Cybersecurity ManagementIdentity & Access Management

Identity & Access Management

BC-620.20 Level 2 Cross-Industry 50 providers 160 API surfaces 21 rated strong or better

IAM, PAM, federation, joiners-movers-leavers.

Identity & Access Management (BC-620.20) is a level-2 business capability under Cybersecurity Management in the Cross-Industry model. The catalog holds 160 API surface(s) from 50 provider(s) that can perform some part of it, 21 of them rated strong or better. Reach is the vendor surface that lands on this capability — it is not a claim about what any particular organisation has deployed.

Where this capability definition comes from. This capability is part of a published business-architecture model that API Evangelist did not author. It is redistributed here under CC-BY-4.0. Turbo EA Capabilities by Vincent Verdet — Turbo EA, https://github.com/vincentmakes/turbo-ea-capabilities, CC BY 4.0 Changes: Consolidated from 333 per-L1 YAML files into one JSON; English only (upstream i18n/ omitted); descriptions whitespace-normalised. No capability was added, removed, renamed or re-parented. Source repository · NOTICE and third-party framework attributions

Sub-capabilities

Identity Lifecycle Management BC-620.20.10

Joiner, mover, leaver processes and identity provisioning.

no catalog coverage

Access Management and Authentication BC-620.20.20

Authentication, MFA, single sign-on, and federation.

no catalog coverage

Privileged Access Management BC-620.20.30

PAM, just-in-time access, and privileged session monitoring.

no catalog coverage

Access Governance and Recertification BC-620.20.40

Access reviews, segregation of duties, and recertification.

no catalog coverage

Customer Identity Management BC-620.20.50

CIAM for external customers, partners, and consumers.

no catalog coverage

Providers that reach this capability

Ordered by rating band. Reach means a provider publishes an API surface that can perform some part of this capability — it is not a claim that any particular organisation has deployed it.

Exemplar 7 Complete, well-documented, and agent-ready
Strong 14 Solid coverage with minor gaps
Developing 13 Usable, with meaningful gaps to close
Thin 13 Limited public surface area
Emerging 3 Early or largely undocumented
This page carries no rating. Capabilities are not rated. A capability is a description of what a business does, not a thing a company publishes, so a Kin Score would have nothing to measure.
The edge table is a Pro feature. This page shows which providers and tags reach Identity & Access Management. The underlying tag → capability edges — each with the quoted fragment of the provider's own OpenAPI that evidences it, a calibrated confidence score, and the contract-provenance gate it passed — are available through the API, along with company-level capability maps. Only edges at confidence ≥ 0.7 with evidence found verbatim in the source contract are published at all.

See plans →  ·  How the edges are graded →