Vittorio Ciabatti

The perimeterhas dissolved.

Identity SecurityArchitecture

Identity fabricHuman, workload, device, and application identities combine with context and policy to govern access to resources.HUMANIDENTITYDEVICEAPPLICATIONCONTEXTPOLICYRESOURCEDECISION

I design Identity Security architectures for complex enterprise environments with a vendor-aware, vendor-neutral approach.

Identity becomes
the control plane.

Explore the architecture
IdentityContextTrustPolicyAccess

01 — Identity fabric

Security no longer begins at the boundary.

It begins with a relationship: who or what is requesting access, under which context, governed by which policy.

02 — Capabilities

Controls built on relationships.

Authentication, authorization, governance, and privilege are not isolated products. They are connected decisions that must remain understandable and operable.

01
Authentication
Sign-in flows, context-aware MFA, passwordless, and federation.
Okta / Entra ID / Ping Identity
02
Authorization
Access policy combining identity, resource, context, and risk.
Conditional Access / Zero Trust
03
Governance
Lifecycle, access reviews, and identity control across complex environments.
Okta / Entra ID / SailPoint
04
CIAM
B2B and B2C architecture for digital access, partners, and customer journeys.
Adaptive MFA / Federation
05
Automation
Repeatable provisioning, configuration, and control of Identity infrastructure.
Terraform / Docker / Ansible

03 — Portfolio

Decisions that hold at scale.

Four anonymized case studies: scale, architecture decision, control model, and outcome—with no generic project theatre.

Portfolio readout

Migration, workforce identity, CIAM, and governance: four distinct problems, one control discipline.

Identities migrated
30,000+
Countries on one lifecycle model
15
Integrated SaaS applications
500+
Identity contexts
B2B / B2C / WORKFORCE
01Workforce migration
  • Migration strategy
  • Lifecycle automation
  • Authentication readiness

Enterprise identity consolidation

Migration of more than 10,000 identities from a legacy IdP to Microsoft 365, with automated provisioning and a zero-downtime cutover.

Key decisionA controlled lifecycle migration with separate readiness gates for provisioning, authentication, and access policy.
Open case study
Scope
10,000+ workforce identities
Control plane
Microsoft Entra ID
Outcome
Zero-downtime cutover
02Global workforce identity
  • SSO
  • Lifecycle automation
  • SaaS provisioning

Global workforce SSO and automation

Okta Workforce Identity Cloud architecture for an international fashion company: lifecycle automation across 15 countries and provisioning to 500+ SaaS applications.

Key decisionCentral identity policy with lifecycle rules separated from connectors and local application differences kept at the edge.
Open case study
Reach
15 countries
Application estate
500+ SaaS
Controls
Okta / SSO / Provisioning
03Customer and partner identity
  • CIAM
  • Adaptive MFA
  • Federation

CIAM platform for the cruise sector

Dual-tenant B2B and B2C CIAM architecture for guest portals and partner integrations, with adaptive MFA and fraud detection.

Key decisionSeparate trust domains for guests and partners, with risk-based step-up applied only where context requires it.
Open case study
Audience
Guests and partners
Model
B2B + B2C tenants
Controls
Adaptive MFA / Fraud signals
04Access governance
  • Permission analysis
  • Access reviews
  • Policy enforcement

Unstructured data governance

SailPoint File Access Manager programs for permission analysis and governance across file servers, automated access reviews, and policy enforcement.

Key decisionA permission graph connecting identities, groups, resources, and accountable owners before remediation begins.
Open case study
Scope
Enterprise file servers
Platform
SailPoint FAM
Controls
Reviews / Policy enforcement

What the portfolio demonstrates

The ability to connect authoritative sources, lifecycle, policy, and operations into Identity architectures that remain explainable and operable.

Discuss the work

04 — Evidence

Technology in context. Credentials as proof.

Infrastructure and automation

Tools in service of control.

  • Terraform IaC
  • Docker Containerization
  • Ansible Configuration

Verified credentials

Evidence, not decoration.

  • Okta Certified Consultant Okta
  • Okta Certified Developer Okta
  • Thales OneWelcome Advanced Engineer Thales

05 — Signals

Signals in the noise.

Identity Security, architecture, AI, systems, and humans: a map of ideas, not a feed.

06 — Contact

Start a technical conversation.

Questions about Identity architecture, Zero Trust patterns, or vendor-neutral notes? This channel is for professional discussion.

LinkedIn ↗