers of the connectivity problem.
Think of MCP as the agent-to-capability layer and A2A as the agent-to-agent collaboration layer.
Together, they provide a foundation for building an interoperable agentic enterprise.

What Is MCP?
The Model Context Protocol (MCP) provides a standardized way for AI applications and agents to interact with external tools, data, and resources.
Instead of having every agent implement a custom integration, an MCP server can expose its capabilities through a common protocol.
For example:

The agent doesn't need to understand every underlying implementation.
It discovers the available capabilities and invokes them through MCP.
The latest MCP specification, released July 28, 2026, has also moved toward a more scalable architecture, including a stateless protocol core, routable HTTP-based interactions, cacheable capability discovery, authorization hardening, and an extensions framework.
That evolution is important because enterprise agent architectures need to operate at much larger scale than the original local-tool use cases.
What Is A2A?
The Agent2Agent (A2A) Protocol is an open standard that enables independent AI agents to communicate and collaborate.
A2A allows agents built using different frameworks, languages, technologies, or vendors to discover capabilities, negotiate interactions, manage tasks, and exchange information without requiring access to each other’s internal state, memory, or tools.
This distinction is critical.
An agent doesn’t necessarily expose its internal reasoning or implementation.
Instead, it exposes a capability boundary.
For example:

The customer service agent doesn’t need to know how the identity agent works.
It only needs to know:
- What can you do?
- What information do you need?
- What task can you perform?
- What result can you return?
That is the essence of agent interoperability.
MCP vs. A2A
The easiest way to understand the difference is:
| Question | MCP | Agent |
| Typical interaction | Tool invocation | Task delegation |
| Example | Agent → CRM API | Agent → Identity Agent |
| Discovery | Tools/resources | Agent capabilities |
| Result | Structured tool output | Task/result exchange |
| Boundary | Capability boundary | Agent boundary |
The official A2A documentation describes the protocols as complementary: MCP connects agents to tools and resources, while A2A enables agents to collaborate.
How MCP and A2A Work Together
This is where the architecture becomes particularly powerful.
Imagine an enterprise security investigation.
A Security Orchestrator Agent receives:
“Investigate whether this user’s recent privileged-access activity represents a security threat.”
The orchestrator may not perform the entire investigation itself.
Instead:
Step 1 — A2A discovers specialized agents
The orchestrator discovers:
- Identity Risk Agent
- Privileged Access Agent
- Endpoint Security Agent
- Threat Intelligence Agent
Step 2 — A2A delegates tasks

Step 3 — Each agent uses MCP
The Identity Agent might use MCP to access:

The PAM Agent might use:

The Endpoint Agent might use:

The individual agents then return their findings through A2A.
The orchestrator combines those results and makes a decision.
The Emerging Enterprise Agent Architecture through MCP + A2A
This leads to a much more scalable architecture:

This creates two distinct connectivity layers:
1. Horizontal connectivity = A2A
- Agents collaborate with other agents.
2. Vertical connectivity = MCP
- Agents connect to enterprise capabilities.
Agent vs. Prompt: When Should You Ask AI to Think—and When Should You Ask It to Act?
The generative AI landscape has evolved past simple text completion. Today, product and engineering teams face a fundamental architectural choice: Do we deploy a smart assistant that thinks on demand, or do we unleash an autonomous agent that acts on our behalf?
Enterprises reach for an agent when the task is hard, and settle for a prompt when the task is easy. Difficulty turns out to be the wrong axis entirely.
Understanding this boundary is critical for designing secure, reliable, and high-performing AI systems.

1. The Prompt: When You Need Structured Thought
A traditional prompt-and-response pattern treats the LLM as an expert consultant. It excels at tasks requiring synthesis, creativity, and analysis without operational side effects.
- Ideal use cases: Ideation, document summarization, code generation, and complex data extraction.
- The core advantage: Zero blast radius. Because the model is not connected to live action tools or state-changing APIs, mistakes are purely cognitive rather than operational.
- Human involvement: The human remains firmly in the loop, reviewing output before any downstream action occurs.
2. The Agent: When You Need Autonomous Execution
An agent introduces loops, state management, and tool-calling capabilities. Instead of just answering a question, the agent evaluates a high-level goal, breaks it down into sub-tasks, and interacts with external APIs to execute them.
- Ideal use cases: Multi-step data retrieval, automated debugging loops, customer support ticketing workflows, and dynamic report generation.
- The core advantage: Scalable efficiency. Agents handle repetitive, multi-step orchestration that would otherwise drain valuable human bandwidth.
- The risk factor: Higher operational risk. Without strict guardrails and authorization boundaries, autonomous action can lead to unintended API calls, looping errors, or data exposure.
3. Choosing Your Paradigm: A Quick Framework
| Dimension | Prompt-Based Systems | Agentic Systems |
| Primary Goal | Ideation, analysis, and synthesis | Multi-step execution and orchestration |
| State Handling | Stateless single-turn or short context | Stateful multi-turn loops with memory |
| Safety Control | Output review (human-in-the-loop) | Pre-execution guardrails and permissioning |
The Mechanical difference
A prompt is one round trip. You supply the context, the model supplies the output, and you are the loop. If the answer is wrong, you notice and you correct it. Your judgment is applied at every single step, because you are every step.
An agent runs its own loop. It plans, calls a tool, reads the result, decides the action on what to do next, and repeats until it thinks it’s finished. You supply the goal and the guardrails. Your judgment is applied at the boundaries: what it’s allowed to touch, and whether you accept the result.
That’s the whole distinction. Everything else follows from it.
Ultimately, the rule of thumb is simple: If the task requires deliberation and insight, prompt it. If the task requires orchestration and execution, empower an agent—provided you have the necessary governance and security guardrails in place.
The biggest shift in enterprise AI isn’t that machines can generate better answers.
It’s that machines can increasingly take responsibility for completing tasks.
- A prompt makes AI useful.
- An agent makes AI operational.
- And autonomy makes AI powerful.
But power without identity, authorization, governance, and accountability creates unacceptable enterprise risk.
The future of AI isn’t just about making models smarter. It’s about making autonomous systems trustworthy enough to act.
The Rise of the AI Workforce: Why Every Agent Needs an Identity, a Passport and a Permission Boundary
We are standing at the precipice of a profound workforce evolution. For decades, enterprise identity systems were built around a simple, immutable truth: every digital actor has a human face, a corporate badge, and a predictable login cycle. But the operational makeup of the modern enterprise is transforming overnight. Autonomous AI agents are no longer experimental tech demos—they are writing code, orchestrating multi-system workflows, querying secure databases, and executing privileged actions across production environments.
Yet, as we unleash these tireless digital workers, we are managing them with security frameworks designed for passive tools. An agent given broad API access without strict identity boundaries is a ticking security liability. To build an enterprise ready for the autonomous era, we must recognize a fundamental mandate: Every AI agent needs an identity, a passport, and a strict permission boundary.
The Anatomy of the Autonomous Risk
Traditional Non-Human Identities (NHIs)—such as service accounts, API keys, and static OAuth tokens—have long been the weakest link in enterprise security. They lack lifecycle management, rarely rotate credentials, and sit silently in forgotten corners of cloud infrastructure until compromised.
AI agents amplify this risk exponentially. Unlike traditional scripts that follow hardcoded execution paths, autonomous agents reason, adapt, and make independent choices based on contextual data. If an agent is compromised or drifts from its intended operational guardrails, the blast radius isn’t limited to a single database or file share. It can traverse connected APIs, impersonate user context, and execute high-impact actions at machine speed.
Securing this new workforce requires us to move beyond perimeter defense and establish a dynamic, verifiable governance architecture.
The AI Identity Fabric
To safely orchestrate autonomous workflows, organizations must implement an end-to-end governance framework that tracks intent, delegation, and execution across every layer of the technology stack:

Decoding the Fabric Layers
- Human Identity: The root of origin. Every agent must trace its lineage back to an accountable human or enterprise stakeholder who authorized its creation and operational scope.
- Agent Identity: A cryptographically verifiable, unique persona for the AI model or instance itself—complete with behavioral baselines, attestation records, and lifecycle policies.
- Delegated Identity: The contextual scope transferred from the user to the agent. When an agent acts on behalf of a human, it must operate under constrained token exchange, ensuring it never exceeds the user’s entitled permissions (the principle of least privilege in motion).
- Tool/API Identity: The authenticated endpoints, microservices, and utilities the agent is permitted to invoke. Not all tools are created equal; high-risk tools require multi-party authorization or step-up verification.
- Data Access: Fine-grained, runtime evaluation of context. The agent’s ability to read specific datasets must adapt dynamically based on data sensitivity, compliance mandates, and current task parameters.
- Privileged Action: The final execution layer. Destructive or high-impact actions—such as modifying production configurations, initiating financial transfers, or revoking access—must trigger mandatory guardrails, human-in-the-loop approvals, or zero-standing-privilege checks.
“An agent without an identity fabric is an insider threat with a supercomputer’s work ethic. We cannot govern autonomous intelligence with static access control.”
The Paradigm Shift for Identity and Access Management
For years, IAM has focused on solving the identity equation for people: provisioning employees, managing contractors, securing customer logins, and enforcing multi-factor authentication. PAM (Privileged Access Management) has focused on locking down root accounts and vaulting credentials for human administrators.
As AI agents become core contributors to enterprise productivity, these silos must collapse. The challenge of the next decade is no longer just managing who has access to what, but governing how autonomous entities reason across systems on our behalf.
The future IAM platform won’t manage only people. It will manage the relationships between humans, AI agents, non-human identities, tools, data and autonomous actions.
Conclusion: Building Trust into Autonomy
The rise of the AI workforce represents an unprecedented leap in organizational capability, but it tests the limits of traditional security models. Passkeys, cryptographic identity verification, and dynamic permission boundaries are no longer optional best practices—they are the foundational infrastructure of the autonomous enterprise.
By establishing a robust AI Identity Fabric, security leaders can stop viewing autonomous agents as uncontrolled risks and start embracing them as secure, accountable members of the modern workforce.
Transitioning to Identity as a Signal: IAL2 Explained
Most organizations treat identity proofing as a one-time gate: collect a document, run a selfie match, mint an account, move on. But NIST’s Identity Assurance Level 2 (IAL2) serves as the sweet spot between low-friction onboarding and high-assurance risk mitigation.
But the benefits of Identity verification are becoming important for the following reasons.
Key Drivers
- Combating Advanced Fraud: IAL2 directly counters synthetic identity creation, stolen credentials, and account takeover (ATO) attacks during onboarding.
- Regulatory Compliance: Essential for adhering to Know Your Customer (KYC), Anti-Money Laundering (AML), and NIST/Federal compliance frameworks in finance, healthcare, and government digital services.
- Zero Trust Security: Organizations must establish verifiable digital trust before granting access to high-privilege applications or sensitive data.
Implementing IAL2 verification requires balancing security with user experience.
The New Identity Security Paradigm
The shift from traditional IAM to Intelligent Identity Security means moving away from “Identity as a Record” toward “Identity as a Signal.”
IAL2 provides the necessary foundation for a true Zero Trust architecture by ensuring that the person behind the device is verified, real, and currently living.
By integrating multi-pathway verification, recording provenance, and closing the recovery loop, organizations can transition from a one-time gate to a continuously governed trust lifecycle.
Is your organization’s identity foundation built on a one-time gate, or a continuously governed trust lifecycle?

5 Surprising Realities of the New Identity Assurance Standard (IAL2)
The 2017 identity guidelines that governed the last decade of digital growth are officially obsolete. With the July 2025 release of NIST SP 800-63A-4, the “good enough” approach to identity relying on stolen passwords, compromised mobile numbers, and easily spoofed “out-of-wallet” questions has moved from a security risk to a massive organizational liability.
As synthetic identities and AI-generated deepfakes flood onboarding queues, NIST Revision 4 introduces a fundamental shift in establishing trust.
At the heart of this evolution is Identity Assurance Level 2 (IAL2).
No longer just a checklist for a selfie and a driver’s license, IAL2 is now the mandatory foundational trust layer for any high-risk digital interaction.
To navigate this new era, executives and architects must look past the interface and understand five surprising technical and strategic realities of the modern standard.
1. The Evidence Ceiling: IAL2 is Not “IAL3 Lite”
The most persistent myth in identity architecture is that IAL3 requires more documentation than IAL2. It doesn’t.
Under Revision 4, IAL2 and IAL3 share identical evidence collection requirements. To reach either level, you must collect one of three combinations:
- One piece of FAIR evidence plus one piece of STRONG evidence.
- Two pieces of STRONG evidence.
- One piece of SUPERIOR evidence (validated cryptographically).
The difference is not how much evidence you provide but how you prove you own it.
IAL3 is strictly “on-site attended,” whereas IAL2 provides the flexibility to mix modalities, including remote, on-site, attended, or unattended pathways.
If you have built an IAL2 process that validates a passport and a driver’s license, you have already hit the “evidence ceiling.”
2. Identity is Not Authentication (The IAL vs. AAL Divide)
A common architectural failure is bundling identity and authentication. NIST Revision 4 enforces a strict divide between them because they solve fundamentally different problems:
- Identity Assurance Level (IAL): “Who are you in the real world?” This is a one-time or periodic proofing event.
- Authentication Assurance Level (AAL): “Are you the same person who enrolled?” This happens at every login.
The strategic flow is: Establish trusted identity (IAL) → Authenticate trusted identity (AAL).
You can have a high-security passkey (AAL3) protecting an account that was never actually verified (IAL1). Conversely, you can prove an employee at IAL2 but allow them to authenticate with a weak SMS code (AAL1).
High-assurance security requires parity; a strong door is useless if you don’t know who you gave the key to.
3. The Rise of “Pathway Provenance” (and the Death of KBV)
In Revision 4, “IAL2” is no longer a monolithic status. There are now three distinct verification pathways:
- Non-Biometric: Verification via a mailed confirmation code or visual comparison by a trained agent.
- Digital Evidence: High-assurance federation or wallet credentials (e.g., mDL or bank account linking).
- Biometric: Automated comparison of a live sample against a validated document.
The Surprising Shift: Credential Service Providers (CSPs) now have a normative obligation to record and surface “Pathway Provenance.” It is no longer enough to assert that a user is IAL2; Relying Parties are entitled to know how that level was reached.
Furthermore, Knowledge-Based Verification (KBV) is officially dead as a proofing control. Revision 4 permits KBV only for fraud management—not for validation or verification. If your flow still relies on “your first car” questions to prove identity, you are not compliant with IAL2.
4. The “Quiet Downgrade” in Account Recovery
The “Achilles’ heel” of modern security is the exception path. You might spend thousands to prove a user at IAL2 during onboarding, only to have a help desk agent reset their credentials after a low-assurance phone call.
When the recovery path is weaker than the enrollment path, the original IAL2 status is effectively nullified. Revision 4 mandates that the recovery bar must match the enrollment bar.
“The exception path is where assurance goes to die.”
If your account recovery relies on a “quiet downgrade” to SMS or simple help-desk verification, your system’s actual assurance level matches the strength of that recovery path, not the high bar of onboarding you paid for.
5. From Binary Checks to “Identity Intelligence”
IAL2 has evolved from a point-in-time “pass/fail” gate into a continuous Identity Intelligence model. Modern compliance requires technical controls that go beyond simple document scanning.
Two mandatory requirements of Revision 4 often surprise organizations:
- Death Records Check: A mandatory check against authoritative death records is now required for every IAL2 proofing process.
- Injection and Forged-Media Defense: You must implement technical controls to detect virtual cameras, emulators, and deepfakes. This includes testing your algorithms against known attack artifacts to establish baseline false-positive rates.
To assert IAL2 conformance for the Biometric Pathway, you must meet specific technical benchmarks: a False Match Rate (FMR) of 1:10,000 or better and a Presentation Attack Detection (PAD) threshold with an IAPAR below 0.07.
The Identity Confidence Profile now includes:
- Evidence Confidence: Validating security features and authoritative sources.
- Injection Defense: Confirming media originates from a genuine sensor.
- Biometric Integrity: Testing against ISO/IEC 30107-3 standards for liveness.
- Fraud Signals: SIM swap detection, device reputation, and mandatory death record checks.
The Death of the Decoy: Why Passkeys and AAL2 Are Rewriting the Rules of Digital Trust

For decades, digital security relied on a fragile illusion: the shared secret. This could be a password memorized by a person, an SMS code intercepted in the air, or a time-based one-time password (TOTP) entered into an app.
For years, enterprise security has operated on a deceptively simple assumption:
If we add another authentication factor, we make the user safer.
That assumption is no longer good enough.
Attackers have become skilled at exploiting the human interaction around authentication. They don’t need to steal your password. They can trick you into approving a push notification, entering a one-time code on a fake website, or surrendering a session to a man-in-the-middle attack.
This raises a much more important question:
What if the strongest authentication isn’t the one that gives users another factor—but the one that gives attackers nothing useful to steal?
That is where AAL2 authenticators and passkeys become particularly interesting.
Attackers realized that tricking a human into giving up that secret means owning the kingdom. This led to the era of Adversary-in-the-Middle (AiTM) phishing kits and push-fatigue scams, where human error remains the ultimate vulnerability.
This raises a more important question:
What Are AAL2 Authenticators?
The National Institute of Standards and Technology (NIST), in its SP 800-63 guidelines, outlines Authenticator Assurance Levels (AALs) to measure how strongly an authentication ceremony proves that the person logging in is actually who they claim to be.
AAL stands for Authenticator Assurance Level.
The concept comes from NIST’s Digital Identity Guidelines and describes the level of confidence a system can have that the person authenticating is actually the legitimate user.
At a high level:
- AAL1 provides basic confidence in the claimant’s identity. AAL1 relies on single-factor authentication (like a simple password).
- AAL2 requires stronger authentication using either a multi-factor authenticator or two distinct authentication factors. AAL2 sits as the vital baseline for modern enterprises and secure platforms. It requires Multi-Factor Authentication (MFA).
- AAL3 provides an even higher level of assurance, including stronger requirements around the authenticator and resistance to attacks. AAL3 demands the highest tiers of hardware-backed security, often requiring specialized physical security tokens.
AAL2 is not simply synonymous with “MFA.”
Traditionally, AAL2 could be met by combining two single-factor elements—such as a password with an SMS text or a TOTP code. However, as automated phishing proxies have become sophisticated enough to harvest these codes in real time, the security industry has realized a harsh truth: not all MFA is created equal. AAL2 frameworks now emphasize methods that resist interception, replay, and man-in-the-middle attacks.
Why Passkeys Are Phishing-Resistant MFA
Passkeys—built on the FIDO2 and WebAuthn protocols—are the gold standard for achieving this modern security bar. They satisfy the core criteria of phishing-resistant MFA through three revolutionary mechanisms:
1. Cryptographic Domain Binding
Unlike a password or TOTP code, which can be typed into any convincing website, a passkey is bound to the domain where it was created. If a malicious actor sets up a look-alike phishing site (e.g., g0ogle.com), your authenticator checks the domain origin. It refuses to sign the cryptographic challenge because the URL doesn’t match the legitimate service. The phishing site gets nothing because the passkey refuses to interact with imposters.
2. Asymmetric Key Pairs (No Shared Secrets)
When you register a passkey, a unique public-private key pair is generated.
- The public key lives on the server. If the server is breached, the public key is useless to an attacker.
- The private key never leaves your hardware-protected key store (like Apple’s Secure Enclave, a Windows TPM, or an Android keystore).
- Because no secret is transmitted across the network during login, there is nothing for an attacker to intercept.
3. Built-in Intent and Biometric Local Gatekeepers
To use a passkey, your device requires local physical presence or biometric confirmation (such as a fingerprint scan, face unlock, or device PIN). This satisfies the requirement for “authentication intent”—proving a human is actively participating now, not a remote script quietly harvesting a session token.
How Passkey works during Authentication
Passkeys fundamentally change the authentication model.
Instead of asking: “What secret can the user prove they know?”
The system asks: “Can this trusted device cryptographically prove that it possesses the credential associated with this website?”
That is a radically different security model.
Passkeys are based on public-key cryptography and the WebAuthn/FIDO2 ecosystem.
During registration:
- Device generates a key pair.
- Private key → stays protected on the user’s device.
- Public key → registered with the identity provider
2. During authentication:
- Identity Provider sends a challenge.
- Authenticator verifies the user.
- Device signs the challenge using the private key.
- Identity Provider verifies the signature using the public key.
And critically, there is no reusable password or OTP for the attacker to steal.
A Paradigm Shift in Digital Trust
The brilliance of passkeys meeting AAL2 requirements is philosophical as much as it is technical: it removes human judgment from the security equation.
For decades, we blamed users for clicking phishing links, falling for social engineering, or failing spot-the-fake-domain tests. Passkeys acknowledge that humans are human and instead build an architecture where, even if you are fooled, the technology is not.
AAL2 + Passkeys: A Powerful Combination
AAL2 provides a useful assurance framework. Passkeys provide a modern authentication mechanism capable of strong phishing resistance.
Together they help organizations move from: “Do we have MFA enabled?” to a much more mature security question.
“What level of assurance does this authentication event provide, and how resistant is it to real-world attacks?”
Rather than simply Username + Password + MFA authentication policy, move to a realistic and strong enterprise identity policy that evaluates User + Device + Credential + Context + Risk.
By tying identity to immutable hardware and mathematical proof instead of shared secrets, we are moving past a world where a clever text message or fake website can compromise a digital life.
The decoy is dead; long live the key.
Rethinking Security: How Autonomous AI Challenges Traditional Models
We have moved beyond when conversational AI was just a fancy chatbot. Now, the real frontier of artificial intelligence is autonomous execution, not just answering questions or drafting emails.
Today’s AI agents can call APIs, access sensitive databases, set up cloud infrastructure, change system settings, create new digital identities, and run code in real time. They do more than just talk—they take action.
This change turns AI from a passive source of answers into an active digital worker. It also brings a serious challenge. Traditional security systems were designed for people, not fast, autonomous systems. How do you protect something that operates at machine speed, has wide digital access, and makes its own decisions?
This is where Identity, Security, and AI converge.
The Paradigm Shift: From Human Intent to Machine Autonomy
In older enterprise security models, every important action like updating a database, moving money, or changing permissions required human involvement. Even when using service accounts or API keys, a person still set up the process.
Autonomous agents change this approach. When an agent can create its own sub-identities and buy cloud resources as needed, the line between user and system disappears.
Consider the capabilities of a modern agentic workflow:
- Dynamic Identity Provisioning: Creating ephemeral service accounts to bypass static permission checks.
- Arbitrary Code Execution: Writing and running scripts on the fly to solve unexpected runtime errors.
- Cross-System Orchestration: Chaining API calls across SaaS platforms, databases, and internal infrastructure.
If an autonomous agent is compromised through prompt injection, data poisoning, or a misaligned goal, it does more than leak data. It can carry out harmful actions on a large scale.
Why Legacy Security Fails Here
We can’t use old tools to solve new problems with autonomous agents. Traditional security controls don’t work well because:
- Static RBAC (Role-Based Access Control) is too rigid. Agents need flexibility to handle complex problems, but fixed roles can’t keep up with AI’s real-time decisions.
- Perimeter defense no longer works. Agents move across cloud services, third-party APIs, and microservices. The real boundary is the agent’s current context, not a firewall.
- Post-hoc auditing is too slow. By the time a security system alerts you to a suspicious database wipe or unauthorized purchase, the autonomous agent has already finished its task.
A New Blueprint: How We Secure Autonomous AI

To secure enterprises using autonomous agents, we need to rethink identity, context, and safeguards from the ground up. Security leaders should focus on three main pillars:
1. Identity-Aware Intent Verification (Beyond OAuth)
An agent identity should be integrated into the broader Non-Human Identity (NHI) security strategy.
But AI agents are different from traditional service accounts.
A service account generally executes predefined functions. An AI agent can interpret context, make decisions, select tools, and initiate actions.
That means identity alone isn’t enough.
We need to know not just who the agent is but also what it is trying to do. An agent should not get all the permissions of its creator. We need dynamic session identities using cryptographic proof of intent. Every risky action, like changing a configuration or running code, should trigger a real-time check: Does this action match the approved business goal, or has the agent’s context been compromised?
Agent identity has to be two-layer:
- A durable workload identity — cryptographically attested, non-transferable, bound to the running code rather than to a secret in a config file. This is what you inventory, certify, and revoke. It answers what this thing is.
- An ephemeral, task-scoped credential — minted at task start, carrying the delegation chain, expiring when the work does. This answers what it may do right now.
2. Zero-Trust Sandboxing for Code and APIs
When an agent can write and execute code or invoke external APIs, that execution must occur within hyper-isolated, ephemeral environments.
- Blast-Radius Containment: If an agent is compromised during a database migration, its access must be hard-capped to that specific transaction, preventing lateral movement.
- API Gateway Interception: All outgoing API calls made by agents should pass through intelligent proxies that inspect payloads for semantic anomalies, preventing exfiltration before the request hits the wire.
3. Continuous Runtime Guardrails & “Circuit Breakers”
We must move from deterministic firewalls to behavioral guardrails. Like high-frequency trading platforms that use circuit breakers to halt runaway algorithms, autonomous AI needs real-time circuit breakers. If an agent suddenly tries to create unauthorized user identities or rapidly purchase high-cost cloud resources, automated systems must freeze the execution graph instantly.
The Thought Leader’s Takeaway
We are standing at the precipice of a fully agentic economy. The companies that win will not be the ones that build the smartest agents, but the ones that build the most trustworthy ones.
Securing AI is no longer just about protecting data from leakage; it is about governing autonomous action. If we fail to secure the hands of our AI systems, we hand over the keys to the enterprise.
The future belongs to security architectures that treat AI not as a tool to be restricted, but as an autonomous actor requiring continuous, intelligent oversight.
You won’t just secure your agents. You’ll have to build the control plane that the enterprise software agents run on over the next decade.
Once AI can act, Identity becomes its foundation, authorization becomes its guardrail, least privilege becomes its boundary, behavioral intelligence becomes its early-warning system, and governance becomes its accountability layer.
Transforming Enterprise Security with AI-Driven NHI Framework
Future enterprises will comprise not only human employees but also a digital workforce that includes applications, workloads, bots, machines, and AI agents.
- Each component of this workforce will require a distinct digital identity, appropriate access privileges, contextual access decisions, and continuous security monitoring.
- Each identity must be granted appropriate access privileges.
- All access decisions should be informed by contextual information.
- Continuous security monitoring is required for every identity.
There is an opportunity to develop an AI-powered Non-Human Identity (NHI) security fabric that transforms identity management from a static directory of accounts into a continuously adaptive security control plane.
The following process framework enables the AI-powered NHI security fabric to function effectively.
1. Discover every identity.
2. Understand every relationship.
3. Protect every interaction.
4. Respond to every risk.
5. Govern continuously.
In an AI-powered enterprise, securing identity extends beyond merely verifying user identity.
It involves understanding which entity is acting, its capabilities, the rationale for its actions, and the degree of trust that can be assigned to it.
What does a Non-Human Identity(NHI) Actually Mean?
A non-human identity (NHI) is any digital identity that authenticates and acts on systems without a person directly behind the keyboard. In practice, the category spans:
- Service accounts and system accounts: the workhorses of legacy and on-prem estates
- API keys, tokens, and secrets: the connective tissue between applications
- OAuth grants and third-party integrations: the SaaS-to-SaaS trust web
- Workload and cloud identities: the IAM roles, managed identities, Kubernetes service accounts, SPIFFE IDs
- Certificates and SSH keys: machine-to-machine trust anchors
- CI/CD and automation credentials: pipeline runners, IaC deployers, RPA bots
- AI agents and copilots: the newest and fastest-growing class, and the only one that reasons about what to do next
The common characteristic among these entities is not merely the possession of credentials, but rather that each represents an authorization surface with persistent privileges and no inherent owner. For example, a compromised employee password is typically rotated quickly due to the immediate impact on users. In contrast, a leaked API key may remain in use for extended periods because its compromise often goes undetected.
The AI-Powered NHI Security Framework
Approaches to Discovery, Protection, Response, and Governance
Developing an Intelligent and Adaptive Security Layer for Non-Human Identities
The rapid growth of cloud computing, APIs, automation, workloads, and agentic AI has created an enterprise ecosystem in which machines increasingly act on behalf of humans and businesses.
Service accounts, workloads, applications, API keys, certificates, bots, automation tools, and AI agents can now access critical systems and data, often operating at machine speed and without direct human oversight.
Traditional IAM was built primarily around human identity.
The next generation of identity security must protect all identities, both human and non-human.
The AI-Powered NHI Security Framework provides a continuous operating model built around four capabilities:
DISCOVER → PROTECT → RESPOND → GOVERN
AI serves as the intelligence layer across all four major tasks.

Step 1: NHI DISCOVER
Discovery tells us what exists and creates an NHI Inventory across the enterprise.
a.) AI Discovery of Sources
AI should continuously ingest signals from:
IAM | PAM | CI/CD | Cloud | Kubernetes | API Gateways | Secrets Managers | SIEM | EDR | Applications | Databases | Network | DevOps | AI Platforms
The objective extends beyond creating a simple inventory.
The aim is to establish a comprehensive Identity 360 view.
b.) Key AI Capability for Discovery
- Identity Entity Resolution
AI correlates fragmented signals to determine whether multiple credentials, accounts, applications, and workloads represent the same logical identity or application ecosystem, and to establish the relationships across NHIs and the resources that they are used against.
Step 2: NHI PROTECT
Protection reduces exposure. Protection should be based on least privilege, context, behavior, and risk.
This step helps to reduce NHI Risk before it becomes an incident.
a.) AI-Powered NHI Risk Scoring
Every NHI should receive a continuously evaluated risk score.
NHI Risk Score
- Risk = Privilege + Exposure + Sensitivity + Behavior + Criticality + Credential Risk + Ownership
b.) AI-Powered Least Privilege
AI can analyze historical behavior to determine:
What permissions does this identity actually need?
c.)AI-Powered Just-in-Time NHI Access
Standing privilege should be treated as an exception rather than the default configuration.
AI Agent dynamically determines whether access should be:
Allow → Step-up → Approve → Limit → Deny
d.) Protecting AI Agents
AI agents require an additional security layer.
Every enterprise AI agent should have:
Agent Identity + Owner + Purpose + Permissions + Tools + Data Scope + Risk Profile + Audit Trail
Step 3: NHI RESPOND
Response answers: What happens when an NHI becomes risky or compromised?
AI can continuously monitor NHI behavior and detect deviations from established behavioral baselines.
a.) AI-Powered Behavioral Intelligence
For each non-human identity (NHI), AI establishes a behavioral baseline:
- Who/what does it normally interact with?
- When does it operate?
- From where?
- What APIs does it call?
- What data does it access?
- How much data does it move?
- What permissions does it normally use?
b.) AI-Powered NHI Response
When risk increases, the system should dynamically determine the appropriate response.
Low Risk
Monitor → Alert → Increase telemetry
Medium Risk
Step-up verification → Reduce privilege → Increase monitoring.
High Risk
Suspend credential → Revoke token → Remove privilege → Isolate workload.
Critical Risk
Quarantine identity → Terminate sessions → Rotate credentials → Block downstream access → Initiate investigation.
This approach establishes an identity-aware autonomous response loop.
Step 4: NHI GOVERNANCE
This process is designed to establish continuous accountability.
Governance is what turns NHI security from a technical capability into an enterprise operating model.
For governance to be implemented, every NHI should have the following attributes.
- An Owner : Who is accountable?
- A Purpose : Why does the identity exist?
- A Business Context: What business process does it support?
- An Access Policy: What should it be allowed to do?
- A Risk Classification: How dangerous would compromise be?
- A Lifecycle: When should it be created, reviewed, rotated, and retired?
- Evidence: Can the organization prove that access is appropriate?
a.) AI-Powered Continuous Governance
Traditional governance often looks like:
→ Quarterly Access Review → Approve → Repeat
AI enables:
→ Continuous Monitoring → Continuous Risk Evaluation → Continuous Policy Validation → Continuous Remediation
AI can proactively identify:
- Orphaned identities
- Dormant identities
- Excessive permissions
- Unused credentials
- Expiring credentials
- Policy violations
- Unknown owners
- Unapproved AI agents
- Toxic access combinations
- Segregation-of-duties violations
- High-risk attack paths
Rather than relying on periodic reviews, governance becomes a continuous process.
Six Ways AI Can Transform Enterprise IAM
AI can transform IAM from a system that manages access into an intelligent, continuously adapting system that understands identity, intent, risk, and context.

Here are the six ways AI can help you transform your Enterprise IAM strategy
1. AI-Powered Identity Risk Scoring
For example:
One of the most powerful opportunities is to move from static access policies to continuous identity risk evaluation.
Instead of simply asking:
“Does this user have permission to access this application?”
an AI-powered IAM system can ask:
“Given everything we know right now, should this identity be allowed to perform this action?”
The risk engine could combine signals from:
- IAM, PAM, MFA, HR, Endpoint, SIEM, UEBA, Cloud, SaaS applications, Data classification, Threat intelligence, Behavioral history, Network context, AI-agent activity
This could produce a dynamic Identity Risk Score.
Identity Risk = 18 → Low
Allow normal access.
Identity Risk = 57 → Elevated
Require phishing-resistant MFA or step-up authentication.
Identity Risk = 86 → High
Block privileged access and trigger investigation.
The result is a shift from periodic authorization to continuous authorization.
2. AI Can Discover Excessive Access
Most large enterprises have an uncomfortable problem:
Nobody really knows who has access to what.
Users accumulate permissions.
Contractors retain old entitlements.
Service accounts remain active.
Applications create machine identities.
And now AI agents are being added to the mix.
AI can analyze identity relationships across the enterprise and identify:
- Unused privileges
- Toxic combinations
- Excessive permissions
- Orphaned accounts
- Dormant identities
- Overprivileged service accounts
- Excessive administrative rights
- High-risk access paths
- Privilege escalation opportunities
Instead of asking an identity administrator to review thousands of entitlements manually, AI could say:
“These 47 identities represent the highest unnecessary privilege risk in your environment. Here is why, and here are the recommended remediation actions.”
That changes IAM from a system of record into a system of intelligence.
3. AI Agents Need Their Own Identity Lifecycle
This may become one of the biggest IAM categories of the next decade.
Imagine an enterprise deploying 50,000 AI agents.
- Who created them?
- Who owns them?
- What systems can they access?
- What data can they see?
- Who approved them?
- What model are they using?
- What tools can they invoke?
- When should they expire?
- What happens when their owner leaves the company?
These are classic identity-governance questions — but applied to machines.
The future enterprise IAM platform should therefore manage an Agent Identity Lifecycle:
Discover → Register → Authenticate → Authorize → Monitor → Review → Revoke → Retire
Every agent should have:
- A unique identity
- An owner
- A sponsor
- A purpose
- A risk classification
- Defined permissions
- Expiration policies
- Activity history
- Access reviews
- Emergency revocation
In other words:
AI agents should be governed like employees — but with much tighter controls.
4. Move From RBAC to Intent-Aware Authorization
Role-Based Access Control has served enterprises well. But AI agents operate differently.
A single agent may perform hundreds of different tasks.
Instead of:
Agent → Role → 500 permissions
we should move toward:
Agent → Intent → Context → Minimum Required Permission
For example:
An HR AI agent might be permitted to:
- Read employee benefits information.
- But that doesn’t mean it should be allowed to:
- Modify compensation records.
A finance agent may be allowed to:
- Read invoices under $100,000.
But not:
- Approve a $5 million payment.
This is where Just-In-Time Access, Zero Standing Privilege, and policy-based authorization become extremely important.
AI should receive the minimum privilege necessary for the specific action — and preferably only for the duration of that action.
5. AI Can Become the IAM Administrator’s Copilot — and Eventually Agent
Identity teams spend enormous amounts of time investigating access issues.
AI can dramatically reduce this operational burden.
Imagine an IAM administrator asking:
“Why does this employee have access to Salesforce?”
The AI could respond:
“The user received the entitlement through the Sales Operations role 14 months ago. The employee changed teams six months ago, but the role assignment was not removed. The user has not accessed the application in 120 days. Recommended action: remove access.”
Or:
“Show me all privileged identities whose behavior deviates from their normal baseline.”
The system could analyze millions of events and return the highest-risk identities.
Eventually, AI could move from recommendation to controlled remediation:
Detect → Explain → Recommend → Approve → Remediate → Verify
With appropriate human oversight, IAM teams could manage environments that would otherwise require many more personnel.
6. Continuous Access Reviews Become Continuous Governance
Traditional access reviews are often periodic.
- Quarterly.
- Semiannual.
- Annual.
But AI agents can continuously change their behavior, tools, permissions, and workflows.
A quarterly review may therefore be obsolete before it is completed.
The future should be:
Continuous Access Governance.
AI continuously evaluates:
- Identity
- Entitlements
- Behavior
- Risk
- Data access
- Agent activity
- Policy compliance
- Business context
When something changes, the system responds.
For example:
Employee changes department
→ AI identifies impacted access.
Risk increases
→ Privileged access is reduced.
Agent changes behavior
→ Agent is quarantined.
Agent owner leaves company.
→ Sponsorship is reassigned, or agent access is suspended.
Unused entitlement detected
→ Access removal is recommended.
Sensitive data requested
→ Step-up authorization is triggered.
This is IAM moving from periodic governance to autonomous governance.
AI’s Impact on Enterprise Identity Management
For twenty years, Enterprise IAM has been organized around a simple assumption: identities are either people or plumbing.
People log in, get provisioned through a joiner-mover-leaver process, and sit through a quarterly access review. Plumbing service accounts, batch jobs, API integrations, gets a long-lived credential, a bounded scope, and an owner who may or may not still work here.
“Who are you, and what are you allowed to access?”
Traditionally, this question applied primarily to human users. Employees, contractors, partners, and administrators would authenticate, receive permissions, utilize applications, and subsequently have those permissions revoked as necessary.
Non-human identities already outnumber human ones by something like seventeen to one, and that population grew by double digits year over year before agents were a meaningful share of it.

However, the advent of AI is fundamentally altering this paradigm. AI agents break this binary. An agent has an identity, credentials, and a scope like a service account does, but its scope changes with every invocation. Currently, organizations deploy AI copilots, autonomous agents, AI-powered applications, and multi-agent workflows. These systems can access data, interact with APIs, execute business processes, and, in some cases, make decisions on behalf of employees.
As a result, the central question has become significantly more complex than “Who are you?”
It is: “Which human, agent, application, or machine is acting, on whose behalf, with what authority, for what purpose, and with what level of risk?”
This development represents an entirely new category of identity management challenge.
This shift presents IAM with a significant opportunity to serve as the primary control system for enterprise AI.
The Emergence of the AI Agent as a Distinct Enterprise Identity
Recent advancements clearly indicate this emerging direction.

Microsoft has introduced Entra Agent ID, specifically designed to provide identities for AI agents and govern their access throughout their lifecycle. The platform includes concepts such as agent identities, owners and sponsors, lifecycle governance, and access packages.
NIST has also launched work focused specifically on identity and authorization for software and AI agents, recognizing that agents require access to diverse data, tools, and applications and therefore need appropriate identification and auth. The security market is also evolving rapidly in this direction. For example, Cyera’s acquisition of Oasis Security, reportedly valued at approximately $1 billion, underscores the increasing significance of non-human identity and AI-agent governance and AI-agent control.
Concurrently, security researchers increasingly advise that AI agents should be regarded as potentially privileged insiders rather than as traditional software entities.
The implications for Chief Information Security Officers (CISOs) and Chief Information Officers (CIOs) are evident:
AI agents need identities.
However, identity alone is insufficient. AI agents require governed identities.
Limitations of Traditional IAM Approaches
Conventional IAM frameworks typically operate based on relatively static concepts:
User → Role → Permission → Application
In contrast, AI introduces a significantly more dynamic model:
Human → Agent → Intent → Context → Tool → Data → Action
For example, when an employee interacts with an AI agent:
“Find the latest customer renewal risks and prepare recommendations for my accounts.”
The agent may need to:
- Identify the employee.
- Determine whether the employee is authorized to access those customers.
- Retrieve CRM information.
- Query analytics systems.
- Access customer-support records.
- Invoke an AI model.
- Generate recommendations.
- Potentially update a business system.
This scenario raises a critical security question:
Should the agent inherit everything the employee can access?
This approach is not advisable. Such a practice would significantly increase the potential impact of security breaches.
Instead, access should be dynamically determined based on:
- Who initiated the request?
- Which agent is executing it
- What the agent is trying to accomplish
- What data is being requested
- Which application is being accessed
- The sensitivity of that data
- The current risk level
- The agent’s behavior
- The duration of access
- Whether the action is read-only or transactional
This context illustrates how AI can fundamentally transform IAM practices. More will follow in my next blog on this topic
Zero Trust Security needs around Remote Access
As the whole world has been taken over by COVID-19 pandemic, and the recovery is still far insight, remote access to applications and data has become the new normal for employees of every company.
The security needs around enabling remote access to enterprise application needs is a primary topic that of interest to me these days.
This brings the focus around addressing these questions.
- How to enable Remote Access to employees, partners, and contractors securely?
- How to keep the IT cost low and productivity high without having to invest in additional desktops and mobile devices? Can we allow users to use their personal/BYOD?
- How do we make sure the devices and endpoints are safe, and they meet the IT compliance needs, so they are no data breach and security attacks on enterprise assets?
These questions are not new when it comes to application security, even though these are the main drivers for a digital workplace, which is the new buzz word for digital transformation at every enterprise. Though the adoption of digital workplace benefits includes increased employee productivity, reduces overall cost reductions, and improves employee trust, the concepts around zero-trust security have remained the same. The evolution around Zero trust security is to take more and more attributes around the identity and the endpoints to defend, secure, and protect applications and the enterprise data on your network.
Digital workspace is a rapidly evolving market and is the green field that enterprises are experimenting with zero-trust security. This market expected to grow $54.2Billion by 2027, with a CAGR of 11.3%.
As I understand, digital workspace is an integrated technology framework that centralizes the management of the enterprise’s applications, data, and endpoints, allowing users to collaborate and work remotely. It also provides users with the self-service, out-of-the-box experiences that can scale across platforms, locations, and devices, allowing them to work in a digital environment. Adopting a Bring Your Own Devices (BYOD) strategy can help drive the adoption of the digital workplace faster since around the globe, users, on average own at least two personal devices on their own, which they use regularly. Building a bridge between BYOD and Digital workspace is the future.
The topic I want to focus on is zero-trust security needs around Remote Access and the best practices around users and endpoints.
Providing Business Agility
One of the vital business aspects of remote access in a digital workplace environment is providing business agility and continuity for users to operate from any device and get access to their applications and data. This would require that the requirements around Remote Access and security are met so your traffic is protected and data breaches are prevented, so the remote access is efficient.
Here are the best practices to follow around the Zero Trust Security requirements for Remote Access.
They fall into these four main categories.
1. Endpoint protection
Remote Access users are typically provided with a managed desktops or can use an unmanaged BYOD to access company apps or data. This would require that the security posture of these devices be validated to ensure that the endpoint meets all the device trust criteria before they are allowed into the network.
Requires these endpoints are validated to prevent data breaches and are kept monitored to keep track of what these device endpoints are doing so the network stays safe at all times.
2. Authentication
Users from managed devices or an unmanaged BYOD have to be authenticated to identify who the user is before they are allowed into the enterprise network. Depending on the device’s security posture, the context or behavior attributes of the user, multi-factor authentication, and encryption for the endpoint should also be enforced.
Identity and access management solution here is what can help address the needs around identity provisioning and authentication needs around devices and users.
3. Vulnerability Assessment
Enforcing a systematic vulnerability assessment for the security weaknesses to satisfy the compliance needs around a managed device or a BYOD will help to assess the threats and keep the risks to the data and the information systems under control. It evaluates if the endpoint devices and the users are susceptible to any known vulnerabilities, assigns severity levels to those vulnerabilities, and recommends remediation or mitigation, if and whenever needed.
Taking steps to do continuous monitoring of the endpoints to meet the device compliance rules, assessing the risks around user’s behaviors, and session through continuous verification will keep the remediation and mitigation efforts to a minimum at all times.
4. Access Management
Access Management is the process that controls and monitors who gets access to what at all times. Typically enforced through a policy framework around a BYOD that allows policy definitions against, type of devices, type of users with additional user criteria like the user context and behaviors, types of applications, type of data, and more. The fine-grained the policy controls are the fine-grained remote access management can be enforced around the apps and resources that a typical remote user would want to access through his BYOD in a digital workplace.
In conclusion, the COVID-19 pandemic has caused rapid and significant changes in how employees adapt to remote access. There is a shift in enterprise security needs to support remote access to applications and data. This requires the adoption of new technologies that can apply the security controls and do a better analysis of the threats faster and accurately to avoid data breaches.
I recently came across an IDC global survey on how COVID-19 impact on the IT strategy. Here are the four main takeaways that are worth noting, which strengthens the case for a strong Zero Trust security strategy to support business agility.
| # | Takeaways | Worldwide | North America |
| 1 | Encourage working from home and support remote work | 40% | 47% |
| 2 | Support for Mobile devices and applications | 39% | 37% |
| 3 | Make changes to IT security strategy and systems. | 36% | 39% |
| 4 | Move data and applications to the cloud aggressively. | 35% | 34% |
Remote access to employees is here to stay, and it’s proven that productivity has not diminished as more and more employees are working from home.
Facilitating the ability for employees to have the same user experience, whether they are using company-provided devices or a BYOD, has to stay the same without compromising enterprise security.
The bottom line is as enterprises embrace and enable a Digital workspace environment for their remote workers, they need a better and reliable security strategy, so there is no compromise on security and risks.
Consumer Digital Identity – Why a business should care.
The business world as we know it is rapidly changing and one of the fundamental drivers is digital transformation( https://www.i-scoop.eu/digital-transformation/). The online interactions between people, business, devices, data, and services are the backbone of the digital economy. This means a business need to have an interconnected view of people, organizations, machines, devices and the internet of things (IoT) at all times to understand who your consumers are and what they want. Consumer digital identity is the one that can address this and is an important factor in today’s digital economy for all enterprises.

What is Consumer digital Identity?
Gone are the days when consumers would come seeking for business solutions. In the current age, a business has to seek the consumers. There is a strong realization that digital identity is the front door for all business.
Enterprises currently have their consumers coming in as anonymous or they have pre-established identities that are distributed across various old and new systems. Know your customer (KYC) has been the biggest challenge for enterprises to solve. Addressing other business problems and efficiency around customer experience, lead generation, building awareness of their products, consumer recommendations, up-selling or reselling, billing, loyalty programs, retention, license management has snowballed this challenge.
64 percent of enterprises already indicate that Security, AI, and analytics as the top three efforts on their list of digital transformation technologies they are most interested in. With the advances in the digital Identity, mechanisms offer the promise of greater efficiency, security, and trust in a wide variety of settings.
Opportunities with Consumer digital Identity
1. Consumer Security and Fraud management.
Data breach is a common problem for a business these days. Hence security is crucial in protecting the consumers as well as their business assets. Identity and access management along with identity governance, audit and compliance allow to monitor and manage who has access to what, when and why. This helps a business to be aware who is coming through their front door so their consumers can access the products and services. This also helps to monitor and manage unwanted solicitors who want to create fraud or damage to the business.
2. Consumer Trust and engagement.
Consumers have a small attention span to engage with a business or a brand. This would mean that the process of engagement should be light and frictionless. At the same time, consumers should feel comfortable to trust the brand or business to share who they are so they can establish an identity.
Establishing trust by engaging customers across multiple channels (phone, web, social media, in-store) with personalized offerings based on real-time insights has to be a priority in order to expand and building a strong customer base.
3. Consumer Brand awareness and lead generation.
Importance of brand awareness is an important task for marketing team in any business. Marketing has a need to identify their consumers and tailor their campaign messages so that there is a better return on investment for their marketing dollars spent.
By leveraging the identity data of a consumer helps marketing to segment, tailor and personalize their campaigns and efficiency around lead generation activities
4. Consumer Retention and loyalty.
Customer loyalty is an intangible but extremely valuable business asset that helps to up-sell and/or resell product and services. The ability to measure and model customer loyalty is an essential element to building customer relationships and expanding the market size. The ability to retain customers is a factor that is important to increase your recurring revenue. Understanding the behavioral and contextual insights of the individual customer through their identity data will allow to influence, advocate and expand the loyalty and retention base for any business.
5. 360 Degree view of your consumers.
Consumer data in a typical enterprise resides in multiple systems depending on the customer journey that an individual takes with various products and services through multiple channels ( i.e cross-device, online, in-store and more). Aggregating data of the consumer from various systems and channels into a single unified view based on an individual’s identity becomes a very valuable asset for any business.
Business can then leverage this 360-degree view and the data to make intelligent business decisions around personalization, discounts, recommendation, alerts, notifications, deliver value-added services and more.
Current Technology and Business Trends in Consumer Digital Identity.
1. Identity and Access Management (IAM) Security Standards.
Standard protocols like SCIM, SAML, OAUTH2, OpenID Connect, UMA, REST make it easy for the business to adopt digital Identity for their consumers. The approach to security standards strengthens interoperability both in a SaaS, on-premise or hybrid IAM environments across users, web, phones, social, devices, desktops, and IoT.
2. Self-service and data-driven consumer journey is the new norm.
Easy to use interfaces in IAM that allow consumer self-service interactions to not only establish their digital identity with a business but also allow to consumers to carry their existing digital identity established with a social provider. This experience should be frictionless.
Consumers want their experiences tailored to their needs and wants. A business will have to take a data-driven customer experience by design approach to collect, analyze and provide a very personalized journey at every touchpoint to their consumers. Self-service UX and Data Analytics along with Identity Governance should be an integral part of IAM.
3. Privacy and Data Protection is in the forefront for consumer trust.
Security and privacy by design is the foundation for data privacy. IAM Technology should be able to help a business to maintain their consumers and prospect data secure at all times including the loss, theft or corruption of data. With General Data Protection Regulation (GDPR) going live in Europe and more GDPR like regulation to come into effect in the US, there is more need for Privacy and Data Protection to be in the forefront for establishing trust with consumers.
4. Devops and Microservice are the new standards for deployment.
A business now operate in a complex model where the consumers identity and access is expanding across users (ex. Employees, Contractors, Partners. Members), devices (ex. Enterprise computers, enterprise devices, public computers, IoT devices, phones) and apps (ex. SaaS apps, Public cloud apps, partner apps, private cloud apps, on-prem apps).
This would mean that the identity and access management solutions should handle DevOps and Microservice are the new standards for deployment for IAM.
5. Disruption and innovation through SaaS, AI/ML, Blockchain, Chabot, Big Data, is the new normal.
With customer data playing the forefront of all innovation, there is a lot of focus on the technology trend like Blockchain to decentralize the consumer identity information that can help business to scale globally.
Use of AI/ML can power insights from a consumer’s history, preferences, context, and behaviors to deliver more targeted offers and better the outcomes that can increase sales and the customer experiences.
The automated tasks like customer on-boarding, post-sale services, and support can be managed by Chatbots which helps to increase the efficiency, scale, and satisfaction for consumers.
Product Management efficiencies to drive Digital Transformation
I am currently reading the book “Slow down to Speed up” by Liz Bywater and understand the importance of leading, succeeding and thriving in the fast pacing 24/7 world of Product Management. Sharing my thoughts to help Product Managers on how you can drive business to achieve complete digital transformation around product development and innovation.
I have been in the software industry as a product manager for the last 15+ years. It’s interesting to see how Product Management and Product development is continuously evolving. Now with Cloud computing and SaaS being the main business drivers for software efficiencies, companies need to pay attention to the details around the digital transformation efforts around strategy, decision making and execution to stay innovative. Understanding the current gaps in their product development process and addressing them at the earliest is critical.
I will cover some of the areas that a Product Manager or a Product Owner can make a difference.
Digital Transformation mindset to explore business problems
Everyone is talking about digital transformation on how it is important for every organization. But there is a specific structure that every company needs to follow if they want to be successful. There are a few variables that each company needs to put in place since Product strategy is a continuous process.
- Executives and senior level management need a new mindset that is flexible and open to exploring a business strategy that is a continuous journey. The strategy will have to be based on various different factors that are continuously monitored and fine-tuned.
- Product Managers and Product owners will need to do the following to have help defining a strategy and get buy-in from the executives on a regular basis.
- Gain knowledge about the macro and micro trends in the industry around their business. Understand the pros, and cons and how that would have an effect on the business needs.
- Maintain a continuous and ongoing dialogue and transparency with the customers to understand their pain points, their business needs and the changes that drive their success.
- Monitor the competitive landscape to understand the gaps and the innovation practices.
- Build partnerships that would add value to the business and can help address gaps.
- Design thinking to define and understand the market problems and brainstorming various ideas driven by outcomes on how the market problems could be addressed.
- Drive continuous experimentation on each idea to gather data on the business outcomes.
Decision-Making to build the right things
Decision-making is both an art and science. There are various frameworks that are available to help Product managers and Product owners in the decision-making process https://blog.usejournal.com/top-11-frameworks-every-product-manager-should-know-aad46dd37b62.
Irrespective of the framework that a company adopts, a data-driven decision-making process makes the decisions error proof and provides insights and learning to innovate. Remember data gathering is a continuous process just like strategy. Data helps you to make better decisions that are low risk but high business value.
Here are a few ideas on how to gather data
- Continuous data gathering through experimentation on ideas. Helps to identify the right market fit and defining business outcomes. Thereby helps to add value to your customers.
- Continuous data gathering through customer engagement with your product to enhance customer experience.
- Continuous data gathering from customer interactions and feedback captured as the voice of the customer.
- Continuous data gathering from sales around win/loss analysis.
- Continuous data gathering from customer success on product issues and improvements.
- Continuous data gathering from marketing around product promotions.
- Continuous data gathering from finance around product pricing
Execution to build and launch things right
Once the decision is made to build an idea into a product, the path to execution starts. The steps that are involved to trigger execution is to break down the idea into smaller and lean set of requirements that can be launched and continuously gather data and insights to improve the building process more efficiently. This is a collaborative effort that a Product Owner drives with engineering. Agile is the popular methodology that is quite common across all companies these days when it comes to how software is built.
This would mean that you take time to do the following steps
- Planning: As a product owner, break down the idea into a smaller subset of requirements and define the acceptance criteria that fit into an agile sprint and add that into to the sprint backlog.
- Prioritization: Leverage the data that you have continuously gathered earlier to prioritize the backlog on what to build next sprint and launch.

- Build: As a product owner, work with engineering to make sure the implementation addresses the requirements, meets the acceptance criteria around functionality, performance baselines and data is captured around specific KPIs.
- Launch: As a product owner, work with marketing, sales, and support to get the market positioning and the sales and support enablement right.
- Analyze Data: As a product owner, analyze the data to gain insights after every launch, fine-tune the KPIs to improve the qualitative data that you capture in each build. Based on insights that you have gathered from the data, go back to Step 2 to re-prioritize the backlog
Execution now is a continuous journey where you rinse and repeat to innovate!
Conclusion
Product Management is a continuous journey of the product you manage. Hence you need to “Slow down to Speed up” to stay current and relevant in the digital transformation age.
My Identity and Access Management (IAM) journey. Where is it heading…
Its been couple of years since I published any articles on my blog site.
I am in London this week and been busy with meetings and other activities around work all day. Also this week I will also be participating two Identity events where we get to see how our customers are adopting the products around Identity and Access Management.
Right now as I am enjoying some quiet time in my hotel room, which has an unusual setup because of the advanced controls, made me think how I have been spending my time at work and where identity and Access Management(IAM) heading. Is the latest trend in IAM solving specific business requirements and making our human lives better? I am thinking to myself where are we going with this trend? I am sure we all get these thoughts and we want to find answers. Thought I will start that journey today and see where that will take me.
I have been working as a Product Manager in the IAM space for the last 15+ years. Though the concepts around Identity and Access Management have stayed the same all these years, the evolution in technology has made us address the Identity and Access Management needs differently. Identity these days is not just limited to users alone. The devices and things (IoT) also have an Identity. We as humans want to track users, devices, and things through an Identity. We want to enrich, personalize our experiences and needs through Identity. We want to share these experiences with others by enforcing access control around this identity. As a result, we now refer to it as Consumer Identity and Access Management (CIAM).
Here is what my CIAM experience this week has been as I walked into the hotel. I was received by a computer terminal which asked me to enter my hotel confirmation number and my last name. It pulled up all my information which I had submitted when I had made my hotel reservation through the web couple of weeks ago. I was asked to confirm my information using my credit card. My identity was registered and linked to my credit card to it. Once the registration to the hotel was confirmed, I was asked to scan a hotel access card in a kiosk which assigned me (i.e my identity) a room number and enabled me access to that room. I take an elevator to the room, scan the card at the door and I am in. Not a single human interaction so far. In the room I see an iPad waiting for me to swipe. Once I swipe in, I can now switch on/off the lights, switch on/off my TV, close/open window blinds, switch on/off my AC and much more.

I was very excited to play with all these settings. I had not seen such a hotel room through all the travels I had done so far. I was also happy to see how the CIAM products that I was helping build was put into action as places like the hotel and room I was in. Soon I get the creepy feeling that the someone can watch me through the iPad camera as it is charging its battery. I immediately think of my privacy. I take steps to address my Privacy issues in my own room.
Two days have passed since I have been in this hotel and the room. I hate every bit of my experience. I miss my TV remote, the light switches, my privacy. This makes me question, all this technology, and the gadgets in the hotel room, who is it really helping. Am I a happy consumer today? Does CIAM address my needs as a human?
More to follow in my next post…..
Top 10 Points for Customer Success
More and more organizations these days focus on customer success when it comes to their go to market strategy to win, serve and retain customers. It is key that you build and deliver products that engage, retain and delight them, especially in the early stages of your product. It is well known that it is easier to keep a customer than to acquire a new one.
Here is what Gartner says:
“80% of your future business will come from 20% of your current customers”
As a product manager I am always conscious of incorporating features that are customer centric and growth centric. From the get go, it is important to have a growth hacking approach to the product development. This leads to a better customer acquisition and retention product strategy.
Here are the 10 important points for a good customer success story board:
1. Onboarding
Provide self-service customer on-boarding, free trials, product evaluation and training. Empower the customer to evaluate the product. Offer online easy to use tutorials and self training for rapid learning. Educate the customer about the value proposition to assist purchase decisio.
2. Proactive Customer Service
In a highly competitive, constantly changing market there is a strong need to engage and provide superior customer service to your customers even before they make any purchase decisions.
- Focus on addressing the end to end product experience (download, install, configure, deploy and use) and not just making the download available.
- Articulate the benefits that the products will offer by solving their business issue and providing a realistic expectation on the ROI instead of focusing on the price and the competitive differentiators alone.
- Invest in resources that will tailor and provide better education and support to the buyers so the end to end experience of the product from purchase to deployment to maintenance is delightful.
3. Voice of the Customer
Understanding what your customers think, experience, and want is critical for retention and growth. Engaging customers to get feedback and responding to them positively will build more confidence and trust with the customers. Make the product sticky.
4. Analytics
From the inception, ensure that your product captures usage metrics that help educate you about different aspects of your product and its usage.
- Product usage metrics: Track signups, logins, and application usage metrics. Capture the app version, the license type, content type, location data, environment data, events, error conditions, peak times of usage, etc.
- Business metrics: is the customers getting the end-result they expected by tracking their performance metrics like response time, application availability, authentication time, users per day and more
- Service utilization metrics: gathering data to see if the customer is fully utilizing the product features, how many product defects gets raised and against which feature.
- Customer rating metrics: Track customer happiness, their experience and their feedback. Gather metrics around sales bookings, churn, ROI and adoption metrics.
- Support and operations metrics: are there any outstanding support, SLA or invoicing issues, unplanned outages. Track the mean time to resolve a support incident, incident initial response time, affected users on a single incident.
5. Customer Experience Mapping
There are several approaches to experience mapping. Understand how customers flow through the organization and the challenges that customers encounter, opportunities lost versus gained, the customer value and cost, their adoption journey, and ROI are all important data points that can help in generating more leads at the same time facilitate to retain existing customers.
6. Customer Segmentation
Categorizing customers into market or service groups and providing services tailored to these segments for winning and retaining the right customers.
7. Customer Engagement and Retention based Marketing
Establish proactive customer outreach programs and tools for effective Communications and Openness thereby to foster better customer relationship and creating customer value and profit margins while preserving existing revenues.
8. Customer Loyalty Rewards
Provide Customers insights to review where their money is spent and consolidate their purchasing under loyalty programs featuring rewards that they actually want. For maximum appeal, offer customer-relevant reward options and a quick, easy redemption process.
9. Customer Win-Back Program
If customers did leave, reach out to understand what happened, tell them about the changes you’ve made to resolve the issues that led to their departure; share product roadmaps and future vision; entice customers to come back with a loyalty offer they’ll value—and then keep them with excellence.
10. Employee Customer Engagement
Last but certainly not least, happy employees are a crucial prerequisite for happy customers: the relationship between employee engagement and customer engagement is undeniable. It is vital to ensure that employees are educated, encouraged, and empowered to promote and enact customer retention strategy at all times.
Security and Privacy in the Cloud
Hortonworks announced their plan to acquire XA Secure and open source it. XA Secure claims it is a comprehensive approach to Hadoop security. This made me think of the the various aspects of security in the cloud.
Security in the cloud spans across multiple layers that involve people, compute, network and storage. Security in the cloud requires an integrated strategy of process and tools, to allow end users be able to complete their work in an environment that enforces compliance without getting in their way.
Here is how I think of the top 5 areas of focus for security in the cloud.
Focus Area 1: APPLICATION SECURITY
Application security mainly deals with protecting the application resources. This includes a multi-pronged approach to cover the following:
- Enforcing strong authentication and authorization
- Date encryption on the wire: End-to-end encryption using SSL for all connections, both browser and APIs
- Data encryption for data at rest
- Data encryption for data in memory
- Application white listing
- Role based access to application resources
- Session tracking
- Controls for privileged or elevated access
- Enforce context awareness and notifications
Focus Area 2: DATA SECURITY
According to Forrester’s TechRadar report () on Data security, security is the second largest portion of the IT budget. In 2014, the investment is expected to rise by 45%. Data security is no more an IT issue. It is an important business driver since data is now closely tied to the the financial cost of companies and the business damage that it can cause as a result of data breaches.
Data masking and Data Loss Prevention(DLP) offerings are best suited for addressing data security. To enforce security on the data you would want to know:
- Where the data exists (both structured and unstructured) to secure it
- Continuously monitoring access to the data
- Protecting both production and non-production data
- Regular audits for maintaining compliance
Focus Area 3: NETWORK AND STORAGE
Explosive growth in data and digital assets in the cloud , drives the need for high performance reliable network and storage. This calls for sensitive information flowing through the network and storage to be encrypted both in-motion and at rest.
With customers requiring the need to continue to productively use their prior investments on software, the hybrid cloud is pushing needs for cloud security to operate in a hybrid model. In such hybrid environments there is need to support secure links and encryption across on-premise networks and storage units.
Some of the important features to pay attention around Network and Storage Security are
- Authentication
- Confidentiality and Data level protection
- Certifications for compliance with legislative and regulatory mandates
- Privileged user access and separation of duties
- Centralized key management
- Realtime monitoring of traffic across network
Focus Area 4: DATA PRIVACY
In this digital age especially in the cloud where we end up capturing personal identifiable information or other sensitive information is collected and stored, privacy concerns are highly prominent. The challenge of data privacy is to share data while protecting personally identifiable information. Data privacy has become of a very high priority in certain markets like Healthcare, Criminal Justice, Financial, Life Sciences and more. These days the laws for the protection of privacy have been adopted worldwide , but their definitions and objectives vary from one country to another.
It is important that the cloud vendors make sure that their cloud offerings gets certified under EU, US and other Safe Harbor Programs.
Focus Area 5: DATA CENTERS
Primarily due to cost effectiveness, customers are adopting cloud and hybrid services as their business model in various stages of their business cycle. This is driving data centers to adopt virtualization technologies to rapidly expanding their data center infrastructures reliably and effectively into the cloud.
Some of the common challenges around security in the data center are:
1. Multi-Tenancy
The resources belonging to multiple customers reside on the same physical platforms. Proper security measures must be adopted such that customer data cannot be breached or spilled over, even if the multiple customers are leveraging the same resources and platform in the virtual environment.
2. Compliance and Privacy Restrictions
Even though the infrastructure and resources of the data centers are managed by the cloud vendor, they should be prevented from monitoring and auditing any components or data. This includes preventing them from inspecting the network through which customer data will be passing because of compliance and privacy restrictions. The cloud vendors should think through these privacy and compliance challenges so you can clearly isolate these tasks and provide ownership to the customers to manage, monitor and audit on their own. Providers may need to comply with the ISO17799 based policies and procedures and be regularly reviewed as part of the SAS70 Type II audit process.
In summary, security enforcement in data centers involves
- Data Protection at the application, network and storage through access control and encryption
- Protecting systems through hardening, intrusion detection and prevention
- Monitoring and Auditing through certifications to meet compliance regulations, change control around upgrades and patches, proper role and privileged access management.
What is Application Platform as a Service (aPaaS)?.
For those who have worked and dealt with Middleware software in the past which provided services to software applications beyond the operating system, the term aPaaS should not be a hard to understand concept.
An aPaaS as per Gartner’s definition is as a PaaS (app middleware + cloud characteristics) designed to enable runtime deployment, management and maintenance of cloud business application services. It supports requirements for business application and application projects and is delivered as-a-service..
Middleware has been the commonly used term for on premise software that enabled communication and management of data in distributed applications. Middleware gained popularity in the 1980s as a solution to the problem of how to link newer applications to older legacy systems. The vendors who built and offered Middleware had a strategy of building a complete and integrated suite of middleware to allow our customers to develop, deploy, and manage applications. For customers the middleware software not only offered off the self features around building and hosting application but also the ease around the integration burdens which facilitated the ability to link applications together and provide more consistent access to information.
You can now relate the same middleware software capabilities to an aPaaS in the cloud that offers the following services
- Platform services
- Identity Services
- Integration services
- Business Process Management Services
- Development Tools
- Deployment Tools
- Management Tools
Why would anyone need an aPaaS?
These days cloud services is picking up lot of traction when it comes to SaaS, PaaS or IaaS. Refer to my earlier blog post ” Why Software-as-a-Service (SaaS) model matters for both customers as well as vendors” as to the reasons why oth customers and vendors are investing in the rapidly evolving application platform.
Gartner recently published their first Magic Quadrant (MQ) for aPaaS with their focuses on public cloud enterprise aPaaS offerings. – See more at: https://www.gartner.com/doc/2645317?pcp=itg. It’s interesting to see how quickly the aPaaS market has evolved in a period of less than 9 months, now that Gartner now has a MQ for this space. Quite a few Platform as a Service (PaaS) vendors whose primary focus in 2013 was providing Platform Services are now posiioing and evolving their services to address the aPaaS space. This is a clear indication that PaaS market has matured and the revenue opportunities are shrinking. The PaaS vendors clearly see that the growth opportunity is to move into the application space and they need to innovate quickly to become market leaders.
An aPaaS infrastructure is a self contained environment that will offer the following
1. Build applications
The application platform provides you with all the tools you need to iterate quickly, and adopt the right technologies for your project
2. Deploy apps in minutes, with tools you love.
Reduces development and deployment time. They offer a way to rollout new application features into production has never been easier. Set up staging and test environments that match production so you can deliver functionality without fear, and continuously make improvements.
3. Scale the application to millions of users.
Tools and features that will help to scale your application at the same time ability to upgrade your database software in a few simple steps.The growth could happen over a year or overnight, but aPaaS will facilitate you to grow on demand to capture opportunity.
4. Integrate with various other applications
Provides additional software services like operating system, database, security and vulnerability management, API and integration infrastructure and more
Stay tuned, in my next log topic that I would like to explore is “What’s next after aPaaS for both vendors and customers?.”
Why Software-as-a-Service (SaaS) model matters for both customers as well as vendors
When times are hard, winning a business or selling smart is important for both customers and vendors who are competing head-to-head which can be cut throat especially when markets are flat or growing slowly.
These days the idea of IT installing and maintaining software onPremise at customer sites is completely winding down. Customers are looking to transition more to make their IT as a service. Meanwhile, software vendors are offering increasing amount of software via direct download or as a cloud hosted service known as Software as a Service (SaaS). The SaaS model is growing popular for personal, business and mobile applications and the market is only expected to get bigger in the coming years. This is why the Software-as-a-Service (SaaS) matters as a very scalable and an economical model for both a software vendor as well as for the customer, who are looking for a easy and a cost effective way to address their immediate software needs.
Take a look at how a SaaS model can address the functional areas for both a vendor and a customer:
|
Functional Areas |
SaaS Vendor |
SaaS Customer |
| Market Problems | The vendor understands the market problems and has a close working relationship with its existing customers and knows what the future potential customers wants. This helps vendors to bring in rapid innovations to market thereby mapping a solid innovation strategy to creating a new market space for their products and solutions | Customers look for a solution with minimal initial investment but with a greater return and value that is easy to onboard, solves their problem and can be accessed from anywhere. |
| Technology | Vendors provides, maintains and manages the hardware and software components of their product and/or solution. The vendor has more control over which hardware/software configurations to support.Vendors need to address scalability and multi tenancy requirements at the software level to allow multiple customers to share hardware and software services.On a long term this becomes a very cost-effective model to support infinite scalability. | Customers don’t care much about the back-end system as long as it works when they want it, fast, securely, and reliably.Each customer will have specific requirements around performance, scalability, and security requirements that vendors to meet so their personal data and information is secure and do not get breached at any point in time. |
| Product/Solution Support | Quality issues might impact everyone in customer base at same time. Hence greater attention will have to be taken by the vendor to provide and maintain controlled quality of serviceNew releases of the product or solution, application of patches and service packs can be released more timely and quickly to the customers, but requires more rigorous quality control. | Customer have a greater need for the Service level agreements(SLAs) to be met by the Vendor specifically around production requirements for system performance and capacity for multiple tenants will have to be addressed.Customers often have higher usability expectations as well.Customers experience a painless software upgrades. |
| Initial & Operational Cost | The initial cost to set up the service (hardware and services) are incurred by the vendor. Also, all the ongoing operational costs of running the service are incurred by the vendor, not the customer. | Customers have overall reduced operations costs and Zero infrastructure cost. |
| Product Performance | Customers will have to monitor and analyze how well the product is performing including product profitability, actual to planned revenue, customer satisfaction, and market share.Areas to focus to monitor performance are:
|
Customers as buyers want proof of uptime and performance level.Customers want predictability and efficiency with more automation of services. |
| Revenue & Pricing | Revenue is recurring for the vendor but is recognized as the service is rendered, not in a lump sum up front like on-premise product/solution. | Pricing for the customer is typically subscription-based with a “pay as you go” model based on the value received for the vendor’s services. This provides better cash flow for the customer.Up-front implementation services cost might be charged to the customer. |
| Sales Process | Sales cycles are typically shorter. | Customers will have greater flexibility to shift to competitive product if they do not see value with an existing vendor offering and services. |
“Lean In” is the beginning. How about we also “Lean On” and “Lean Out” for one another.
Ever since Sheryl Sandberg’s book ‘Lean In’ came out, I see that women are excited with the message. Most of my friends bought the book and have read it already. They also have joined forces as members of the LeanIn.org and want to be active participants of this movement. I still have not read the book yet. But, I have been tuning in to all the TV and Radio interviews that Sheryl Sandberg has been on so far. It has been interesting to watch how the media has created a buzz around this book which is good for Sandberg’s cause. Sadly, I also see more push back and citicism for Sandberg’s Lean In is coming from other women who think that Sandberg is preaching a wrong message. This made me ask myself – How about we women also ‘Lean on’ and ‘Lean out’ to support one another.
‘Lean In’ is just one side of the problem
Speaking from experience as a woman, a mother and a professional, I am glad Sheryl Sandberg is using her position and voice to generate awareness around the controversial topic at workplace differences between men and women. She is encouraging women to Lean In, be more ambitious and to demand and expect more for their contributions at the work place, as men do it.
As we all know Sheryl Sandberg is a Harvard-educated, who is now the chief operating officer of Facebook who previously was the Vice President at Google. She had longtime mentors like Larry Summers and other influential people along the way that helped her to be where she is now in her career. Though she was a privileged along the way I appreciate that she took the courage and passion to make the fight for women’s rights at workplace her cause now.
But, I feel that Sheryl Sandberg has only scratched the tip of the iceberg and there is much more serious issues that we women need to address among ourselves even before we deal with workplace inequalities.
‘Lean on’ and ‘Lean out’ to others
If we need to see real change in the betterment of women in all places and situations we need to learn to “Lean on” and “Lean out” for this cause. Right now women can be the biggest critics and road block for other women. We can be mean and intimidating to one another. But we women need to support one another, build a strong support network so we can let others who need our support to ‘Lean On’ us, whether it is at work or other places. Women in power can use their position to help, influence and bring change for other women who need that support by ‘Leaning Out’.
Only then we all can say we have the power and win this uphill battle for good.
Evolution of Entrepreneurship
I recently came across a presentation from Bret Victor which was both educational and enlightening for me. Thought I will share this with you all and add in my 2 cents to see if all this make sense to the fabric of reality.
Current Entrepreneur Trend
I am seeing a shift in the business world where Social entrepreneurship is picking up a lot of steam among both the old and the younger generations. Social entrepreneurship by definition means identifying or recognizing a social problem and using entrepreneurial principles to organize, create, and manage a social venture to achieve a desired social change. You can build a social entrepreneurship as a non-profit venture or as a for-profit venture but with a strong intention to create a social change. The dynamics and sustainability of both these models do need cash flows and hence the business rules and functions remain the same.
One well-known social entrepreneur that comes to mind is Muhammad Yunus, founder of Grameen Bank a micro finance organization and community development bank which got started in Bangladesh to address a social problem that his country was facing and desperately needed attention. He got the idea of helping the people with the concept of micro loans which helped a lot of people in Bangladesh to stay out of poverty. Muhammad Yunus was awarded a Nobel Peace Prize in 2006 for his work for his country. The concept of microfinance is now every popular in all developing countries and many local banks in these counties are now exploring it as a banking option as part of their business model.
Check out the top 5 trends Entrepreneurs will see in 2013: http://www.businessnewsdaily.com/3688-entrepreneur-trends-new-year.html
Social Entrepreneurship will succeed since we are all connected…
As per the theory of Quantum mechanics, which Albert Einstein in 1935 called it Quantum entanglement, two particles in different locations, even if they are on other sides of the universe, influences each other and stays in communication with each other since they are connected. Albert Einstein named it the “spooky action at a distance”.
Recently, I saw in the news that Christoph Simon and Boris Braverman from the Massachusetts Institute of Technology published a paper which proposes a way in which the effect of quantum entanglement, this spooky action can be shown experimentally.
Since we all humans are spiritual biological beings who are embedded in matter and part of this universe, whose brain produces mind and consciousness, we are all connected. On the basis of Quantum entanglement we can say that every action from every individual on this planet counts to make this world a better place and generate an unified field.
On this basis it makes more sense now that business and entrepreneurs are leaning towards Social entrepreneurship.
Time for us all to plant a seed in your subconscious mind and see where that journey will take us.
Real-time Intelligence Driven Security, is it the next trend or a hype?
Recently there has been a lot of attention in the media around the incidents where Chinese Government and agencies have attacked American infrastructure and organizations to steal information. We have also seen Cyber Criminals have hacked into companies like Apple and Facebook. The scale and range of such possible attacks has huge implications for National Security, which has led to the Cybersecurity 3.0 initiatives by the US Government. If this continues, they are seeing great danger to critical public infrastructure like electric grids, water supply, defense and financial systems. A posts on The White House Blog by Schmidt outlines the new cyber security strategy. This is now becoming a global issue and countries like United States are spear heading this initiative with a great deal of urgency. The article “World War 3.0” in the Vanity Fair magazine by Michael Joseph Gross describes it as “ a new global conflict that could split the virtual world as we know it.”. With the evolution of the information technology the threat landscape has evolved. As we Americans has become more reliant on modern technology, we have become more vulnerable to cyber attacks. Take a look at the data around the 2012 Cyber Attacks Statistics.
This is not a hype, it is real
I was at the RSA conference yesterday and was amazed at the vendor solutions that are already gearing up to address this security gap. Real-time security intelligent systems with the use of Big Data controls is where the solutions landscape is heading. Though lot of innovation in this area is yet to happen, it’s still in the early stages. This is a good time that all security vendors start thinking about this space more seriously. Vendors like Juniper and RSA are becoming the industry leaders in this area and are rapidly innovating and sharing information around CyberSecurity threats to the community.
Real-Time Intelligence Driven Security Solution Attributes
The days are over where we knew what are the types and the factors that lead to security threats around our information infrastructure. We are moving into a territory of known unknowns and unknown knowns. Hence the security realm around infrastructure, systems, network, users and data has to be enforced at real-time through Big Data control and advanced machine learning algorithms. This would require that we gather the right and valuable data about our infrastructure, systems, network, users, gather intelligence knowledge base in a data ware house and constantly analyze the anomalies and threat levels and take appropriate actions. Below is a picture that highlights the attributes that are critical for a “Real-Time Intelligence Driven Security” Solution
The need for real-time security intelligence is becoming a necessity and coming up with new innovative solution is important. The security model of the past has evolved and changed. Security vendors have to think of new strategies of using Big Data and machine learning and support automated tools within their security solution to build intelligent predictive models to address new security threats.
Hope you all see the same trend as me!
“SoccerLogger” the next generation tool for all young soccer players
Having been a soccer mom for the last 10 years through which I have watched and cheered my daughter Samiksha play soccer from the side lines, my husband Deepak and I always wished we had a tool to capture and track her progress over the years she has grown and transformed into a competitive player. Now that Samiksha is fourteen and a freshman in high school who has a big desire to play college soccer, we felt it would be nice to build a mobile app where we can track her progress for the next four years and then present that as part of her college resume. Therefore, the idea of ‘SoccerLogger’ got a kick.![]()
Now, I am getting ready to launch this app soon on the iTunes App Store. We are starting first with an app for the iPhone, but have plans for a tablet version as well. I wanted to share this news so other young soccer players, their parents and coaches can use this app as a real-time game logger and generate comprehensive reports to analyze individual and team performance, during the game and after. SoccerLogger revolutionizes how a soccer player and team data can be captured, tracked and analyzed using various reports to help improve the game for an individual player and the team. It also helps bring the collective forces of player, parent and coach together to create a fact based assessment solely aimed at understanding and improving overall team and individual performance.
For more on the app and its benefits check out SoccerLogger at http://www.soccerlogger.com and also subscribe to our email list so we can notify you as soon as it is available in the app store.
If you have any questions or suggestions regarding the app feel free to send me an email at ‘soccerlogger@gmail.com‘
You and I, can now keep track of all our games!!.![]()
© 2013. Alur Labs LLC. All Rights Reserved.
Leadership style that is important to succeed in the 21st century
I recently came across an article which is to be published in the February issue of Fortune magazine about how “eBay is back“. Coincidently, I was on site at eBay for a business meeting last week and surprisingly I could see and feel that the organization energy at eBay was very high. I sensed a very positive attitude and optimism from the employees who worked at eBay. Having read the article earlier to my visit, it clearly proved to me that eBay is really back and John Donahoe as the CEO was definitely leading the company with a different leadership style which is also allowing the leadership team downstream to execute the strategy and vision that he was practicing and preaching from the top.
This is a clear example how great leaders can create both economic and social value without sacrificing one objective for another. In fact the book “How Great Leaders Create Economic and Social Value” talks about CEO’s like John Donahoe who highlights that leadership is not just a skill about a company meeting its quarterly financial goals but also at the same time helping people achieve their personal goals by creating a healthy company culture that helps to promote social values with in the company and the communities that their employees live in.
For the last 17 years that I have lived in the heart of Silicon valley, I have worked for several large and small software companies and start-ups. Having worked at various organizations has allowed me to experience and observe how the leadership style has shifted recently where more and more focus is given by the CEO’s and the leadership team only to the financial performance of the company and no emphasis on the company culture at all. Recent research shows that this style of leadership will turn out to be more damaging to the company in the long run if Leaders don’t make a conscious shift soon enough to save these companies from disaster. In my earlier blog I tried to address the leadership topic in a subtle way through the topic “Why Good Leadership matters...”.
Now that I see examples like eBay making a difference, it’s time more companies pay attention to this style of leadership that can help them to be successful. The next generation leadership style that is important to succeed for the 21st century leaders will have to include strategies that will meet the needs of not just the customers and shareholders but also with the employees and communities.
- Strategy: Need to create a strategy that will connect the head and heart with shared values with all the employees. Leaders will have to identify the capabilities of a company and its employees, which will together help them to build a shared commitment to excel.
- Trust: Leaders need to earn the right to lead by being open with their vision, ideas and strategy and thereby gain trust and credibility.
- Diversity: Since most companies compete in a global market, leaders have a greater responsibility to promote diversity with a shared purpose that can help everyone to contribute to the company vision, at the same time add in their values and achieve their aspirations.
- Performance: Good leadership has to start from the top with the CEO taking the lead and being a role model. It should flow down the leadership chain so it gets well communicated to all so everyone is accountable for the overall success. Through fairness, everyone should be evaluated based on what and how they execute and equally recognized for their efforts and inputs that result in the growth of the company.
What I Wish I Knew When I was 20
My weekend on Saturday started a bit unusual. Because of the cold weather outside, I did not have great plans to do anything outdoors with my family during the day other than going out for dinner that night. Lack of plans made me think at my breakfast table how I was going to spend my time that day. Just then I heard the door bell ring. When I checked at the door I saw a packaged shipped to me from Amazon. I realized that the book I had placed an order on Amazon a day before was at my door step ( I am amazed at the quality of customer service that amazon offers to its customers. I am a prime customer and I do most of my shopping these days online through amazon because of the connivence and the choices around products that amazon provides!!. Amazon business model is a topic that can be covered in a blog another day! ). I opened the package and there was this book “What I Wish I Knew When I was 20“. I was happy that I could spend the day reading some new material.
“What I Wish I Knew When I was 20” is a book written by Tina Seelig, a neuroscientist from Stanford School of Medicine. She is the executive director of the Stanford Technology Ventures program and also teaches courses on entrepreneurship and innovation at the Stanford university. She wrote this book as the 20th birthday gift to her son based on her experiences and her interactions she had with her students and with various entrepreneurs around the world. As Tina Seelig puts it this book is ” A Crash course on making your place in the world”. The information in this book is amazing and has brought a new perspective to the way I will look at new ideas or problems that I come across in my day today life. This book is filled with fascinating examples from classroom to the boardroom, of individuals defying expectations, defying assumptions and achieving amazing success.
I wish I had read this book 20 yrs ago!!. I would have been a different person all together.
Though its not too late for me, I have decided to pass on the baton. I have handed over the book to my 14 yr old daughter Samiksha to read. I am quite sure this book will change the course of her life and the outcome, who is already exploring the path to entrepreneurship through her non-profit that she recently started called Soccer4Kids.
I hope I am passing on a small gift of inspiration as a parent to my daughter!!.
Good Leadership matters…
As President Barack Obama sets off on his second-term journey with the big inaugural yesterday, Jan 21 2013, which also coincided with Martin Luther King Jr. day, watching MLK’s ” I Have a Dream” speech on this day provided a new meaning on how far this country has come since independence .
This also, made me wonder what Leadership is all about and the leaders we see in our lives today. What can we learn from these proven leaders!!.
What makes one a good Leader?
A Leader is the one who provides “hope” and “change” through his leadership.
Leadership as we know is a learned behavior and rarely is one born to lead.
Authentic leaders do not crave power. They have a set of morals and values, exemplary character, confidence, and trustworthiness.
A leader needs to be trusted and be known to live their life with honesty and integrity.
A good leader “walks the talk” and in doing so earns the right to have responsibility for others.
In order to lead and set direction, a leader should inspire confidence in others and draw the trust and best efforts of the team to complete the task well.
A leader should work to inspire the team and its members to achieve the objectives so the whole team is successful in the long run.
Hence we need to understand that “Leaders are not born they are made“.
Macho Leadership is Overrated …
A current trend in the leadership philosophy that I see today is where leaders try to lead the way as bullies. These leaders lack goodwill, empathy nor sympathy. They are greedy for power and they have a personal agenda to be the leaders. It is their way or the highway!!.
It’s important to identify such macho leaders early on who try to operate through bullying and brute force to achieve their personal glory. This type of leadership can cause more damage than good to any organization, team or a company.
Hence…
Good Leadership matters because no one and nothing comes to success without it.
I came across an article of Deepak Chopra “The Conscious Lifestyle: The Soul of Leadership” on the spiritual side of leadership.
In recent years the business world has become more competitive and more volatile. Technological changes are faster, there is greater international competition and the market is global.
So a good Leader is one if he can provide hope to the folks around him to the changes, through good leadership by providing a solid vision and a strategy that leads the way to facilitate better and greater innovations.
Hope you share similar thoughts on this topic!!.
Enterprise Mobility Requirements
For couple of years now, mobile innovation has primarily focused all its resources and time on the consumer market. In 2013 there are tremendous opportunities and market demand for innovative solutions and products that address the needs of a mobile strategy for enterprises.
In 2013, analysts have forecasted 1.2 billion smartphones and tablets will be sold worldwide, up from 821 million in 2012. With more and more enterprise encouraging the idea of BYOD for their users, having a mobile strategy is not an option anymore. It is a necessity for all enterprises.
What is it to have a mobile strategy?
Most enterprises now have aligned a strategy to address their mobile user needs to meet their business goals through evolving technologies. Hence creating a compelling mobile experience for their users is now becoming a competitive necessity.
Here is the standard requirements that companies have adopted around a mobile strategy so far:
1. Mobile Apps to provide easy and secure access:
Most companies have a mobile strategy starts with mobile app to accommodate the user driven IT world and provide easy access to content like the ability to connect to files and documents from smartphones and tablets as efficiently as they can from laptops and desktops.
The mobile apps could be a native apps to support and meet the needs of specific mobile devices, which are made downloadable through the app stores or they it could rich HTML5 based web apps. Refer to my earlier post for more on the benefits of HTML5 : Future of Web Applications as I see it.
Also, check out this article on HTML5 vs native app
2. Maintain control and security while providing a simple End-User experience
This would require the need to support a mobile device and access management solution to make sure they can enforce and control these mobile devices on who, how, where and what resources the users can access. Refer to my earlier post for more on Mobile Security – BYOD Trends and Needs
3. Support a Social-Business context through evolving technologies
Mobile users are using the mobile devices for their personal and their professional lives— whether they’re working remotely on mobile devices or at the home office. This means that tools around collaboration, file sharing, workflow systems, WLAN capacity, network bandwidth and other network resources should allow users to fully engage both on business and social terms at the same time. This would require enterprises to support a flexible model to support their evolving business needs through technologies to provide better, faster and secure transactions without compromising the privacy of these mobile users.
So far go good…It will be interesting to watch how this strategy will evolve in the future?.
What it means to adopt a Cloud strategy?.
Cloud computing in the areas of Platform as a Service (PaaS), Infrastructure as a Service (IaaS) and Software as a service (SaaS) were the words of 2012. Vendors like SAP, IBM,Microsoft, RedHat, Oracle, VMWare and Citrix all entered this space early on and now we see that these solutions are evolving into second generation products in 2013 (Read more at http://venturebeat.com/2013/01/14/the-second-generation-of-cloud-startups-is-here/#ST0T4K7MFbYxhGlA.99)
Now that cloud computing is making a huge impact in other market areas like big data, social and mobility, to help drive and support new business scenarios, we will see more and more hardware and software vendors embarking this journey around their products and solutions. ( See: Gartner: 10 critical IT trends for the next five years)

Source: Business value of Cloud Computing
Benefits of the cloud offerings is often associated with reducing cost and increasing agility. While this is true, the more strategic role that cloud solutions can play for the customers and the vendors are in achieving operational excellence, product leadership, customer intimacy, and open innovation. Cloud computing is part of a long and powerful trend towards virtualization. Virtualization acts as a stepping stone for cloud which mainly helps to bring down the operation cost down, at the same time facilitate speed and agility in deployment and maintenance in the long run.
Given the above factors, the following are typical areas to consider when thinking of ROI when adopting a cloud strategy:
- Hardware costs – how much will this save in terms of the servers and storage devices.
- Maintenance for the hardware – will there be any savings ?
- Software licenses cost – usually the license post for a cloud solution is priced less than on premise. How much cost can be reduced per seat?
- Maintenance for the software – include both the vendor support and your internal support costs
- Facilities costs – can you lower the power, HVAC, building costs etc.?
- Productivity/efficiency costs– what is the learning curve, are the people who will use the new system more productive? what is the cost involved for training?
- Agility around new opportunities – are you able to respond faster, but cheaper, to opportunities that otherwise would have taken more development time and money?
Role of Innovation in a Software Product Lifecycle
Over the weekend the CBS 60 minutes program covered the approach of Design Thinking (http://www.cbsnews.com/video/watch/?id=50138327n) where company like IDEO incorporates human behavior into product design, an innovative approach that is now being taught at Stanford university these days to get the younger generation to think differently.
This made me wonder why innovation is not a topic that is strictly enforced by all product development companies. When it comes to the product life-cycle, innovation is a word that is loosely thrown around. Management tells their employees that they promote innovation but there is no goals or requirements that is tracked around innovation specifically.
Importance of Innovation
It’s a well know fact that ‘creativity’ is about coming up with ideas while ‘innovation’ is about bringing ideas to life. If product companies have to innovate they need to take risk with their ideas which requires time, investment and resources. Let’s take the example of Proctor & Gamble (P&G), an american multinational market leader in consumer goods. This isn’t accidental. It’s the result of a strategic effort by P&G over the past decade to systematize innovation and growth. Their product portfolio at any point of time is a result of dedicated focus on innovation. They will lose their #1 place in the consumer goods market if they do not innovate. Apple is another well know example who had dominance with its product portfolio because of its innovative culture that Steve Jobs always championed for. If Apple does not maintain its track record with innovation, the company will very soon lose its market share against other competitive vendors.
Role of Innovation in Software companies
80-90% of the big software companies these days take small and safe bets to innovate with their products. They mostly listen to their customers and their feedback and meet their needs by adding features and functionality to the existing products. They then tag that as their strategy for innovation. On the other hand, all the big innovations of new ideas are brought to life in software startups. Startups are backed by venture capitalist who fund them to convert the bigger and smarter ideas to transform them into profitable, commercial revenue generating product and services.
Overtime big software companies lose their product edge over competitors and to stay current in the market they acquire these software startup companies and integrate them into the existing product portfolio. Over the process of integration the products produced by larger companies lose their real value, the product becomes bulky and complex. Hence this strategy is not always effective. This need to change!.
Innovation as a Strategy
There are various well-known innovation frameworks and best practices that is already available, which enforces the importance of adopting the concepts of innovation at every step of the product life cycle. This should be the new way of thinking irrespective of whether the software products are developed in large or small companies.
In order to promote the cycle of innovation as the heart of a software product life-cycle, companies should enforce a strategy and promote a culture with specific goals that can be tracked and monitored around the product.
Here are some of the steps that can turn innovation into success for any product.
- Encourage free flow of ideas and reward them.
- Allow to share knowledge around the ideas across the company.
- Allow to interact with inside as well as outside the company resources who have the knowledge around these ideas.
- Educate and allow to seek knowledge around market and the technology trends.
2. Market research:
- Is there a need or desire for the product?
-
Is the size of the potential market adequate?
-
Will the customer buy the product?
- Will the product satisfy the market needs?
3. Competitive and Risk analysis:
- Will the product have a competitive advantage?
- Is the advantage profitable ?
- Do we have all the internal resources to build and sustain and make the difference?
- Can we get a buy-in from the top management and support it?
4. Revenue and growth:
- Are forecasted returns greater than costs?
- Are the risks acceptable?
- Does the product fit your overall growth strategy?
- Can it help us tap into additional markets?
- Can it help us to be market leaders and establish to strengthen the brand?
Security Intelligence – Role of Big Data in Fraud Prevention and Management
Fraud is a serious problem and requires new way of thinking to address this problem. Irrespective of the market type whether its financial services, online retail, point of sale or healthcare, fraud prevention and management is the biggest pain point for all customers these days.
In the security market to address Fraud, the real-time security intelligence along with the power of Big Data is spearheading the growth of solution vendors to innovate and differentiate their solutions from old-school security vendors.
Fraud causes companies to lose money in many ways. These days there is a greater need for a real-time solution to help to organizations automatically detect the anomalies with their users or system behaviours early on, which then can help to notify and take appropriate action This will prevent fraud and the loss of revenue.
Let’s take the example of healthcare to list out some of the well know challenges around fraud.
- Organized groups defrauding insurance companies through elaborate schemes against government-sponsored programs or private health insurers
- Patient medical IDs are stolen or duplicated for financial benefits
- User impersonation for prescription drug benefits and many more…
Meanwhile, hospitals and HMO pay a heavy price through fines and litigations if they don’t comply to all the Healthcare laws that are enforced by the government. So, they have to ensure appropriate checks and measures to prevent violations by their users/patients/doctors when they use the applications and systems.
Old school way of Fraud management:
Most companies have invested and adopted multi-factor authentication methods (ex: password, smart cards, One-Time Password (OTP), biometrics etc) as an only mechanism to identify and protect their users who are using their applications and systems but also a way to manage fraud. The picture here suggests a mechanism that they enforce currently to do a fraud evaluation.
These companies have quickly understood that multi-factor authentication alone cannot scale and address fraud issues since the bad guys have figured out a way to break through these multi-factor authentication mechanisms.
This is why there is a need for real-time intelligence security solution!.
Real-time Security Intelligence through Big Data
The challenges that makes realtime intelligence gathering the right approach to address fraud are:
- No single layer or a multi factor authentication is enough to keep determined fraudsters out of enterprise systems. Multiple layers must be employed to defend against today’s attacks and those that are yet to appear.
- No authentication measure on its own, especially when communicating through a browser, is sufficient to counter today’s threats. Additional fraud prevention layers must be utilized.
- Malware is the biggest immediate threat, malware-based attacks are spreading to multiple sectors and enterprises.
Let’s take the example of an online retail scenario where users have to shop for good through the browser supported on the PC, smart phone or the tablet.
Like the picture shows, a typical user will make multiple clicks and will interact with multiple applications in the background through a browser before he gets to the shopping cart. This would mean there is a way for us to gather a lot more data and information about the user and analyse his behavior realtime
Here are come of the steps that will help us build real-time intelligence around the user behavior:
1. End point Data : involves capturing context of users at the endpoint which is his device. For example is he using the browser on a PC, desktop, tablet, smart phone. Capture the user’s IP, geo-location, authentication credentials and many more.
2. Session Data: gather, monitor and analyze user’s session (ex. http post parameters and other session attributes) and his navigation behavior on the browser. Compare this with his earlier navigation patterns to identify abnormal patterns based on his transitional history.
3. User Data: gather to monitor and analyzes user’s behavior to identify any anomalous behaviors during the transaction .
4. Context Analysis: Analyse the relationships among internal and/or external entities, systems and their attributes (for example, users, accounts, account attributes, machines and machine attributes etc.). Analyze the application logs, system logs, database logs and build predictive models for the user behaviour around applications and the systems involved.
The intelligence gathering and analysis in the above steps involves gathering the right data and also analyzing the data with an effective algorithm. This is where the Big Data plays a role to help build an effective and accurate model based on the user’s interaction with the application and system, that will help detect anomalies and prevent and manage fraud efficiently.
The secret to the success of such a Real-time Security Intelligence solution boils down to the quality of data collection and the advanced algorithms that addresses the 3 Vs of Big Data not only to build accurate predictive models but also support self learning for the solution to get smarter over time.
Big Data: Why Enterprises need to start paying attention to their Data sooner?
The awareness around Big Data is on the rise and is exciting!. As we all know in the technology space the word Big Data revolves around the 3 V’s, the Volume, Velocity and Variety of the data that is typically seen in all enterprises these days.
The blog on visualize the 3V concept is a good resource that provides a view into Big Data if you are not so familiar with have this question: “What is Big Data?.”
It’s 2013, the time is so right for all enterprises to pay more attention to their Big Data. With the right technology and processes around their Big Data, enterprises can now trigger new ideas around business growth in 2013.
Some of the exciting new strategies that enterprises should look at for their Big Data are:
1. Build advanced predictive models with the information that they already have around their customers and products to create new product and marketing services that will help to differentiate them from their competitors.
2. Data Mining that will help to understand their customers buying persona that will facilitate to capture new customers and markets.
3. Real-time analytics to understand the past behavior patterns of the customers which then will provide greater ability to satify the existing customers by providing personalized services that is relevant to meet their needs and wants.
The Beginning…
Facebook hit the Big Data issues where they had to process huge amounts of structured ( ex. …)and unstructured ( ex. video, email, text) data half decade ago. Facebook joining forces with Yahoo then lead to the creation of Hadoop, a software platform for processing and analyzing epic amounts of data streaming across the modern web. These days the social media platforms like Twitter and LinkedIn have to deal with Big Data to keep their system operational. Guess what they are using to process and manage their Big Data. It is all done through Hadoop. Today we have eBay, and dozens of other high-profile web vendors are using Hadoop to analyzes their vast amounts of data generated during their online operations.
Reshaping the Business Model around Big Data
Most enterprise have Big Data that they have gathered in their data warehouses over the years. But they do not know how to use them nor do they know what the benefits that the various data that they have gathered over the years or the new data that they can collect will help. This is why business needs to spend more time to understand the importance of their existing data and think of ways that they can incorporate data which can help them to grow their revenue.
Let’s look at some examples to understand the value of Big Data in these specific markets. Mobile applications, tablets and smartphones are creating customers and services to consume and integrate structured and unstructured data from a variety of sources.
1. HealthCare Market:
Business objective: Providing, enhancing and streamlining how hospitals connect with and care for their patients. Develop and facilitate personalized therapies and diagnostics to the patients
Big Data opportunity : Incorporate a Big Data analysis engine to build predictive models against patients cynical history, genetics, blood work etc.models.
Why: This will facilitate the doctors to make best treatment recomendations in a timely fashion for their patients. This will help to offer the best care at the same time reducing the healthcare cost by avoiding unnecessary treatments to patients.
2. Retail Online Market :
Business objective: Revolves around connecting the merchants with the consumers in a more effective way such that the consumers can find what they want conveniently and effectively in a timely fashion. This would require merchants to know what the consumers are looking, when and where.
Big Data opportunity : Incorporate a Big Data analysis engine that builds predictive models that will help to make better decisions
- Build consumer models with their transactional history, buying pattern, interest in types of goods, browsing pattern, buying power pattern in $ amount etc.
- Generate a catalogue for the Merchants based on the type of goods, price, value and access.
Why: The predictive models will help to effectively connect the merchants with the consumer so its a win-win for all business entities.
3. Financial Market
Business objective: Provide a High-Performance Trading platform that is effective,accurate and reliable
Big Data opportunity : Advanced analytical engine that will allow for the analysis of complex data sets and the ability to connect patterns and relationships applied to analysing news, social media feeds, scanning incoming emails, or disecting company regulatory filings to generate predictable models
Why: This will facilitate the traders to make effective and accurate trading decisions that is profitable
Big Data Technology and Solutions:
With the 3 Vs around Big Data, enterprises will have to look at the technologies, solutions and data stores that will help them to be successful with Big Data.
Big Data Technology & Data Stores: There are lot of vendors that can offer products around Big Data software platforms and data stores. This was the first areas that got a lot of attention from vendors to address the Data management, processing and operational issues around Big Data. Machine Learning engines are still evolving which will help build accurate and a reliable predictive models . Because of the nature of volume, variety and the velocity with which Big Data has to processed it requires an accurate and a reliable model-building process which has to be automated through advanced algorithms to be effective.
Big Data Solutions:
Right now most of enterprises are trying to build specific tailored solutions in-house to address their basic needs. The Big Data solution space is still a evolving and there is lot of opportunities for innovation and creativity The solution market for Big Data is still an untapped market.
The story is a bit different when it comes to realtime analytics. Enterprises clearly understand the importance of real-time analytics and how it provides a value to the current business. As a result there are vendors who have already built cool realtime analytical solutions that the market wants and that help enterprises reshape their existing business model.
Call for Shift in the Marketing Paradigm for Enterprise Software
Having been a product manager for the 10+ years for enterprise software, I have always watched and observed how the Product marketing teams handle product launches, their go-to market initiatives and the ongoing marketing programs around the Enterprise software products. It’s always one thing to build a kick ass software product which the market wants but the success of market adoption of the product and the ability of sales team to convert it into positive selling opportunities greatly depends on how the marketing is handled for the product. I see that in the Enterprise software realm more importance is given to the product quality alone (ex. features, packaging, UX, etc) instead on the importance of the product marketing to clearly identify, understand, serve and satisfy the market.
If you look back at Microsoft and what Bill Gates did to take the company to where it is today, Microsoft became the market leader not because of better products they had then but because of better marketing. Look at how consumers are fascinated with Apple products these days. It’s because Apple has done an excellent job in understanding what its consumers want.
We all know that the ultimate marketing secret weapon for all products whether its consumer based products or enterprise software products, is to make the consumers/buyers/customers understand the Unique Selling Proposition(USP) of a product. But as per the old school of thinking the USP always revolves around 4 Ps which is Product, Price, Place & Positioning. Based on my observation of the consumer products and comparing that to Enterprise software products, continuing the USP marketing strategy on the 4P approach for Enterprise software will not been very effective in the long run and definitely needs a paradigm shift.
The paradigm shift around marketing Enterprise software should now involve emphasis from Products to Solutions, Place to Access, Price to Value and Positioning to Education. The new school of thought calls it the SAVE approach of Product Marketing (see the latest Harvard Business Review magazine article “Rethinking the 4 P’s”)
Here is what Product Marketing need to do:
- Instead of focusing on defining the product features start to highlight what are the solutions that buyers/customers can build with the product to address their business issues. This would require a good understanding of the buyer’s persona and what their pain points
- Focus on addressing the end to end experience that the buyer/customer will have to get access to the Product instead of focusing only on the packaging and downloading aspects of the product
- Articulate the benefits that the products will offer by solving their business issue and providing a realistic expectation on the ROI instead of focusing on the price and the competitive differentiators alone.
- Invest in resources that will tailor and provide better education of the product to the buyers so the end to end experience of the product from purchase to deployment to maintenance of the Enterprise software is a pleasant experience for the buyer and the customer that you are targeting in specific markets.
Sooner the Product Marketing team adopts the SAVE way of thinking, the better it would be for the overall growth and success of Enterprise software products!!.
Technology product gaps for the mobile consumer market
The article in the recent HBR magazine on how How People Really Use Mobile opened up my mind to validate how I use my smart phone on a daily basis. This also made me to look into this topic further to see if I could connect the dots between the mobile consumer behavior and the technology product gaps that I specifically see that we need to pay attention to in the mobile space.
How are consumers using a Mobile Device:
Based on a industry research study called “Seven Shades of Mobile” conducted by InsightsNow for AOL and BBDO, the data show that 68% of consumers’ smartphone use happens at home. For a typical mobile user the common activity is not shopping or socializing but engaging in what researchers at BBDO and AOL are calling it the “me time.”.
Also checkout some additional interesting facts and case studies about brand messaging through mobile apps in this webinar “Seven Shades of Mobile: The Hidden Motivations of Mobile Users
What are the Technology product gaps for the mobile consumer market?.
The mobile growth trend is here to stay. If you want to know how big the mobile market is, take a look at the stats here. Based on the “Me time” data from I mentioned above, it is important that the technology vendors pay attention to the market needs in the following technology space so they can build value added solutions and products to address the market need of the mobile users.
1. App Development Tools
- Mobile consumers will use mobile apps to purchase goods and services, do banking and billing, to do in-store kiosk transactions, support mobile portals, apps for education and training, apps for games and entertainment.
- The app development tools should be simple and flexible so the apps are built once and can be used on multiple mobile devices to support portability and interoperability.
2. Security Tools
- Mobile user’s identity and privacy will have to be safe guarded at all times. So the security tools/solutions should protect user’s identity information as well his data on the mobile device and during transactions over the network.
3. User Management and Metering Tools
- Better management tools will help to encourage mobile users to get comfortable and help improve their confidence to do more business transactions on the device.
- Metering Tools that will help users to track, analyse and monitor their data, transactions and quality of service over a period of time.
4. Advertising and Messaging Tools
- Need better tools to engage and educate mobile users to the brands, value and benefits, accessibility of products and help with personalize data based on consumer’s usage trend and habits.
5. Data Management Tools
- User data could be of several forms like the identity data, application data, their search data, user’s contextual data, etc. This data will grow overtime and needs to be managed effectively so they are backed up and archived timely so no data is lost and can be will be used as a knowledge base for future use.
Time to innovate and be creative!
Inspirations from the Mayans for the New year
Happy New year everyone!. I am looking forward for an exciting year ahead of me in 2013. Hoping this year will be filled with lot of new ideas and positive thinking which can lead us to more happiness, joy and peace on this planet.
Over the holiday break I took a trip with my family to Cancun & Rivera Maya. This trip was filled with relaxation on the most beautiful beaches in the world along with some exploration and knowledge seeking on the Mayan land, their history, culture, architecture and their food. I am all refreshed and charged up for the New year!.
Cancun and Rivera Maya
Cancun is an island shaped as a 7 in Mexico, with the Caribbean Sea on one side and a lagoon on the other side. Riviera Maya, also known as the Mayan Riviera, is a new tourism district along the Caribbean coastline. This area was mainly developed for tourism with large-scale resorts along the belt facing the Caribbean Sea.
This island has the most beautiful white sanded beaches I have ever seen. The water is so blue and refreshing. The warm weather in the 72 degree in the month of December was the best.
Maya Land – Chichen Itza and Tulum
We visited the great Mayan cities of Chichen Itza and Tulum. The history behind these cities and the ruins of temples,tombs and houses of nobles, that still exists at these places, has been restored to depict the initial architecture is mind-blowing. The Mayans seem to have had a great knowledge around architecture, mathematics and astronomy which helped them to develop their well know and famous mayan calendar.
Also, got to see one of the amazing Cenote in Quintana Roo, which is a limestone sinkhole that is filled with water.It was an amazing site to see people so many people swimming through I did not have the courage to try it.
Along the way we got to enjoy some good local food (tasty mayan dishes, a super green drink made from chaya leaf) and local entertainment which we enjoyed.
Overall this trip has been a fun way to end 2012 and start with new year of 2013. Also as per the real prediction of the Mayan calendar on Dec 21st, 2012 we completed the ‘Great cycle’ where the period equals 5,125-year cycle in the Mayan calendar (Here is how I know it !!, Mayan calendar started in 3113 B.C. + 2012 A.D. = 5125 yrs).
……..and now we have entered the new Mayan cycle in 2013, which is supposed to be a better age for mankind. I hope for it and will work to make it better.
Importance of competitive intelligence as a business strategy
Companies investing time and resources to do a regular analysis of their competitive landscape is a must to stay innovative and to be a visionary market leader.
How does competitive intelligence help?.
Understanding the competitive landscape helps to address these questions for any business. Having the information to these questions will help to make the competitive information more valuable which then can be further analyzed and to make a decisions that can strengthen the overall strategy around business, sales, product and execution.
- How do other vendors think?
- What are their strengths?.
- What are their weaknesses?
- Where are they vulnerable?
- How do they differentiate themselves?
- What is their buyer’s requirements?
Once the competitive data is collected, several folks within the company can leverage it to make effective decisions:
- The leadership management team can leverage this data to drive business decisions
- Sales can use this as a good set of metrics to find new prospects or to up sell to existing customers.
- Product Managers can figure out a plan to address the gaps and weaknesses through product development or through product acquisition
- Marketing can prioritize their marketing budget to better address the market with the right messaging and positioning statements to validate the strengths against other vendors.
How to go about with gathering competitive intelligence?.
1. Do SWOT Analysis: Competitive intelligence professionals often use an analytical technique called SWOT — an acronym for Strengths, Weaknesses, Opportunities, and Threats. The effectiveness of SWOT’s, it can be the starting point for analyzing your position relative to that of your rivals.
2. Study competitors company website, products features, product pricing, product positioning, marketing channels and delivery models to seek their differentiation factors.
Check out additional ideas around these steps from another blog site http://productmanagementtips.com/2011/02/26/competitive-analysis-sources/
3. Talk to the analysts and read through the analyst reports to understand the market trends and the overall market scope.
4. Do regular win/loss analysis to better understand your customer’s and prospect’s buying requirements and needs.
5. Present at trade shows and speaking at conferences can facilitate a way to understand the needs of existing and future customers.
Send me your comments if you have additional ideas to make this exercise a move effective program for any company to adopt.
Difference between Enterprise and Consumer software
Having been a Product Manager managing Enterprise software all my work life, I wanted to take a shot at how Enterprise vs Consumer software has evolved in recent times.
Now with the popularity of cloud and software-as-a-service (SaaS) through the gap between the enterprise space is becoming more like the consumer space, there are still differences between “enterprise” versus “consumer” software. Here’s is my take.
1. Market Problem and Buyer Persona:
- Enterprise software address a business problem for user communities that are large groups of people having the need to solve a common business need. In consumer, the software is mainly to address and enhance the needs of a single user.
- The Enterprise software vendors will have to regularly listen and take feedback from the user groups if they need to keep these users happy and loyal to their software product. Hence the Voice of the customers (VoC) is important.
- Consumers take what they’re given. If the user does not like what the software offers then he will pick a software from an other vendor
2. Sales:
- Enterprise software, you sell to organizations. The consumer software, you sell to people. Does high volume sales mostly through retail.
- Enterprise software sales are direct. For consumer software, sales are done mostly through self-service, you can now deliver the product via the web. In enterprise, you deliver a packaged software that can either be hosted in the cloud as SaaS or a managed service that can be hosted onPremise.
- Pricing and packaging needs are very different for Enterprise software than Consumer. For Enterprise software the cost of ownership is a big factor that drives sales. Hence pricing of the software has to be thought through well before the software is released. The pricing for consumer software can be set depending on the buying power of the individual user.
3. Product Requirements:
- Engineering requirements for Enterprise software has special needs. The requirements around hardware, localization, security, scalability, interoperability are factors that need to be taken into consideration early on in the product development cycle. For consumer software the feature sets are controlled and dictated by the vendor instead of the individual user contributing to the required features of the vendor software.
- Enterprise software rely on early adopters in the user community to test and provide feedback on the software before it gets released to the market. The consumer software does not have the luxury of early adopters, hence the software is tested after is out in the market.
Future of Web Applications as I see it
If enterprises have to stay current they have to invest and innovate to make sure that their web applications and user experience stays on top of their list when it comes to their web strategy. As cloud computing grows in 2013 and SasS becomes one of the main delivery models for the software enterprises, the Web will be the primary access model for the application users.
Enterprises will see an increases in demand for web resources. The web application development will also evolve at a faster pace with the advent of innovations like HTML5 to help support rich web applications . To keep the development and maintenance costs low and reduce the cost of ownership, there will be a greater need to make sure the web applications that the enterprises build are supported across multiple platforms, cross browsers (IE, Chrome,Safari, Mozilla) and cross devices (desktops & mobile).
What’s the magic bullet?.
HTML5 is the future!. Steve Jobs saw this coming in In April 2010 when he announced the demise of Flash and what the future is for HTML5 in his public letter titled “Thoughts on Flash”.
Why HTML5?.
Fast, Secure, Responsive, Interactive, Rich, Easy, Portable, Stunningly beautiful are the words that is used to describe the web application developed with HTML5.
HTML5 not only supports the core HTML components to help define an enterprise quality structure of the web application but also allows support for CSS3 to have a great visual presentation and support for JavaScript helps to control and manage the behavior of the application. Will all these capabilities in HTML5 developers can have a very rich web application framework to build on top. Since most browsers already support HTML5 is becoming the de fecto standard at a faster rate than expected.
Here is what some early adopters like Apple showcased in 2010 on what HTML5 can do http://mashable.com/2010/06/03/apple-html5-showcase/
Recently, I came across a demo put together by the Sencha’s team around the power of HTML5 captured in this video http://vimeo.com/55486684. This proves how native mobile application development will soon become the topic of the past and the future of web applications is HTML5
2013 Mobile Predictions – from Appcelerator/IDC Report
With the BYOD becoming the norm for enterprise application and its users, here is an IDC report on how the mobile development landscape will look like in 2013.
Download the Appcelerator/IDC Q4 2012 Mobile Developer Report.
Some Key findings:
- Interest in iOS and Android Platforms Remains Stable
Despite the introduction of new products in Q4 and the massive success of devices like the iPod mini, Amazon Kindle, Samsung Galaxy S III, and iPhone 5, developer interest in the most popular platforms (i.e. iOS, Android, Blackberry) remains high, but relatively unchanged since Q3 2012. - Amazon Kindle Struggles
Despite Amazon’s sizeable investment in its signature Kindle tablet, developers doubt that the device provides significant revenue opportunities. - Google Nexus Starts Strong
An unprecedented number of respondents express strong interest in developing mobile apps for the Nexus platform. - Microsoft Surface Insufficient
Microsoft’s Surface tablet has yet to excite the developer community. - Mobile Will Forever Change Retail
Mobile developers anticipate that it is “likely to very likely” that most retail companies will have enabled mobile commerce in 2013.
Art of defining Market Requirements..
Irrespective of whether you are a Product Manager or a Product owner you have a responsibility of translating the Market requirements into product requirements. But how product managers go about gathering and defining the product requirements is an art that product managers needs to excel over time if he/she needs to be seen as result oriented product leader.
To make sure that the requirements add value to the product and not just features, every Product Manager need to follow these steps to be successful.
Step 1. Identify the Market Problems
The best way to have a better view of the market problems, every product manager needs to monitor the pulse of the market. This includes closely watching the market trends, regularly engaging with prospects and do the win/loss analysis, identifying the product issues, understanding your customer pain points with regular feedbacks and regularly analyzing your backlogs.
Step 2: Seek the Market Evidence
Once you have gained the market knowledge from Step 1, talk to the analysts and market experts to see if you there is market evidence to back up the data that was collected earlier. Further validate with data obtained from competitive analysis, technology assessments and through innovative ideas.
Step 3: Define to deliver to the Market
Translate the market evidence from Step 2 into specific functional requirements that are achievable and realistic by your team. Each functional requirement should be measurable and time bound so it can be tracked. Including user scenarios along with benefits and positioning statements will enhance the clarity of the requirement definition.Each functional requirement should also target how it will address other targeted areas like
- Standardization
- Certification
- Installation
- Customization
- Localization
- Documentation
- Education
By following the above three steps can help Product Managers to communicate the requirements better to all the stakeholders thereby you can make sure what you build is what the customers wants and will buy. Hence a win-win for all!!.
Mobile Security – BYOD Trends and Needs
As more and more users are embracing the mobile devices, including smartphones and tablets into their daily lives, enterprises have started adopting the trend of allowing its users to bring their own devices (BYOD). Though BYOD allows more freedom for the employees enabling them to consolidate personal and business functions in one mobile device , it has opened new security risks for organizations. Hence all enterprises and organizations need to have a mobile security strategy around its users and the mobile devices that they use.
Security breaches on mobile devices that organizations should pay attention to?
- Avoiding personal and corporate data getting commingled on the user’s mobile device
- Making sure that if the mobile devices are lost or stolen there is a way to prevent the company data getting into the hands of hackers and thieves thereby avoiding misuse of the data.
- Prevent Third-party programs or malware entering into the company network resulting in data incompatibility and integrity.
- Unauthorized users getting their hands into confidential company network and data
- Avoiding data corruption and lower mobile device performance as a result of insufficient security enforcement on the device itself.
Organizations require several critical security components to make sure that BYOD are protected to address the above trends
- Adopt a mobile device management (MDM) solutions to enforce user authentication, authorization and data protection around their device, the data and applications that they use. Most of the MDM solutions offer remote configuration and administration of the mobile devices and allows monitoring and enforcing policies that meet the organization’s IT policies.
- Ensure safe accessibility to corporate networks with VPN security for these mobile devices. This will allow to safeguard the company networks at the same time will provide the users an optimized, secure path to corporate resources like the corporate intranet, email, network resources and other software applications.
- Enforcement of a high-level device encryption to safeguard data on the mobile devices. This will help to provides a high level of encryption of the data that is stored on the device or during transmission. The security goal is to prevent data getting into the wrong hands.
Today, enterprises around the world are struggling to manage a growing trend of their mobile workforce using multiple devices and the increased data consumption. As a result of this fast growing trend mobile security investment is expected to climb 44% each year through 2015. We can all expect more innovation to happen on the solution side as well.
How important is Mobile Security for Enterprises?
Here are the facts and issues around how enterprise users are using mobile devices:
- Email continues to be the killer app for mobility. Employees expecting to get their email just about anywhere drive the use of smartphones and now tablets.
- Enterprises users are finding other use cases for mobile devices, including everything from applications for day-to-day activities to SharePoint access.
- Enterprises are struggling to create a policy that addresses consumerization. Lack of a stronger policy for mobile users is driving requirements for risk management for mobile devices because the greater the mobile connectivity, the more options exist to limit the information actually stored on the user’s device.
- BYOD, or the idea of employees using their personal devices for work, is currently seen as something that is inevitable by enterprises.
- Configuration may sit between the help desk technician and the user. These factors can prevent IT from accessing the user’s machine using traditional remote control tools.
- More and more enterprises are using phones as an alternative to specialized authentication tokens for remote access to enterprise networks, as well as for online banking and similar services.
- Authentication is being done using either one-time-password software tokens for smartphones or out of band (OOB) authentication via text messaging or automated voice calls
- Mobile phones and tablets will overtake PCs as the most common Web access device worldwide during the next year or two, and the value of a phone as a token is used as an authentication credential. For many medium risk use cases, this will be good enough, but for higher-risk use cases, something else is needed.
- While the availability of device-embedded biometric authentication in mobile phones remains low and inconsistent, server- or cloud-based biometric authentication products can exploit phones as capture devices for face and typing rhythm.
From these above facts its quite clear that every enterprise needs to have a strong mobile security strategy to protect its user’s identity, their data and their mobile devices.
I will explore the challenges around mobile security in details in the coming blogs.
What makes a Product successful?
Over my years of experience as a Product Manager these are these principle factors that I follow to make a product successful. Remember all these six principles irrespective of the product will have to be fine tuned with your customers in mind:
- Cost: Lower cost of the product will allow deployment and the ownership cost for the customer. The high license cost for the onPremise vendor software is what is driving more and more customers to look at cloud services these days. Being creative with your pricing model will help you to justify the cost.
- Usability: User experience matters not just for external-facing client software but also for overall administration, manageability and deployment use cases. Simplification of the deployment, manageability and administration of the product will facilitate faster evaluation and help to capture more customers in this market.
- Manageability: Provide tools and protocols that enable the deployment, administration, and monitoring through a remote console. This will help to facilitate better user experience at the same time reduce support and maintenance cost for the customer.
- Flexibility: Making sure that the product can provide flexibility for the customer when a future need to extend the business needs will encourage the customers to adopt the product faster. The flexibility then will become a value add that will help strengthen the overall portfolio for the product.
- Integration: Providing the ability for the product to coexist with other vendor products should always be the focus. This would mean you provide enough hooks within the product through APIs and an SDK. This can help to integrate the product with other software vendors thereby address any unique business case that the customer may have
- Market Leadership: Strive for market leadership. This would require that you clearly understand the market trends and the competitive landscape. Build differentiators that will help to position the product based on the value add it can offer. Its comes back to the creativity and Inovation of the whole team working on the product.
Why startups need Product Managers?
I am noticing more and more startups emerge with a great business plan and get funded to start building products that they think can help meet a market need. What is appalling to me is that while the product is the key thing that will make or break the company, they completely ignore the one role that can really help them accelerate and deliver a better market, the role of a good product manager. Initially, these companies may not feel the impact of this decision, but over time, as product starts materializing, and users/customers start showing up, this becomes a costly mistake. By the time they realize what an impact a product manager would have made in the early stages of the Product Life cycle, its often too late.
It is important to identify early on what is the role of a Product Manager in a startup.
A product manager can bring a lot of value to the product definition and focus, both through the inbound and out bound activities.
Some of the key inbound activities are:
- Product requirement scoping and setting clear priorities with the development team as to what are the value add features that will drive revenue and customer acceptance. If the engineers know why they are building what they are building, they will be much happier and produce a far more superior product.
- Clearly identifying and understanding the competitive market space and defining the market-scope for the product. When the engineers know what they are asked to compete against, they will often excel and beat the competition. If sales team can articulate this, then this results in better sales!
- Make sure all the skate holders (sales, support, engineering, professional services, marketing, and executive sponsors) understand the market well enough about what market need and pain points the product aims to address.
On the other hand, outbound activities are important too, such as:
- Identify and build relationship with the the early adopters and that would be willing to participate early on at the Beta testing and provide timely feedback. This enables you to deliver a better product to the market.
- Make sure the sales teams are trained and are confident to pitch the products to the market. If they don’t understand what they are selling and who they are selling to, you won’t get the sales numbers you need.
- Build a strong relationship with customers and partners to make sure the value add of the product is well understood before they start adopting the product. This yields a happier customer who does not get frustrated with a misunderstood product.
- Work with the marketing team to fine tune and update the messaging and positioning of the product to create buzz and awareness of the product in the industry. Leverage social media to spread the word out, and don’t forget talking to the analysts, they need to know how cool your stuff is so they can tell their clients.
So, if you are a startup or working in one, make sure you understand the importance of a product manager who can be the passionate evangelist of the product and technology you are building. Behind every successful product, is a successful product manager! 🙂
Creativity and Innovation
Here is a new beginning to a new journey .
This is my first day at my personal blog. I always wanted to take time to setup a personal blog. Because of my hectic schedule I always was pushing it aside. Now I am making time to do this and I will be focusing more to write on topics that is close to my heart.
I always believe that passion is what drives ‘Creativity and Innovation’. Every problem in life or at work is an opportunity for a creative solution. The way you view any problem depends on your attitude. Passion is necessary, and drives you to pursue creative and innovative solution to the problem.
To be successful in what you do anywhere and any place, you need to find the right balance between your passion, your skills, and what the market wants. The right mix of all these ingredients will lead you to a successful life and career.
That is my goal for this blog, to write with passion and make sure this leads to creativity and innovation.














