Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
Passkey/WebAuthn support and no-code per-app configuration are current maturity signals; a platform requiring custom code for basic MFA toggling is weaker.
A concrete peak-load figure with a named customer event is stronger evidence than a generic "scales to millions of users" marketing claim.
Automatic downstream consent-withdrawal propagation is materially stronger than a consent record that only lives in the CIAM system with no enforcement elsewhere.
Real account-linking/deduplication logic is a meaningful differentiator; probe for how conflicts (e.g., same email, different social provider) are resolved.
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
Fully embeddable, brand-consistent UI is stronger for consumer-facing use cases where a redirect to an obviously third-party login page hurts trust/conversion.
Native multi-tenant isolation with per-tenant branding is a real differentiator over a single flat consumer identity pool with no tenant separation.
A concrete, customer-referenced fraud-reduction figure is stronger than a generic "advanced bot protection" claim.
Per-region configurable residency is stronger for a genuinely global consumer base than a single fixed data-residency region.
MAU-based pricing has real, well-known budget implications at consumer scale — ask for a concrete cost projection at realistic growth, not just an introductory-tier price.
Strong answers describe real mass-incident response capability at consumer scale with a customer example, not just standard per-account security features.
Ask for specific, named marketing/CDP integrations rather than a generic claim of downstream data propagation — real integration depth varies significantly by platform.
Forcing a mass password reset during migration causes real user friction and support burden — ask for a specific hash-migration or progressive-migration capability and a real customer timeline.
A CIAM outage is uniquely severe since it blocks the customer's entire revenue-facing consumer base, not just internal staff — ask for a real historical uptime track record, not just a contractual SLA number.
This is a genuine, often-overlooked compliance requirement for consumer-facing platforms with any plausible minor user base — a vendor should give a specific answer rather than assuming this doesn't apply.
Strong answers point to real SDKs and a customer-validated timeline for custom integration work, not just out-of-the-box UI component customization.
Trend-over-time reporting is a distinct capability from a real-time fraud dashboard — confirm this exists as a maintained, exportable report.