Customer Identity & Access Management (CIAM)
Also known as: CIAM · Consumer IAM
Definition
Customer Identity & Access Management (CIAM) is the category of IAM platforms purpose-built for customer-facing authentication, registration, account recovery, and profile management — distinct from workforce IAM.
CIAM workloads differ fundamentally from workforce: larger user base, adversarial threat model (credential stuffing, account takeover), UX-sensitive (every step costs conversion), and B2B-multitenant for many SaaS products. The leaders are Auth0 (Okta), Microsoft External ID, Ping Identity Cloud, WorkOS, Stytch, and FrontEgg.
Key CIAM capabilities: progressive profiling, social login, passkey rollout, B2B Organizations pattern, MFA tuned for low friction, leaked-credential detection, and ATO defense.