IAM From Mars... Are We Doing It Wrong? Bridging the Gap Between Enterprise Product Paradigms and Research & Education Reality
Identity and Access Management (IAM) is often treated by the tech industry as a solved problem with universal paradigms. If you talk to most mainstream IAM professionals, the conversations neatly center around familiar terms: Workforce IAM, B2B, B2C, and Customer Identity (CIAM)[cite: 249]. The market builds commercial-off-the-shelf (COTS) products designed around clean software-of-record (SOR) lines, assuming clear transitions as users are provisioned, updated, and eventually deprovisioned[cite: 249, 252, 277].
But when you try to drop those rigid enterprise product models into the world of Research and Education (R&E), the gear teeth grind, the paradigms shatter, and you realize we are speaking entirely different languages[cite: 250, 254, 255].
At Identiverse, I wanted to pull back the curtain on this fundamental misalignment—what I call the Vendor-to-Prospect Mismatch—and explore why treating higher education and large-scale research institutions like standard corporate networks is a recipe for failure[cite: 255, 277].
The R&E Landscape: A High-Scale, Multilateral World
To understand why traditional enterprise IAM doesn’t fit, you have to look at the unique operational requirements of the Research & Education sector[cite: 156, 157]. Higher education doesn’t operate as a single vertical monolith; it functions as a highly distributed, federated ecosystem[cite: 176, 258].
- Federated-First Approach: Long before the commercial sector began adopting modern single sign-on protocols, the R&E community pioneered federated identity infrastructure out of pure necessity[cite: 176, 177]. Since the early 2000s, ecosystems built on CoSign, CAS, and Shibboleth/SAML have driven collaboration across institutional boundaries[cite: 177].
- The Scale Problem: Traditional corporate IAM assumes a closed universe where an Identity Provider (IdP) connects to a known, bounded set of applications (Relying Parties). In contrast, modern R&E multilateral federations handle massive scale, connecting over 6,000 Identity Providers and 7,000+ Service Providers globally[cite: 268, 274].
- Dynamic and Bounded Applications: Service providers and collaborative research platforms spin up and shut down constantly without the central IT department’s explicit knowledge or manual intervention[cite: 258, 259]. IdP-initiated single sign-on or rigid application portals simply do not scale in an environment with thousands of globally dispersed academic resources[cite: 274].
Breaking the Enterprise Dichotomy: One Identity, Many Personas
The defining limitation of most commercial IAM platforms is their binary view of users. You are either an employee (Workforce) or a customer (B2C)[cite: 249, 256].
In Research & Education, that boundary doesn’t exist[cite: 250]. The life cycle of an academic identity is highly fluid, non-linear, and multi-faceted. We have to manage complex Affiliations, which represent far more than simple access entitlements[cite: 248].
Consider the classic Joiners, Movers, and Leavers lifecycle[cite: 182, 191]:
- “You can check out any time you like, but you can never leave…” [cite: 247] When a corporate employee leaves a job, you disable their account, wipe their access, and reassign their files. In higher education, a single person can be a returning alumnus, an alumni donor, a retiree, active faculty, an emeritus professor, a visiting researcher, and a guest—sometimes all at once or sequentially over decades[cite: 247].
- The Problem of Personas: A single digital identity might access the exact same institutional resource under entirely different personas at the same or different times[cite: 251]. Managing this fluid context requires thousands of intersecting Sources of Record (SORs) spanning student systems, HR databases, guest registries, and departmental rosters[cite: 247, 252].
- Persistent Lifelong Footprints: When a researcher leaves an institution, you cannot simply deprovision their digital footprint[cite: 197, 256]. Their identity is tied to historical audit logs, POSIX group information, ongoing file ownership, and orphaned documents[cite: 193, 194, 195, 196]. Most critically, they must maintain lifelong contact info linked to published research and data repositories[cite: 197].
Connecting the Scholarly Web: ORCID Integration
Because researchers frequently move between institutions or hold multiple concurrent appointments, the academic world relies on persistent digital identifiers like ORCID iDs to unambiguously and definitively link scholars with their lifelong work products[cite: 242, 259].
To handle this architecturally, the community formalized standards like eduPersonOrcid (defined within the eduPerson object class schema; OID: 1.3.6.1.4.1.5923.1.1.1.16)[cite: 166, 234]. This allows institutions to natively synchronize multi-valued persistent identifiers to map institutional identities to global scholarly work[cite: 240, 242].