<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>digital identity Archives - IDPro</title>
	<atom:link href="https://idpro.org/tag/digital-identity/feed/" rel="self" type="application/rss+xml" />
	<link>https://idpro.org/tag/digital-identity/</link>
	<description>The Professional Organization for Digital Identity Management</description>
	<lastBuildDate>Thu, 04 Dec 2025 19:51:39 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://idpro.org/wp-content/uploads/2023/07/cropped-idpro_stickerA-circle-100-32x32.jpg</url>
	<title>digital identity Archives - IDPro</title>
	<link>https://idpro.org/tag/digital-identity/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>The Identity of Everything… Else</title>
		<link>https://idpro.org/the-identity-of-everything-else/</link>
		
		<dc:creator><![CDATA[VTM Web Services]]></dc:creator>
		<pubDate>Thu, 04 Dec 2025 19:51:37 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Newsletter]]></category>
		<category><![CDATA[digital identity]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[identity management]]></category>
		<guid isPermaLink="false">https://idpro.org/?p=2903</guid>

					<description><![CDATA[<p>This article is about “identity.” However, this is explicitly not about user accounts and what some may call “digital identities”. [&#8230;]</p>
<p>The post <a href="https://idpro.org/the-identity-of-everything-else/">The Identity of Everything… Else</a> appeared first on <a href="https://idpro.org">IDPro</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>This article is about “identity.”</p>



<p>However, this is explicitly <em>not </em>about user accounts and what some may call “digital identities”. It’s also not about non-human identities (NHIs), workload, service, machine-to-machine, or customer accounts.&nbsp;</p>



<p>There are a lot of great articles already written on each and every one of these identity types by thought leaders, so I’d like to address the neglected others.</p>



<p>So, if this article is about identities, but none of the above, then what’s this article about? This is about other constructs that are fundamental to all Identity and Access Management programs, and to their related tools and applications. I’m referring to the identities of constructs like groups, applications, policies, networks, etc.</p>



<h2 class="wp-block-heading"><strong>Identity Constitution</strong></h2>



<p>Allow me to simplify the constitution of ‘Identity’ into having three parts: </p>



<ol class="wp-block-list">
<li>An identifier (as unique as possible)</li>



<li>Attributes, which provide further differentiation, context, etc.</li>



<li>Relationships (e.g., “belongs to”), which can be documented as part of #2</li>
</ol>



<p>“My dog’s name is Lola” ← These five words already encompass the three parts above:</p>



<ol class="wp-block-list">
<li>Her identifier: Lola</li>



<li>Attributes: type: Dog</li>



<li>Relationships: owner: Me (although, if Lola could talk, she’d tell you her human is my wife)</li>
</ol>



<p>An example of a non-living object is “my lucky t-shirt”. I’ve had this t-shirt for years, and it’s green, and it has a print of mountains with “Colo ‘rad’ o” written above (I’m a dad, I love it). At home, I may say, “have you seen my lucky t-shirt?”, and in the context of my family, chances are they’d know which one I’m talking about. If my daughter is not sure which t-shirt I’m talking about, she may ask, “what color is it?” (It’s green, an attribute). Life gives us an extensible schema to define any number of attributes to identify objects.</p>



<p>In the examples above, I shared the ‘Identities’ of two objects. The point is to ‘identify’ them.</p>



<p>If we turn to IAM-related objects, we can look at groups as in immediate need of proper identification. A group’s system identifier may be “xyz123”, attributes may include Group Name = “App X Users” (this may be considered the identifier, to the human eyes at least), and Group Description = “Accounts with access to App X”. Is this sufficient? Perhaps initially you’ll think “absolutely”. I’d argue that there’s a rich group identity hidden behind the ID, Name, and Description for this group. </p>



<p>The IAM systems I’m most familiar with allow me to define a rich, extensible schema for accounts with many different attributes and even different attribute-types (string, Boolean, array, etc). This is excellent and much needed. In the last few years, the ‘group schema’ became available, so I may now define a Boolean value ‘For SSO’, ‘For SCIM Provisioning’, or ‘For Policy’. In addition, I want to define ‘Pushed to App’ as a Boolean value, and if TRUE, then ‘App’ (string type, as I can’t define an App object relationship).</p>



<p>But, there’s no extensible schema for ‘Apps’, or for ‘Group Rules’, or ‘Policies’, or ‘Networks’, etc. Lots of opportunities here to elevate the schemas of other objects to a whole new level.&nbsp;</p>



<h2 class="wp-block-heading"><strong>The CMDB is an Identity Management system</strong></h2>



<p>It follows that the system of record for constructs such as applications, systems, and perhaps groups is actually an IAM system, but for constructs other than accounts.</p>



<p>A proper CMDB will contain the creation date for any of its configuration items (CIs), its reason for being, its location, and, importantly, its relationships to other CIs.</p>



<h3 class="wp-block-heading"><strong>A Source of Truth</strong></h3>



<p>One way to make your IAM system compliant and elevate its security is to delegate account creation to the correct source of truth. HR-driven provisioning is one example of this. If the IAM system delegates employee account creation to a correlated HR record, and the permissions to create accounts are removed from humans, a bad actor would have to shift their tactics to the HR system in order to create an account, which would likely require creating a role requisition, an applicant account, and then a hire/onboarding process.</p>



<p>Similarly, if the base attributes for a group, application, or other IAM construct are established and properly governed by the right source of truth, then the entire identity fabric will be more secure and compliant, but it’ll be like a self-maintaining organism, keeping the parts that are needed and auto-shedding those that have come to the end of their useful existence. </p>



<h2 class="wp-block-heading"><strong>Naming Conventions Don’t Work</strong></h2>



<p>You’ve likely implemented or have seen many naming conventions implemented to address this very topic. In my experience, a naming convention typically encodes attributes into the name (perhaps into a `Description`) with the intent to give more context to the object. This may work in some situations and it may help humans visually inspect the object. The problem begins when these existing encoded dimensions change or no longer capture the entirety of the object’s schema. When faced with this challenge, proper hygiene means renaming all existing objects, or, in the more common scenario, breaking the naming convention altogether. The end result is heterogeneous names and paralysis due to confusion and the need to research.</p>



<h2 class="wp-block-heading"><strong>Suggested Actions</strong></h2>



<p>If you have access to an extensible schema for your objects, use it. Give those objects a rich identity that empowers a complete lifecycle of the object, from creation to decommissioning.</p>



<p>In the case of our Lola, she has her tag on her collar with her name and our cell phone numbers. However, she also has a microchip that extends the schema of her attributes to include our details, her vaccinations, etc. in case she gets lost and loses her collar.</p>



<p>If you’re building or managing IAM software, expand the universe to enable rich schemas in the system. Some of us may want to have a “lucky” group/policy/agent, and we certainly want better ways to identify and protect our Lola’s.</p>



<p></p>



<p><em>Disclaimer: The views expressed in the content are solely those of the author and do not necessarily reflect the views of the IDPro organization.</em></p>



<p></p>



<h2 class="wp-block-heading">About the author</h2>



<div class="wp-block-group is-nowrap is-layout-flex wp-container-core-group-is-layout-ad2f72ca wp-block-group-is-layout-flex">
<figure class="wp-block-image size-full"><img fetchpriority="high" decoding="async" width="400" height="400" src="https://idpro.org/wp-content/uploads/2025/12/image.jpeg" alt="" class="wp-image-2904" srcset="https://idpro.org/wp-content/uploads/2025/12/image.jpeg 400w, https://idpro.org/wp-content/uploads/2025/12/image-300x300.jpeg 300w, https://idpro.org/wp-content/uploads/2025/12/image-150x150.jpeg 150w, https://idpro.org/wp-content/uploads/2025/12/image-320x320.jpeg 320w" sizes="(max-width: 400px) 100vw, 400px" /></figure>



<p>Pablo Valarezo is an Identity practitioner building and modernizing secure IAM programs over the last decade. His primary focus has been in the workforce side of IAM. He came to Information Security via system administration, project management, and audit and compliance.</p>
</div>



<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><img decoding="async" width="346" height="350" data-id="2898" src="https://idpro.org/wp-content/uploads/2025/11/image-2.png" alt="" class="wp-image-2898" srcset="https://idpro.org/wp-content/uploads/2025/11/image-2.png 346w, https://idpro.org/wp-content/uploads/2025/11/image-2-297x300.png 297w" sizes="(max-width: 346px) 100vw, 346px" /></figure>



<figure class="wp-block-image size-large"><img decoding="async" width="600" height="600" data-id="2390" src="https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author.png" alt="" class="wp-image-2390" srcset="https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author.png 600w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author-300x300.png 300w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author-150x150.png 150w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author-320x320.png 320w" sizes="(max-width: 600px) 100vw, 600px" /></figure>
</figure>
<p>The post <a href="https://idpro.org/the-identity-of-everything-else/">The Identity of Everything… Else</a> appeared first on <a href="https://idpro.org">IDPro</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>What do you wish you&#8217;d known when you first started in identity?</title>
		<link>https://idpro.org/what-do-you-wish-youd-known-when-you-first-started-in-identity/</link>
		
		<dc:creator><![CDATA[VTM Web Services]]></dc:creator>
		<pubDate>Wed, 29 Jun 2022 20:23:11 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[digital identity]]></category>
		<category><![CDATA[iam]]></category>
		<guid isPermaLink="false">https://idpro.org/?p=1711</guid>

					<description><![CDATA[<p>By Greg Smith The Internet Identity Workshop meets twice a year and publishes proceedings for those who were unable to [&#8230;]</p>
<p>The post <a href="https://idpro.org/what-do-you-wish-youd-known-when-you-first-started-in-identity/">What do you wish you&#8217;d known when you first started in identity?</a> appeared first on <a href="https://idpro.org">IDPro</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>By Greg Smith</p>



<p>The <a href="https://internetidentityworkshop.com/">Internet Identity Workshop</a> meets twice a year and publishes proceedings for those who were unable to join. IIW34 was held at the end of April, and our own Heather Flanagan led a topic entitled “What do you wish you&#8217;d known when you first started in identity?”, which is a topic near and dear to all of us in IDPro. Here’s a quick overview of some of the thoughts participants came up with (I deliberately did <em>not</em> edit the bullets captured from the whiteboard):</p>



<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-2 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="449" height="568" data-id="1717" src="https://idpro.org/wp-content/uploads/2022/06/Capture-3.png" alt="" class="wp-image-1717" srcset="https://idpro.org/wp-content/uploads/2022/06/Capture-3.png 449w, https://idpro.org/wp-content/uploads/2022/06/Capture-3-237x300.png 237w" sizes="auto, (max-width: 449px) 100vw, 449px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="474" height="632" data-id="1714" src="https://idpro.org/wp-content/uploads/2022/06/Identity-Workshop-Image.png" alt="" class="wp-image-1714" srcset="https://idpro.org/wp-content/uploads/2022/06/Identity-Workshop-Image.png 474w, https://idpro.org/wp-content/uploads/2022/06/Identity-Workshop-Image-225x300.png 225w" sizes="auto, (max-width: 474px) 100vw, 474px" /></figure>
</figure>



<p></p>



<p>Wish I’d been there for the live discussion! These are some of the same challenges we’ve all had throughout our careers. Fortunately, we now have IDPro to help newcomers to the identity and access management industry with some of these challenges, starting with our <a href="https://idpro.org/body-of-knowledge/">Body of Knowledge</a>, which addresses many of the questions above.</p>



<p>The green statement added to the first bullet stating that there’s “always a new context to solve for” especially rang true for me. This is a workspace that is constantly evolving, and you’re never really “done”.&nbsp; That definitely feeds into the “Don’t worry solve everything” idea. Huh? Wait, what? Had to check with Heather on that one, and in the heat of the moment, words were missed on the whiteboard. The discussion actually went along the lines of “Don’t worry about solving for everything; every process is an evolution.” Okay, that makes more sense. To look at identity from an agile perspective, this is clearly a practice that benefits from iteration as new contexts continually show up.</p>



<p>Not captured on the whiteboard, but every bit as relevant, IDPro member Joe Andrieu said “I wish I knew that identity is how we recognize, remember, and respond to specific people and things. I also wish I knew that different people have fundamentally different mental models of what identity means. And we often talk past each other even as we honestly try to communicate.” So true! He also shared links to his <a href="https://github.com/WebOfTrustInfo/rwot6-santabarbara/blob/master/topics-and-advance-readings/functional-identity-primer.md">Functional Identity Primer</a> and <a href="https://github.com/WebOfTrustInfo/rwot7-toronto/blob/master/final-documents/mental-models.md">Five Mental Models of Identity</a> articles with the group. Definitely worth a read, folks!</p>



<p>What else do you wish you’d known when you got started in this space? Let us know in our <a href="https://app.slack.com/client/T344KSH3R/C33BT7ZGB">Slack workspace</a> and keep the conversation going.</p>



<div class="wp-block-media-text alignwide has-media-on-the-right is-stacked-on-mobile" style="grid-template-columns:auto 21%"><figure class="wp-block-media-text__media"><img loading="lazy" decoding="async" width="161" height="162" src="https://idpro.org/wp-content/uploads/2022/03/GregSmith.png" alt="" class="wp-image-1549 size-full" srcset="https://idpro.org/wp-content/uploads/2022/03/GregSmith.png 161w, https://idpro.org/wp-content/uploads/2022/03/GregSmith-150x150.png 150w" sizes="auto, (max-width: 161px) 100vw, 161px" /></figure><div class="wp-block-media-text__content">
<p></p>



<p class="has-text-align-right"><em>Greg Smith</em></p>



<p class="has-text-align-right"><em>Chair, IDPro Editorial</em></p>



<p class="has-text-align-right"><em>Radiant Logic</em></p>
</div></div>



<p>Greg Smith is a Solutions Architect with Radiant Logic. He has been implementing Identity &amp; Access Management solutions for over 35 years. He holds BSEG and MSBA degrees from Bucknell University, where he also began his professional career before moving into the Pharmaceutical industry in 1996. After a 25 year career there, he recently retired from Johnson &amp; Johnson, where he led the engineering team for J&amp;J’s single sign-on, risk based authentication, multi-factor authentication, access governance, directory synchronization and virtualization, provisioning automation, and PKI services. He has spoken at Identiverse® and other industry events on numerous occasions. He was recently CIDPRO<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> certified and is also a founding member of IDPro, where he currently chairs the editorial committee.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="475" height="124" src="https://idpro.org/wp-content/uploads/2022/03/GregBadges.png" alt="" class="wp-image-1550" srcset="https://idpro.org/wp-content/uploads/2022/03/GregBadges.png 475w, https://idpro.org/wp-content/uploads/2022/03/GregBadges-300x78.png 300w" sizes="auto, (max-width: 475px) 100vw, 475px" /></figure>
<p>The post <a href="https://idpro.org/what-do-you-wish-youd-known-when-you-first-started-in-identity/">What do you wish you&#8217;d known when you first started in identity?</a> appeared first on <a href="https://idpro.org">IDPro</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Announcing IDPro®’s Diversity &#038; Inclusion Packages for Identiverse® 2022!</title>
		<link>https://idpro.org/announcing-idpros-diversity-inclusion-packages-for-identiverse-2022/</link>
		
		<dc:creator><![CDATA[VTM Web Services]]></dc:creator>
		<pubDate>Thu, 02 Jun 2022 18:18:21 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[digital identity]]></category>
		<category><![CDATA[diversity]]></category>
		<category><![CDATA[iam]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[identity management]]></category>
		<category><![CDATA[idpro]]></category>
		<category><![CDATA[inclusion]]></category>
		<guid isPermaLink="false">https://idpro.org/?p=1650</guid>

					<description><![CDATA[<p>As part of IDPro®’s continued efforts to promote a diverse and inclusive identity community, we are pleased to announce that [&#8230;]</p>
<p>The post <a href="https://idpro.org/announcing-idpros-diversity-inclusion-packages-for-identiverse-2022/">Announcing IDPro®’s Diversity &#038; Inclusion Packages for Identiverse® 2022!</a> appeared first on <a href="https://idpro.org">IDPro</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>As part of IDPro<sup>®</sup>’s continued efforts to promote a diverse and inclusive identity community, we are pleased to announce that we are offering two Diversity &amp; Inclusion Packages for those wishing to attend <a href="https://identiverse.com/">Identiverse<strong><sup>®</sup></strong></a> 2022.&nbsp;</p>



<p>These packages include one Identiverse event ticket, donated by Identiverse, and up to $1,000 for expense reimbursement, fully funded by generous donations from IDPro<strong><sup> </sup></strong>members.</p>



<p>“We are excited to be able to offer these Diversity &amp; Inclusion Packages to the identity community.<strong> </strong>I have been a firsthand witness to the impact these values are having on this industry and am very proud of our organization for being able to support this effort.”<strong> </strong>—<strong> </strong>Heather Vescent, Executive Director and President of IDPro.</p>



<p>To be considered, please submit a personal statement of no more than 300 words to <a href="mailto:director@idpro.org">director@idpro.org</a> by 11:59 PM PDT on June 7, 2022. Your personal statement should answer the following questions:</p>



<ol class="wp-block-list"><li>Can you please share a little bit about your background?</li><li>How did your interest in identity come about?</li><li>What do you hope to learn at Identiverse 2022?</li><li>Why are diversity and inclusion important to you?</li><li>Are you willing to write a brief blog post or be interviewed about what you learn at Identiverse 2022?&nbsp;</li></ol>



<p>Please include any social media links in your personal statement.&nbsp;</p>



<p>Our vision at IDPro drives us toward enabling a diverse, supportive, and inclusive identity community and we are grateful for our dedicated members who are helping us achieve this important goal. We look forward to reviewing your submissions and we hope to see you at Identiverse 2022!</p>
<p>The post <a href="https://idpro.org/announcing-idpros-diversity-inclusion-packages-for-identiverse-2022/">Announcing IDPro®’s Diversity &#038; Inclusion Packages for Identiverse® 2022!</a> appeared first on <a href="https://idpro.org">IDPro</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Minified using Disk

Served from: idpro.org @ 2026-04-05 22:12:41 by W3 Total Cache
-->