Anonymized architecture · Customer and partner identity

CIAM platform for the cruise sector

Dual-tenant B2B and B2C CIAM architecture for guest portals and partner integrations, with adaptive MFA and fraud detection.

Audience
Guests and partners
Model
B2B + B2C tenants
Controls
Adaptive MFA / Fraud signals
Guest or partner → Context and risk → Adaptive policy → Digital services
Guest or partnerDigital services

Architecture focus

Separate trust domains for guests and partners, with risk-based step-up applied only where context requires it.

Demonstrated capabilities

  • CIAM
  • Adaptive MFA
  • Federation

Decision log

01

The challenge

Guest journeys and partner operations shared digital services but required different trust models. The architecture needed to protect high-risk actions without turning every interaction into authentication friction.

02

Architecture decision

B2C and B2B populations were separated into dedicated tenants while sharing explicit integration contracts. This kept lifecycle, consent, and federation concerns distinct without duplicating the service layer.

03

Control model

Adaptive MFA combined identity context, transaction sensitivity, and fraud signals. Step-up controls were applied where risk increased, while lower-risk journeys remained lightweight.

04

Outcome

The dual-tenant model created a clear boundary between guest and partner identities while enabling a consistent access experience across portals and integrations.

Next project · 04Unstructured data governance