Customer Identity and Access Management (CIAM) is the set of identity capabilities that face external users — your customers, applicants, members, citizens. Unlike workforce IAM, CIAM is judged on conversion rate as much as on security. Every additional step in registration drops sign-ups; every false-positive in fraud detection costs a real customer. The market leaders (Okta CIC, Auth0, Microsoft Entra External ID, Ping, ForgeRock Identity Cloud) compete largely on developer experience and time-to-launch.
The hard problems are different from the workforce side: progressive profiling without surveillance creep, consent and preference management compliant with GDPR / CCPA / Quebec Law 25, integrated fraud and bot detection, account-takeover defense at scale, and orchestration of complex onboarding flows (KYC, AML, age verification) without rebuilding auth from scratch.
This page tracks our reporting on CIAM platforms, breach response in B2C contexts, and architectural patterns that scale to millions of identities without losing privacy.