aBmeSubscribe
SEC-004·SEC Track·Advanced·18–90 hrs saved

Stop Losing Track of Who Has Access to What — and Why — Across the Entire Identity Lifecycle

An AI-assisted workflow to design an accountable, risk-based identity governance and administration program that controls human and non-human access from joiner to leaver.

3Phases
15Quick wins
18–90Hours saved
4Deliverables

Executive Brief

Your Challenge

Your organization manages identities through disconnected systems and informal processes — access granted over email, no authoritative source, delayed terminations, and access retained after every role change. You cannot reliably answer who has access to what, why they have it, who approved it, when it was last reviewed, or when it should be removed. Former employees keep access, employees accumulate permissions, contractors stay enabled, and privileged access is difficult to control while audit findings recur.

Common Obstacles

The failure modes cluster in predictable places. Contractors present greater lifecycle risk than employees because their identity data is less reliable, yet they are governed less. Terminations disable the primary directory account but leave non-federated SaaS access intact. Privileged access is predominantly permanent. Access reviews are completed but revocations are never tracked to enforcement, so a completed campaign leaves access unchanged. Non-human identities — service accounts, application registrations, workload identities — carry broad, poorly monitored access with no owners and non-expiring credentials.

The ABME Approach

This workflow builds the program in the right order: establish authoritative identity sources and data quality, then design the joiner, mover, and leaver lifecycle, then the access-request, role, and privileged-access models, then certification, segregation of duties, and non-human identity governance — measured by a maturity model and validated end to end. You define an owner for every identity and entitlement, treat data quality as a control, distinguish approval from provisioning and review completion from revocation completion, and require human accountability for every material access decision. AI accelerates the analysis; accountable owners approve the outcomes.

Insight Summary

Identity governance is not the administration of accounts. It is the continuous, evidence-based control of who and what may access resources, why, for how long, and who is accountable for the risk.
phase-1

Identity data quality is a security control, not a hygiene concern. Poor identity data creates poor access decisions no matter how good the workflow above it is.

phase-2

Role changes create more risk than onboarding. Employees accumulate access when they move, and the access nobody removes is the access nobody is accountable for.

phase-2

Standing privilege is the multiplier on every account compromise. Permanent privileged assignments turn one stolen credential into unlimited blast radius.

phase-3

A completed access review is not complete until revocations are enforced. A revoke decision does not reduce risk until access is actually removed.

tactical

Contractors present greater lifecycle risk than employees precisely because their identity data is less reliable — govern them harder, not softer.

The Journey

Three phases; each lists the tools you'll use there.

1

Establish Authoritative Identity and Data Quality

Define identity types, authoritative sources, correlation, and data-quality controls before designing any workflow.
  • Gather identity governance policy, IAM architecture, and inventories
  • Classify all identity types including non-human identities
  • Define authoritative sources and source-of-truth requirements
  • Assess identity data quality and correlation
  • Define core principles and program objectives
2

Design the Lifecycle and Access Models

Use the prompt pack to design joiner-mover-leaver controls, access requests, roles, privileged access, and non-human identity governance.
  • Run the primary AI prompt with the gathered evidence
  • Design joiner, mover, and leaver controls with deprovisioning validation
  • Build the entitlement catalog and access-request workflow
  • Design role-based access and privileged-access governance
  • Govern service accounts, workload identities, and application registrations
3

Certify, Validate, and Operationalize

Prove access is appropriate, revocations are enforced, and the program is measured and governed.
  • Run risk-based access certification campaigns
  • Track revocations to completion separately from review completion
  • Run the validation checklist across every domain
  • Wire identity events into monitoring and dashboards
  • Execute the twelve-month roadmap

What's Inside the Execution Layer

Numbered deliverables grouped by phase. Membership unlocks every tool.

1. PHASE 1Checklistprotected

Prerequisites Checklist

Gather the identity data, inventories, and records the AI needs to design or assess a governance program before the first prompt runs.
Use this to
  • Assemble the full identity governance evidence base
  • Surface inventory and integration gaps early
  • Confirm regulatory and policy inputs up front

Gather as much of the following as possible:

2. PHASE 2Prompt Packprotected

Identity Governance Prompt Pack

One primary prompt and twenty-seven targeted follow-ups that design or assess a comprehensive identity governance and administration program.
Use this to
  • Design or assess an end-to-end IGA program
  • Target specific domains like JML, privileged access, or SoD
  • Generate dashboards, inventories, and remediation findings

Primary AI Prompt

Start here with the gathered identity data and inventories.
You are a senior identity governance architect, identity and access management strategist, privileged access specialist, cloud identity architect, compliance advisor, security risk consultant, and enterprise process designer.

I will provide some or all of the following:

• Identity governance policies
• IAM architecture
• Authoritative identity sources
• Human resources data
• Contractor data
• Identity provider configuration
• Directory inventory
• Application inventory
• Entitlement catalog
• Role catalog
• Group inventory
• Privileged role inventory
• Service account inventory
• Workload identity inventory
• Access request records
• Approval workflows
• Access review records
• Segregation-of-duties rules
• Dormant account data
• Termination records
• Provisioning and deprovisioning logs
• Privileged access logs
• Credential inventory
• Exception records
• Identity incidents
• Audit findings
• Compliance requirements
• Metrics

Your task is to design or assess a comprehensive identity governance and administration program.

Do not assume that an enabled identity is valid.
Do not assume that approved access remains necessary.
Do not assume that a completed access review means revocations were implemented.

First:

1. Summarize:
• Organizational context
• Identity types
• Authoritative sources
• Identity platforms
• Application landscape
• Current lifecycle process
• Current access-request process
• Privileged-access model
• Certification process
• Contractor model
• Service-account model
• Current governance maturity

2. Separate:
• Confirmed facts
• Validated evidence
• Reported observations
• Inferences
• Assumptions
• Unknowns

3. Identify missing evidence that materially affects the assessment.

4. Evaluate:
• Identity inventory
• Identity ownership
• Authoritative sources
• Identity data quality
• Identity correlation
• Joiner controls
• Mover controls
• Leaver controls
• Termination timing
• Deprovisioning validation
• Birthright access
• Access requests
• Approval quality
• Entitlement catalog
• Role design
• Attribute-based access
• Privileged access
• Emergency access
• Access certifications
• Reviewer effectiveness
• Revocation execution
• Segregation of duties
• Contractor access
• Guest access
• Partner access
• Service accounts
• Workload identities
• Application registrations
• Consent governance
• Credential governance
• Dormant accounts
• Shared accounts
• Local accounts
• Exceptions
• Monitoring
• Incident response
• Privacy
• Reporting
• Metrics
• Governance

5. For each weakness provide:
• Finding ID
• Domain
• Severity
• Confidence
• Evidence
• Business impact
• Security impact
• Operational impact
• Compliance impact
• Recommended action
• Owner
• Dependencies
• Validation
• Estimated effort
• Priority
• Target timing

6. Identify:
• Orphaned identities
• Dormant identities
• Stale contractors
• Former employees with access
• Accounts missing owners
• Excessive access
• Privilege accumulation
• Permanent privilege
• Shared accounts
• Unowned service accounts
• Expired credentials
• Unowned applications
• Segregation-of-duties conflicts
• Access-review failures
• Unexecuted revocations
• Expired exceptions
• Deprovisioning failures

7. Classify findings as:
• Critical
• High
• Medium
• Low
• Informational

8. Recommend:
• Immediate containment
• Process remediation
• Technical remediation
• Governance change
• Automation
• Owner
• Due date
• Validation method
• Exception path
• Escalation path

Requirements:
• Require an owner for every identity and entitlement.
• Treat identity data quality as a control.
• Treat role changes as access reevaluation events.
• Prioritize termination and privileged-access failures.
• Identify standing privilege.
• Identify service-account and workload-identity risk.
• Require expiration for contractors, guests, credentials, and exceptions where practical.
• Distinguish approval from provisioning.
• Distinguish review completion from revocation completion.
• Identify segregation-of-duties conflicts.
• Do not recommend role mining without business validation.
• Avoid creating roles that preserve historical excess.
• Identify manual bottlenecks.
• State where human, legal, human resources, privacy, security, compliance, or business-owner review is required.
• State when evidence is insufficient.
• Do not expose credentials, secrets, or personal data.

Then produce:
1. Executive summary.
2. Identity governance maturity assessment.
3. Identity architecture overview.
4. Identity inventory assessment.
5. Authoritative-source assessment.
6. Identity data-quality assessment.
7. Joiner process.
8. Mover process.
9. Leaver process.
10. Termination control assessment.
11. Access-request and approval model.
12. Entitlement catalog model.
13. Role and policy model.
14. Privileged-access governance model.
15. Emergency-access model.
16. Access-certification program.
17. Segregation-of-duties framework.
18. Contractor and guest governance.
19. Service-account governance.
20. Workload-identity governance.
21. Application registration and consent governance.
22. Credential governance.
23. Dormant and stale-access process.
24. Exception process.
25. Identity monitoring and incident-response integration.
26. Metrics and dashboards.
27. Risk register.
28. Quick wins.
29. Twelve-month implementation roadmap.
30. Responsibility matrix.
31. Governance recommendations.
32. Open questions.
33. Final recommendation.

Assess Identity Governance Maturity

To score the program against the five-level maturity model.
Assess the maturity of this identity governance program.

Evaluate:
• Identity sources
• Data quality
• Joiners
• Movers
• Leavers
• Access requests
• Approvals
• Entitlement catalog
• Roles
• Privileged access
• Access reviews
• Segregation of duties
• Contractors
• Service accounts
• Workload identities
• Exceptions
• Metrics
• Governance

Score each domain from Level 1 through Level 5 and explain the evidence.

Design the Joiner, Mover, and Leaver Process

To design the full identity lifecycle.
Design a complete joiner, mover, and leaver process.

For each lifecycle event include:
• Trigger
• Source
• Required data
• Approval
• Provisioning or deprovisioning
• Timing
• Validation
• Failure handling
• Escalation
• Evidence
• Metrics

Review Termination Controls

To audit leaver deprovisioning across all systems.
Assess employee and contractor termination controls.

Review:
• Notification timing
• Identity disablement
• Session revocation
• Token revocation
• Privileged accounts
• Cloud access
• SaaS access
• VPN
• Device access
• Shared credentials
• Data preservation
• Ownership transfer
• Validation

Identify any termination failures requiring immediate action.

Analyze Mover Risk

To find access retained after role changes.
Analyze identity and access risk caused by role changes.

Identify:
• Access retained from prior roles
• Department access
• Privileged access
• Approval authority
• Segregation-of-duties conflicts
• Data access
• Cloud roles
• Group membership
• Application roles

Recommend access to retain, remove, modify, or review.

Build an Entitlement Catalog

To construct the catalog underpinning access requests.
Create an entitlement catalog.

For each entitlement include:
• Application
• Entitlement
• Description
• Business purpose
• Risk
• Data sensitivity
• Owner
• Approver
• Prerequisites
• Segregation-of-duties rules
• Default duration
• Review frequency
• Provisioning method
• Deprovisioning method

Design an Access Request Workflow

To build a risk-based request-to-provision flow.
Design a risk-based access-request workflow.

Include:
• Requestor
• Beneficiary
• Resource
• Entitlement
• Business justification
• Duration
• Manager approval
• Application-owner approval
• Data-owner approval
• Security approval
• Segregation-of-duties check
• Provisioning
• Validation
• Expiration
• Evidence

Improve Approval Quality

To detect rubber-stamping and fix the approval model.
Review this access-approval process.

Identify:
• Rubber-stamp behavior
• Self-approval
• Missing context
• Approval after provisioning
• Excessive approval layers
• Approval bottlenecks
• Inappropriate approvers
• Unexplained bulk approval

Recommend a stronger and more efficient approval model.

Design Role-Based Access

To define roles aligned to job functions.
Design a role-based access-control model.

For each role define:
• Name
• Business purpose
• Eligible population
• Owner
• Entitlements
• Exclusions
• Risk
• Approval
• Segregation-of-duties rules
• Review frequency
• Lifecycle status

Avoid preserving historically excessive access.

Perform Role Mining

To derive candidate roles from access patterns — with business validation.
Analyze current access patterns to identify candidate business roles.

Exclude or flag:
• Privileged outliers
• Dormant access
• Unowned entitlements
• Historical excess
• Segregation-of-duties conflicts
• Individual exceptions

Provide confidence and require business-owner validation.

Review Privileged Access

To assess standing privilege and PIM posture.
Assess privileged-access governance.

Review:
• Permanent assignments
• Eligible assignments
• Just-in-time access
• Approval
• MFA
• Device restrictions
• Session logging
• Credential vaulting
• Emergency access
• Privileged service accounts
• Dormant administrators
• Review frequency

Identify privileges requiring immediate removal or containment.

Design Just-in-Time Privilege

To replace standing privilege with time-bound elevation.
Design a just-in-time privileged-access process.

Include:
• Eligibility
• Request
• Business justification
• Approval
• MFA
• Device requirement
• Activation duration
• Scope
• Session logging
• Ticket reference
• Alerting
• Review
• Automatic expiration

Review Emergency Accounts

To audit break-glass account controls.
Assess emergency-access accounts.

Review:
• Number of accounts
• Ownership
• Credential protection
• MFA
• Monitoring
• Sign-in restrictions
• Last use
• Testing
• Password rotation
• Custodian access
• Post-use review
• Recovery capability

Design an Access Certification Program

To build risk-based recurring reviews.
Design a risk-based access-certification program.

Define:
• Campaign scope
• Reviewer
• Frequency
• Review context
• Risk indicators
• Decision options
• Escalation
• Delegation
• Revocation workflow
• Completion validation
• Evidence
• Metrics

Improve an Access Review Campaign

To fix fatigue and unexecuted revocations in an existing campaign.
Review this access-certification campaign.

Identify:
• Review fatigue
• Missing context
• Inappropriate reviewers
• Bulk approval
• Overdue reviews
• Unexecuted revocations
• Low-value entitlements
• High-risk access not emphasized
• Evidence gaps

Recommend improvements.

Analyze Segregation-of-Duties Conflicts

To detect incompatible-duty combinations in entitlements.
Analyze these entitlements for segregation-of-duties conflicts.

For each conflict provide:
• Rule
• Conflicting access
• Business process
• Risk
• Severity
• Existing controls
• Recommended resolution
• Owner
• Exception authority
• Monitoring

Design Contractor Governance

To build a contractor and third-party lifecycle.
Design a contractor and third-party identity governance process.

Include:
• Sponsor
• Company
• Contract status
• Start date
• End date
• Business purpose
• Access scope
• MFA
• Device requirements
• Data restrictions
• Review frequency
• Extension approval
• Automatic expiration
• Offboarding validation

Review Guest Access

To audit external-user access risk.
Assess guest and external-user access.

Identify:
• Missing sponsors
• Expired guests
• Dormant guests
• Broad group membership
• Sensitive data access
• Weak authentication
• Untrusted domains
• Cross-tenant risk
• Missing expiration
• Incomplete review

Recommend remediation.

Build a Service Account Inventory

To catalog service accounts and their controls.
Create a service-account inventory.

Include:
• Account
• Purpose
• Business owner
• Technical owner
• Application
• Environment
• Privilege
• Authentication method
• Credential location
• Rotation
• Interactive-logon status
• Dependencies
• Last used
• Review date
• Lifecycle status

Review Service Account Risk

To prioritize service-account containment and modernization.
Assess service-account risk.

Identify:
• Missing owners
• Excessive privilege
• Interactive logon
• Shared use
• Stale credentials
• Hard-coded secrets
• Missing rotation
• Dormant accounts
• Unknown dependencies
• Cross-environment use
• Missing monitoring

Recommend containment and modernization.

Review Workload Identities

To assess service principals, managed identities, and automation accounts.
Assess workload identities, service principals, managed identities, API clients, and automation accounts.

Review:
• Ownership
• Purpose
• Permissions
• Scope
• Credential type
• Credential expiration
• Last use
• Environment
• Creation source
• Monitoring
• Review
• Decommissioning

Prioritize excessive permission and expired-owner findings.

Review Application Registrations

To govern app registrations and their credentials.
Assess application registrations.

Identify:
• Missing owners
• High-risk API permissions
• Administrative consent
• Expired credentials
• Long-lived secrets
• Unverified publishers
• Unused applications
• Unsafe redirect URIs
• Multi-tenant exposure
• Excessive scope
• Incomplete monitoring

Review Consent Grants

To audit user and admin application consent.
Assess user and administrative application consent.

Identify:
• High-risk permissions
• Unverified publishers
• Dormant applications
• Excessive delegated access
• Broad application permissions
• Unnecessary tenant-wide consent
• Missing owner
• Missing business justification
• Consent requiring revocation

Find Dormant and Orphaned Accounts

To identify stale identities and recommend actions.
Analyze identity data to identify:
• Dormant users
• Orphaned accounts
• Former employees
• Expired contractors
• Unowned service accounts
• Dormant privileged accounts
• Stale guests
• Unused application registrations
• Expired credentials

For each item recommend validate, suspend, disable, remove, or escalate.

Review Identity Exceptions

To assess and dispose of standing exceptions.
Review these identity and access exceptions.

Assess:
• Business justification
• Risk
• Compensating controls
• Owner
• Approver
• Start date
• Expiration
• Review date
• Remediation plan
• Monitoring

Recommend approve, conditionally approve, reject, or escalate.

Create an Identity Risk Dashboard

To design executive-level identity risk reporting.
Design an executive identity-risk dashboard.

Include:
• Failed terminations
• Orphaned accounts
• Dormant accounts
• Permanent privilege
• High-risk access
• Contractor expiration
• Access-review completion
• Revocation completion
• Segregation-of-duties conflicts
• Service-account risk
• Expired credentials
• Exceptions
• Identity incidents
• Automation coverage

Create an Operational Dashboard

To design day-to-day operational identity reporting.
Design an operational identity-governance dashboard.

Include:
• Pending requests
• Approval backlog
• Provisioning failures
• Deprovisioning failures
• Access-review backlog
• Unexecuted revocations
• Expired contractors
• Dormant identities
• Credential expiration
• Privileged activations
• Emergency-account activity
• Segregation-of-duties violations
3. PHASE 2Matrixprotected

Responsibility Matrix

A RACI-style assignment of identity governance capabilities across HR, managers, the identity team, application owners, security, and operations.
Use this to
  • Assign accountability for each governance capability
  • Resolve ownership gaps before launch
  • Anchor governance decisions in a shared RACI
Reference rows from the blueprint — downloads ship as an empty skeleton
CapabilityHRManagerIdentity TeamApplication OwnerSecurityOperations
Workforce identity sourceAccountableInformedConsultedInformedInformedSupports
Joiner processResponsibleApprovesAccountableConsultedConsultedExecutes
Mover processResponsibleApprovesAccountableConsultedConsultedExecutes
Leaver processResponsibleInformedAccountableConsultedConsultedExecutes
Access requestInformedResponsibleGovernsAccountable for resourceConsultedExecutes
Role designInformedConsultedResponsibleAccountableConsultedSupports
Privileged accessInformedConsultedSupportsConsultedAccountableResponsible
Access certificationInformedResponsibleGovernsAccountable for resourcesConsultedExecutes revocation
Segregation of dutiesInformedConsultedSupportsResponsibleConsultedInformed
Service accountsInformedInformedGovernsAccountableConsultedResponsible
ExceptionsInformedResponsibleSupportsConsultedAccountable for security reviewExecutes controls
4. PHASE 3Checklistprotected

Validation Checklist

The domain-by-domain acceptance gate an identity governance program must pass across governance, lifecycle, access, and non-human identities.
Use this to
  • Verify each governance domain is controlled
  • Confirm terminations, revocations, and NHI controls work
  • Gate the program before declaring it operational

Verify the program against each domain:

Governance

Identity Data

Joiners

Movers

Leavers

Access Requests

Privileged Access

Certifications

Contractors and Guests

Non-Human Identities

Monitoring and Reporting

🔒 The full execution layer — every checklist, matrix, and the prompt pack — is included with ABME membership.

Unlock Full Blueprint

Full Playbook

Overviewpublic

Identity governance and administration is the structured process used to ensure that the right people and systems receive the right access to the right resources for the right reasons and for the appropriate period of time.

Identity governance extends beyond authentication.

It addresses:

  • Identity ownership
  • Joiner, mover, and leaver processes
  • Access requests
  • Access approval
  • Role design
  • Entitlement management
  • Privileged access
  • Access reviews
  • Segregation of duties
  • Contractor access
  • Service accounts
  • Workload identities
  • Emergency access
  • Policy enforcement
  • Evidence
  • Risk
  • Compliance
  • Deprovisioning

A mature identity governance program should answer:

“Who has access to what, why do they have it, who approved it, when was it last reviewed, and when should it be removed?”

The objective is not to centralize every identity decision into a single tool.

The objective is to create a reliable, accountable, risk-based operating model that governs human and non-human access throughout its lifecycle.

A successful program reduces:

  • Excessive access
  • Orphaned accounts
  • Dormant accounts
  • Privilege accumulation
  • Unauthorized access
  • Separation-of-duties conflicts
  • Contractor access risk
  • Shared-account use
  • Manual provisioning delays
  • Audit effort
  • Access-review fatigue
  • Identity-related incident impact

Business Problempublic

Organizations often manage identities through disconnected systems and informal processes.

Common symptoms include:

  • Access granted through email
  • No authoritative identity source
  • Inconsistent onboarding
  • Delayed termination
  • Access retained after role changes
  • Excessive administrator rights
  • Shared accounts
  • Unowned service accounts
  • Manual access reviews
  • Rubber-stamp approvals
  • No entitlement catalog
  • Inconsistent contractor controls
  • Weak application integration
  • Multiple identity stores
  • Poor access visibility
  • No evidence of business justification
  • Permanent privileged assignments
  • Dormant cloud identities
  • Unmanaged API credentials
  • Access exceptions that never expire

Without effective identity governance:

  • Former employees may retain access.
  • Employees accumulate unnecessary permissions.
  • Contractors remain enabled.
  • Privileged access becomes difficult to control.
  • Audit findings recur.
  • Sensitive systems become overexposed.
  • Security teams cannot determine actual access.
  • Business owners cannot make informed approval decisions.
  • Incident response becomes slower.
  • Access-related support costs increase.

Expected Outcomepublic

After completing this workflow, the organization should have:

  • Identity governance strategy
  • Program charter
  • Identity-source model
  • Identity lifecycle process
  • Joiner, mover, and leaver controls
  • Identity classification model
  • Access-request workflow
  • Approval model
  • Role and entitlement model
  • Privileged-access model
  • Access-certification process
  • Segregation-of-duties framework
  • Contractor-access process
  • Service-account governance
  • Workload-identity governance
  • Emergency-access process
  • Exception process
  • Evidence-retention model
  • Metrics and dashboards
  • Implementation roadmap
  • AI-assisted analysis prompts
  • Automation opportunities

🔒 The complete playbook — reference models, worked examples, and operational guidance — is included with ABME membership.

Unlock Full Blueprint

Program Objectivesprotected

The identity governance program should answer:

  1. What is the authoritative identity source?
  2. Which identity types exist?
  3. Who owns each identity?
  4. How are new identities created?
  5. How are role changes handled?
  6. How quickly is access removed after termination?
  7. How is access requested?
  8. Who approves access?
  9. What business justification is required?
  10. Which access is role-based?
  11. Which access is individually assigned?
  12. Which access is privileged?
  13. How are entitlements cataloged?
  14. How are incompatible duties identified?
  15. How are access reviews conducted?
  16. How are reviewers selected?
  17. How are dormant accounts handled?
  18. How are contractors governed?
  19. How are service accounts governed?
  20. How are workload identities governed?
  21. How are emergency accounts controlled?
  22. How are exceptions approved?
  23. How is deprovisioning validated?
  24. How is evidence retained?
  25. How is identity risk measured?
  26. How are mergers, acquisitions, and divestitures handled?
  27. How are application owners held accountable?
  28. How are identity-related incidents investigated?
  29. How are manual processes reduced?
  30. How is program effectiveness measured?

Core Principlesprotected

Recommended Principles

Principles that should govern the identity program.
  • Every identity must have an owner.
  • Access must have a business purpose.
  • Access should be least privilege.
  • Access should be time-bound when practical.
  • Privileged access should not be permanent.
  • Birthright access should be limited.
  • Role changes should trigger access reevaluation.
  • Termination should trigger immediate deprovisioning.
  • Access reviews should be risk-based.
  • Reviewers need meaningful context.
  • Exceptions should expire.
  • Shared accounts should be eliminated or tightly controlled.
  • Service accounts require lifecycle governance.
  • Workload identities should use short-lived credentials.
  • Evidence should be retained automatically.
  • Identity governance should be integrated with business processes.
  • Automation should not remove accountability.
  • High-risk access requires stronger controls.
  • Identity data quality is a security control.
  • Governance decisions require human ownership.

Identity Typesprotected

Workforce Identities

  • Employees
  • Temporary employees
  • Interns
  • Executives
  • Administrators
  • Developers
  • Service desk personnel

External Identities

  • Contractors
  • Consultants
  • Vendors
  • Partners
  • Suppliers
  • Guests
  • Customers
  • Volunteers

Privileged Identities

  • Domain administrators
  • Cloud administrators
  • Security administrators
  • Database administrators
  • Network administrators
  • Application administrators
  • Emergency administrators

Non-Human Identities

  • Service accounts
  • Managed identities
  • Workload identities
  • API clients
  • Application registrations
  • Bots
  • Automation accounts
  • Certificates
  • Tokens
  • SSH keys
  • Database accounts
  • Integration accounts
  • Device identities

Identity Source Architectureprotected

Identity Source Architecture

Define the authoritative sources for:

  • Employee identities
  • Contractor identities
  • Vendor identities
  • Customer identities
  • Organizational structure
  • Job role
  • Manager
  • Department
  • Cost center
  • Location
  • Employment status
  • Start date
  • End date
  • Leave status
  • Risk status

Typical authoritative systems include:

  • Human resources information systems
  • Contractor management systems
  • Vendor management systems
  • Customer identity platforms
  • Student information systems
  • Volunteer management systems

Source-of-Truth Requirements

The authoritative source should provide:

  • Unique identity identifier
  • Reliable status
  • Start date
  • End date
  • Manager
  • department
  • Job code
  • Employment type
  • Location
  • Legal entity
  • Cost center
  • Sponsoring organization
  • Data-quality controls
  • Timely updates
  • Audit history

Identity Data Quality

Assess:

  • Duplicate identities
  • Missing managers
  • Missing end dates
  • Invalid departments
  • Stale contractor records
  • Inconsistent names
  • Reused identifiers
  • Incorrect employment status
  • Missing sponsors
  • Delayed updates
  • Invalid cost centers

Poor identity data creates poor access decisions.

Identity Correlation

Where multiple identity systems exist, correlate identities using:

  • Immutable employee or contractor ID
  • Email address
  • Username
  • Legal name
  • Manager
  • Department
  • Human resources record
  • Device ownership
  • Application account
  • Cloud identity
  • Privileged account relationship

Avoid relying only on display name.

Identity Lifecycle: Joiner, Mover, Leaverprotected

Joiner Process

The joiner process governs new identities.

Define:

  • Identity creation trigger
  • Start-date handling
  • Pre-hire access
  • Manager approval
  • Birthright access
  • Role-based access
  • Equipment provisioning
  • MFA enrollment
  • Training requirements
  • Policy acknowledgment
  • Privileged-access restrictions
  • Contractor-specific controls
  • Initial access review
  • Evidence retention

Pre-Hire Access

Pre-hire access should be limited.

Control:

  • Earliest activation date
  • Permitted applications
  • Sponsor
  • Expiration
  • MFA
  • Device restrictions
  • Sensitive-data restrictions
  • Monitoring
  • Automatic conversion or removal

Birthright Access

Birthright access may include:

  • Email
  • Collaboration tools
  • Intranet
  • Basic productivity platforms
  • Standard endpoint access
  • Employee self-service
  • Required training systems

Birthright access should not automatically include:

  • Sensitive data
  • Administrative privileges
  • Financial approval
  • Production access
  • Broad shared drives
  • Regulated systems
  • High-risk cloud roles

Mover Process

Role changes often create more risk than onboarding.

The mover process should:

  • Detect department changes.
  • Detect job changes.
  • Detect manager changes.
  • Detect location changes.
  • Detect legal-entity changes.
  • Detect employment-type changes.
  • Reevaluate existing access.
  • Remove incompatible access.
  • Add approved new access.
  • Reassess privileged roles.
  • Reevaluate segregation-of-duties conflicts.
  • Record decisions.

Access Accumulation

Access accumulation occurs when employees retain previous permissions after changing roles.

Detect:

  • Old group membership
  • Legacy application roles
  • Prior department access
  • Shared-folder access
  • Privileged assignments
  • Cloud roles
  • Distribution lists
  • Database roles
  • Approval authority
  • VPN profiles

Leaver Process

Termination controls should address:

  • Immediate termination
  • Scheduled termination
  • Leave of absence
  • Retirement
  • Contractor expiration
  • Vendor separation
  • Death
  • Legal hold
  • Investigation
  • Acquired-company separation

Termination Timing

Define:

  • Trigger source
  • Notification timing
  • Deactivation deadline
  • Emergency termination path
  • Session revocation
  • Token revocation
  • Password reset
  • Device access removal
  • VPN removal
  • Privileged-access removal
  • SaaS deprovisioning
  • Data preservation
  • Mailbox handling
  • File ownership transfer
  • Certificate revocation
  • Shared-secret rotation

Immediate Terminations

For high-risk or involuntary terminations:

  • Coordinate with human resources.
  • Coordinate with legal.
  • Pre-stage deactivation.
  • Disable interactive access.
  • Revoke active sessions.
  • Revoke refresh tokens.
  • Disable privileged accounts.
  • Remove remote access.
  • Isolate managed devices if required.
  • Rotate shared secrets.
  • Preserve evidence.
  • Validate deprovisioning.

Leave of Absence

Define controls for:

  • Temporary access suspension
  • Continued email access
  • Delegate access
  • Privileged-access removal
  • Remote-access restrictions
  • Return-date activation
  • Data preservation
  • Access review upon return

Deprovisioning Validation

Do not assume the workflow completed successfully.

Validate:

  • Primary identity disabled
  • Privileged identity disabled
  • Cloud access removed
  • SaaS access removed
  • VPN access removed
  • Sessions revoked
  • Tokens revoked
  • Service accounts reassigned
  • Shared secrets rotated where needed
  • Devices secured
  • Ownership transferred
  • Evidence retained

Access Request and Approvalprotected

Access Request Management

A controlled access request should include:

  • Requestor
  • Beneficiary
  • Resource
  • Entitlement
  • Business justification
  • Requested duration
  • Data sensitivity
  • Risk level
  • Required training
  • Manager approval
  • Resource-owner approval
  • Security approval where required
  • Segregation-of-duties result
  • Expiration
  • Provisioning status
  • Validation
  • Evidence

Request Catalog

Create an entitlement catalog containing:

  • Application
  • Resource
  • Entitlement
  • Description
  • Business purpose
  • Risk
  • Data sensitivity
  • Owner
  • Approver
  • Prerequisites
  • Segregation-of-duties rules
  • Default duration
  • Review frequency
  • Provisioning method
  • Deprovisioning method

Approval Models

Possible approval steps include:

  • Manager approval
  • Application-owner approval
  • Data-owner approval
  • Security approval
  • Compliance approval
  • Financial approval
  • Privileged-access approval
  • Project-owner approval
  • Sponsor approval

Approval should reflect risk, not organizational habit.

Approval Context

Approvers should receive:

  • Requested access
  • Business purpose
  • User role
  • Existing access
  • Data sensitivity
  • Risk
  • Segregation-of-duties conflicts
  • Requested duration
  • Prior review history
  • Similar-role access
  • Anomalies
  • Recommended decision

Rubber-Stamp Approval

Detect:

  • Extremely rapid approvals
  • Near-100% approval rates
  • Approvals without justification
  • Reviewers approving large volumes
  • Approvals while unavailable
  • Repeated approval of conflicts
  • Self-approval
  • Approval after provisioning
  • Bulk approval without context

Access Control Modelsprotected

Least Privilege

Least privilege requires:

  • Minimum required permissions
  • Minimum required scope
  • Minimum required duration
  • Appropriate environment
  • Appropriate data access
  • Appropriate administrative level
  • Periodic review
  • Removal after use

Role-Based Access Control

Role-based access should align entitlements with defined job functions.

A role should include:

  • Role name
  • Business purpose
  • Eligible population
  • Owner
  • Included entitlements
  • Excluded entitlements
  • Risk
  • Segregation-of-duties rules
  • Approval
  • Review frequency
  • Version
  • Lifecycle status

Role Engineering

Role engineering may use:

  • Top-down business analysis
  • Bottom-up access mining
  • Peer-group analysis
  • Job-code analysis
  • Department analysis
  • Application-role analysis
  • Entitlement clustering
  • Risk review
  • Business-owner validation

Role Explosion

Avoid excessive role creation.

Warning signs include:

  • One role per user
  • Highly overlapping roles
  • Many unused roles
  • Roles with unclear purpose
  • Roles containing individual exceptions
  • Roles owned by inactive employees
  • Roles that are never reviewed

Role Mining

Use current access patterns carefully.

Current access may reflect historical excess, not valid requirements.

Role mining should:

  • Identify common entitlement patterns.
  • Exclude privileged outliers.
  • Exclude stale access.
  • Incorporate job function.
  • Require business validation.
  • Check segregation-of-duties conflicts.
  • Track confidence.

Attribute-Based Access Control

Attribute-based access may consider:

  • Department
  • Job code
  • Location
  • Employment type
  • Clearance
  • Device trust
  • Risk level
  • Resource classification
  • Time
  • Network
  • Project
  • Contract status

Attributes must be trustworthy and governed.

Policy-Based Access

Policies may restrict access based on:

  • Data classification
  • Device compliance
  • Authentication strength
  • User risk
  • Sign-in risk
  • Geography
  • Network location
  • Time of day
  • Employment status
  • Privilege
  • Application sensitivity

Entitlement Ownership

Every entitlement should have:

  • Business owner
  • Technical owner
  • Approval owner
  • Review owner
  • Risk classification
  • Description
  • Lifecycle status
  • Associated resource
  • Deprovisioning method

Unowned entitlements should not remain requestable.

Privileged and Emergency Accessprotected

Privileged Access Governance

Privileged access requires stronger controls.

Govern:

  • Eligibility
  • Approval
  • Activation
  • Duration
  • MFA
  • Device trust
  • Session logging
  • Command logging
  • Credential vaulting
  • Justification
  • Ticket reference
  • Emergency use
  • Review
  • Recertification

Standing Privilege

Reduce permanent privileged assignments.

Preferred models include:

  • Just-in-time access
  • Just-enough administration
  • Time-bound activation
  • Approval-based elevation
  • Scoped roles
  • Privileged access workstations
  • Session monitoring
  • Separate administrative accounts

Privileged Account Separation

Administrators should use:

  • Standard account for normal work
  • Dedicated account for administrative tasks
  • Separate cloud or domain roles where needed
  • Stronger authentication
  • Restricted workstation
  • Limited internet access
  • Enhanced monitoring

Privileged Access Requests

Capture:

  • Requested role
  • Target resource
  • Purpose
  • Ticket or change reference
  • Start time
  • End time
  • Approver
  • Authentication method
  • Device
  • Session record
  • Actions taken
  • Closure

Privileged Access Reviews

Review:

  • Permanent assignments
  • Eligible assignments
  • Recent activations
  • Dormant privileged users
  • High-risk roles
  • Emergency access
  • Privileged service accounts
  • Privilege outside normal role
  • Direct versus group assignment
  • Cross-tenant privilege

Emergency Access

Emergency accounts should be:

  • Few in number
  • Strongly protected
  • Excluded from routine use
  • Monitored continuously
  • Stored securely
  • Tested periodically
  • Documented
  • Assigned to named custodians
  • Reviewed after every use

Emergency Account Controls

Include:

  • Long, unique credentials
  • Credential vault
  • Hardware-based authentication where feasible
  • Restricted sign-in
  • Alerting
  • Log review
  • Test schedule
  • Change process
  • Recovery procedures
  • Executive ownership

Access Certificationprotected

Access Certification

Access certification is the periodic review of user and system access.

Certification campaigns may target:

  • High-risk applications
  • Privileged access
  • Regulated data
  • Financial systems
  • Production environments
  • Contractors
  • Dormant accounts
  • External users
  • Service accounts
  • High-risk entitlements

Review Frequency

Example frequencies:

Critical Privileged Access: Monthly or quarterly

High-Risk Applications: Quarterly

Standard Business Applications: Semiannually or annually

Contractors and Guests: Monthly or quarterly

Service Accounts: Quarterly or semiannually

Frequency should reflect risk and change rate.

Reviewer Selection

Possible reviewers include:

  • Manager
  • Application owner
  • Data owner
  • Role owner
  • Privileged-access owner
  • Sponsor
  • Business-process owner

The person best positioned to understand business need should review the access.

Certification Context

Reviewers should see:

  • User
  • Employment status
  • Job role
  • Department
  • Manager
  • Access
  • Entitlement description
  • Risk
  • Last used
  • Last reviewed
  • Approval history
  • Similar-user access
  • Segregation-of-duties conflicts
  • Privileged activity
  • Requested duration
  • Recommended action

Certification Decisions

Possible decisions:

  • Approve
  • Revoke
  • Modify
  • Delegate review
  • Request information
  • Escalate
  • Accept temporarily
  • Remove at expiration

Review Fatigue

Reduce review fatigue by:

  • Scoping campaigns by risk
  • Removing low-value items
  • Grouping entitlements logically
  • Providing context
  • Highlighting anomalies
  • Using peer comparison
  • Using last-used data
  • Pre-identifying high-risk access
  • Limiting campaign duration
  • Measuring reviewer performance

Review Completion Validation

Confirm:

  • All reviews completed
  • Revocations executed
  • Failed removals remediated
  • Delegations valid
  • Exceptions approved
  • Evidence retained
  • Reviewer anomalies investigated
  • Metrics reported

A completed review is not complete until revocations are enforced.

Segregation of Dutiesprotected

Segregation of Duties

Segregation of duties prevents one person from controlling incompatible business functions.

Examples include:

  • Create vendor and approve payment
  • Create user and approve access
  • Develop code and approve production deployment
  • Submit expense and approve reimbursement
  • Create transaction and reconcile transaction
  • Administer logs and delete audit evidence
  • Request privileged access and self-approve

Segregation-of-Duties Rule

Each rule should include:

  • Rule ID
  • Business process
  • Conflicting entitlement A
  • Conflicting entitlement B
  • Risk
  • Severity
  • Owner
  • Preventive or detective control
  • Exception authority
  • Review frequency

Preventive Versus Detective Controls

Preventive: Blocks conflicting access before provisioning.

Detective: Identifies existing conflicts after provisioning.

Preventive controls are preferred for high-risk conflicts, but detective controls may be necessary for complex environments.

Conflict Resolution

Possible actions include:

  • Reject request
  • Remove existing access
  • Reduce scope
  • Add secondary approval
  • Add transaction monitoring
  • Add supervisory review
  • Time-limit access
  • Create exception
  • Reassign responsibility

Contractor and Third-Party Accessprotected

Contractor and Third-Party Access

Contractor identities should include:

  • Sponsor
  • Company
  • Purpose
  • Start date
  • End date
  • Contract status
  • Resource scope
  • Device requirements
  • Data restrictions
  • MFA
  • Network restrictions
  • Review frequency
  • Automatic expiration

Contractor Sponsorship

Sponsors should:

  • Confirm continued need.
  • Review access.
  • Update end dates.
  • Report role changes.
  • Approve extensions.
  • Validate offboarding.
  • Accept accountability.

Guest Access

Govern:

  • Invitation
  • Sponsor
  • Domain restrictions
  • Terms of use
  • MFA
  • Data access
  • Group membership
  • Expiration
  • Review
  • Removal
  • Cross-tenant configuration

Partner Access

Partner access may require:

  • Federation
  • Contract controls
  • Security requirements
  • Authentication assurance
  • Named sponsors
  • Scoped access
  • Data restrictions
  • Logging
  • Incident notification
  • Termination process

Non-Human Identity Governanceprotected

Service Account Governance

Every service account should have:

  • Unique identifier
  • Purpose
  • Business owner
  • Technical owner
  • Application
  • Environment
  • Privilege
  • Authentication method
  • Credential location
  • Rotation schedule
  • Interactive-logon setting
  • Dependencies
  • Monitoring
  • Review frequency
  • Expiration or lifecycle date

Service Account Risks

Common risks include:

  • Shared ownership
  • Unknown dependency
  • Permanent password
  • Excessive privilege
  • Interactive login
  • No rotation
  • Hard-coded credentials
  • Dormant account
  • Production access from development
  • No monitoring
  • No decommissioning plan

Service Account Controls

Prefer:

  • Managed identity
  • Workload identity federation
  • Short-lived credentials
  • Certificate authentication
  • Secret vault
  • Automatic rotation
  • Restricted logon
  • Network restriction
  • Scoped privilege
  • Usage monitoring

Workload Identity Governance

Govern:

  • Application registrations
  • Managed identities
  • Service principals
  • API clients
  • Cloud roles
  • Kubernetes service accounts
  • CI/CD identities
  • Automation identities
  • Integration identities

Workload Identity Inventory

Capture:

  • Identity ID
  • Display name
  • Owner
  • Application
  • Environment
  • Purpose
  • Permissions
  • Credential type
  • Credential expiration
  • Last used
  • Resource scope
  • Creation source
  • Review date
  • Lifecycle status

Application Registration Governance

Control:

  • Who may create applications
  • Required owner count
  • Naming
  • Publisher verification
  • API permissions
  • Admin consent
  • Secrets
  • Certificates
  • Redirect URIs
  • Multi-tenant configuration
  • Expiration
  • Review
  • Deletion

Consent Governance

Review:

  • User consent
  • Administrative consent
  • High-risk permissions
  • Unverified publishers
  • Multi-tenant applications
  • Dormant applications
  • Delegated permissions
  • Application permissions
  • Consent grants
  • Revocation

Credential Governance

Manage:

  • Passwords
  • Secrets
  • Certificates
  • Tokens
  • SSH keys
  • API keys
  • Signing keys
  • Encryption keys

Capture:

  • Owner
  • Resource
  • Purpose
  • Creation date
  • Expiration
  • Rotation
  • Storage
  • Last used
  • Revocation process

Dormant, Shared, and Local Accountsprotected

Dormant and Stale Access

Define thresholds for:

  • Inactive users
  • Inactive privileged accounts
  • Unused entitlements
  • Dormant application accounts
  • Unused service accounts
  • Stale guest accounts
  • Expired contractors
  • Unused application registrations
  • Old credentials

Dormant Account Response

Actions may include:

  • Notify owner
  • Suspend account
  • Remove high-risk access
  • Revoke sessions
  • Require revalidation
  • Disable
  • Delete after retention period
  • Preserve data
  • Escalate

Shared Accounts

Shared accounts reduce accountability.

Where unavoidable, require:

  • Documented owner
  • Business justification
  • Credential vault
  • Individual checkout
  • MFA where possible
  • Session logging
  • Password rotation
  • Restricted use
  • Review
  • Retirement plan

Local Accounts

Govern local accounts on:

  • Servers
  • Workstations
  • Network devices
  • Appliances
  • Databases
  • Applications
  • Cloud workloads

Use:

  • Central management
  • Unique local passwords
  • Automated rotation
  • Inventory
  • Restricted use
  • Logging
  • Disablement where unnecessary

Exceptionsprotected

Identity Exceptions

Each exception should include:

  • Exception ID
  • Identity or access
  • Business justification
  • Risk
  • Compensating controls
  • Owner
  • Approver
  • Start date
  • Expiration date
  • Review date
  • Remediation plan
  • Monitoring requirements

Exception Expiration

Expired exceptions should:

  • Trigger review
  • Suspend or revoke access where appropriate
  • Notify the owner
  • Escalate overdue decisions
  • Update risk reporting
  • Require new evidence for renewal

Identity Monitoring and Incident Responseprotected

Identity-Related Risk Events

Monitor for:

  • Impossible travel
  • Suspicious sign-in
  • MFA fatigue
  • Disabled-account activity
  • Dormant-account use
  • Privileged-role activation
  • New credential creation
  • Consent grant
  • Password reset
  • Group membership change
  • Application-owner change
  • Emergency-account use
  • Service-account interactive login
  • Excessive access requests
  • Access-review anomalies

Identity Threat Detection

Integrate identity governance with:

  • SIEM
  • XDR
  • User and entity behavior analytics
  • Cloud security
  • Privileged-access monitoring
  • Data loss prevention
  • Insider-risk management
  • Threat intelligence
  • Incident response

Identity Incident Response

Prepare playbooks for:

  • Compromised user
  • Compromised administrator
  • MFA fatigue attack
  • Stolen token
  • Malicious application consent
  • Service-account compromise
  • Leaver access failure
  • Insider misuse
  • Emergency-account use
  • Privilege escalation

Mergers, Acquisitions, and Divestituresprotected

Mergers and Acquisitions

Assess:

  • Identity overlap
  • Duplicate domains
  • Trust relationships
  • Legacy directories
  • Privileged accounts
  • Contractor records
  • Application ownership
  • Guest access
  • Separation-of-duties conflicts
  • Deprovisioning
  • Federation
  • Data residency
  • Transitional access

Divestitures

Plan:

  • Identity separation
  • Data ownership
  • Access removal
  • Shared-service transition
  • Domain separation
  • Application transfer
  • Credential rotation
  • Vendor access
  • Legal hold
  • Monitoring
  • Post-separation validation

Privacy Considerations

Identity governance data may include:

  • Employment status
  • Manager
  • Department
  • Access history
  • Activity
  • Location
  • Risk score
  • Review decisions
  • Investigation data

Define:

  • Purpose
  • Access
  • Retention
  • Legal basis
  • Data minimization
  • Review
  • Employee notice
  • Cross-border handling

Metrics and Dashboardsprotected

Identity Governance Metrics

Useful metrics include:

  • Joiner provisioning time
  • Mover completion time
  • Termination deprovisioning time
  • Failed deprovisioning events
  • Orphaned accounts
  • Dormant accounts
  • Unowned accounts
  • Privileged accounts
  • Permanent privileged assignments
  • Just-in-time activation rate
  • Access-review completion
  • Revocation completion
  • Overdue certifications
  • Access-request approval time
  • Access-request rejection rate
  • Segregation-of-duties conflicts
  • Open exceptions
  • Expired exceptions
  • Contractor accounts past end date
  • Service accounts without owners
  • Credentials nearing expiration
  • Application registrations without owners
  • Emergency-account use
  • Access-related incidents
  • Manual provisioning rate
  • Automated provisioning rate

Metrics to Avoid Misusing

Avoid relying solely on:

  • Number of accounts
  • Number of access reviews completed
  • Number of access requests approved
  • Number of applications connected
  • Number of roles created
  • Percentage of accounts with MFA without risk context

A completed campaign may still leave access unchanged.

Executive Dashboard

Include:

  • High-risk access
  • Permanent privilege
  • Orphaned accounts
  • Contractor expiration
  • Failed termination events
  • Access-review completion
  • Revocation completion
  • Segregation-of-duties conflicts
  • Exception age
  • Service-account risk
  • Application-owner gaps
  • Identity incidents
  • Automation coverage
  • Business-unit accountability

Operational Dashboard

Include:

  • Pending requests
  • Approval bottlenecks
  • Provisioning failures
  • Deprovisioning failures
  • Expired contractors
  • Access-review backlog
  • Unexecuted revocations
  • Dormant identities
  • Credential expiration
  • Unowned service accounts
  • Privileged activations
  • Emergency-account activity
  • Segregation-of-duties violations

Identity Governance Maturity Modelprotected

Level 1 — Ad Hoc

  • Manual provisioning
  • Email approvals
  • Incomplete inventory
  • No access reviews
  • Weak termination controls
  • Limited ownership

Level 2 — Developing

  • Basic workflows
  • Central identity provider
  • Partial automation
  • Periodic reviews
  • Inconsistent application integration
  • Limited service-account governance

Level 3 — Defined

  • Authoritative source
  • Documented lifecycle
  • Entitlement catalog
  • Risk-based approvals
  • Access certifications
  • Privileged-access governance
  • Exception process

Level 4 — Managed

  • Broad automation
  • Role and attribute-based access
  • Strong data quality
  • Continuous monitoring
  • Risk-based reviews
  • Measured performance
  • Workload-identity governance

Level 5 — Optimized

  • Continuous identity assurance
  • Adaptive access
  • Automated anomaly detection
  • Predictive access recommendations
  • Minimal standing privilege
  • Near-real-time deprovisioning
  • Continuous control validation

Governanceprotected

Define standards for:

  • Identity types
  • Authoritative sources
  • Naming
  • Unique identifiers
  • Joiner process
  • Mover process
  • Leaver process
  • Access requests
  • Approval
  • Role design
  • Entitlement ownership
  • Privileged access
  • Access reviews
  • Segregation of duties
  • Contractors
  • Guests
  • Service accounts
  • Workload identities
  • Shared accounts
  • Local accounts
  • Emergency access
  • Exceptions
  • Evidence retention
  • Metrics
  • Program review

Roles and Responsibilitiesprotected

Identity Governance Team

Responsible for:

  • Program policy
  • Workflow design
  • Entitlement catalog
  • Certifications
  • Role governance
  • Metrics
  • Exceptions
  • Program improvement

Human Resources

Responsible for:

  • Authoritative workforce data
  • Employment status
  • Start and end dates
  • Organizational changes
  • Termination notifications
  • Data quality

Managers

Responsible for:

  • Business justification
  • Access approval
  • Periodic review
  • Contractor sponsorship
  • Role-change notification

Application and Data Owners

Responsible for:

  • Entitlement definition
  • Risk classification
  • Approval
  • Access review
  • Segregation-of-duties rules
  • Deprovisioning validation

Security

Responsible for:

  • High-risk access policy
  • Privileged access
  • Threat monitoring
  • Exception review
  • Identity incident response
  • Control validation

IT Operations

Responsible for:

  • Provisioning
  • Deprovisioning
  • Directory operations
  • Integration
  • Failure remediation
  • Technical evidence

Risk and Compliance

Responsible for:

  • Risk framework
  • Certification requirements
  • Segregation-of-duties oversight
  • Exceptions
  • Audit evidence
  • Reporting

Example Environmentprotected

Organization

A 6,000-person hybrid enterprise with:

  • Microsoft Entra ID
  • On-premises Active Directory
  • Microsoft 365
  • 250 SaaS applications
  • AWS and Azure
  • 800 contractors
  • Several legacy applications
  • Multiple privileged-access tools
  • Manual application onboarding
  • Quarterly access reviews for financial applications

Current State

  • Human resources is authoritative for employees.
  • Contractors are managed in spreadsheets.
  • Terminations disable the primary directory account.
  • SaaS deprovisioning is partially manual.
  • Privileged access is frequently permanent.
  • Service accounts lack consistent ownership.
  • Access reviews are completed, but revocation execution is not centrally tracked.
  • Application registrations are not reviewed regularly.

Example Executive Findingsprotected

SEC-004-001 — Contractor Identities Lack a Reliable Authoritative Source

Severity: Critical
Confidence: High

Evidence: Contractor identities are created from email requests and tracked through separate spreadsheets without consistent end dates or sponsor validation.

Business Impact: Contractor access may remain active after the business relationship ends.

Recommendation: Establish a contractor identity source containing sponsor, company, start date, end date, contract status, and automatic expiration.

SEC-004-002 — Termination Does Not Revoke All SaaS Access

Severity: Critical
Confidence: High

Evidence: The directory account is disabled promptly, but several non-federated SaaS applications require manual deprovisioning.

Security Impact: Former personnel may retain direct application access after termination.

Recommendation: Identify all non-federated applications, implement SCIM or API-based deprovisioning where possible, create emergency manual procedures, and validate access removal.

SEC-004-003 — Privileged Access Is Predominantly Permanent

Severity: High
Confidence: High

Evidence: Most cloud and directory administrators maintain standing privileged roles without activation, expiration, or approval.

Recommendation: Move privileged users to eligible assignments, require MFA and justification, limit activation duration, and review permanent exceptions.

SEC-004-004 — Access Review Revocations Are Not Tracked to Completion

Severity: High
Confidence: High

Evidence: Review campaigns record revoke decisions, but removal is performed manually and no central validation confirms completion.

Recommendation: Integrate certification decisions with deprovisioning, track failed removals, and report revocation-completion metrics separately from review completion.

SEC-004-005 — Service Accounts Lack Ownership and Rotation

Severity: High
Confidence: Medium

Evidence: Approximately thirty percent of identified service accounts have no current owner, and many use non-expiring passwords.

Recommendation: Complete service-account inventory, assign business and technical owners, move credentials to a vault, enforce rotation, and replace eligible accounts with managed identities.

SEC-004-006 — Application Registrations Are Not Governed

Severity: High
Confidence: High

Evidence: Application registrations can be created broadly, several applications have one or no owners, and long-lived secrets are common.

Recommendation: Restrict registration creation, require multiple owners, govern API permissions and consent, enforce credential expiration, and review unused applications.

Automation Opportunitiesprotected

  • Identity creation
  • Identity correlation
  • Data-quality checks
  • Birthright access
  • Role assignment
  • Contractor expiration
  • Access requests
  • Approval routing
  • Segregation-of-duties checks
  • Provisioning
  • Deprovisioning
  • Session revocation
  • Access certifications
  • Revocation execution
  • Privileged activation
  • Credential rotation
  • Service-account inventory
  • Workload-identity inventory
  • Dormant-account detection
  • Exception expiration
  • Dashboard reporting
  • Identity risk alerts

Pro Tipsprotected

  • Start with authoritative identity data.
  • Assign an owner to every identity.
  • Treat role changes as access-review events.
  • Validate termination across every application.
  • Revoke active sessions and tokens.
  • Keep birthright access limited.
  • Give approvers meaningful context.
  • Build an entitlement catalog.
  • Use roles carefully.
  • Reduce standing privilege.
  • Separate standard and administrative accounts.
  • Track access-review revocations to completion.
  • Require contractor sponsors and end dates.
  • Govern service accounts as identities.
  • Prefer managed and federated workload identities.
  • Inventory application registrations.
  • Review consent grants.
  • Expire credentials and exceptions.
  • Monitor emergency access.
  • Measure identity risk reduction, not only workflow completion.
  • Integrate identity governance with security operations.
  • Require human validation for AI-generated access recommendations.

Common Mistakesprotected

  • Treating Authentication as Identity Governance: Authentication proves identity. Governance determines whether access is appropriate.
  • Governing Employees but Not Contractors: Contractors often present greater lifecycle risk because identity data is less reliable.
  • Disabling the Primary Account but Missing SaaS Access: Non-federated applications may remain accessible after directory deactivation.
  • Ignoring the Mover Process: Employees frequently accumulate access when changing roles.
  • Creating Too Much Birthright Access: Convenience can create broad, unnecessary exposure.
  • Approving Access Without Context: Approvers need business purpose, risk, current access, and conflict information.
  • Using Current Access to Define Roles: Existing access may contain historical excess and control failures.
  • Completing Reviews Without Enforcing Revocation: A revoke decision does not reduce risk until access is removed.
  • Reviewing Every Entitlement Equally: Risk-based reviews reduce fatigue and improve decision quality.
  • Leaving Privileged Access Permanent: Standing privilege increases the impact of account compromise.
  • Ignoring Non-Human Identities: Service accounts, applications, and automation identities often have broad and poorly monitored access.
  • Allowing Credentials to Never Expire: Long-lived secrets increase compromise and continuity risk.
  • Treating Shared Accounts as Normal: Shared accounts reduce attribution and complicate incident response.
  • Accepting Exceptions Without Expiration: Temporary access frequently becomes permanent.
  • Automating Poor Processes: Automation can accelerate incorrect access decisions if source data and policy are weak.
  • Using AI Recommendations as Approval: AI can identify anomalies and suggest actions, but accountable business and security owners must approve material access decisions.

Security Considerationsprotected

  • Identity governance information may contain sensitive data such as employee status, contractor status, manager relationships, job roles, access rights, privileged activity, risk indicators, investigation data, termination timing, personal identifiers, and authentication information.
  • Before sharing information with an AI system: remove passwords, secrets, tokens, private keys, and active session details.
  • Minimize personal information and mask employee identifiers where practical.
  • Avoid sharing confidential termination details.
  • Follow human resources, legal, and privacy requirements.
  • Use an approved AI platform and confirm retention and model-training settings.
  • Restrict generated reports appropriately.
  • AI should not independently make employment, disciplinary, termination, or legal decisions.

Brian Diamond

Founder, BrianOnAI

Twenty-five years designing, operating, and governing enterprise infrastructure — from MSP operations across dozens of client environments to enterprise infrastructure leadership. This blueprint codifies the operating model he's implemented in production, not theory.

⚠ Normalization Warnings — 11 for review

  • CLASSIFICATION TO CONFIRM: 'Prerequisites' classified as a checklist TOOL (gather-before-start items are completable). Alternative: body/prose.
  • CLASSIFICATION TO CONFIRM: 'Core Principles' classified as body/reference (a consultable list of governing principles). Alternative: body/prose. 'Program Objectives' kept as body/prose (question list, consulted not completed) — confirm.
  • RESTRUCTURE: 'Primary AI Prompt' and 'Follow-Up Prompts' (two source H1s plus H2 subsections) combined into one prompt_pack tool with 28 prompts; 'when' guidance lines are editorial additions, prompt text verbatim.
  • RESTRUCTURE: 'Responsibility Matrix' converted from the source RACI table into a matrix TOOL with rows as example_rows verbatim. Note: some cells contain non-standard RACI values (Approves, Governs, Executes, Supports) preserved from the source.
  • GROUPING: The document contains ~60 domain H1 sections; these were grouped by theme (Identity Source Architecture, Identity Lifecycle, Access Request and Approval, Access Control Models, Privileged and Emergency Access, Access Certification, Segregation of Duties, Contractor and Third-Party Access, Non-Human Identity Governance, Dormant/Shared/Local Accounts, Exceptions, Monitoring and Incident Response, Mergers/Acquisitions/Divestitures, Metrics and Dashboards, Roles and Responsibilities) to avoid a flat 60-item render. Confirm grouping boundaries.
  • CLASSIFICATION: 'Identity Types' and 'Identity Governance Maturity Model' classified as body/reference (tiered taxonomies consulted, not completed). 'Preventive Versus Detective Controls' kept as prose within the SoD group.
  • CLASSIFICATION: 'Common Mistakes', 'Security and Privacy Considerations', 'Automation Opportunities', 'Pro Tips', 'Quick Wins', and 'Twelve-Month Roadmap' mapped to playbook flat lists (standard tail sections). Common Mistakes items combined heading+explanation into single strings.
  • CLASSIFICATION: 'Example Environment' and 'Example Executive Findings' classified as body/example (worked/illustrative instances). The findings include a stat: '~30% of service accounts have no owner' — this is illustrative example data, not a workflow stat, so excluded from overlay.stats.
  • CLASSIFICATION: 'Validation Checklist' classified as a checklist TOOL (verifiable pass/fail items with ☐ markers in source). 'Metrics to Avoid Misusing', 'Executive Dashboard', and 'Operational Dashboard' kept as body/prose within Metrics group (consulted reference lists, not completed).
  • AUTOMATION: The numbered 'mature automated identity governance workflow' list under Automation Opportunities was omitted from playbook.automation_opportunities (which holds the flat 'Automate:' list); confirm whether the 20-step aspirational workflow should be preserved as body/prose. Flagging as potential dropped content.
  • overlay.stats.deliverables set to 4 (the four typed tools). Source lists many conceptual deliverables in Expected Outcome; counted only shipped tools per convention. quick_wins counted as 15 from the Quick Wins list.

SEO Block

  • Title tag: Design Identity Governance & Administration | ABME (50 chars)
  • Meta: Design a risk-based identity governance program: joiner-mover-leaver controls, least-privilege access, certification, SoD, and non-human identity governance. (157 chars)
  • Schema: HowTo · noindex: false
  • Related: sec-001, sec-002, sec-003, sec-005, sec-006, sec-008, sec-009, cl-002, cl-003, cl-008, cl-010
  • Keywords: identity governance, identity governance and administration, joiner mover leaver, access certification, segregation of duties, privileged access governance, service account governance, workload identity governance, least privilege access, entitlement catalog, access request workflow, IGA program design
Copied