Saving the World with User-centric Identity.

Missing: Privileged Account Management for the Social Web.

This year at SXSW I moderated a panel about OpenID, OAuth and data portability in the Enterprise. We had a community lunch after the panel, and walking back to the convention center, I had an insight about a key missing piece of software - Privileged Account Management (PAM) for the Social Web - how are companies managing multiple employees logging in to their official Twitter, Facebook and YouTube accounts?

I thought I should also explain some key things to help understand conventional PAM then get to social web PAM in this post covering:

  1. regular identity management in the enterprise,
  2. regular Privileged Account Management in the enterprise
  3. Privileged Account Management for the Social Web.


1) IdM (Identity Management) in the Enterprise

There are two words you need to know to get IdM and the enterprise: "provisioning" and "termination".

a) An employee is hired by a company. In order to login to the company's computer systems to do their work (assuming they are a knowledge worker), they need to be provisioned with an "identity" that they can use to log in to the company systems.

b) When an employee leaves (retires, quits, laid off, fired), the company must terminate this identity in the computer systems so that the employee no longer has access to these systems.

The next thing to understand is logs.

So, an employee uses the company identity to do their work and the company keeps logs of what they do on company systems. This kind of logging is particularly important for things like accounting systems - it is used to audit and check that things are being accurately recorded, and who did what in these systems is monitored, thus addressing fraud with strong accountability.

I will write more about other key words to understand about IdM in the enterprise (authentication, authorization, roles, directories) but I will save these for another post.

2) Ok, so what is Privileged Account Management in the Enterprise?

A privileged account is an "über"-account that has special privileges. It is the root account on a UNIX system, a Windows Administrator account, the owner of a database or router access. These kinds of accounts are required for the systems to function, are used for day-to-day maintenance of systems and can be vital in emergency access scenarios.

They are not "owned" by one person, but are instead co-managed by several administrators. Failure to control access to privileged accounts, knowing who is using the account and when, has led to some of the massive frauds that have occurred in financial systems. Because of this, the auditing of logs of these accounts are now part of compliance mandates in

  • Sarbanes-Oxley
  • the Payment Card Industry Data Security Standard (PCI DSS),
  • the Federal Energy Regulatory Commission (FERC),
  • HIPAA.

Privileged Account Management (PAM) tools help enterprises keep track of who is logged into a privileged account at any given time and produce access logs. One way this software works is: an administrator logs in to the PAM software, and it then logs in to the privileged account they want access to. The privileged account management product grants privileged user access to privileged accounts [1].

Links to articles on PAM, [1] Burton Group Identity and Privacy Blog, KuppingerCole, Information Security Magazine.

3) Privileged Account Management on the Social Web.

Increasingly companies have privileged accounts on the social web. Dell computers has several for different purposes. Virgin America, (they link to the account from their website - thus "validating" that this is their real account), JetBlue, Southwest Airlines, Zappos CEO, (employees who twitter), Comcast Cares (Frank Eliason) (interestingly comcast on twitter is blank).

Twitter is just the tip of the iceberg - there are also "fan pages" on Facebook for brands. Coca-Cola, Zappos, NYTimes, Redbull, Southwest, YouTube Channels, Dunkin' Donuts, etc, etc. on thousands of other platforms and yet-to-be-invented services.

These are very powerful accounts - they are managed and maintained by many employees around the clock and are the public voices of companies.

I have yet to see or hear of any software tools to enable enterprises to manage Social Web privileged accounts. How are companies managing access by multiple employees to these accounts?

Is there software that does this yet?

Is anyone working on these kinds of tools?

Leave your comments here or tweet with me @identitywoman

Digg This
Reddit This
Stumble Now!
Buzz This
Vote on DZone
Share on Facebook
Bookmark this on Delicious
Kick It on DotNetKicks.com
Shout it
Share on LinkedIn
Bookmark this on Technorati
Post on Twitter
  • Share/Bookmark

Related posts:

  1. Yet another BaseCamp Account
  2. Higgins opens up
  3. Legal Haze for Social networks. Identity and Freedom of Expression.
  4. Peeling back the twitter layers
  5. International Telecommunications Union Focus Group on Identity Management

Printed from: http://www.identitywoman.net/missing-privilidged-account-management-for-the-social-web .
© Kaliya Young Hamlin 2010.

3 Comments   »

  • Matt Flynn says:

    Interesting question. Is there a reason traditional PAM solutions wouldn't help with social web apps?...I would've assumed they can handle these the same as any other apps.

  • Matt Flynn says:

    Oh, and apps like Chatterbox should help. I actually think it's preferable to have individual contributers rather than a master account - I think that approach is more in-line with what will be effective in social media. Chatterbox would allow multiple support reps to monitor, share, discuss internally and post from a single Twitter account.

  • bonj says:

    Specific to Twitter, I like HootSuite. I just upgraded to version 2.0, which came out this week. 2.0 didn't really change much in regards to account management, which was already good, but the interface is more TweetDeck like, yet within your browser. As you are really managing HootSuite accounts, the Twitter Account credentials are not given to users, yet HootSuite allows one access to post to Twitter Profiles, based upon how accounts are administered in HootSuite. You can checkout their video tour http://ow.ly/iBUh of 2.0.

RSS feed for comments on this post , TrackBack URI

Leave a Reply

  • Latest Tweets


    • She's Geeky NYC registration is LIVE!!! super early bird only lasts for a week http://bit.ly/bKOUxl 2 days ago

    • @pamelarosiedee has a post inspired by the lastest women in technology kerfullful. http://bit.ly/dCwFrL 2 days ago

    • I just posted more information about or DC venue for IIW - http://bit.ly/cja7SP 3 days ago

    • "Help" I am saving illustrator images as Jpg. that start out white then turn grey-black. what to do? 5 days ago

    • hi @RobBonta thanks for the follow cause I live in Alameda. Bad news is I can't vote I am Canadian (for now). 5 days ago

    • I went to your site @redjotter and like what I see there. I think focus on service design will be key for "identity" & #vrm services 5 days ago

    • @jayhori you mean the one in NYC? we are still trying to find a venue that doesn't cost the moon. 7 days ago

  • Archives

    • 2010 (16)
    • 2009 (82)
    • 2008 (112)
    • 2007 (167)
    • 2006 (300)
    • 2005 (189)
  • Categories

    • Active Clients (1)
    • Art (1)
    • Articles in other Publications (1)
    • Biometric (2)
    • Books/Papers on ID (7)
    • Business Cases (2)
    • Canada (5)
    • Community (1)
    • Community Dinner (2)
    • Community Management (2)
    • Digital Death (1)
    • Electronic Beacons (1)
    • Enterprise ID (1)
    • Environment (2)
    • Event Annoucements (11)
    • Event Review (7)
    • Facebook (4)
    • Facilitation (1)
    • Freedom (1)
    • Future (11)
    • Government (7)
    • ID Protocol (10)
    • Identitification (6)
    • Identity Commons (5)
    • Identity Gang (9)
    • Identity Layer (4)
    • Identity Rights (7)
    • IIW (14)
    • Industry Commentary (9)
    • Industry Developments (16)
    • Innovation (5)
    • Interesting (7)
    • interop (3)
    • Kids (1)
    • Legal Cases (4)
    • Legislation-Regulation (2)
    • me (6)
    • Media Commentary (5)
    • Media Coverage (2)
    • Mobile (1)
    • National ID (7)
    • Non-US (2)
    • NPTech (2)
    • Open Source (3)
    • Past Lessons (5)
    • Physical Devices (2)
    • Presos/Podcasts/Videos (19)
    • Privacy (14)
    • Representational Systems (1)
    • reputation (3)
    • Reputation Currents (2)
    • She’s Geeky (2)
    • Social Implications (2)
    • Social Network (7)
    • Tool Usage (9)
    • Uncategorized (771)
    • unconferences (2)
    • User Centrism (3)
    • Virtual World (1)
    • visionary (1)
    • What is Identity? (6)
    • Women (3)