How Human-Centered Research Improves IAM

TL;DR
Human-centered research improves identity and access management by revealing usersβ goals, behaviors, needs, and working contexts before teams commit to a solution. Applying research during strategy, configuration, development, and measurement can expose ineffective concepts early, reduce risks such as low adoption and security workarounds, and help teams design actionable tools for enterprise users.
Transcript
Good afternoon, everyone. Our next session is the Value of Human-Centered Research in Identity and Access Management. Um, before I turn it over to the speakers, just a couple of quick housekeeping, um, reminders. Right after this session, we have another one coming up, so if you could please, um, exit the room and the speakers can definitely take q... Read More
Key Insights
- Human-centered research is the study of usersβ needs, goals, behaviors, preferences, expectations, and working contexts. It provides a broader foundation than software testing, usability testing, or measuring user satisfaction alone, especially when technology must operate within a complicated enterprise environment.
- Enterprise technology succeeds through both technical capability and attention to people. Employees bring expectations and habits shaped by the technology they use in everyday life, and those influences can significantly affect whether a mandated security policy produces its intended business outcome.
- Poorly understood user contexts can create low adoption, security workarounds, rework, business disruptions, and excessive help desk demand. Human-centered research helps mitigate these risks by investigating the people and circumstances affected before teams finalize configurations, deployments, or product designs.
- Research belongs throughout the development cycle. During exploration and strategy, teams identify users and needs. During configuration or development, they iteratively assess whether the design is appropriate. After release or deployment, they measure performance and use the findings to prioritize subsequent work.
- Enterprise security experiences should be user-centric rather than solely IT-centric. The examples cited by the presenters emphasize understanding business operations, recognizing data-quality challenges early, enabling painless migration, putting employees in control, and maintaining a strong focus on internal and external usability.
- Concept testing can reveal whether an apparently reasonable solution addresses the real problem. Interviews about the G Suite Security Center showed that proposed dashboards did not adequately help security administrators manage incidents because the information they displayed did not provide a clear action to take.
- Actionability is essential for a useful security dashboard. A security administrator confronted with a count of ninety-seven thousand unauthorized, unauthenticated messages questioned what could be done with that information, illustrating that visibility alone does not necessarily support incident management.
- Journey mapping is a visualization of the steps a user takes to accomplish a goal. It is particularly useful in enterprise research because it can capture every step and location involved in the work, including activities performed outside the product or system being studied.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: What is human-centered research in identity management?
Human-centered research investigates who the users are, what goals and needs they have, how they behave, and the contexts in which they perform their work. In identity and access management, it complements technical development by helping teams understand how people will experience security products, configurations, policies, and deployments. It is broader than software testing, usability testing, or an effort focused only on making users happy.
Q: Why does identity and access management need user research?
Identity and access management operates in an environment where employees and partners access company resources around the clock, from different locations and devices. Technical solutions alone do not account for usersβ preferences, expectations, goals, and behaviors. Research helps teams understand those factors before deployment, reducing the risk that a carefully implemented policy produces low adoption, security workarounds, rework, business disruption, or help desk overload.
Q: When should teams conduct human-centered research?
Teams should incorporate research throughout the development cycle. During exploration and strategy, research identifies users, needs, goals, behaviors, and context. During configuration or development, iterative studies assess whether the team is on the right track and whether the proposed design works. After release or deployment, measurement shows how the system is performing and provides evidence for prioritizing the next round of improvements.
Q: How is human-centered research different from usability testing?
Usability testing evaluates how effectively people can interact with a design, but human-centered research covers a wider set of questions. It examines who users are, what they are trying to achieve, how their work unfolds, and what environmental or organizational factors shape their behavior. Usability testing can be one useful method, but it cannot replace the foundational investigation needed to determine whether a team is solving the right problem.
Q: What problems can user research prevent in enterprise security?
User research can help teams avoid unintended outcomes such as low adoption, attempts to work around security controls, repeated implementation work, disruptions to business operations, and excessive demand on help desks. These problems can emerge when technology is configured or deployed without a sufficient understanding of users and their working environment. Research reduces that risk by connecting security decisions with actual behaviors, goals, needs, and expectations.
Q: Why were the proposed security dashboards not effective?
The dashboard concepts did not adequately help security administrators manage incidents because they were not actionable. They could display large volumes of security information, but users did not necessarily know what response to make. One administrator cited a figure of ninety-seven thousand unauthorized, unauthenticated messages and questioned what could be done with it. The finding showed that presenting information is insufficient when a tool does not support a clear next action.
Q: What is journey mapping in user-experience research?
Journey mapping is a visualization of the steps a user takes to accomplish a particular goal. The number of steps depends on the person and the activity being studied. In enterprise research, the method helps researchers examine the complete workflow, including where each step occurs and whether it happens inside or outside the product. This creates a more complete account of the userβs work than examining one interface in isolation.
Q: How can IT practitioners apply human-centered research?
IT practitioners can begin by identifying the people affected by a configuration or deployment and investigating their goals, needs, behaviors, and operating context. They can then evaluate concepts iteratively while configuring the system, checking whether the design supports real work and provides actionable information. After deployment, they can measure outcomes and use the evidence to decide what to improve next, rather than treating release as the end of the process.
Summary & Key Takeaways
-
Human-centered research goes beyond software testing, usability checks, or simply trying to make users happy. It examines who users are, what they need, how they behave, what goals they pursue, and the contexts in which they work. These findings help enterprise teams make better product and deployment decisions.
-
Research can support the full development cycle. Exploratory methods identify users and needs during strategy, iterative evaluation tests whether teams have chosen the right design during configuration or development, and post-release measurement shows how a deployed system performs and helps teams prioritize the work that should follow.
-
The G Suite Security Center case shows why early exploration matters. A team developed dashboard concepts to help security administrators manage phishing and oversharing risks, but concept interviews found that the dashboards presented large quantities of information without actionable guidance. The team therefore returned to foundational research and journey mapping.
Read in Other Languages (beta)
Share This Summary π
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity π






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator