How to use the Digital Identity Technology Radar
Introduction
Technology is moving fast and new technologies and innovations appear continuously.
It's essential for a iC Consult as a consulting and technology company with focus on Identity and Access Managment to constantly improve and keep track with the latest useful innovations. It is important to openly look for innovations and new technologies and to question established technologies and methods every now and then.
But, it is also important to wisely choose which technologies to suggest to clients and use in the different projects we are carrying out. As we all know: There is no silver bullet.
What is the Digital Identity Technology Radar
The Tech Radar is an overview of different technologies - from standards, frameworks, tools and patterns to specific approaches - that we consider "new or mentionable". The radar therefore doesn't provide an overview of all established technologies - but it focuses on items that have recently gained in importance or changed.
How it is created
The items in the technology radar are raised by the different teams and therefore a lot of the items are related to the work and challenges the teams face in the different projects. In fact, we don't include anything on the radar, which we haven't already looked at ourselves at least once.
There have been a lot of valuable discussions in different expert groups about the classification and details of each of technologies and innovations. And the result of all this can be found in the latest technology radar.
Who creates the radar
The Digital Identity Technology Radar is maintained and curated by Kai and Max, who work together to ensure the radar stays current and relevant. They coordinate with the various teams and expert groups, gather input from ongoing projects, and synthesize the discussions and insights into the comprehensive overview you see here. Their dedication ensures that the radar reflects the collective knowledge and experience of iC Consult in the field of Identity and Access Management.

Kai Mindermann, M.Sc.
Kai Mindermann is the Head of the Center of Excellence (CoE) for Project Management and a Lead Consultant at iC Consult GmbH. With an M.Sc. in Computer Science and extensive hands‑on experience across multiple clients and projects, he blends deep technical expertise with pragmatic leadership. Kai champions governance and best‑practice adoption and is known for long‑term, cost‑benefit‑aligned delivery, balancing scalability, maintainability, and business impact to achieve sustainable outcomes in complex engagements.

Maximilian Schüle, B.Sc.
Maximilian Schüle is a working student at iC Consult GmbH. Maximilian holds a B.Sc. in Software Engineering and is currently pursuing an M.Sc. in the same field. Maximilian contributes to projects that integrate academic knowledge with practical application, supporting technical and organizational initiatives while gaining hands-on experience in a dynamic consulting environment.
How should it be used
The radar acts as an overview of technologies that we think everyone in the teams and through them our clients should currently know about.
Its goal is to act as a guide and inspiration for the daily work in the teams. Its purpose is also to provide helpful information and a bird's-eye perspective - so that decisions can be taken with a much deeper understanding of the subject matter. This results in more-informed and better-aligned decisions.
What is the Expected Impact?
Expected Impact refers to the anticipated outcome and influence that a particular technology is expected to have on an organization's operations, processes, and overall performance. It is an assessment of the potential benefits, changes, and value that the technology is projected to bring about upon its implementation and adoption. The expected impact serves as a crucial consideration in decision-making processes, as organizations evaluate and prioritize technologies based on their potential to drive positive transformations, optimize efficiency, enhance user experience, and ultimately contribute to the achievement of strategic goals. By understanding the expected impact, organizations can make informed decisions regarding the adoption and integration of technologies that align with their vision and objectives, paving the way for sustainable growth and success.
Higher Expected Impact: The technology is anticipated to revolutionize processes, drive substantial cost savings, and empower the organization with unparalleled efficiency and competitive advantage.
Normal Expected Impact: The technology is expected to deliver notable improvements in operational efficiency, streamline workflows, and enhance productivity within the organization.
Lower Expected Impact: While the technology may offer some incremental benefits, its overall impact on the organization is anticipated to be limited, with modest improvements in specific areas of operation.
Quadrants and Rings
The quadrants are:
- Access Management: Access Management quadrant covers technologies and strategies aimed at managing and securing user access to digital resources. Access Management solutions encompass authentication mechanisms, such as Single Sign-On (SSO) and multi-factor authentication (MFA), to verify user identities. They also provide authorization capabilities, including fine-grained access controls, policy-based access management, and dynamic authorization frameworks. Access Management solutions help organizations enforce access policies, reduce identity-related risks, improve user experience, and ensure appropriate access to resources across diverse systems and applications.
- Identity governance and administration (IGA): Identity Governance and Administration (IGA) quadrant encompasses technologies, processes, and practices that enable organizations to effectively manage and govern digital identities and their access rights. IGA solutions facilitate identity lifecycle management, including user provisioning, deprovisioning, and modification processes. They also provide capabilities for managing entitlements, roles, and access policies to ensure consistent and compliant access control. By implementing IGA solutions, organizations can streamline identity-related processes, improve visibility and accountability, and enhance security and compliance posture.
- Privileged Access Management (PAM): Privileged Access Management (PAM) quadrant revolves around technologies and practices aimed at securing and managing privileged accounts and access. PAM solutions provide robust mechanisms to control and monitor privileged user activities, reduce the attack surface, and prevent unauthorized access to critical systems and data. Key components of PAM include password vaults, privileged session management, least privilege enforcement, just-in-time access, and privileged access analytics. By implementing PAM solutions, organizations can mitigate insider threats, enforce least privilege principles, and enhance the overall security and compliance of their IT infrastructure.
- Identity Security: Identity Security quadrant encompasses technologies and measures designed to protect digital identities, secure identity-related processes, and safeguard identity data. Identity Security solutions include technologies like identity-based encryption, biometric authentication, identity-based firewalls, and identity-based threat detection and prevention. These solutions aim to strengthen the security of identity-related operations, mitigate identity-related risks and fraud, and protect sensitive identity information. By focusing on Identity Security, organizations can enhance the confidentiality, integrity, and availability of their identity management processes and safeguard the trustworthiness of digital identities.
Each of the items is classified in one of these rings:
- Adopt: We can clearly recommend this technology. It has been used for longer period of time at many customers and it has proven to be stable and useful.
- Trial: We have used it with success and recommend to have a closer look at the technology in this ring. The goal of items here is to look at them more closely, with the goal to bring them to the adopt level.
- Assess: We have tried it out and we find it promising. We recommend having a look at these items when you face a specific need for the technology in your project.
- Hold: This category is a bit special. Unlike the others, we recommend to stop doing or using something. That does not mean that they are bad and it often might be ok to use them in existing projects. But we move things here if we think we shouldn't do them anymore - because we see better options or alternatives now.
Based on the Open Source AOE Tech Radar: AOE Tech Radar on Github