Back to Field Notes
Identity & Access/Field Note

CIAM Architecture — Why Customer Identity Is Different

Customer identity has different scale, different recovery flows, different fraud surface. Build it on a CIAM, not on your workforce IdP.

Author

Yusuf Ahmed

Principal Engineer, Platform Security

Published

March 20, 2026

Read

9 min

Share
AI-generated illustration of a banking facility
AI-generated illustration of a banking facility
Key Takeaways
  • 01CIAM is often shoehorned onto a workforce IdP. Result: friction for customers and security gaps that workforce-grade controls do not address.
  • 02Where CIAM differs: scale (millions of users not thousands), recovery (most customers cannot call your service desk), fraud surface (account takeover and synthetic accounts, not insider risk), privacy (consent management, marketing prefs, DSARs), conversion (every friction point loses customers — different math).
  • 03CIAM-grade authentication menu: passkeys as the strong primary, social login as low-friction option, password as legacy fallback, MFA via app or push for high-risk events, friction proportional to risk (step-up for sensitive actions, not for browsing). All with consent capture, marketing pref handling, full GDPR/CCPA workflows.
  • 04Threat-aware CIAM: bot mitigation, credential stuffing detection, behavioral biometrics, fraud signal integration. CIAM that does not have these is a 2018-grade product.

Customer identity and access management (CIAM) is often shoehorned onto a workforce IdP. The result is friction for customers and security gaps that workforce-grade controls do not address.

Where CIAM differs

  • 01Scale — millions of users, not thousands
  • 02Recovery — most customers cannot call your service desk
  • 03Fraud — account takeover and synthetic accounts are the threat, not insider risk
  • 04Privacy — consent management, marketing preferences, data subject rights
  • 05Conversion — every friction point loses customers; the math is different

The CIAM-grade authentication menu

Passkeys as the strong primary, social login as a low-friction option, password as the legacy fallback, MFA via app or push for high-risk events, friction proportional to risk (step-up for sensitive actions, not for browsing). All of this with consent capture, marketing preference handling, and full GDPR/CCPA workflows.

Threat-aware CIAM

Bot mitigation, credential stuffing detection, behavioral biometrics, fraud signal integration. CIAM that does not have these is a 2018-grade product.

#CIAM#Customer Identity#Authentication

/WRITTEN_BY

Yusuf Ahmed

Principal Engineer, Platform Security · Alexa Cybersecurity