3 ms·
I don't disagree, but fundamentally, you're talking about burden for IT operators. The opposite of burden is convenience, and that's fine to be charged for, in
by sebk 4y ago
I don't disagree, but fundamentally, you're talking about burden for IT operators. The opposite of burden is convenience, and that's fine to be charged for, in my book. An app implementing strong authentication might not offer a phishable password reset email, but rather have your password reset by an operator out of band, which is again, a burden.
I mention this in a sibling comment, but I think lumping SSO with lifecycle management for offboarding and profile syncinc is an example of convenience in lieu of security. You might be making an argument for SSO _and_ SCIM to be part of base subscription for enterprise software, and I wonder where does the line get drawn for what's tables takes. Are approval workflows required? What about anomaly detection? These features are not off the shelf commodities -- SSO might be closer to it, but SCIM and the other definitely aren't -- and making them table stakes raises the barrier to entry for every SaaS. Or, from a consumer perspective, if I'm a small operation that doesn't need that convenience, I'd rather not subsidize other customers that do when I get the base subscription.
> Former auth PM for a big SaaS
Then there's a good chance we've worked together :)
- haswell 4y ago> The opposite of burden is convenience, and that's fine to be charged for, in my book. If we zoom out a bit more, the entire product is about convenience. The customer pays for the product because they have a problem/burden that justifies the purchase of a product. But customers usually buy a product for the things that are unique about it. SSO is not one of those things and is trending towards commoditization. The fact that it affords additional convenience doesn't necessarily mean customers are willing to pay for that. SCIM is a bit more interesting, because it provides an abstraction layer over the things that are unique about a product. SCIM is also probably overkill for products with sufficiently simple offboarding needs. > You might be making an argument for SSO _and_ SCIM to be part of base subscription for enterprise software, and I wonder where does the line get drawn for what's tables takes SCIM hasn't reached the level of adoption (and customer expectation) that traditional forms of SSO have, and as a result I don't think it's in the table stakes conversation at this point. I think this will change over time if SCIM sees widespread adoption. From a customer perspective, a product without SSO can be a non-starter. A product without SCIM just means some additional integration/automation will be needed, or at worst, a manual process will be implemented around offboarding. > Then there's a good chance we've worked together :) This particular world is definitely a small one, so maybe! ;)