Stage 02 of 07 · Identity across the lifecycle

Identify

Identify is where an anonymous visitor becomes a verified customer — the first point a login, a hashed email, or a loyalty number attaches to the profile with enough confidence to act on. Get identifier-first design right here and every downstream stage inherits a customer, not a guess. Get it wrong and you're resolving the same person five different ways for the rest of the lifecycle.

Last reviewed 27 Sept 2026

The fragmentation

Identify happens five times for one person

Separate login systems per brand or region mean the same customer authenticates against five different identity providers, each minting its own verified ID. Nothing downstream ever finds out they're the same customer, because nothing upstream ever said so.

Tell — you find out when a customer complains that a loyalty balance from one brand doesn't show up on another.

What resolved looks like

One identifier-first login layer, regardless of entry point

A single hosted login layer front-ends every brand and region, issuing one verified identity — the OIDC `sub` claim — no matter which brand's page the customer signed in on. SAP CDC, Adobe IMS and Keycloak all support this; almost none of them default to it.

Systems that read this stage — SAP CDC · Adobe IMS · Keycloak · OIDC

subemail_sha256cdc_uid

See it in a live engagement → One login layer across brands and regions