Stop Losing Track of Who Has Access to What — and Why — Across the Entire Identity Lifecycle
An AI-assisted workflow to design an accountable, risk-based identity governance and administration program that controls human and non-human access from joiner to leaver.
Executive Brief
Your Challenge
Your organization manages identities through disconnected systems and informal processes — access granted over email, no authoritative source, delayed terminations, and access retained after every role change. You cannot reliably answer who has access to what, why they have it, who approved it, when it was last reviewed, or when it should be removed. Former employees keep access, employees accumulate permissions, contractors stay enabled, and privileged access is difficult to control while audit findings recur.
Common Obstacles
The failure modes cluster in predictable places. Contractors present greater lifecycle risk than employees because their identity data is less reliable, yet they are governed less. Terminations disable the primary directory account but leave non-federated SaaS access intact. Privileged access is predominantly permanent. Access reviews are completed but revocations are never tracked to enforcement, so a completed campaign leaves access unchanged. Non-human identities — service accounts, application registrations, workload identities — carry broad, poorly monitored access with no owners and non-expiring credentials.
The ABME Approach
This workflow builds the program in the right order: establish authoritative identity sources and data quality, then design the joiner, mover, and leaver lifecycle, then the access-request, role, and privileged-access models, then certification, segregation of duties, and non-human identity governance — measured by a maturity model and validated end to end. You define an owner for every identity and entitlement, treat data quality as a control, distinguish approval from provisioning and review completion from revocation completion, and require human accountability for every material access decision. AI accelerates the analysis; accountable owners approve the outcomes.
Insight Summary
Identity governance is not the administration of accounts. It is the continuous, evidence-based control of who and what may access resources, why, for how long, and who is accountable for the risk.
Identity data quality is a security control, not a hygiene concern. Poor identity data creates poor access decisions no matter how good the workflow above it is.
Role changes create more risk than onboarding. Employees accumulate access when they move, and the access nobody removes is the access nobody is accountable for.
Standing privilege is the multiplier on every account compromise. Permanent privileged assignments turn one stolen credential into unlimited blast radius.
A completed access review is not complete until revocations are enforced. A revoke decision does not reduce risk until access is actually removed.
Contractors present greater lifecycle risk than employees precisely because their identity data is less reliable — govern them harder, not softer.
The Journey
Three phases; each lists the tools you'll use there.
Establish Authoritative Identity and Data Quality
- Gather identity governance policy, IAM architecture, and inventories
- Classify all identity types including non-human identities
- Define authoritative sources and source-of-truth requirements
- Assess identity data quality and correlation
- Define core principles and program objectives
Design the Lifecycle and Access Models
- Run the primary AI prompt with the gathered evidence
- Design joiner, mover, and leaver controls with deprovisioning validation
- Build the entitlement catalog and access-request workflow
- Design role-based access and privileged-access governance
- Govern service accounts, workload identities, and application registrations
Certify, Validate, and Operationalize
- Run risk-based access certification campaigns
- Track revocations to completion separately from review completion
- Run the validation checklist across every domain
- Wire identity events into monitoring and dashboards
- Execute the twelve-month roadmap
What's Inside the Execution Layer
Numbered deliverables grouped by phase. Membership unlocks every tool.
Prerequisites Checklist
- Assemble the full identity governance evidence base
- Surface inventory and integration gaps early
- Confirm regulatory and policy inputs up front
Gather as much of the following as possible:
Identity Governance Prompt Pack
- Design or assess an end-to-end IGA program
- Target specific domains like JML, privileged access, or SoD
- Generate dashboards, inventories, and remediation findings
Primary AI Prompt
Start here with the gathered identity data and inventories.You are a senior identity governance architect, identity and access management strategist, privileged access specialist, cloud identity architect, compliance advisor, security risk consultant, and enterprise process designer. I will provide some or all of the following: • Identity governance policies • IAM architecture • Authoritative identity sources • Human resources data • Contractor data • Identity provider configuration • Directory inventory • Application inventory • Entitlement catalog • Role catalog • Group inventory • Privileged role inventory • Service account inventory • Workload identity inventory • Access request records • Approval workflows • Access review records • Segregation-of-duties rules • Dormant account data • Termination records • Provisioning and deprovisioning logs • Privileged access logs • Credential inventory • Exception records • Identity incidents • Audit findings • Compliance requirements • Metrics Your task is to design or assess a comprehensive identity governance and administration program. Do not assume that an enabled identity is valid. Do not assume that approved access remains necessary. Do not assume that a completed access review means revocations were implemented. First: 1. Summarize: • Organizational context • Identity types • Authoritative sources • Identity platforms • Application landscape • Current lifecycle process • Current access-request process • Privileged-access model • Certification process • Contractor model • Service-account model • Current governance maturity 2. Separate: • Confirmed facts • Validated evidence • Reported observations • Inferences • Assumptions • Unknowns 3. Identify missing evidence that materially affects the assessment. 4. Evaluate: • Identity inventory • Identity ownership • Authoritative sources • Identity data quality • Identity correlation • Joiner controls • Mover controls • Leaver controls • Termination timing • Deprovisioning validation • Birthright access • Access requests • Approval quality • Entitlement catalog • Role design • Attribute-based access • Privileged access • Emergency access • Access certifications • Reviewer effectiveness • Revocation execution • Segregation of duties • Contractor access • Guest access • Partner access • Service accounts • Workload identities • Application registrations • Consent governance • Credential governance • Dormant accounts • Shared accounts • Local accounts • Exceptions • Monitoring • Incident response • Privacy • Reporting • Metrics • Governance 5. For each weakness provide: • Finding ID • Domain • Severity • Confidence • Evidence • Business impact • Security impact • Operational impact • Compliance impact • Recommended action • Owner • Dependencies • Validation • Estimated effort • Priority • Target timing 6. Identify: • Orphaned identities • Dormant identities • Stale contractors • Former employees with access • Accounts missing owners • Excessive access • Privilege accumulation • Permanent privilege • Shared accounts • Unowned service accounts • Expired credentials • Unowned applications • Segregation-of-duties conflicts • Access-review failures • Unexecuted revocations • Expired exceptions • Deprovisioning failures 7. Classify findings as: • Critical • High • Medium • Low • Informational 8. Recommend: • Immediate containment • Process remediation • Technical remediation • Governance change • Automation • Owner • Due date • Validation method • Exception path • Escalation path Requirements: • Require an owner for every identity and entitlement. • Treat identity data quality as a control. • Treat role changes as access reevaluation events. • Prioritize termination and privileged-access failures. • Identify standing privilege. • Identify service-account and workload-identity risk. • Require expiration for contractors, guests, credentials, and exceptions where practical. • Distinguish approval from provisioning. • Distinguish review completion from revocation completion. • Identify segregation-of-duties conflicts. • Do not recommend role mining without business validation. • Avoid creating roles that preserve historical excess. • Identify manual bottlenecks. • State where human, legal, human resources, privacy, security, compliance, or business-owner review is required. • State when evidence is insufficient. • Do not expose credentials, secrets, or personal data. Then produce: 1. Executive summary. 2. Identity governance maturity assessment. 3. Identity architecture overview. 4. Identity inventory assessment. 5. Authoritative-source assessment. 6. Identity data-quality assessment. 7. Joiner process. 8. Mover process. 9. Leaver process. 10. Termination control assessment. 11. Access-request and approval model. 12. Entitlement catalog model. 13. Role and policy model. 14. Privileged-access governance model. 15. Emergency-access model. 16. Access-certification program. 17. Segregation-of-duties framework. 18. Contractor and guest governance. 19. Service-account governance. 20. Workload-identity governance. 21. Application registration and consent governance. 22. Credential governance. 23. Dormant and stale-access process. 24. Exception process. 25. Identity monitoring and incident-response integration. 26. Metrics and dashboards. 27. Risk register. 28. Quick wins. 29. Twelve-month implementation roadmap. 30. Responsibility matrix. 31. Governance recommendations. 32. Open questions. 33. Final recommendation.
Assess Identity Governance Maturity
To score the program against the five-level maturity model.Assess the maturity of this identity governance program. Evaluate: • Identity sources • Data quality • Joiners • Movers • Leavers • Access requests • Approvals • Entitlement catalog • Roles • Privileged access • Access reviews • Segregation of duties • Contractors • Service accounts • Workload identities • Exceptions • Metrics • Governance Score each domain from Level 1 through Level 5 and explain the evidence.
Design the Joiner, Mover, and Leaver Process
To design the full identity lifecycle.Design a complete joiner, mover, and leaver process. For each lifecycle event include: • Trigger • Source • Required data • Approval • Provisioning or deprovisioning • Timing • Validation • Failure handling • Escalation • Evidence • Metrics
Review Termination Controls
To audit leaver deprovisioning across all systems.Assess employee and contractor termination controls. Review: • Notification timing • Identity disablement • Session revocation • Token revocation • Privileged accounts • Cloud access • SaaS access • VPN • Device access • Shared credentials • Data preservation • Ownership transfer • Validation Identify any termination failures requiring immediate action.
Analyze Mover Risk
To find access retained after role changes.Analyze identity and access risk caused by role changes. Identify: • Access retained from prior roles • Department access • Privileged access • Approval authority • Segregation-of-duties conflicts • Data access • Cloud roles • Group membership • Application roles Recommend access to retain, remove, modify, or review.
Build an Entitlement Catalog
To construct the catalog underpinning access requests.Create an entitlement catalog. For each entitlement include: • Application • Entitlement • Description • Business purpose • Risk • Data sensitivity • Owner • Approver • Prerequisites • Segregation-of-duties rules • Default duration • Review frequency • Provisioning method • Deprovisioning method
Design an Access Request Workflow
To build a risk-based request-to-provision flow.Design a risk-based access-request workflow. Include: • Requestor • Beneficiary • Resource • Entitlement • Business justification • Duration • Manager approval • Application-owner approval • Data-owner approval • Security approval • Segregation-of-duties check • Provisioning • Validation • Expiration • Evidence
Improve Approval Quality
To detect rubber-stamping and fix the approval model.Review this access-approval process. Identify: • Rubber-stamp behavior • Self-approval • Missing context • Approval after provisioning • Excessive approval layers • Approval bottlenecks • Inappropriate approvers • Unexplained bulk approval Recommend a stronger and more efficient approval model.
Design Role-Based Access
To define roles aligned to job functions.Design a role-based access-control model. For each role define: • Name • Business purpose • Eligible population • Owner • Entitlements • Exclusions • Risk • Approval • Segregation-of-duties rules • Review frequency • Lifecycle status Avoid preserving historically excessive access.
Perform Role Mining
To derive candidate roles from access patterns — with business validation.Analyze current access patterns to identify candidate business roles. Exclude or flag: • Privileged outliers • Dormant access • Unowned entitlements • Historical excess • Segregation-of-duties conflicts • Individual exceptions Provide confidence and require business-owner validation.
Review Privileged Access
To assess standing privilege and PIM posture.Assess privileged-access governance. Review: • Permanent assignments • Eligible assignments • Just-in-time access • Approval • MFA • Device restrictions • Session logging • Credential vaulting • Emergency access • Privileged service accounts • Dormant administrators • Review frequency Identify privileges requiring immediate removal or containment.
Design Just-in-Time Privilege
To replace standing privilege with time-bound elevation.Design a just-in-time privileged-access process. Include: • Eligibility • Request • Business justification • Approval • MFA • Device requirement • Activation duration • Scope • Session logging • Ticket reference • Alerting • Review • Automatic expiration
Review Emergency Accounts
To audit break-glass account controls.Assess emergency-access accounts. Review: • Number of accounts • Ownership • Credential protection • MFA • Monitoring • Sign-in restrictions • Last use • Testing • Password rotation • Custodian access • Post-use review • Recovery capability
Design an Access Certification Program
To build risk-based recurring reviews.Design a risk-based access-certification program. Define: • Campaign scope • Reviewer • Frequency • Review context • Risk indicators • Decision options • Escalation • Delegation • Revocation workflow • Completion validation • Evidence • Metrics
Improve an Access Review Campaign
To fix fatigue and unexecuted revocations in an existing campaign.Review this access-certification campaign. Identify: • Review fatigue • Missing context • Inappropriate reviewers • Bulk approval • Overdue reviews • Unexecuted revocations • Low-value entitlements • High-risk access not emphasized • Evidence gaps Recommend improvements.
Analyze Segregation-of-Duties Conflicts
To detect incompatible-duty combinations in entitlements.Analyze these entitlements for segregation-of-duties conflicts. For each conflict provide: • Rule • Conflicting access • Business process • Risk • Severity • Existing controls • Recommended resolution • Owner • Exception authority • Monitoring
Design Contractor Governance
To build a contractor and third-party lifecycle.Design a contractor and third-party identity governance process. Include: • Sponsor • Company • Contract status • Start date • End date • Business purpose • Access scope • MFA • Device requirements • Data restrictions • Review frequency • Extension approval • Automatic expiration • Offboarding validation
Review Guest Access
To audit external-user access risk.Assess guest and external-user access. Identify: • Missing sponsors • Expired guests • Dormant guests • Broad group membership • Sensitive data access • Weak authentication • Untrusted domains • Cross-tenant risk • Missing expiration • Incomplete review Recommend remediation.
Build a Service Account Inventory
To catalog service accounts and their controls.Create a service-account inventory. Include: • Account • Purpose • Business owner • Technical owner • Application • Environment • Privilege • Authentication method • Credential location • Rotation • Interactive-logon status • Dependencies • Last used • Review date • Lifecycle status
Review Service Account Risk
To prioritize service-account containment and modernization.Assess service-account risk. Identify: • Missing owners • Excessive privilege • Interactive logon • Shared use • Stale credentials • Hard-coded secrets • Missing rotation • Dormant accounts • Unknown dependencies • Cross-environment use • Missing monitoring Recommend containment and modernization.
Review Workload Identities
To assess service principals, managed identities, and automation accounts.Assess workload identities, service principals, managed identities, API clients, and automation accounts. Review: • Ownership • Purpose • Permissions • Scope • Credential type • Credential expiration • Last use • Environment • Creation source • Monitoring • Review • Decommissioning Prioritize excessive permission and expired-owner findings.
Review Application Registrations
To govern app registrations and their credentials.Assess application registrations. Identify: • Missing owners • High-risk API permissions • Administrative consent • Expired credentials • Long-lived secrets • Unverified publishers • Unused applications • Unsafe redirect URIs • Multi-tenant exposure • Excessive scope • Incomplete monitoring
Review Consent Grants
To audit user and admin application consent.Assess user and administrative application consent. Identify: • High-risk permissions • Unverified publishers • Dormant applications • Excessive delegated access • Broad application permissions • Unnecessary tenant-wide consent • Missing owner • Missing business justification • Consent requiring revocation
Find Dormant and Orphaned Accounts
To identify stale identities and recommend actions.Analyze identity data to identify: • Dormant users • Orphaned accounts • Former employees • Expired contractors • Unowned service accounts • Dormant privileged accounts • Stale guests • Unused application registrations • Expired credentials For each item recommend validate, suspend, disable, remove, or escalate.
Review Identity Exceptions
To assess and dispose of standing exceptions.Review these identity and access exceptions. Assess: • Business justification • Risk • Compensating controls • Owner • Approver • Start date • Expiration • Review date • Remediation plan • Monitoring Recommend approve, conditionally approve, reject, or escalate.
Create an Identity Risk Dashboard
To design executive-level identity risk reporting.Design an executive identity-risk dashboard. Include: • Failed terminations • Orphaned accounts • Dormant accounts • Permanent privilege • High-risk access • Contractor expiration • Access-review completion • Revocation completion • Segregation-of-duties conflicts • Service-account risk • Expired credentials • Exceptions • Identity incidents • Automation coverage
Create an Operational Dashboard
To design day-to-day operational identity reporting.Design an operational identity-governance dashboard. Include: • Pending requests • Approval backlog • Provisioning failures • Deprovisioning failures • Access-review backlog • Unexecuted revocations • Expired contractors • Dormant identities • Credential expiration • Privileged activations • Emergency-account activity • Segregation-of-duties violations
Responsibility Matrix
- Assign accountability for each governance capability
- Resolve ownership gaps before launch
- Anchor governance decisions in a shared RACI
| Capability | HR | Manager | Identity Team | Application Owner | Security | Operations |
|---|---|---|---|---|---|---|
| Workforce identity source | Accountable | Informed | Consulted | Informed | Informed | Supports |
| Joiner process | Responsible | Approves | Accountable | Consulted | Consulted | Executes |
| Mover process | Responsible | Approves | Accountable | Consulted | Consulted | Executes |
| Leaver process | Responsible | Informed | Accountable | Consulted | Consulted | Executes |
| Access request | Informed | Responsible | Governs | Accountable for resource | Consulted | Executes |
| Role design | Informed | Consulted | Responsible | Accountable | Consulted | Supports |
| Privileged access | Informed | Consulted | Supports | Consulted | Accountable | Responsible |
| Access certification | Informed | Responsible | Governs | Accountable for resources | Consulted | Executes revocation |
| Segregation of duties | Informed | Consulted | Supports | Responsible | Consulted | Informed |
| Service accounts | Informed | Informed | Governs | Accountable | Consulted | Responsible |
| Exceptions | Informed | Responsible | Supports | Consulted | Accountable for security review | Executes controls |
Validation Checklist
- Verify each governance domain is controlled
- Confirm terminations, revocations, and NHI controls work
- Gate the program before declaring it operational
Verify the program against each domain:
Governance
Identity Data
Joiners
Movers
Leavers
Access Requests
Privileged Access
Certifications
Contractors and Guests
Non-Human Identities
Monitoring and Reporting
🔒 The full execution layer — every checklist, matrix, and the prompt pack — is included with ABME membership.
Unlock Full BlueprintFull Playbook
Overviewpublic
Identity governance and administration is the structured process used to ensure that the right people and systems receive the right access to the right resources for the right reasons and for the appropriate period of time.
Identity governance extends beyond authentication.
It addresses:
- Identity ownership
- Joiner, mover, and leaver processes
- Access requests
- Access approval
- Role design
- Entitlement management
- Privileged access
- Access reviews
- Segregation of duties
- Contractor access
- Service accounts
- Workload identities
- Emergency access
- Policy enforcement
- Evidence
- Risk
- Compliance
- Deprovisioning
A mature identity governance program should answer:
“Who has access to what, why do they have it, who approved it, when was it last reviewed, and when should it be removed?”
The objective is not to centralize every identity decision into a single tool.
The objective is to create a reliable, accountable, risk-based operating model that governs human and non-human access throughout its lifecycle.
A successful program reduces:
- Excessive access
- Orphaned accounts
- Dormant accounts
- Privilege accumulation
- Unauthorized access
- Separation-of-duties conflicts
- Contractor access risk
- Shared-account use
- Manual provisioning delays
- Audit effort
- Access-review fatigue
- Identity-related incident impact
Business Problempublic
Organizations often manage identities through disconnected systems and informal processes.
Common symptoms include:
- Access granted through email
- No authoritative identity source
- Inconsistent onboarding
- Delayed termination
- Access retained after role changes
- Excessive administrator rights
- Shared accounts
- Unowned service accounts
- Manual access reviews
- Rubber-stamp approvals
- No entitlement catalog
- Inconsistent contractor controls
- Weak application integration
- Multiple identity stores
- Poor access visibility
- No evidence of business justification
- Permanent privileged assignments
- Dormant cloud identities
- Unmanaged API credentials
- Access exceptions that never expire
Without effective identity governance:
- Former employees may retain access.
- Employees accumulate unnecessary permissions.
- Contractors remain enabled.
- Privileged access becomes difficult to control.
- Audit findings recur.
- Sensitive systems become overexposed.
- Security teams cannot determine actual access.
- Business owners cannot make informed approval decisions.
- Incident response becomes slower.
- Access-related support costs increase.
Expected Outcomepublic
After completing this workflow, the organization should have:
- Identity governance strategy
- Program charter
- Identity-source model
- Identity lifecycle process
- Joiner, mover, and leaver controls
- Identity classification model
- Access-request workflow
- Approval model
- Role and entitlement model
- Privileged-access model
- Access-certification process
- Segregation-of-duties framework
- Contractor-access process
- Service-account governance
- Workload-identity governance
- Emergency-access process
- Exception process
- Evidence-retention model
- Metrics and dashboards
- Implementation roadmap
- AI-assisted analysis prompts
- Automation opportunities
🔒 The complete playbook — reference models, worked examples, and operational guidance — is included with ABME membership.
Unlock Full BlueprintProgram Objectivesprotected
The identity governance program should answer:
- What is the authoritative identity source?
- Which identity types exist?
- Who owns each identity?
- How are new identities created?
- How are role changes handled?
- How quickly is access removed after termination?
- How is access requested?
- Who approves access?
- What business justification is required?
- Which access is role-based?
- Which access is individually assigned?
- Which access is privileged?
- How are entitlements cataloged?
- How are incompatible duties identified?
- How are access reviews conducted?
- How are reviewers selected?
- How are dormant accounts handled?
- How are contractors governed?
- How are service accounts governed?
- How are workload identities governed?
- How are emergency accounts controlled?
- How are exceptions approved?
- How is deprovisioning validated?
- How is evidence retained?
- How is identity risk measured?
- How are mergers, acquisitions, and divestitures handled?
- How are application owners held accountable?
- How are identity-related incidents investigated?
- How are manual processes reduced?
- How is program effectiveness measured?
Core Principlesprotected
Recommended Principles
- Every identity must have an owner.
- Access must have a business purpose.
- Access should be least privilege.
- Access should be time-bound when practical.
- Privileged access should not be permanent.
- Birthright access should be limited.
- Role changes should trigger access reevaluation.
- Termination should trigger immediate deprovisioning.
- Access reviews should be risk-based.
- Reviewers need meaningful context.
- Exceptions should expire.
- Shared accounts should be eliminated or tightly controlled.
- Service accounts require lifecycle governance.
- Workload identities should use short-lived credentials.
- Evidence should be retained automatically.
- Identity governance should be integrated with business processes.
- Automation should not remove accountability.
- High-risk access requires stronger controls.
- Identity data quality is a security control.
- Governance decisions require human ownership.
Identity Typesprotected
Workforce Identities
- Employees
- Temporary employees
- Interns
- Executives
- Administrators
- Developers
- Service desk personnel
External Identities
- Contractors
- Consultants
- Vendors
- Partners
- Suppliers
- Guests
- Customers
- Volunteers
Privileged Identities
- Domain administrators
- Cloud administrators
- Security administrators
- Database administrators
- Network administrators
- Application administrators
- Emergency administrators
Non-Human Identities
- Service accounts
- Managed identities
- Workload identities
- API clients
- Application registrations
- Bots
- Automation accounts
- Certificates
- Tokens
- SSH keys
- Database accounts
- Integration accounts
- Device identities
Identity Source Architectureprotected
Identity Source Architecture
Define the authoritative sources for:
- Employee identities
- Contractor identities
- Vendor identities
- Customer identities
- Organizational structure
- Job role
- Manager
- Department
- Cost center
- Location
- Employment status
- Start date
- End date
- Leave status
- Risk status
Typical authoritative systems include:
- Human resources information systems
- Contractor management systems
- Vendor management systems
- Customer identity platforms
- Student information systems
- Volunteer management systems
Source-of-Truth Requirements
The authoritative source should provide:
- Unique identity identifier
- Reliable status
- Start date
- End date
- Manager
- department
- Job code
- Employment type
- Location
- Legal entity
- Cost center
- Sponsoring organization
- Data-quality controls
- Timely updates
- Audit history
Identity Data Quality
Assess:
- Duplicate identities
- Missing managers
- Missing end dates
- Invalid departments
- Stale contractor records
- Inconsistent names
- Reused identifiers
- Incorrect employment status
- Missing sponsors
- Delayed updates
- Invalid cost centers
Poor identity data creates poor access decisions.
Identity Correlation
Where multiple identity systems exist, correlate identities using:
- Immutable employee or contractor ID
- Email address
- Username
- Legal name
- Manager
- Department
- Human resources record
- Device ownership
- Application account
- Cloud identity
- Privileged account relationship
Avoid relying only on display name.
Identity Lifecycle: Joiner, Mover, Leaverprotected
Joiner Process
The joiner process governs new identities.
Define:
- Identity creation trigger
- Start-date handling
- Pre-hire access
- Manager approval
- Birthright access
- Role-based access
- Equipment provisioning
- MFA enrollment
- Training requirements
- Policy acknowledgment
- Privileged-access restrictions
- Contractor-specific controls
- Initial access review
- Evidence retention
Pre-Hire Access
Pre-hire access should be limited.
Control:
- Earliest activation date
- Permitted applications
- Sponsor
- Expiration
- MFA
- Device restrictions
- Sensitive-data restrictions
- Monitoring
- Automatic conversion or removal
Birthright Access
Birthright access may include:
- Collaboration tools
- Intranet
- Basic productivity platforms
- Standard endpoint access
- Employee self-service
- Required training systems
Birthright access should not automatically include:
- Sensitive data
- Administrative privileges
- Financial approval
- Production access
- Broad shared drives
- Regulated systems
- High-risk cloud roles
Mover Process
Role changes often create more risk than onboarding.
The mover process should:
- Detect department changes.
- Detect job changes.
- Detect manager changes.
- Detect location changes.
- Detect legal-entity changes.
- Detect employment-type changes.
- Reevaluate existing access.
- Remove incompatible access.
- Add approved new access.
- Reassess privileged roles.
- Reevaluate segregation-of-duties conflicts.
- Record decisions.
Access Accumulation
Access accumulation occurs when employees retain previous permissions after changing roles.
Detect:
- Old group membership
- Legacy application roles
- Prior department access
- Shared-folder access
- Privileged assignments
- Cloud roles
- Distribution lists
- Database roles
- Approval authority
- VPN profiles
Leaver Process
Termination controls should address:
- Immediate termination
- Scheduled termination
- Leave of absence
- Retirement
- Contractor expiration
- Vendor separation
- Death
- Legal hold
- Investigation
- Acquired-company separation
Termination Timing
Define:
- Trigger source
- Notification timing
- Deactivation deadline
- Emergency termination path
- Session revocation
- Token revocation
- Password reset
- Device access removal
- VPN removal
- Privileged-access removal
- SaaS deprovisioning
- Data preservation
- Mailbox handling
- File ownership transfer
- Certificate revocation
- Shared-secret rotation
Immediate Terminations
For high-risk or involuntary terminations:
- Coordinate with human resources.
- Coordinate with legal.
- Pre-stage deactivation.
- Disable interactive access.
- Revoke active sessions.
- Revoke refresh tokens.
- Disable privileged accounts.
- Remove remote access.
- Isolate managed devices if required.
- Rotate shared secrets.
- Preserve evidence.
- Validate deprovisioning.
Leave of Absence
Define controls for:
- Temporary access suspension
- Continued email access
- Delegate access
- Privileged-access removal
- Remote-access restrictions
- Return-date activation
- Data preservation
- Access review upon return
Deprovisioning Validation
Do not assume the workflow completed successfully.
Validate:
- Primary identity disabled
- Privileged identity disabled
- Cloud access removed
- SaaS access removed
- VPN access removed
- Sessions revoked
- Tokens revoked
- Service accounts reassigned
- Shared secrets rotated where needed
- Devices secured
- Ownership transferred
- Evidence retained
Access Request and Approvalprotected
Access Request Management
A controlled access request should include:
- Requestor
- Beneficiary
- Resource
- Entitlement
- Business justification
- Requested duration
- Data sensitivity
- Risk level
- Required training
- Manager approval
- Resource-owner approval
- Security approval where required
- Segregation-of-duties result
- Expiration
- Provisioning status
- Validation
- Evidence
Request Catalog
Create an entitlement catalog containing:
- Application
- Resource
- Entitlement
- Description
- Business purpose
- Risk
- Data sensitivity
- Owner
- Approver
- Prerequisites
- Segregation-of-duties rules
- Default duration
- Review frequency
- Provisioning method
- Deprovisioning method
Approval Models
Possible approval steps include:
- Manager approval
- Application-owner approval
- Data-owner approval
- Security approval
- Compliance approval
- Financial approval
- Privileged-access approval
- Project-owner approval
- Sponsor approval
Approval should reflect risk, not organizational habit.
Approval Context
Approvers should receive:
- Requested access
- Business purpose
- User role
- Existing access
- Data sensitivity
- Risk
- Segregation-of-duties conflicts
- Requested duration
- Prior review history
- Similar-role access
- Anomalies
- Recommended decision
Rubber-Stamp Approval
Detect:
- Extremely rapid approvals
- Near-100% approval rates
- Approvals without justification
- Reviewers approving large volumes
- Approvals while unavailable
- Repeated approval of conflicts
- Self-approval
- Approval after provisioning
- Bulk approval without context
Access Control Modelsprotected
Least Privilege
Least privilege requires:
- Minimum required permissions
- Minimum required scope
- Minimum required duration
- Appropriate environment
- Appropriate data access
- Appropriate administrative level
- Periodic review
- Removal after use
Role-Based Access Control
Role-based access should align entitlements with defined job functions.
A role should include:
- Role name
- Business purpose
- Eligible population
- Owner
- Included entitlements
- Excluded entitlements
- Risk
- Segregation-of-duties rules
- Approval
- Review frequency
- Version
- Lifecycle status
Role Engineering
Role engineering may use:
- Top-down business analysis
- Bottom-up access mining
- Peer-group analysis
- Job-code analysis
- Department analysis
- Application-role analysis
- Entitlement clustering
- Risk review
- Business-owner validation
Role Explosion
Avoid excessive role creation.
Warning signs include:
- One role per user
- Highly overlapping roles
- Many unused roles
- Roles with unclear purpose
- Roles containing individual exceptions
- Roles owned by inactive employees
- Roles that are never reviewed
Role Mining
Use current access patterns carefully.
Current access may reflect historical excess, not valid requirements.
Role mining should:
- Identify common entitlement patterns.
- Exclude privileged outliers.
- Exclude stale access.
- Incorporate job function.
- Require business validation.
- Check segregation-of-duties conflicts.
- Track confidence.
Attribute-Based Access Control
Attribute-based access may consider:
- Department
- Job code
- Location
- Employment type
- Clearance
- Device trust
- Risk level
- Resource classification
- Time
- Network
- Project
- Contract status
Attributes must be trustworthy and governed.
Policy-Based Access
Policies may restrict access based on:
- Data classification
- Device compliance
- Authentication strength
- User risk
- Sign-in risk
- Geography
- Network location
- Time of day
- Employment status
- Privilege
- Application sensitivity
Entitlement Ownership
Every entitlement should have:
- Business owner
- Technical owner
- Approval owner
- Review owner
- Risk classification
- Description
- Lifecycle status
- Associated resource
- Deprovisioning method
Unowned entitlements should not remain requestable.
Privileged and Emergency Accessprotected
Privileged Access Governance
Privileged access requires stronger controls.
Govern:
- Eligibility
- Approval
- Activation
- Duration
- MFA
- Device trust
- Session logging
- Command logging
- Credential vaulting
- Justification
- Ticket reference
- Emergency use
- Review
- Recertification
Standing Privilege
Reduce permanent privileged assignments.
Preferred models include:
- Just-in-time access
- Just-enough administration
- Time-bound activation
- Approval-based elevation
- Scoped roles
- Privileged access workstations
- Session monitoring
- Separate administrative accounts
Privileged Account Separation
Administrators should use:
- Standard account for normal work
- Dedicated account for administrative tasks
- Separate cloud or domain roles where needed
- Stronger authentication
- Restricted workstation
- Limited internet access
- Enhanced monitoring
Privileged Access Requests
Capture:
- Requested role
- Target resource
- Purpose
- Ticket or change reference
- Start time
- End time
- Approver
- Authentication method
- Device
- Session record
- Actions taken
- Closure
Privileged Access Reviews
Review:
- Permanent assignments
- Eligible assignments
- Recent activations
- Dormant privileged users
- High-risk roles
- Emergency access
- Privileged service accounts
- Privilege outside normal role
- Direct versus group assignment
- Cross-tenant privilege
Emergency Access
Emergency accounts should be:
- Few in number
- Strongly protected
- Excluded from routine use
- Monitored continuously
- Stored securely
- Tested periodically
- Documented
- Assigned to named custodians
- Reviewed after every use
Emergency Account Controls
Include:
- Long, unique credentials
- Credential vault
- Hardware-based authentication where feasible
- Restricted sign-in
- Alerting
- Log review
- Test schedule
- Change process
- Recovery procedures
- Executive ownership
Access Certificationprotected
Access Certification
Access certification is the periodic review of user and system access.
Certification campaigns may target:
- High-risk applications
- Privileged access
- Regulated data
- Financial systems
- Production environments
- Contractors
- Dormant accounts
- External users
- Service accounts
- High-risk entitlements
Review Frequency
Example frequencies:
Critical Privileged Access: Monthly or quarterly
High-Risk Applications: Quarterly
Standard Business Applications: Semiannually or annually
Contractors and Guests: Monthly or quarterly
Service Accounts: Quarterly or semiannually
Frequency should reflect risk and change rate.
Reviewer Selection
Possible reviewers include:
- Manager
- Application owner
- Data owner
- Role owner
- Privileged-access owner
- Sponsor
- Business-process owner
The person best positioned to understand business need should review the access.
Certification Context
Reviewers should see:
- User
- Employment status
- Job role
- Department
- Manager
- Access
- Entitlement description
- Risk
- Last used
- Last reviewed
- Approval history
- Similar-user access
- Segregation-of-duties conflicts
- Privileged activity
- Requested duration
- Recommended action
Certification Decisions
Possible decisions:
- Approve
- Revoke
- Modify
- Delegate review
- Request information
- Escalate
- Accept temporarily
- Remove at expiration
Review Fatigue
Reduce review fatigue by:
- Scoping campaigns by risk
- Removing low-value items
- Grouping entitlements logically
- Providing context
- Highlighting anomalies
- Using peer comparison
- Using last-used data
- Pre-identifying high-risk access
- Limiting campaign duration
- Measuring reviewer performance
Review Completion Validation
Confirm:
- All reviews completed
- Revocations executed
- Failed removals remediated
- Delegations valid
- Exceptions approved
- Evidence retained
- Reviewer anomalies investigated
- Metrics reported
A completed review is not complete until revocations are enforced.
Segregation of Dutiesprotected
Segregation of Duties
Segregation of duties prevents one person from controlling incompatible business functions.
Examples include:
- Create vendor and approve payment
- Create user and approve access
- Develop code and approve production deployment
- Submit expense and approve reimbursement
- Create transaction and reconcile transaction
- Administer logs and delete audit evidence
- Request privileged access and self-approve
Segregation-of-Duties Rule
Each rule should include:
- Rule ID
- Business process
- Conflicting entitlement A
- Conflicting entitlement B
- Risk
- Severity
- Owner
- Preventive or detective control
- Exception authority
- Review frequency
Preventive Versus Detective Controls
Preventive: Blocks conflicting access before provisioning.
Detective: Identifies existing conflicts after provisioning.
Preventive controls are preferred for high-risk conflicts, but detective controls may be necessary for complex environments.
Conflict Resolution
Possible actions include:
- Reject request
- Remove existing access
- Reduce scope
- Add secondary approval
- Add transaction monitoring
- Add supervisory review
- Time-limit access
- Create exception
- Reassign responsibility
Contractor and Third-Party Accessprotected
Contractor and Third-Party Access
Contractor identities should include:
- Sponsor
- Company
- Purpose
- Start date
- End date
- Contract status
- Resource scope
- Device requirements
- Data restrictions
- MFA
- Network restrictions
- Review frequency
- Automatic expiration
Contractor Sponsorship
Sponsors should:
- Confirm continued need.
- Review access.
- Update end dates.
- Report role changes.
- Approve extensions.
- Validate offboarding.
- Accept accountability.
Guest Access
Govern:
- Invitation
- Sponsor
- Domain restrictions
- Terms of use
- MFA
- Data access
- Group membership
- Expiration
- Review
- Removal
- Cross-tenant configuration
Partner Access
Partner access may require:
- Federation
- Contract controls
- Security requirements
- Authentication assurance
- Named sponsors
- Scoped access
- Data restrictions
- Logging
- Incident notification
- Termination process
Non-Human Identity Governanceprotected
Service Account Governance
Every service account should have:
- Unique identifier
- Purpose
- Business owner
- Technical owner
- Application
- Environment
- Privilege
- Authentication method
- Credential location
- Rotation schedule
- Interactive-logon setting
- Dependencies
- Monitoring
- Review frequency
- Expiration or lifecycle date
Service Account Risks
Common risks include:
- Shared ownership
- Unknown dependency
- Permanent password
- Excessive privilege
- Interactive login
- No rotation
- Hard-coded credentials
- Dormant account
- Production access from development
- No monitoring
- No decommissioning plan
Service Account Controls
Prefer:
- Managed identity
- Workload identity federation
- Short-lived credentials
- Certificate authentication
- Secret vault
- Automatic rotation
- Restricted logon
- Network restriction
- Scoped privilege
- Usage monitoring
Workload Identity Governance
Govern:
- Application registrations
- Managed identities
- Service principals
- API clients
- Cloud roles
- Kubernetes service accounts
- CI/CD identities
- Automation identities
- Integration identities
Workload Identity Inventory
Capture:
- Identity ID
- Display name
- Owner
- Application
- Environment
- Purpose
- Permissions
- Credential type
- Credential expiration
- Last used
- Resource scope
- Creation source
- Review date
- Lifecycle status
Application Registration Governance
Control:
- Who may create applications
- Required owner count
- Naming
- Publisher verification
- API permissions
- Admin consent
- Secrets
- Certificates
- Redirect URIs
- Multi-tenant configuration
- Expiration
- Review
- Deletion
Consent Governance
Review:
- User consent
- Administrative consent
- High-risk permissions
- Unverified publishers
- Multi-tenant applications
- Dormant applications
- Delegated permissions
- Application permissions
- Consent grants
- Revocation
Credential Governance
Manage:
- Passwords
- Secrets
- Certificates
- Tokens
- SSH keys
- API keys
- Signing keys
- Encryption keys
Capture:
- Owner
- Resource
- Purpose
- Creation date
- Expiration
- Rotation
- Storage
- Last used
- Revocation process
Exceptionsprotected
Identity Exceptions
Each exception should include:
- Exception ID
- Identity or access
- Business justification
- Risk
- Compensating controls
- Owner
- Approver
- Start date
- Expiration date
- Review date
- Remediation plan
- Monitoring requirements
Exception Expiration
Expired exceptions should:
- Trigger review
- Suspend or revoke access where appropriate
- Notify the owner
- Escalate overdue decisions
- Update risk reporting
- Require new evidence for renewal
Identity Monitoring and Incident Responseprotected
Identity-Related Risk Events
Monitor for:
- Impossible travel
- Suspicious sign-in
- MFA fatigue
- Disabled-account activity
- Dormant-account use
- Privileged-role activation
- New credential creation
- Consent grant
- Password reset
- Group membership change
- Application-owner change
- Emergency-account use
- Service-account interactive login
- Excessive access requests
- Access-review anomalies
Identity Threat Detection
Integrate identity governance with:
- SIEM
- XDR
- User and entity behavior analytics
- Cloud security
- Privileged-access monitoring
- Data loss prevention
- Insider-risk management
- Threat intelligence
- Incident response
Identity Incident Response
Prepare playbooks for:
- Compromised user
- Compromised administrator
- MFA fatigue attack
- Stolen token
- Malicious application consent
- Service-account compromise
- Leaver access failure
- Insider misuse
- Emergency-account use
- Privilege escalation
Mergers, Acquisitions, and Divestituresprotected
Mergers and Acquisitions
Assess:
- Identity overlap
- Duplicate domains
- Trust relationships
- Legacy directories
- Privileged accounts
- Contractor records
- Application ownership
- Guest access
- Separation-of-duties conflicts
- Deprovisioning
- Federation
- Data residency
- Transitional access
Divestitures
Plan:
- Identity separation
- Data ownership
- Access removal
- Shared-service transition
- Domain separation
- Application transfer
- Credential rotation
- Vendor access
- Legal hold
- Monitoring
- Post-separation validation
Privacy Considerations
Identity governance data may include:
- Employment status
- Manager
- Department
- Access history
- Activity
- Location
- Risk score
- Review decisions
- Investigation data
Define:
- Purpose
- Access
- Retention
- Legal basis
- Data minimization
- Review
- Employee notice
- Cross-border handling
Metrics and Dashboardsprotected
Identity Governance Metrics
Useful metrics include:
- Joiner provisioning time
- Mover completion time
- Termination deprovisioning time
- Failed deprovisioning events
- Orphaned accounts
- Dormant accounts
- Unowned accounts
- Privileged accounts
- Permanent privileged assignments
- Just-in-time activation rate
- Access-review completion
- Revocation completion
- Overdue certifications
- Access-request approval time
- Access-request rejection rate
- Segregation-of-duties conflicts
- Open exceptions
- Expired exceptions
- Contractor accounts past end date
- Service accounts without owners
- Credentials nearing expiration
- Application registrations without owners
- Emergency-account use
- Access-related incidents
- Manual provisioning rate
- Automated provisioning rate
Metrics to Avoid Misusing
Avoid relying solely on:
- Number of accounts
- Number of access reviews completed
- Number of access requests approved
- Number of applications connected
- Number of roles created
- Percentage of accounts with MFA without risk context
A completed campaign may still leave access unchanged.
Executive Dashboard
Include:
- High-risk access
- Permanent privilege
- Orphaned accounts
- Contractor expiration
- Failed termination events
- Access-review completion
- Revocation completion
- Segregation-of-duties conflicts
- Exception age
- Service-account risk
- Application-owner gaps
- Identity incidents
- Automation coverage
- Business-unit accountability
Operational Dashboard
Include:
- Pending requests
- Approval bottlenecks
- Provisioning failures
- Deprovisioning failures
- Expired contractors
- Access-review backlog
- Unexecuted revocations
- Dormant identities
- Credential expiration
- Unowned service accounts
- Privileged activations
- Emergency-account activity
- Segregation-of-duties violations
Identity Governance Maturity Modelprotected
Level 1 — Ad Hoc
- Manual provisioning
- Email approvals
- Incomplete inventory
- No access reviews
- Weak termination controls
- Limited ownership
Level 2 — Developing
- Basic workflows
- Central identity provider
- Partial automation
- Periodic reviews
- Inconsistent application integration
- Limited service-account governance
Level 3 — Defined
- Authoritative source
- Documented lifecycle
- Entitlement catalog
- Risk-based approvals
- Access certifications
- Privileged-access governance
- Exception process
Level 4 — Managed
- Broad automation
- Role and attribute-based access
- Strong data quality
- Continuous monitoring
- Risk-based reviews
- Measured performance
- Workload-identity governance
Level 5 — Optimized
- Continuous identity assurance
- Adaptive access
- Automated anomaly detection
- Predictive access recommendations
- Minimal standing privilege
- Near-real-time deprovisioning
- Continuous control validation
Governanceprotected
Define standards for:
- Identity types
- Authoritative sources
- Naming
- Unique identifiers
- Joiner process
- Mover process
- Leaver process
- Access requests
- Approval
- Role design
- Entitlement ownership
- Privileged access
- Access reviews
- Segregation of duties
- Contractors
- Guests
- Service accounts
- Workload identities
- Shared accounts
- Local accounts
- Emergency access
- Exceptions
- Evidence retention
- Metrics
- Program review
Roles and Responsibilitiesprotected
Identity Governance Team
Responsible for:
- Program policy
- Workflow design
- Entitlement catalog
- Certifications
- Role governance
- Metrics
- Exceptions
- Program improvement
Human Resources
Responsible for:
- Authoritative workforce data
- Employment status
- Start and end dates
- Organizational changes
- Termination notifications
- Data quality
Managers
Responsible for:
- Business justification
- Access approval
- Periodic review
- Contractor sponsorship
- Role-change notification
Application and Data Owners
Responsible for:
- Entitlement definition
- Risk classification
- Approval
- Access review
- Segregation-of-duties rules
- Deprovisioning validation
Security
Responsible for:
- High-risk access policy
- Privileged access
- Threat monitoring
- Exception review
- Identity incident response
- Control validation
IT Operations
Responsible for:
- Provisioning
- Deprovisioning
- Directory operations
- Integration
- Failure remediation
- Technical evidence
Risk and Compliance
Responsible for:
- Risk framework
- Certification requirements
- Segregation-of-duties oversight
- Exceptions
- Audit evidence
- Reporting
Example Environmentprotected
Organization
A 6,000-person hybrid enterprise with:
- Microsoft Entra ID
- On-premises Active Directory
- Microsoft 365
- 250 SaaS applications
- AWS and Azure
- 800 contractors
- Several legacy applications
- Multiple privileged-access tools
- Manual application onboarding
- Quarterly access reviews for financial applications
Current State
- Human resources is authoritative for employees.
- Contractors are managed in spreadsheets.
- Terminations disable the primary directory account.
- SaaS deprovisioning is partially manual.
- Privileged access is frequently permanent.
- Service accounts lack consistent ownership.
- Access reviews are completed, but revocation execution is not centrally tracked.
- Application registrations are not reviewed regularly.
Example Executive Findingsprotected
SEC-004-001 — Contractor Identities Lack a Reliable Authoritative Source
Severity: Critical
Confidence: High
Evidence: Contractor identities are created from email requests and tracked through separate spreadsheets without consistent end dates or sponsor validation.
Business Impact: Contractor access may remain active after the business relationship ends.
Recommendation: Establish a contractor identity source containing sponsor, company, start date, end date, contract status, and automatic expiration.
SEC-004-002 — Termination Does Not Revoke All SaaS Access
Severity: Critical
Confidence: High
Evidence: The directory account is disabled promptly, but several non-federated SaaS applications require manual deprovisioning.
Security Impact: Former personnel may retain direct application access after termination.
Recommendation: Identify all non-federated applications, implement SCIM or API-based deprovisioning where possible, create emergency manual procedures, and validate access removal.
SEC-004-003 — Privileged Access Is Predominantly Permanent
Severity: High
Confidence: High
Evidence: Most cloud and directory administrators maintain standing privileged roles without activation, expiration, or approval.
Recommendation: Move privileged users to eligible assignments, require MFA and justification, limit activation duration, and review permanent exceptions.
SEC-004-004 — Access Review Revocations Are Not Tracked to Completion
Severity: High
Confidence: High
Evidence: Review campaigns record revoke decisions, but removal is performed manually and no central validation confirms completion.
Recommendation: Integrate certification decisions with deprovisioning, track failed removals, and report revocation-completion metrics separately from review completion.
SEC-004-005 — Service Accounts Lack Ownership and Rotation
Severity: High
Confidence: Medium
Evidence: Approximately thirty percent of identified service accounts have no current owner, and many use non-expiring passwords.
Recommendation: Complete service-account inventory, assign business and technical owners, move credentials to a vault, enforce rotation, and replace eligible accounts with managed identities.
SEC-004-006 — Application Registrations Are Not Governed
Severity: High
Confidence: High
Evidence: Application registrations can be created broadly, several applications have one or no owners, and long-lived secrets are common.
Recommendation: Restrict registration creation, require multiple owners, govern API permissions and consent, enforce credential expiration, and review unused applications.
Automation Opportunitiesprotected
- Identity creation
- Identity correlation
- Data-quality checks
- Birthright access
- Role assignment
- Contractor expiration
- Access requests
- Approval routing
- Segregation-of-duties checks
- Provisioning
- Deprovisioning
- Session revocation
- Access certifications
- Revocation execution
- Privileged activation
- Credential rotation
- Service-account inventory
- Workload-identity inventory
- Dormant-account detection
- Exception expiration
- Dashboard reporting
- Identity risk alerts
Pro Tipsprotected
- Start with authoritative identity data.
- Assign an owner to every identity.
- Treat role changes as access-review events.
- Validate termination across every application.
- Revoke active sessions and tokens.
- Keep birthright access limited.
- Give approvers meaningful context.
- Build an entitlement catalog.
- Use roles carefully.
- Reduce standing privilege.
- Separate standard and administrative accounts.
- Track access-review revocations to completion.
- Require contractor sponsors and end dates.
- Govern service accounts as identities.
- Prefer managed and federated workload identities.
- Inventory application registrations.
- Review consent grants.
- Expire credentials and exceptions.
- Monitor emergency access.
- Measure identity risk reduction, not only workflow completion.
- Integrate identity governance with security operations.
- Require human validation for AI-generated access recommendations.
Common Mistakesprotected
- Treating Authentication as Identity Governance: Authentication proves identity. Governance determines whether access is appropriate.
- Governing Employees but Not Contractors: Contractors often present greater lifecycle risk because identity data is less reliable.
- Disabling the Primary Account but Missing SaaS Access: Non-federated applications may remain accessible after directory deactivation.
- Ignoring the Mover Process: Employees frequently accumulate access when changing roles.
- Creating Too Much Birthright Access: Convenience can create broad, unnecessary exposure.
- Approving Access Without Context: Approvers need business purpose, risk, current access, and conflict information.
- Using Current Access to Define Roles: Existing access may contain historical excess and control failures.
- Completing Reviews Without Enforcing Revocation: A revoke decision does not reduce risk until access is removed.
- Reviewing Every Entitlement Equally: Risk-based reviews reduce fatigue and improve decision quality.
- Leaving Privileged Access Permanent: Standing privilege increases the impact of account compromise.
- Ignoring Non-Human Identities: Service accounts, applications, and automation identities often have broad and poorly monitored access.
- Allowing Credentials to Never Expire: Long-lived secrets increase compromise and continuity risk.
- Treating Shared Accounts as Normal: Shared accounts reduce attribution and complicate incident response.
- Accepting Exceptions Without Expiration: Temporary access frequently becomes permanent.
- Automating Poor Processes: Automation can accelerate incorrect access decisions if source data and policy are weak.
- Using AI Recommendations as Approval: AI can identify anomalies and suggest actions, but accountable business and security owners must approve material access decisions.
Security Considerationsprotected
- Identity governance information may contain sensitive data such as employee status, contractor status, manager relationships, job roles, access rights, privileged activity, risk indicators, investigation data, termination timing, personal identifiers, and authentication information.
- Before sharing information with an AI system: remove passwords, secrets, tokens, private keys, and active session details.
- Minimize personal information and mask employee identifiers where practical.
- Avoid sharing confidential termination details.
- Follow human resources, legal, and privacy requirements.
- Use an approved AI platform and confirm retention and model-training settings.
- Restrict generated reports appropriately.
- AI should not independently make employment, disciplinary, termination, or legal decisions.
Related Blueprints
⚠ Normalization Warnings — 11 for review
- CLASSIFICATION TO CONFIRM: 'Prerequisites' classified as a checklist TOOL (gather-before-start items are completable). Alternative: body/prose.
- CLASSIFICATION TO CONFIRM: 'Core Principles' classified as body/reference (a consultable list of governing principles). Alternative: body/prose. 'Program Objectives' kept as body/prose (question list, consulted not completed) — confirm.
- RESTRUCTURE: 'Primary AI Prompt' and 'Follow-Up Prompts' (two source H1s plus H2 subsections) combined into one prompt_pack tool with 28 prompts; 'when' guidance lines are editorial additions, prompt text verbatim.
- RESTRUCTURE: 'Responsibility Matrix' converted from the source RACI table into a matrix TOOL with rows as example_rows verbatim. Note: some cells contain non-standard RACI values (Approves, Governs, Executes, Supports) preserved from the source.
- GROUPING: The document contains ~60 domain H1 sections; these were grouped by theme (Identity Source Architecture, Identity Lifecycle, Access Request and Approval, Access Control Models, Privileged and Emergency Access, Access Certification, Segregation of Duties, Contractor and Third-Party Access, Non-Human Identity Governance, Dormant/Shared/Local Accounts, Exceptions, Monitoring and Incident Response, Mergers/Acquisitions/Divestitures, Metrics and Dashboards, Roles and Responsibilities) to avoid a flat 60-item render. Confirm grouping boundaries.
- CLASSIFICATION: 'Identity Types' and 'Identity Governance Maturity Model' classified as body/reference (tiered taxonomies consulted, not completed). 'Preventive Versus Detective Controls' kept as prose within the SoD group.
- CLASSIFICATION: 'Common Mistakes', 'Security and Privacy Considerations', 'Automation Opportunities', 'Pro Tips', 'Quick Wins', and 'Twelve-Month Roadmap' mapped to playbook flat lists (standard tail sections). Common Mistakes items combined heading+explanation into single strings.
- CLASSIFICATION: 'Example Environment' and 'Example Executive Findings' classified as body/example (worked/illustrative instances). The findings include a stat: '~30% of service accounts have no owner' — this is illustrative example data, not a workflow stat, so excluded from overlay.stats.
- CLASSIFICATION: 'Validation Checklist' classified as a checklist TOOL (verifiable pass/fail items with ☐ markers in source). 'Metrics to Avoid Misusing', 'Executive Dashboard', and 'Operational Dashboard' kept as body/prose within Metrics group (consulted reference lists, not completed).
- AUTOMATION: The numbered 'mature automated identity governance workflow' list under Automation Opportunities was omitted from playbook.automation_opportunities (which holds the flat 'Automate:' list); confirm whether the 20-step aspirational workflow should be preserved as body/prose. Flagging as potential dropped content.
- overlay.stats.deliverables set to 4 (the four typed tools). Source lists many conceptual deliverables in Expected Outcome; counted only shipped tools per convention. quick_wins counted as 15 from the Quick Wins list.
SEO Block
- Title tag: Design Identity Governance & Administration | ABME (50 chars)
- Meta: Design a risk-based identity governance program: joiner-mover-leaver controls, least-privilege access, certification, SoD, and non-human identity governance. (157 chars)
- Schema: HowTo · noindex: false
- Related: sec-001, sec-002, sec-003, sec-005, sec-006, sec-008, sec-009, cl-002, cl-003, cl-008, cl-010
- Keywords: identity governance, identity governance and administration, joiner mover leaver, access certification, segregation of duties, privileged access governance, service account governance, workload identity governance, least privilege access, entitlement catalog, access request workflow, IGA program design
