Shared Signals and CAEP: ending a leaver's live sessions, not only the account
ILM Reference editors · Published 2026-09-16 · 4 minute read
Disabling a leaver's directory account stops new authentications, but sessions and tokens already issued can stay valid in downstream applications until they expire. The OpenID Foundation's Shared Signals Framework lets one system tell another that something changed, and its CAEP and RISC profiles define events such as Session Revoked and account disabled. NIST IR 8587, published on 15 September 2026, recommends SSF and CAEP.
Why is disabling the account not enough?
Leaver processes are usually measured by one timestamp: when the directory account was disabled. That covers new authentications. It does not cover what was already issued, such as a session in a SaaS application, a refresh token held by a mobile client, or an API token used by a script. Those persist until they expire or until the application is told to end them.
For applications the directory does not front at all, including local accounts in disconnected applications, the directory action changes nothing. The disconnected applications guide covers that case separately.
NIST SP 800-53 AC-2 (h) asks organizations to notify account managers when users are terminated or transferred, and AC-2 (l) asks them to align account management with personnel termination and transfer processes. Security events sent between systems are one way to do that notification within minutes rather than by ticket.
What are SSF, CAEP and RISC?
The OpenID Foundation's Shared Signals Working Group maintains three related specifications.
| Specification | What it does | Example events or functions | Status on the working group page |
|---|---|---|---|
| Shared Signals Framework (SSF) | An API for asynchronous communication between a transmitter and a receiver | Describe a transmitter; create, start, pause and delete a stream | Implementers' Draft 3 |
| CAEP (Continuous Access Evaluation Profile) | Events about changes that affect an active session | Session Revoked, Token Claims Change, Credential Change, Assurance Level Change, Device Compliance Change | Final Specification approved 2 September 2025 |
| RISC (Risk Incident Sharing and Coordination) | Events about account-level risk shared between providers | Account Credential Change Required; Account Purged, Disabled or Enabled; Identifier Changed or Recycled; Credential Compromise | Final Specification approved 2 September 2025 |
For a leaver, the useful events are CAEP Session Revoked, which tells a receiving application to end the person's session, and RISC account disabled, which tells it the account is no longer valid.
What does NIST IR 8587 recommend?
NIST IR 8587, Protecting Tokens and Assertions from Forgery, Theft, and Misuse, was published as final on 15 September 2026 by authors from NIST, CISA and Accenture Federal Services. Its stated audience is federal agencies and cloud service providers, and it covers key management, token verification and lifecycle controls. The OpenID Foundation noted on 16 September 2026 that the report recommends SSF and CAEP.
For a private-sector program it is guidance, not an obligation. It is still a clear public statement that continuous evaluation belongs in token lifecycle controls, and a useful reference when an auditor asks how quickly a leaver's access actually ended.
How does this fit a leaver process?
- The HR event starts the leaver workflow in the IGA.
- The directory account is disabled.
- The system acting as transmitter, typically the identity provider, sends events to every application registered as a receiver.
- Receiving applications end sessions and revoke tokens for that person.
- Applications that are not receivers, and local accounts anywhere, still need a direct removal step or a ticket. Confirm with a fresh account pull, as in the joiner-mover-leaver process.
Signals only reach applications that implement a receiver. List which of your critical applications do, and keep the others on the explicit removal path.
The time the account was disabled, the time each receiving application confirmed the session ended, and the time each non-receiving application was cleaned up. The gap between the first and last timestamp is your real leaver time.
What should buyers ask vendors?
- Does the product act as an SSF transmitter, a receiver, or both, and for which events?
- Which of our critical applications can receive CAEP Session Revoked today?
- What happens to local accounts in applications that cannot receive signals?
- Is each signal, and the action it caused, logged as audit evidence?
Shared Signals support is not part of this site's scoring rubric. The editorial method lists the criteria we score.
Sources
- NIST SP 800-53 Rev. 5
- AC-2 control text, catalog mirror
- OpenID Foundation, Shared Signals Working Group
- NIST IR 8587
- OpenID Foundation, on NIST IR 8587
Reviewed Sep 2026