Identity lifecycle management university: glossary and short lessons
A reference shelf for the vocabulary and the control language behind identity lifecycle work. The glossary defines 46 terms, with the standard or regulator linked where a term comes from one. The eleven lessons are grouped in three tracks and take 2 to 5 minutes each.
What is in the glossary?
Alphabetical definitions from access certification to zero standing privilege, including the three terms with their own page.
Which lessons are available?
Start with Basics if you are new to lifecycle work; auditors and GRC teams may prefer to start with Controls and standards.
Basics
Account types, account states and the provisioning standard most connectors use.
Human, non-human and agent identities
Every account type in the lifecycle, and the owner who answers for it.
2 minute read
SCIM provisioning basics
The standard behind most automated provisioning, and the accounts it never sees.
3 minute read
Controls and standards
What NIST SP 800-53, DORA and the access-control models ask for, in plain terms.
RBAC, ABAC and least privilege
Two ways to decide who gets access, and the principle both are meant to serve.
2 minute read
DORA access requirements
The two articles that turn DORA into joiner, mover, leaver and review requirements.
3 minute read
Separation of duties
Defining conflicting access, and checking it at the three moments it can appear.
3 minute read
Running the program
Inventory, reconciliation, leaver timing and mover drift: the work that keeps lifecycle control honest.
Application inventory
You cannot deprovision from an application you do not know exists.
2 minute read
Account reconciliation
The step that turns an account list into a list of orphans, owners and exceptions.
2 minute read
Leaver deprovisioning time
One metric, measured per application, that shows where the leaver process is slow.
2 minute read
Mover access drift
Joiners and leavers get attention. Movers are where access quietly accumulates.
3 minute read