At a glance
Controls who can sign in and what they can do, for customers, agents and partners.
Key data
Receives from
- Channels
- Enterprise directory
Sends to
- Every BSS module (authorisation)
How it works
The main steps, end to end.
- 1User signs in with password, OTP or SSO
- 2Identity verified and session issued
- 3Roles and permissions checked per request
- 4Access logged for audit
- 5Identity changes and removals managed
Core Capabilities
What IAM provides across the platform
Authentication
- Username and password authentication for subscribers and agents
- Multi-factor authentication (MFA): OTP via SMS or email
- Step-up authentication for sensitive actions: payment change, account transfer
- Biometric authentication support for mobile app channel
- Account lockout and brute-force protection policies
- Password strength enforcement and rotation policies for agent accounts
Authorisation
- Role-based access control (RBAC) for all platform users and services
- Subscriber roles: standard, business, family group owner
- Agent roles: care agent, billing agent, sales agent, supervisor, admin
- Permission sets defined at resource level: read, write, approve, override
- Dynamic permission evaluation at request time — not cached
- Least-privilege principle enforced across all roles
Identity Management
- Subscriber identity lifecycle: registration, update, suspension, deletion
- Agent identity provisioning and deprovisioning on HR event
- Credential management: password reset, MFA device enrolment
- Identity linking: platform account linked to external identity provider
- Profile attributes: contact details, preferred language, notification preferences
API Access Control
- API key and OAuth token management for service-to-service calls
- Token validation at API gateway for every inbound request
- Scoped access tokens: each service receives only the permissions it needs
- Token expiry and rotation policies per API consumer type
- Rate limiting per API key to prevent abuse
SSO & Federation
- Single sign-on across self-care portal, mobile app and care tools
- Session sharing with configurable inactivity timeout
- Identity federation with external providers where required
- Token-based session: JWT issued on login, validated on each request
- Logout propagation: single logout invalidates all active sessions
Access Audit
- Every login, logout and authentication event logged with timestamp and device
- Failed authentication attempts tracked for anomaly detection
- Permission grant and revocation events recorded
- Privileged action audit: admin overrides, role assignments
- Audit log retained for configurable period for compliance review
Storage & Persistence
How and where IAM stores its data
Document Data Store
- Subscriber and agent identity documents
- Role and permission assignments
- MFA device enrolment records
- Session state documents
Credential Store
- Hashed password credentials — never plaintext
- API keys and service tokens (hashed)
- MFA seed values encrypted at rest
- Token signing keys with rotation policy
Audit Log Store
- Every authentication and authorisation event
- Failed login attempts and lockout events
- Role grant and revocation records
- Privileged action audit trail
Design Principles
Key architectural decisions behind IAM
RBAC at Every Layer
Role-based access control is enforced at the API gateway, at the service layer and at the data layer. Passing authentication does not guarantee authorisation — every request is evaluated against the caller's role and permissions at the time of the request, not at session start.
Zero Trust API Access
No service-to-service call is trusted by default. Every inter-service API call presents a scoped access token that is validated by the API gateway on every request. Tokens are short-lived and scoped to the minimum permissions needed for the calling service.
Immutable Audit Log
Every identity and access event is written to an immutable audit log that cannot be modified or deleted within its retention period. This provides an unalterable record of all authentication and authorisation decisions for security investigations and regulatory compliance.
Ask for extra verification only when a login looks unusual.
Spot credential stuffing and SIM-swap attacks.
More in 30 AI & ML use cases and AIOps for BSS.