Partner Identity & Access Management

Partner IAM –
Your business depends on people you do not employ

Partner IAM gives suppliers, service providers, resellers and integration partners secure access to the applications they need. You define the rules and organizational framework. Your partners manage their users within it.

Delegated Administration
Partner Federation
Contextual Authorization
Lifecycle & Governance

Leading enterprises trust cidaas

From SMEs to large international corporations – cidaas protects millions of digital identities across Europe.

Kaufland – cidaas customer
Hornbach – cidaas customer
Takko Fashion – cidaas customer
Europa Park – cidaas customer
ProSiebenSat.1 – cidaas customer
REHAU – cidaas customer
RATIONAL AG – cidaas customer
1. FSV Mainz 05 – cidaas customer
EWE AG – cidaas customer
SachsenEnergie – cidaas customer
Creditplus Bank – cidaas customer
die Bayerische – cidaas customer
THE INITIAL SITUATION

Partner identities do not fit into Workforce IAM

YOUR APPLICATIONS
Ordering portal
Service portal
Partner portal
Identity Layer
Group types
Roles
Policies
PARTNER ORGANIZATIONS
Supplier
Invitation
Reseller
Self-registration
Service partner
Federated login
Delegated User Administration
YOUR CONTROL PLANE
Control
Group type
defines which roles may be assigned
ROLE MODES
Predefined
Allowed roles
Any role
Inherit
API SCOPE
cidaas:delegated_admin
PARTNER ADMIN UI
Invite or add users
View users and user activities
Assign permissions
Delete users
USER
ROLE
ACTIONS
User A
Assigned role
⋯
User B
Assigned role
⋯
User C
Assigned role
⋯

One Partner IAM framework

Different ways to bring identities in.

Invitation

The partner admin invites a colleague, who is assigned to the partner group automatically.

Self-registration with approval

The person registers, the partner admin approves.

Federated login

Just-in-time account creation at the partner identity provider (Partner SSO).

OpenID Connect
OAuth2
SAML
One framework

Identity Layer

ESTABLISHES
Group
Roles
Policies

One identity. Multiple partner contexts.

An integration partner supports several platform customers.
A service company supports multiple sites or business units.
A logistics provider operates in several supplier relationships.
GROUP SELECTION AT LOGIN
One person
Works for an integrator partner
Customer A
Technical admin
Customer B
Ticket agent
Customer C
Read only
ACCESS IN THE SELECTED GROUP
Customer A
Tenant configuration
User administration
Tickets
Data of other customers
PARTNER LIFECYCLE MANAGEMENT

Control access throughout the Partner IAM lifecycle

Partner Lifecycle Management covers the complete journey from onboarding and authentication to authorization, user management, access reviews and offboarding.

01 Onboard

Check the verified organization and verify the user through self-services or federation. Accounts can be activated directly from the portal. This process is invitation-based.

02 Authenticate

One-time passwords by email or phone, push notifications, authenticator apps, mobile biometrics and FIDO certified authenticators including passkeys.

03 Authorize

Role, attribute and Policy-based Access Control . The group type defines the available roles.

04 User Management

Manage partner users throughout their lifecycle, including changes to roles, group memberships and access rights.

05 Review IGA (Add-On)

Multi-step approvals, segregation of duties and access recertification.

06 Offboard

For federated partners, deactivating the user at the partner’s identity provider automatically removes access to connected applications. Otherwise the partner admin removes the user, and session timeouts apply.

cidaas Partner IAM capabilities

Organizations & Groups

Model partner companies, sites and teams as first class structures, so access follows the way your ecosystem is actually organized.

Delegated Administration

Let one or multiple partner administrators manage their own users inside the scope you define, without opening up your own environment.

Enterprise Federation

Connect a partner Identity Provider over OpenID Connect, OAuth2 or SAML so people sign in with the account they already use at work.

Contextual Authorization

Use organizational context alongside roles, so access reflects the relationship a person is acting in.

Lifecycle & Governance

Cover onboarding, change and removal of partner access. Approval workflows and recertification are available as a Governance Add-On.

Identity & Business Verification

Confirm who is registering and which organization they belong to before external users reach your applications.

Partner IAM use cases across your business ecosystem

MECHANISM
Time-limited access
Industry and mechanical engineering

A maintenance firm gets access for the duration of a job.

MECHANISM
Delegated admin
Retail and wholesale

A supplier manages people and access for all of your locations.

MECHANISM
Delegated administration
Insurance and financial services

An agency manages its own advisors, and each one works with the permissions their role allows.

MECHANISM
One identity, multiple contexts
SaaS

A system integrator works in several customer tenants with different permissions in each.

2026 LC Label CIAM

Why choose cidaas Partner IAM?

European platform

Hosted in the EU, ISO 27001 certified.

Open standards

OpenID Connect, OAuth2, SAML, SCIM and REST, so nothing is locked to one vendor.

Recognized by analysts

Overall Leader, Product Leader and Innovation Leader in the KuppingerCole Leadership Compass B2B IAM 2026.

One platform

Partner access, customer identities and workforce identities on the same platform.

Scale partner access without losing control

Create secure access for external organizations while keeping policies, administrative boundaries and authorization under your control.

FAQs: Partner IAM

Partner IAM is identity and access management for people who work for external organizations such as suppliers, service providers, resellers and integration partners. Your company defines the organizations, roles, policies and applications, and partner administrators manage their own users within that framework.
B2B IAM is the broader platform capability for managing identities that belong to other companies. Partner IAM focuses specifically on partner organizations in your business ecosystem, which can be suppliers, providers and other partners.
Workforce identities are connected to internal HR and workforce processes. Partner users belong to external organizations with their own structures and responsibilities, and their access can depend on company, location, role and the business relationship, which internal workforce processes do not describe.
Delegated administration means one or multiple administrators at a partner organization perform operational user management inside a scope you define. You set the organizational boundaries, available roles, policies, applications, security requirements and permitted administrative actions.
Yes. A person can act for several partner organizations, for example an integration partner supporting several platform customers. Partner IAM evaluates which organization the person is acting for, their role in that context and the resource being accessed.
Users can be onboarded through self-service, invitation or federation. Access can be removed locally by a partner administrator or connected to the partner's own identity lifecycle. Which offboarding signals are available depends on the integration model in place.
Additional approval workflows and access recertification are available as a governance add-on, and can be applied where partner access needs periodic confirmation.
OpenID Connect, OAuth2 and SAML can be used to connect a partner Identity Provider to Partner IAM and to the applications behind it.
Partner IAM fits when external organizations need access to your applications, when those organizations should manage their own users, and when access decisions depend on organizational context such as company, site or business relationship.
Scroll to Top