Initially, it started off with single sign-on and promoted single sign-on within multiple single sign-ons.
Over time, it morphed into also implementing what we call authorization policies. That includes limiting when people can access an application in terms of the time of day, or limiting which user populations can use a particular application.
It's mainly an access management tool.
Over the last four years or so, we've leveraged the integration between Access Manager and the advanced integration framework so that we can now also implement multi-factor authentication.