Overview
Identity and access management is the part of an enterprise platform where a design mistake is not an inconvenience, it is an incident. Give someone too little access and they file a ticket. Give them too much and nobody finds out until it matters.
At Nutanix I design IAM for Prism Central, the console customers use to run their private cloud. The model is small enough to say in one line: access is a user, plus a role, plus a scope. Who they are, what they are allowed to do, and which slice of the infrastructure they are allowed to do it on. Almost every problem in this case study comes from the gap between how simple that sentence is and how hard the product makes it to answer.