SAP Customer Identity
Last reviewed:
Registration, login, and consent that work, and that your legal and security teams will not reject. SAP Customer Identity, configured for B2C and B2B use cases.
Natively integrated: CRM to ERP, one data flow
Key capabilities
Single Sign-On (SSO)
One login across all your digital touchpoints: web, mobile, portal. Customers don't re-authenticate. You don't manage multiple identity stores.
Social Login
Google, LinkedIn, Microsoft, and Apple login in minutes. Reduces registration drop-off and gives you verified email addresses from day one.
Progressive Profiling
Collect customer data gradually over multiple sessions. No wall of fields on the first visit. You capture what you need, when it's appropriate to ask.
Consent & Preference Management
Marketing consents captured, stored, and synchronised to Emarsys and SAP CDP. GDPR and CCPA compliance built into the registration flow.
MFA & Risk-Based Authentication
Step-up authentication triggered by unusual login behaviour. Security that doesn't add friction for normal users.
API-First Integration
Headless identity layer that connects to any commerce, service, or marketing platform via REST APIs.
What is SAP Customer Identity and Access Management (CIAM)?
SAP Customer Identity and Access Management (CIAM) is SAP’s platform for customer registration, authentication, and consent: single sign-on, social login, MFA, progressive profiling, and auditable consent records for B2C and B2B. Built on the former Gigya platform, it is delivered as part of SAP Customer Data Cloud; the official SAP CIAM product page and SAP’s CIAM explainer are the canonical references.
Spadoom implements SAP Customer Identity for clients across Switzerland, Germany, Austria, and Italy, with the GDPR and Swiss nDSG consent layer designed in from day one. The rest of this page covers what we deliver, how CIAM differs from a CDP, and where the value of a well-run identity project comes from.
From the Medion project with SAP Customer Data Cloud. Read the case study.
What Spadoom delivers
Identity management is infrastructure. Getting it wrong costs you twice: lost conversions at registration and legal exposure when consent is not captured correctly.
Spadoom is an SAP Gold Partner with offices in Zug (headquarters) and Wädenswil, plus Cornate d’Adda near Monza (Italy), Vienna and Tallinn. We implement SAP Customer Identity for companies that need registration, login, and consent management integrated with their SAP CX stack. Our team delivers on-site across the DACH region and Northern Italy. No offshore handoffs.
Common scenarios we handle:
- A retailer deploying SAP Commerce Cloud who needs a proper login and consent system from day one
- A B2B distributor replacing a custom-built registration flow that has become a maintenance burden
- A brand operating multiple regional web properties that need unified identity across countries
- A company preparing for Swiss nDSG or EU GDPR audits and discovering that their consent records are incomplete
Identity also has an ERP side. A B2B login is only useful once it maps to the right business partner, sold-to account and price agreement in the ERP; otherwise the buyer logs in and sees the wrong prices, or none. Spadoom delivers SAP S/4HANA Public Cloud and the CX stack with one team, so that mapping is designed by the people who build both sides instead of being handed across a vendor boundary. Where it needs an extension, we build it on SAP BTP.
Our delivery follows the SAP Activate methodology, five phases from discovery through hyper-care, adapted for identity projects. Every implementation includes screen-set configuration, consent flow design, integration setup, and end-user testing with your legal and marketing teams.
For a broader look at how SAP’s identity and data tools fit together, our overview of SAP Customer Data Cloud covers the full CDC landscape, including where CIAM sits within it.
Customer Identity vs CDP: what’s the difference?
Customer Identity (CIAM) and the Customer Data Platform (CDP) often get bundled in the same sentence, but they own very different jobs. Most enterprises end up needing both, and confusing them is the most common architectural mistake we see.
Customer Identity is the front door. It handles the moment a stranger becomes a known customer, registration, login, social sign-in, password reset, MFA, and the moment they tell you what they’re comfortable with: marketing consent, data-processing consent, preference flags. It owns identity, authentication, and consent capture.
The Customer Data Platform is the engine room. It takes the identity and consent signals from CIAM, combines them with everything that person has ever done with you, orders, service tickets, browse behaviour, email engagement, and builds a unified, activate-ready profile. CDP owns unification, segmentation, and real-time activation.
Historically SAP grouped both capabilities under the SAP Customer Data Cloud (SAP CDC) umbrella. Since then SAP has split the offering into discrete products, Customer Identity for the CIAM job, Customer Data Platform for the unification and activation job, so you can buy, scope, and scale each one independently. In a typical SAP CX architecture, CIAM feeds registration and consent events into CDP in real time, and CDP feeds enriched, consent-compliant profiles back to Sales, Service, Commerce, and SAP Engagement Cloud (formerly Emarsys).
Where the value comes from
Identity is not a cost centre. A well-implemented CIAM deployment pays back in three areas, and each one can be measured against your own baseline.
Registration conversion. Social login and progressive profiling reduce friction at the point of registration. Replacing a 12-field form with social login plus two or three essential fields removes most of the reasons people abandon. Every registration you keep adds to your addressable customer base.
Consent compliance rates. With SAP Customer Identity, consent capture is part of the registration flow, not an afterthought pop-up. A clear, structured consent request inside the flow tends to earn more marketing opt-ins than a generic cookie banner, and every opt-in is documented. Higher opt-in means a larger audience for Emarsys campaigns and better data quality in your Customer Data Platform.
Support ticket reduction. Self-service password reset, SSO, and clear account management screens eliminate the most common identity-related support requests. Count your “I can’t log in” tickets before go-live and again three months after: the difference is time returned to your support team.
The compliance layer
Consent management is where legal and engineering intersect. You need consent records that are timestamped, versioned, and auditable. You need them synchronised to every system that uses them. And you need opt-out to propagate reliably, not on the next batch run but immediately.
The consent vault. SAP Customer Identity stores every consent event with a timestamp, the exact wording shown to the customer, and the version of your privacy policy at the time. This is what auditors ask for. Without it, you are guessing.
Granular consent types. We configure separate consent categories: email marketing, SMS, data processing, third-party data sharing, profiling. Each consent is independent. A customer can opt into email but decline profiling. The system enforces this distinction downstream.
Downstream propagation. When we connect SAP Customer Identity to SAP Customer Data Platform and Emarsys, consent changes propagate in real time. A customer revokes marketing consent at 14:07. By 14:07, Emarsys stops sending. No batch delay. No manual suppression list. This is not optional for GDPR and nDSG compliance. It is the requirement.
Swiss nDSG specifics. The revised Swiss Federal Act on Data Protection (nDSG), in force since September 2023, requires documented consent for certain data processing activities. SAP Customer Identity’s consent vault meets this standard. We configure it to capture and store the specific legal basis for each processing activity, which matters if your DPO is ever asked to produce records.
The consented profile data that flows into CDP then powers segmentation and personalisation. Our deep dive into SAP Customer Data Platform explains how that works in practice.
Progressive profiling in practice
Asking for 15 fields on a registration form is a conversion killer. Progressive profiling is the alternative: collect data gradually, across multiple sessions, based on what you actually need at each stage.
How it works. On the first visit, you capture email and a password (or social login, with no password at all). On the second login, you ask for company name and role. After the third purchase, you ask for communication preferences. SAP Customer Identity manages this logic through configurable screen sets. Each screen set defines which fields to show, when to show them, and what triggers the next step.
The impact on conversion. Fewer fields on the first screen means more completed registrations. We compare the registration funnel before and after go-live, so you see the effect in your own numbers rather than in a benchmark.
Data quality improves too. When you ask for information at the right moment, customers give you accurate answers. A job title provided during a product demo request is more reliable than one filled in during a rushed checkout. Progressive profiling gives you better data, not just more data.
Configuration, not code. SAP Customer Identity’s screen-set editor lets you adjust profiling flows without developer involvement. Marketing can add a field. Legal can require a new consent checkbox. Neither needs a release cycle to make it happen.
B2B identity specifics
B2B identity is more complex than B2C. You have company accounts with multiple users, varying permission levels, and approval workflows that differ by customer.
Delegated administration. SAP Customer Identity supports a hierarchy: organisation, then groups, then individual users. A company admin can invite new users, assign roles, and deactivate former employees, without contacting your support team. This is table stakes for B2B portals with more than 50 buyer accounts.
Role-based access. Different users within the same company need different access. A procurement manager sees pricing and can place orders. A technical user sees documentation and support tickets. An executive sees reporting dashboards. We configure these roles in SAP Customer Identity and enforce them across your commerce and service portals.
Account approval workflows. Not every self-registered user should get immediate access. For B2B, we configure approval workflows where a new registration triggers a review by the account owner or your internal sales team. The user gets notified when access is granted. No manual email chains.
Integration with B2B Commerce. When paired with SAP Commerce Cloud, delegated admin maps directly to the commerce organisation model. Buyers see their company’s negotiated pricing, order history, and credit limits. Identity and commerce stay in sync without custom middleware.
If your B2B portal currently requires a support ticket to add a new buyer, this is worth looking at.
SSO and passwordless authentication
Passwords are the weakest link in customer identity. They get forgotten, reused, and stolen. SAP Customer Identity gives you alternatives.
Single sign-on (SSO). One authentication event covers every connected property: web store, mobile app, support portal, partner portal. Customers authenticate once. Your systems share the session. You stop managing multiple identity stores, and customers stop resetting passwords across five different sites.
Social login. Google, Apple, LinkedIn, and Microsoft login integrations ship out of the box. Adding a social login provider takes hours, not weeks. The benefit: verified email addresses from day one and fewer abandoned registrations than with a traditional email-and-password form.
FIDO2 and WebAuthn. Passwordless authentication using device biometrics (fingerprint, face recognition) or hardware security keys. SAP Customer Identity supports FIDO2/WebAuthn for customers who want the highest security without the friction of typing passwords. Adoption is growing, especially on mobile devices where biometric authentication is already the default.
Risk-based MFA. Not every login needs a second factor. SAP Customer Identity evaluates login context, device, location, time of day, IP reputation, and triggers step-up authentication only when risk indicators appear. A returning customer on their usual laptop gets straight in. The same account logging in from a new country at 3 AM gets prompted for a verification code. Security that adapts to the situation, not a blanket policy that frustrates everyone.
The integration advantage
SAP Customer Identity is most valuable when it connects to the rest of your stack. Identity data in isolation is a directory. Identity data connected to commerce, marketing, and service becomes a growth driver.
SAP Commerce Cloud. CIAM provides the registration, login, and consent layer for your storefront. Customer identity flows into Commerce Cloud’s customer model. One account, one login, one set of preferences, whether the customer is on your B2C webshop or your B2B ordering portal. Read more about SAP Commerce Cloud.
Emarsys. Consent captured in CIAM determines what Emarsys can send and to whom. Profile data collected through progressive profiling enriches Emarsys segments. When a customer updates their preferences in CIAM, Emarsys reflects the change in real time. This connection is what makes compliant personalisation possible. Read more about Emarsys.
SAP Customer Data Platform. CIAM feeds first-party identity data into CDP. CDP stitches it with behavioural data from web, app, and offline sources to build a unified profile. Without CIAM as the identity source, CDP is working with anonymous fragments. Read more about SAP CDP.
SAP Sales Cloud V2. For B2B use cases, customer identity data from CIAM can inform the CRM. When a buyer registers on your portal, that event can create or update a contact in Sales Cloud. Your sales team sees portal activity alongside pipeline data.
Non-SAP systems. SAP Customer Identity exposes REST APIs, JavaScript SDKs, and webhook events. Salesforce, Shopify, custom-built portals, and third-party analytics platforms can all be connected. If your system accepts HTTP calls, it can receive identity events.
What good looks like
A well-implemented SAP Customer Identity deployment produces results you can track in the first 90 days, against a baseline we measure with you before go-live:
- Registration completion rates above your pre-launch baseline, from reduced form friction
- Marketing consent captured inside the registration flow, with every opt-in documented
- Fewer identity-related support tickets (password resets, login issues)
- Consent audit readiness: every record timestamped, versioned, and retrievable on demand
- SSO in use across the connected properties
Six months after go-live, we review these numbers with you. If your B2B delegated admin is not reducing support load, we adjust the configuration. If progressive profiling is not lifting data completeness, we rework the screen sets. The implementation is not done at go-live. It is done when the metrics prove it works.
Got an identity project to discuss? Talk to us about your requirements. No pitch deck, just a conversation.
We've done this before
Fressnapf: Pragmatic Architecture for an E-Commerce Leader
Frequently asked questions
What is SAP Customer Identity (CIAM)?
SAP Customer Identity (CIAM) is SAP's customer identity and access management platform, built on SAP CDC (formerly Gigya). It manages B2C and B2B registration, authentication (SSO, social login, passwordless), progressive profiling, GDPR consent, and MFA. It integrates with SAP Commerce Cloud, Emarsys, and CDP to carry consented identity data across the SAP CX stack.
What is the difference between SAP CIAM and standard IAM?
Standard IAM (like Okta or Azure AD) manages employee identities: workforce login, access control, on/off-boarding. CIAM manages consumer identities at scale: millions of external users with self-service registration, social login, marketing consent, and privacy controls. SAP CIAM is specifically built for the consumer-facing use case with built-in consent management and CX integration.
How does SAP CIAM handle GDPR compliance?
SAP CIAM provides a consent vault that stores explicit, timestamped consent for each customer. Consent preferences are granular (email marketing, data processing, third-party sharing) and propagated to connected systems. Consent can be withdrawn at any time, triggering downstream updates across SAP Commerce, Emarsys, and CDP. This covers EU GDPR and Swiss nDSG requirements.
Does SAP CIAM work with headless commerce storefronts?
Yes. SAP CIAM exposes REST APIs and JavaScript SDKs used directly in React, Vue, or other frontend frameworks. SAP Commerce Cloud Composable Storefront has a reference implementation for CIAM. Spadoom implements CIAM for both accelerator-based and composable storefronts; the [Medion case study](/en/success-stories/medion-unified-identity/) shows one identity pool serving five national storefronts.
How long does it take to implement SAP Customer Identity?
Implementation timelines depend on the project scope: a standalone CIAM deployment with SSO and consent management is the smaller scope, while a full integration across SAP Commerce Cloud, Emarsys, and CDP with B2B delegated administration takes longer. What drives the timeline is the number of identity sources, the consent requirements, and the downstream integrations involved. Spadoom commits to a timeline after the discovery phase, once those are known.
How much does SAP Customer Identity cost?
SAP Customer Identity pricing is based on monthly active users (MAU), not named seats. The exact cost depends on your MAU volume, contract term, and whether you bundle it with other SAP CX products like Commerce Cloud or CDP. SAP offers tiered pricing: higher volumes lower the per-user cost. Spadoom provides a full cost estimate as part of every scoping engagement so you know the investment before committing.
Can SAP CIAM integrate with non-SAP systems?
Yes. SAP Customer Identity is built API-first. It exposes REST APIs and JavaScript SDKs for frontend integration, and supports webhooks for event-driven workflows. You can connect it to Salesforce, Shopify, custom-built portals, third-party marketing platforms, or any system that accepts HTTP calls. Mapping, error handling and monitoring for those connections are scoped in the project.
Personally accountable
AI speeds up the work. We stand behind it.
You speak with the people who build your system. We use AI in delivery; decisions, quality and accountability stay with our team.
Direct contact
You know your project lead and can reach the engineers building your solution. We discuss open questions directly with you.
Clarity early
You see our Jira and budget forecast. When scope, costs or deadlines come under pressure, we raise it early and agree the next step with you.
Responsible until it works
If something within the agreed scope does not work, we fix it at our expense. We agree post-go-live support and availability with you in advance.
Your contact
Dario Pedol
Founder & CEO, SAP CX Architect
Talk to the person who is responsible, not to a sales queue.
Ask about SAP Customer Identity
Answers drawn from what Spadoom has published on this site, with links to the pages they come from.
Try one of these
AI-generated answers. Verify before acting. Questions are stored anonymously, without your IP address, so we can improve our content. Please do not enter personal data.
Ready to cut the noise?
Tell us what you run today. We will tell you honestly what is realistic.
Discuss your projectCustomers our team has worked with