Identity Before Loyalty
What it takes to recognise one customer across a multi-brand group, and why loyalty and marketing leaders should take a closer look at their identity strategy.
The intention of this piece is to provide insights for multi-brand groups building loyalty across a portfolio, with or without a formal program. Single brands face a smaller version of the same problem so there is utility in what we outline but the challenges tend to be far more straightforward to overcome.
Most multi-brand groups we work with start from the same ambition: one customer, recognised the same way across every brand, app and store. It's a good ambition when customers can see the benefit because it enables more seamless loyalty value exchange.
It's also hard to deliver out of the gate, because the customer's “identity” doesn't live in one place.
The Key is in Five (or Six!) Places
The common assumption is that the loyalty program holds the customer. It has the member record, the email address and the marketing consent, so it gets treated as the master identity for the group. In our experience that assumption is often wrong. The loyalty profile is one fragment, and treating it as the whole is where cross-brand recognition breaks down.
Across the groups we work with, the signals that identify a customer sit in at least five places:
Customer Identity and Access Management (CIAM) holds the credential: the login, verified email or phone, authentication history. It knows the account is the same everywhere it's used, and very little about what that account is worth, what it can do (beyond access) or any tangible insights on the customer.
The loyalty program holds the declared relationship: member record, consented profile, earn and redemption history. It can be one of the richest profiles in the group yet is often isolated to a single program view (in the case there are multiple programs or loyalty mechanics in play) or doesn’t complete the full picture.
Commerce holds the behaviour: transactions and carts, in store and online, many of them made without a login or a scan.
CRM or Service platforms (if present) hold the relationship history: service interactions, campaign responses, stated preferences. And likely these service or CRM platforms are different per brand.
Consent holds permission: what can be communicated, by which brand, and whether it extends across the group.
Data & Analytics could also hold a sixth set of enriched customer data and insights, linked by a key identifier
None of them on its own gives you a customer you can act on per se. To activate someone across brands you need to know who they are, where they are, which loyalty lever you're pulling and whether you're permitted to contact them.
That takes all five to be in a position to support activating the customer. Most groups resolve one or two (typically loyalty and CRM, often through a Customer Data Platform or CDP – CIAM is the front door but rarely masters the loyalty or marketing identity).
The intersection of all five (or six..) is what increasingly needs designing.
Forrester's late-2025 Identity Resolution Solutions Landscape - which I reviewed so you don’t have to - has begun to define this work; resolving fragmented signals into one persistent view of a real person, through deterministic matching (authentication, email) and probabilistic matching (patterns that strongly suggest the same person).
It also and adds yet another acronym and potential platform to content with, IRS.
So, do you now need an IRS? Possibly.
Before rushing to “Yet Another Platform” our view is that most organisations already have the underlying capabilities (i.e. the landscape), just not a design that connects them.
Who, Not What.
Fragmentation, plus shifting privacy, security and digital media conditions, is why identity needs to be its own layer rather than a feature of the loyalty platform, an authentication concern, or something a CDP partly covers.
"Who this customer is" and "what this customer has earned" are different records doing different jobs. Make the loyalty profile the identity, and the moment you change, scale or replace the loyalty platform you're also unpicking how every brand recognises its customers.
The groups that get this right separate the layers. Identity answers who someone is, loyalty what they've earned, access what they can use, and consent who can be contacted and in what scenario. Get the separation right and you can change the loyalty mechanics without touching identity. Get it wrong and the two stay stuck together, which makes extending loyalty across brands difficult.
Identity Strategy First.
Before shortlisting vendors from the Forrester Landscape, formalise the identity strategy across all five areas. Identity is usually cobbled together over time, and the exercise forces two questions:
If you're building a unified cross-brand identity, what creates and masters it? Is it CIAM or something else, and what are the trade-offs either way? CIAM can play a fundamental role but struggles with anonymous customers
What is a customer? What identifies them, is that consistent or fragmented across brands, and is anonymity something to solve for?
Fix Data Next.
A unified profile only means something if the data underneath it is clean, connected and there when a decision needs to be made - what we would term “Activating on the customer”.
Teams underestimate this part as the core reason to unlock value from a strong identity strategy - we fix identity but data is still a mess.
The 2026 Gartner Magic Quadrant for Customer Data Platforms describes a market splitting between platformisation and agentification, with buying groups now spanning two to three functions. The data foundation is now a shared call between marketing and technology, not as it often once was; a marketing buy with a technology sign-off.
The same pattern runs through 2025 and 2026 CDP commentary: teams went looking for better AI and found the constraint was the data feeding it. Our long-held view is that a CDP is only as effective as the identity resolution above it. Most CDPs rely on simpler deterministic identity, focus on digital signals and struggle to provide identity for the wider organisation.
Consent Carries Weight.
Identity and consent are tightly coupled. Consent attaches to an individual, so you need to identify that individual cleanly.
For loyalty, the stakes climb with every brand you join. Under the Privacy Act, consent has to be informed and specific, and the Office of the Australian Information Commissioner (OAIC) is clear that bundling it into a single take-it-or-leave-it tick-box doesn't meet the test. Unifying data behind the scenes increases that obligation, because you're joining things a person may never have expected to see joined. Someone happy for a supermarket to track their weekly shop might feel very differently about that sitting next to their banking, insurance quotes or pharmacy history.
Consent is broadly in our experience fragmented in exactly the way identity is. CIAM captured one permission at registration, the loyalty program another at join, each brand's CRM a few more, and they rarely align.
So, consent has to be resolved fragment by fragment, alongside identity: what did this person agree to, in which repository, and does it stretch to the joined-up use you now have in mind?
Across the consent reviews we've run, the same themes come up. Most organisations can say how many records they hold, but not how many de-duplicated, currently contactable customers they have. Opt-outs are enforced in owned email and SMS channels, while few can confirm they reach paid and retail media audiences. Digital tracking consent sits largely apart from customer identity. The gap sits in the same place each time: where identity and consent should meet.
The Privacy Act reforms now rolling through (tracked by Deloitte Australia and Norton Rose Fulbright) raise the bar further, with broader definitions of personal information, stronger individual rights and a new statutory tort for serious invasions of privacy. A defensible consent framework belongs inside the identity design, not bolted on at the end. It decides what the unified profile is actually allowed to do.
CIAM matters here beyond security. Adaptive, risk-based multi-factor authentication (MFA) protects the profile without making every login a chore, and Expert Insights' December 2025 market read puts that verification at the centre of where identity platforms are heading. CIAM is also one of the most reliable ways to resolve to a single individual where there is likely a clear consent attachment given they are a known customer, so building it a cross brand loyalty experience, rather than resolving after the fact, goes a long way to enabling a unified profile.
Loyalty Flows When Identity Is Solved.
We've left loyalty mechanics to the end on purpose. As programs evolve as multi-brand or multi-partner, tiers, points, earn-and-burn and the coalition model tend to dominate the discussion.
Look at the retail coalition programs that genuinely work, the big ones with millions of members. Their mechanics matter less than two other things: a high-frequency anchor like the weekly shop, which earns a member's attention on things they were buying anyway, and a resolved identity that carries that member across every partner. The data all that frequency throws off powers the personalised offers, and increasingly the retail media on top.
Design points before you've resolved identity and you end up with a loyalty program nobody can quite explain, sitting on a customer view that's difficult to activate.
Where to Start.
Map where identity actually lives across CIAM, loyalty, commerce, CRM and consent, and resolve those fragments into one view of the customer from a logical perspective. This essentially forms your Identity Resolution Service framework and creates a clear design on how to enable Identity in a multi-brand scenario – its still useful in a single brand context if aspects of customer activation feel harder than they need to be
Establish how to get the data underneath clean and connected. This doesn’t happen immediately but there will be clear pockets of data value that you will want to activate the customer. As part of this process establish what consent permits (or needs to permit).
Do this as part of any major loyalty evolution. For a business about to modernise customer identity, we'd start with an identity and consent audit run in parallel with program design: a clear map of the five repositories, what each knows and what each is allowed to share.
Work out who your customer is and what you're allowed to do with that knowledge. In our view, that smooths the way for solid loyalty execution versus creating operational headaches and unnecessary risk – particularly in light of strengthening privacy laws (at least in Australia).