B2B Identity & Access Management

B2B IAM –
Your customer is a company,
your CIAM should know that.

B2B IAM lets you manage business customers as organizations: with their own users, administrators, Identity Providers, roles and access contexts.

Customer Groups
Delegated Administration
Enterprise SSO
Context-aware Access

Leading enterprises trust cidaas

From SMEs to large international corporations – cidaas protects millions of digital identities across Europe.

Kaufland – cidaas customer
Hornbach – cidaas customer
Takko Fashion – cidaas customer
Europa Park – cidaas customer
ProSiebenSat.1 – cidaas customer
REHAU – cidaas customer
RATIONAL AG – cidaas customer
1. FSV Mainz 05 – cidaas customer
EWE AG – cidaas customer
SachsenEnergie – cidaas customer
Creditplus Bank – cidaas customer
die Bayerische – cidaas customer
Why B2B IAM

Identity needs organizational context

Identity
Personal Information
Customer Group Membership
Roles
customer organization as groups
Customer organization
Customer hierarchy
Customer organization
Organization
Customer organization
Subsidiary Subsidiary for a country
Level 2
Location Local subsidiary
Level 3
Location Local subsidiary
Level 3
Several subsidiaries
Several locations
Level 1 · Customer organization
Level 2 · Subsidiary
Level 3 · Location
Delegated User Administration

Let customer admins manage users within your rules

Customer admins can invite and remove users, manage memberships and assign the roles made available to them. The platform owner defines the boundaries and allowed roles.

Delegated user administration becomes part of the product experience, close to the people who know who should have access.

YOUR CONTROL PLANE
Control
Group type
defines which roles may be assigned
ROLE MODES
Predefined
Allowed roles
Any role
API SCOPE
cidaas:delegated_admin
CUSTOMER ADMIN UI
Invite or add users
View users and user activities
Assign permissions
Delete users
USER
ROLE
ACTIONS
User A
Assigned role
⋯
User B
Assigned role
⋯
User C
Assigned role
⋯

One B2B IAM. Different ways to bring users in.

Customers can add users in cidaas B2B IAM through self-service, invitation or Enterprise SSO. All three routes end in the same customer-group structure and role model. Whatever the entry point, the identity lands in the same organizational framework and is governed by the same roles and policies.

Invitation
The customer admin invites a colleague, who is assigned to the customer group automatically.
Self-registration with approval
The person registers, the customer admin approves.
Federated login
Just-in-time account creation at the federated identity provider.
OpenID Connect OAuth2 SAML
cidaas
One framework
Identity Layer
ESTABLISHES • SECURES • MANAGES
Group Roles Policies
Customer group
One group and role model

Integrate customer identity providers, applications and business services through standards such as OpenID Connect, OAuth 2.0, SAML and SCIM. JIT provisioning, APIs, directory synchronisation and webhooks help automate identity data and user access across connected systems. For more complex environments, identity orchestration via the cnips iPaaS can connect onboarding, provisioning and access permissions across multiple application, organizations and data sources.

One identity. Multiple customer contexts.

Choose your working context

Select the role or team you're working in. Your access and permissions will change with the selected context.

One identity. Multiple roles.
♙
John Smith

Works across multiple teams at a manufacturing company.

Customer Group A
▥
Customer Group A
Manufacturing company
⌖ Munich, Germany   |   Managing Director
♙
His role in this team

John Smith is a Managing Director in Customer Group A, with access to company-wide administration and approvals.

B2B Customer access lifecycle

Keep customer access current

Customer access starts with onboarding, is periodically reviewed where required, and ends through local removal or a connected customer lifecycle. A B2B customer lifecycle in cidaas can look like the following:

01 Onboard

Add users through self-service, invitation or federation.

02 Authenticate

One-time passwords by email or phone, push notifications, authenticator apps, mobile biometrics and FIDO certified authenticators including passkeys.

03 Authorize

Role, attribute and Policy-based Access Control. The group type defines the available roles.

04 User Management

Customer User Management throughout their lifecycle, including changes to roles, group memberships and access rights.

05 Review IGA (Add-On)

Confirmation of memberships and roles.

06 Offboard

Local removal of access or via the customer’s identity lifecycle (depending on the integration model).

B2B IAM use cases
for digital products and platforms

B2B SaaS platforms

Each business customer operates within its own tenant, with dedicated groups and users, administrators and roles.

Multi-Tenancy Enterprise SSO

B2B e-commerce platforms

A business customer gets its own group on your shop. Administrators add colleagues and give each one a role. One places orders, one collects them, one sees the invoices.

Customer Admin Role-based Access

Business service platforms

Configurators, procurement portals and service portals are used by teams, not by single logins. Each business customer manages its own team: who may configure, who may submit, who may only view.

Customer Groups User Lifecycle

cidaas is recognized as a Leader in B2B IAM

Recognized by analysts

Why choose cidaas B2B IAM?

Built around organizations

Organizations, groups and administrative boundaries are part of the identity model.

Customer identity sources

Self-service, local identities and customer federation can coexist.

Authorization with context

Organizational context can inform access decisions.

European SaaS platform

Headquarted in Germany, hosted in the EU. ISO 27001 certified.

Make every customer organization part of your digital product

Give business customers their own users, administrators, Identity Providers and access contexts while your platform keeps control of the framework.

FAQs: B2B IAM

B2B IAM manages identities from organizations outside your workforce, including business customers as well as partners, suppliers and contractors. This page focuses on the business-customer side: making a customer organization, with its users and access context, part of a digital product or platform.
CIAM manages customer identities broadly, often as individuals who register and maintain their own accounts. B2B IAM adds the organization a person belongs to, the roles that apply within it and the administrators who manage access for that organization.
Workforce IAM manages your own employees and typically uses your HR systems as a source of truth. B2B IAM covers people from external organizations whose access depends on a customer, partner or other business context.
Both manage people who belong to external organizations. This page focuses on business customers using your product or platform. Partner IAM focuses on suppliers, service providers, resellers and collaboration partners working with your organization.
A customer organization represents a business customer as a group structure rather than a set of unrelated accounts. It can contain subsidiaries and locations, keeping members and roles in the correct organizational context.
cidaas B2B IAM connects roles to customer-group memberships. A person can hold a different role in each customer context, and selecting the active context determines which role applies.
cidaas B2B IAM supports onboarding and offboarding within the customer-group structure. Access recertification can be added with the Governance add-on where required. Removal can happen locally or through a connected customer lifecycle, depending on the integration model.
OpenID Connect and SAML support federation and Enterprise SSO. OAuth 2.0 authorizes API and resource access. SCIM, JIT provisioning, REST APIs, directory synchronization and webhooks can support integration depending on the setup.
Scroll to Top