← All articles

The Identity Fabric: Multi-Vendor IAM Without the Chaos

6 April 2026· 6 min read· Identity Fabric· Strategy· Architecture
The Identity Fabric: Multi-Vendor IAM Without the Chaos
Figure - the identity fabric: one governed capability layer over deliberate heterogeneity.Download diagram (SVG)

Working as the identity design authority for a group operating in more than a hundred countries teaches you one thing quickly: the single-vendor identity end state is a fantasy. Acquisitions, divestments, regional platforms and product history guarantee heterogeneity. The choice is not whether to have multiple identity technologies - it is whether they form a governed fabric or an accidental sprawl.

What a fabric actually is

An identity fabric is an architectural stance, not a product. It says: identity capabilities - authentication, federation, provisioning, governance, privileged access, policy decision - are defined as vendor-neutral services with contracts between them, and each capability is fulfilled by one or more platforms behind that contract. The fabric is the set of contracts, trust relationships and integration patterns; the vendors are replaceable tenants within it.

The non-negotiables

  • One authoritative source per attribute. Usually the HR platform for workforce identity. Every downstream system is a consumer, never a competing author.
  • Explicit trust topology. Federation relationships between identity domains are designed, documented and reviewed - never established ad hoc because a project needed SSO by Friday.
  • Protocol discipline. OIDC and SAML at the edges, SCIM for provisioning, and a stated deprecation path for anything legacy. The fabric’s strength is that its seams are standard.
  • Centralised policy, federated enforcement. Access policy is governed once; enforcement happens wherever the workload lives.
  • One governance plane. Whatever mix of IGA tooling you run, certification, JML and audit must present as a single coherent process to the business.

Vendor-agnostic is a skill, not a slogan

Fabric design demands architects who understand the patterns beneath the products - token flows, trust models, provisioning semantics - well enough to evaluate Okta, Ping, SailPoint, Saviynt or the Microsoft stack on fit rather than familiarity. That is also what keeps vendor selection honest: when the architecture is defined in capabilities and contracts, a platform swap is a migration, not a re-architecture.

Where to start

Draw the current state honestly: every identity store, every trust relationship, every provisioning flow, every place policy is decided. Most organisations have never seen that picture in one diagram. The gap between that picture and a deliberate fabric is your identity strategy - and unlike a slideware strategy, it comes with an executable backlog.

Have an identity challenge worth solving?

I take a small number of freelance and contract engagements each year.

Start a conversation