# What is Customer Identity and Access Management (CIAM)?

> Customer identity and access management (CIAM) is the branch of identity and access management that supports people using an organization’s customer-facing digital services.

- Canonical URL: https://yellowcube.eu/glossary/customer-identity-and-access-management/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It governs registration, sign-in, account recovery, profile management, authorization, and account closure for customers, consumers, citizens, partners, and other external users rather than primarily managing the workforce.

CIAM operates where identity security, privacy, service reliability, fraud resistance, and user experience meet. Public registration and recovery paths face automated abuse and large, unpredictable demand, while the identity data involved may be personal or sensitive. Designs should collect only justified attributes, make assurance proportionate to the transaction, and give users understandable control over relevant profile and preference data.

### Key points

- **Lifecycle scope:** Define enrollment, identity proofing where needed, authentication, consent or preference handling, profile changes, recovery, suspension, deletion, and retention responsibilities.
- **Risk-based experience:** Allow low-risk access without unnecessary friction, but require stronger evidence or authentication before sensitive changes, valuable transactions, or disclosure of protected data.
- **Operational design:** Protect public APIs, registration and recovery workflows, sessions, credentials, administrative access, and downstream customer records; monitor abuse without treating every unusual customer as malicious.
- **Important limitation:** CIAM is an industry category with no universal feature set. A CIAM service does not by itself prevent fraud, establish a person’s legal identity, or satisfy privacy and consumer-protection obligations.

### Related terms

[Identity and access management (IAM)](<https://yellowcube.eu/glossary/identity-and-access-management/>) · [Authentication](<https://yellowcube.eu/glossary/authentication/>) · [Authorization](<https://yellowcube.eu/glossary/authorization/>) · [Federated identity](<https://yellowcube.eu/glossary/federated-identity/>) · [Account takeover (ATO)](<https://yellowcube.eu/glossary/account-takeover/>)

### Sources

[NIST SP 800-63-4: Digital Identity Guidelines](https://csrc.nist.gov/pubs/sp/800/63/4/final) · [U.S. Department of State Foreign Affairs Manual: ICAM definitions](https://fam.state.gov/FAM/05FAM/05FAM0160.html) · [IDPro Body of Knowledge: Introduction to Customer Identity and Access Management](https://bok.idpro.org/article/98/galley/231/download/)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

