Leading enterprises trust cidaas
From SMEs to large international corporations – cidaas protects millions of digital identities across Europe.
Partner identities do not fit into Workforce IAM
Employee identities are connected to internal HR and workforce identity processes. A hire, a transfer and a departure all originate in systems your company runs, and access follows from there.
Partner users belong to external organizations. A Partner and Supplier IAM for external partner and supplier identities needs to reflect organizational structures, staffing decisions and the responsibility each organization has for who works on your business.
They are also more than unrelated consumer accounts: Company, location, role and the business relationship itself can all affect what a partner user is allowed to see and do.
You define the framework.
Your partners manage within it.
Delegated Administration is a core product of Partner Access Management. Delegation is not a transfer of control. Your company sets the boundaries and the rules: which organizations exist, which roles are available, which policies apply and which administrative actions a partner is permitted to perform.
Inside that scope, one or multiple partner administrators handle the operational Partner User Management. They see their own organization and nothing beyond it.
One Partner IAM framework
Different ways to bring identities in.
Partner organizations differ in size and in the identity infrastructure they run. A partner can register users through self-service, receive invitations from their own administrator, or connect an existing Identity Provider.
These paths can coexist across your ecosystem and even within a single partner. Whatever the entry point, the identity lands in the same organizational framework and is governed by the same roles and policies.
Invitation
The partner admin invites a colleague, who is assigned to the partner group automatically.
Self-registration with approval
The person registers, the partner admin approves.
Federated login
Just-in-time account creation at the partner identity provider (Partner SSO).
Identity Layer
Partner SSO: Sign in with the account they already have
With Partner federation over OpenID Connect, OAuth2 or SAML connects partner access more closely to the IAM lifecycle a partner already operates. People sign in with their existing work account, and the partner keeps responsibility for the credentials.
Depending on the integration model, changes in the partner identity system can affect authentication, the information available at onboarding, authorization context and access to connected applications.
The account the person already uses at work.
One identity. Multiple partner contexts.
External work rarely maps to a single relationship. Partner IAM needs to differentiate, which organization a person is acting for, what their role is in that context, and which resource they are trying to reach.
Control access throughout the Partner IAM lifecycle
Partner Lifecycle Management covers the complete journey from onboarding and authentication to authorization, user management, access reviews and offboarding.
Check the verified organization and verify the user through self-services or federation. Accounts can be activated directly from the portal. This process is invitation-based.
One-time passwords by email or phone, push notifications, authenticator apps, mobile biometrics and FIDO certified authenticators including passkeys.
Role, attribute and Policy-based Access Control . The group type defines the available roles.
Manage partner users throughout their lifecycle, including changes to roles, group memberships and access rights.
Multi-step approvals, segregation of duties and access recertification.
For federated partners, deactivating the user at the partner’s identity provider automatically removes access to connected applications. Otherwise the partner admin removes the user, and session timeouts apply.
cidaas Partner IAM capabilities
Organizations & Groups
Model partner companies, sites and teams as first class structures, so access follows the way your ecosystem is actually organized.
Delegated Administration
Let one or multiple partner administrators manage their own users inside the scope you define, without opening up your own environment.
Enterprise Federation
Connect a partner Identity Provider over OpenID Connect, OAuth2 or SAML so people sign in with the account they already use at work.
Contextual Authorization
Use organizational context alongside roles, so access reflects the relationship a person is acting in.
Lifecycle & Governance
Cover onboarding, change and removal of partner access. Approval workflows and recertification are available as a Governance Add-On.
Identity & Business Verification
Confirm who is registering and which organization they belong to before external users reach your applications.
Partner IAM use cases across your business ecosystem
A maintenance firm gets access for the duration of a job.
A supplier manages people and access for all of your locations.
An agency manages its own advisors, and each one works with the permissions their role allows.
A system integrator works in several customer tenants with different permissions in each.
Part of a recognized B2B IAM platform
Partner IAM is one of the scenarios supported by the broader cidaas B2B IAM platform. In the KuppingerCole Leadership Compass B2B IAM 2026, cidaas is recognized as Overall Leader, Product Leader and Innovation Leader.
Why choose cidaas Partner IAM?
European platform
Hosted in the EU, ISO 27001 certified.
Open standards
OpenID Connect, OAuth2, SAML, SCIM and REST, so nothing is locked to one vendor.
Recognized by analysts
Overall Leader, Product Leader and Innovation Leader in the KuppingerCole Leadership Compass B2B IAM 2026.
One platform
Partner access, customer identities and workforce identities on the same platform.
Scale partner access without losing control
Create secure access for external organizations while keeping policies, administrative boundaries and authorization under your control.











