2 Days. 10+ Experts. Countless IAM & GRC Insights. Register for NEXIS INVOLVE | September 9-10 | Regensburg

IAM

From Research to Practice: Advancing Identity and Access Management at Nexis

21 Jul 2026
Dr. Thomas Baumer
Dr. Thomas Baumer Senior Software Engineer

Identity and Access Management (IAM) is key to modern cybersecurity, but remains challenging. My dissertation, conducted with Nexis, targets three research areas: Interoperability, Quantification, and Access Reviews, aiming to connect research with practice.

This article provides an overview of key results and discusses their impact on both industry and science, while considering emerging trends shaping the future of IAM.

Why This Research Matters

At its core, IAM seeks to answer the question: “Who can access what?”. In practice, organizations contend with complexity, regulatory pressure, and distributed knowledge.

My work tackles these challenges by structuring IAM improvements along three dimensions:

  • Interoperability → Connecting IAM services and data.
  • Quantification → Measuring and steering IAM performance.
  • Access Reviews (Usability) → Improving human decision-making.

Interoperability: Connecting the IAM Ecosystem

Key Results

Modern IAM systems are distributed. My research shows interoperability is essential for scalable IAM.

Contributions

  • Extension of the SCIM standard to support access management and RBAC.
  • Formalization and integration of transaction logs as a valuable IAM data source.
  • Definition of design principles for IAM APIs: validity, simplicity, and flexibility.

Key Insight

Interoperability must go beyond simple data exchange—it requires a shared understanding of IAM data models across systems.

Industry Impact: The results reduce integration costs for IAM vendors and customers while enabling Identity Fabric architectures that seamlessly orchestrate multiple IAM services. In addition, the work provides actionable blueprints for real-world implementations, which have already been validated through case studies.

Scientific Contribution: The research delivers the first structured combination of SCIM, RBAC, and real-world vendor practices. It also establishes a formal grounding of transaction logs as a reliable analytical foundation for IAM.

Quantification: Making IAM Measurable

Key Results

IAM is generally perceived as complex and opaque. My research shows that systematic quantification, when aligned with business goals, can address this perception.

Contributions

  • Identification of 16 measurable quality properties for access control policies (ACPs, rules defining who can access what).
  • Comprehensive survey of 43 IAM metrics, aligned with strategic goals and audiences.
  • Mapping between metrics, goals, and stakeholders.

Key Insight

Quantification is not just about metrics—it is about strategic alignment. Metrics only create value when they are tied to goals, like security, compliance, operational efficiency, and overall quality.

Industry Impact: The results enable data-driven IAM governance and align IAM practices with established frameworks such as ITIL or COBIT. They also provide a common language that bridges the gap between technical and business stakeholders.

Scientific Contribution: The research introduces the first holistic framework linking IAM goals, metrics, and audiences, and establishes access control policy (ACP) quality as a form of data quality, thereby opening new directions for future research.

Access Reviews: Improving Human Decision-Making

The Problem

Access reviews are a cornerstone for compliance with IGA-relevant regulations, but they are highly inefficient: Only 1.2% of access rights are revoked in real case studies, despite ~22.8% being expected to be excessive.

Key Results

My research treats access reviews as a usability challenge. Design improvements can significantly boost outcomes.

Contributions: The research formalizes the Access Review Problem (ARP) and introduces as well as evaluates digital nudges, specifically choice defaults and identity grids.

Key Findings: Identity grids significantly improve decision accuracy and consistency, while choice defaults steer decisions toward more secure outcomes. However, these improvements come with trade-offs, as they increase time consumption and cognitive load.

Additional Practical Insight: A threshold-based formula enables the detection of low-quality access reviews even without ground truth by estimating the amount of excessive authorizations. Furthermore, limiting the number of revokes helps prevent decision degradation.

Industry Impact: The results are directly applicable to IAM products and have already been implemented at Nexis, leading to improved compliance and reduced risk. They also enable scalable human-in-the-loop security by supporting more effective and structured decision-making processes.

Scientific Contribution: The research establishes access reviews as a measurable and comparable research domain and provides experimental evidence demonstrating the effectiveness of behavioral interventions in cybersecurity.

Bridging Industry and Science

A main theme is translating research insights into practical solutions.

For Industry: The work provides concrete design artifacts, including APIs, metrics, and UI patterns, and demonstrates validated improvements through real-world case studies. It also ensures immediate applicability in IAM platforms such as those developed by Nexis.

For Science: The research introduces formal models and frameworks covering IAM interoperability, IAM metrics and governance, and access review usability. In addition, it contributes empirical evidence derived from user studies and close collaboration with industry.

This dual contribution is critical. Many IAM challenges remain unsolved, not because of a lack of theory but because of a lack of integration between research and practice.

Looking Ahead: Trends Shaping IAM

AI Agents

We observe a rise in AI agents, IoT devices, and Machine identities. These developments require a comprehensive reevaluation of IAM. Non-human entities behave differently from humans, demanding new identity models and governance approaches.

Identity Fabrics

IAM is moving toward orchestrated ecosystems. Multiple services should connect via standardized APIs towards real-time data sharing across systems. This trend reinforces the importance of interoperability, as explored in this dissertation.

Evolution of Access Reviews

Access reviews will likely evolve by integrating AI and more advanced analytics, supported by improved UX through behavioral design and automation. Despite these improvements, access reviews remain tedious and imperfect, underscoring the need for ongoing research.

Conclusion

This dissertation demonstrates that advancing IAM requires a holistic approach:

  • Interoperability enables scalable architectures.
  • Quantification provides transparency and control.
  • Access Reviews ensure human decisions remain effective.

These contributions demonstrate the direct effect of research developed in partnership with Nexis.

As IAM continues to evolve, the intersection of data, humans, and intelligent systems will define the next generation of solutions. This work lays a foundation for that future.