01
What CIAM covers
The discipline handles sign-in and access for people outside the organization. Registration, authentication and account security all sit inside it, along with the consent and retention obligations that most jurisdictions attach to consumer data.
Every point of friction added to a customer flow is measured directly in abandoned registrations, which is why CIAM decisions are made jointly with the people who own conversion. A workforce identity team can require an enrollment step. A CIAM team can only make one attractive enough to complete.
Sign-up is open to the whole internet
Anyone can begin a registration, so the system meets traffic spikes and automated abuse in the same minute as a genuine new customer, and it has to distinguish them without an interview.
Protection built into the sign-in flow
Protection against account takeover has to operate without a customer configuring anything. Optional controls are skipped by precisely the people most likely to be targeted.
Customer records bring privacy obligations
Almost every jurisdiction attaches consent, access request and retention obligations to customer records. Most of that data lives in the identity system, and most of those requests arrive there first.
Sign-in is part of the customer experience
For many products the sign-in is both the first screen a customer meets and the one they return to most. It is a surface with a measurable conversion rate rather than an internal utility.
02
How CIAM differs from workforce identity
On a feature list the two look alike; in production they behave nothing alike. What separates them is leverage. An employee can be instructed to enroll a managed device and finish a training module. A customer can be asked, and that is where the authority ends.
Scale runs in the opposite direction too. Workforce directories hold thousands of records with demanding assurance requirements and a helpdesk standing behind them. Customer directories can hold millions, with a firm limit on what may be asked of each person and no support organization sized to absorb the difference.
The population being served
Workforce identity serves staff and contractors the organization employs and supports directly. CIAM serves external customers who cannot be trained, instructed or issued equipment.
What you can ask customers to do
Instruct an employee to use a managed device and they will. Instruct a customer and they close the tab, which is why the secure route has to be both the default and the quickest one on offer.
How capacity and licensing are counted
Headcount sizes a workforce system. A customer system is sized on traffic and generally licensed against monthly active users, since most registered accounts sit idle in any given month.
03
What a CIAM stack needs
Most CIAM evaluations converge on the list below, and the conflict inside it is genuine. Any method that asks a customer for extra effort sets security and usability against one another.
That tension is the argument for deleting the credential instead of layering steps around it. When there is nothing to type, the quick path and the secure path are the same path, which is an exit from the trade rather than a compromise inside it.
- A sign-in that completes in seconds on a phone, on the first attempt.
- Phishing-resistant authentication enabled by default rather than offered as an option.
- Standards coverage: OIDC, OAuth 2.0 hardened by PKCE and PAR, and SAML 2.0 where partners federate.
- A recovery path designed as carefully as the sign-in, because attackers will use it.
- Consent, retention and deletion handling that a privacy team can operate without engineering.
- Tenant isolation and role-based access control for the staff who administer all of it.
04
Common CIAM failure points
Failures cluster in a small number of places, and none of them are the login screen everybody spent the design review discussing.
Recovery is the usual one. A phishing-resistant sign-in in front of an email-based recovery flow inherits the security of the email account, and attackers know which of the two to attack. The others are optional security nobody opts into, and consent records that were never designed to answer the question a regulator eventually asks.
Recovery inherits the weakest channel
Whatever the primary method proves, the recovery path decides the real security level. Design it first, and measure how often it is used before assuming it is an edge case.
Optional controls can leave protection gaps
Security features that customers must find and enable are adopted by a small, already careful minority. The default is the policy, whatever the settings page offers.
Keep consent records current
Consent captured without version, scope and timestamp cannot answer a data subject request two years later. That work is cheap at design time and expensive under a deadline.
05
How SenseCrypt supports CIAM
SenseCrypt is a passwordless identity provider for customer identity. A customer is enrolled from a photograph already on file and then signs in with a live face check on their own phone, where liveness and matching both run in the companion app.
Nothing has to be chosen, remembered or reused, and nothing is quoted back during a sign-in, which leaves a phishing page aimed at a customer with no shared password to harvest. IdP retains quantum-safe, sealed, biometric-free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. No face images or templates are retained in the documented phone flow. Licensed on-premises Webcam processes captures inside the customer deployment. For a consumer base, that is a materially smaller privacy exposure than a credential database and a face gallery.
Customer identity is licensed per monthly active user rather than per registered account, which matches how consumer directories actually behave, since most accounts are dormant in any given month. Current terms, minimums and trial details are best confirmed directly with us.
There is nothing to remember
No password exists at any stage of the lifecycle, and nothing is quoted back at sign-in. That retires the reset queue, ordinarily the biggest single source of support contacts in a consumer product.
Tested liveness on ordinary phones
Liveness detection tested by iBeta to ISO/IEC 30107-3 Levels 1 and 2. It reads an ordinary 2D RGB camera and needs no depth sensor, so enrollment is not restricted to newer handsets.
Recognition is evaluated by NIST
Face recognition is evaluated in the NIST Face Recognition Technology Evaluation under Seventh Sense's own name, participation since 2021. We describe that as NIST-evaluated because NIST evaluates algorithms and certifies nothing.
Tenants, roles and records included
Multi-tenant isolation where each tenant is its own issuer, role-based access control for the staff who administer the directory, and a hash-chained tamper-evident log of console actions, with end-user sign-ins recorded separately as a read-only activity stream.
06
Frequently asked questions
What is CIAM?
Customer identity and access management: the system that handles registration, sign-in and access for external customers. It covers authentication, account security, and the consent and retention obligations attached to consumer data.
What is the difference between CIAM and workforce IAM?
Workforce IAM manages employees you can equip, train and instruct. CIAM manages customers you cannot, at public scale, where every extra step costs conversions. The protocols overlap; the operating constraints do not.
Does CIAM help with privacy compliance?
It is where most of the work happens, because the identity system holds the records a request concerns. SenseCrypt contributes by storing no face image and no biometric template, and by keeping a tamper-evident record of administrative actions on customer data.
How do customers recover access if they lose their phone?
A replacement handset is bound with a one-time PIN sent by email, copied to SMS where the account carries a mobile number, or by proving possession of the email address through CIBA. No password fallback exists and there is no self-service face recovery, so this path deserves rehearsal before launch. The replacement must also prove a new device key; the account remains bound to the enrolled person through biometric-free, disposable face tokens, and the live face check is still required at sign-in.
How is SenseCrypt licensed for customer identity?
Per monthly active user rather than per registered account, which reflects how consumer directories behave in practice. Contact us for current terms, minimums and trial details.