REGISTER REVISED SEPTEMBER 2026

Identity lifecycle management glossary

SUMMARYREV. 2026-09

Short definitions of the terms used across this reference, in alphabetical order. Where a term comes from a standard or regulator, the source is linked. Three terms have their own page.

A

AREV. 2026-09

AC-2 (account management)

The NIST SP 800-53 control for managing system accounts: defining account types, approving creation, monitoring use, reviewing accounts at a set frequency and disabling accounts that are no longer needed.

Read more

Source: NIST SP 800-53 Rev. 5 · Reviewed Sep 2026

AREV. 2026-09

Access certification

A scheduled review in which managers or app owners confirm or revoke each person's access.

Read more

AREV. 2026-09

Access package

A bundle of access (groups, application roles, sites) that people request or are assigned as one unit, with its own approval and expiry policy. The term is used in Microsoft Entra ID Governance entitlement management.

Source: Microsoft Learn · Reviewed Sep 2026

AREV. 2026-09

Access request

A request for access that is not granted automatically, routed for approval before it is provisioned. Okta Identity Governance and Microsoft Entra ID Governance both describe access requests with approval workflows.

Source: Okta · Reviewed Sep 2026

AREV. 2026-09

Account reconciliation

Matching the accounts that exist inside an application against the people and owners in your authoritative sources, so every account is either linked to a current owner or flagged for action.

Read more

AREV. 2026-09

Application owner

The person accountable for an application's access: approving requests, reviewing accounts in certifications and acting on leavers where the application is not connected to the IGA.

AREV. 2026-09

Attribute-based access control (ABAC)

An access control method where authorization is decided by evaluating attributes of the subject, the object, the requested operation and sometimes the environment against policy.

Read more

Source: NIST SP 800-162 · Reviewed Sep 2026

AREV. 2026-09

Authoritative source

The system trusted as the record of who a person is and whether they still work for you, usually the HR system for employees and a contract or vendor record for contractors. Lifecycle events start from changes in it.

AREV. 2026-09

AuthZEN

An OpenID Foundation working group defining a standard API between applications and authorization engines. Its Authorization API 1.0 was approved as a Final Specification on 12 January 2026.

Source: OpenID Foundation · Reviewed Sep 2026

B

BREV. 2026-09

Birthright access

Access granted automatically to everyone in a population on day one, such as email and HR self-service.

BREV. 2026-09

Break-glass account

An emergency account kept outside normal sign-in and approval flows so administrators can recover access when those flows fail. It needs a named owner, stored credentials and a review after every use.

C

CREV. 2026-09

CAEP (Continuous Access Evaluation Profile)

An OpenID Foundation profile of the Shared Signals Framework for events that affect an active session, such as Session Revoked and Credential Change.

Read more

Source: OpenID Foundation · Reviewed Sep 2026

D

DREV. 2026-09

Deprovisioning

Removing or disabling a person's accounts and access when they leave or no longer need it. In connected applications it runs through a connector or SCIM; in disconnected ones it is a manual task that needs a record.

Read more

DREV. 2026-09

Disconnected application

An application the identity provider or IGA cannot read from or write to.

Read more

DREV. 2026-09

DORA

The EU Digital Operational Resilience Act, Regulation (EU) 2022/2554, which applies from 17 January 2025. Its technical standard, Delegated Regulation (EU) 2024/1774, requires a lifecycle process for identities and accounts and periodic access review.

Read more

Source: EUR-Lex · Reviewed Sep 2026

DREV. 2026-09

Dormant account

An account with an owner that has not been used for a defined period.

E

EREV. 2026-09

Entitlement

A specific permission inside an application, such as a role, group or permission set. Access reviews are only as clear as the entitlement descriptions reviewers see.

EREV. 2026-09

Entitlement creep

The gradual build-up of access beyond what a role needs, usually because movers gain new access without losing the old. Also called privilege drift; Orchid Security lists privilege drift among the issues it detects inside applications.

Read more

Source: Orchid Security · Reviewed Sep 2026

H

HREV. 2026-09

Hardcoded credential

A username and password, token or key written into application code or configuration. It behaves like an account nobody reviews. Orchid Security lists hardcoded accounts and credentials among the issues it detects.

Source: Orchid Security · Reviewed Sep 2026

I

IREV. 2026-09

Identity Dark Matter

Identity Dark Matter is a trademark of Orchid Security. Orchid uses the term for identity activity and accounts inside applications that central IAM does not see; its home page states that identity dark matter hides in applications.

Source: Orchid Security · Reviewed Sep 2026

IREV. 2026-09

Identity observability

Continuous visibility into how identities actually authenticate and use access inside applications.

Read more

IREV. 2026-09

Identity provider (IdP)

The system that authenticates users and provides sign-on to connected applications through federation protocols. It controls sign-on, not the accounts an application keeps in its own user store.

Read more

IREV. 2026-09

IGA (identity governance and administration)

Software that automates provisioning, access reviews and access policy.

IREV. 2026-09

IT general controls (ITGC)

The controls auditors test over the IT environment that supports financial reporting, including who can access programs and data. PCAOB AS 2201 tells auditors to understand how IT affects the company's flow of transactions.

Read more

Source: PCAOB AS 2201 · Reviewed Sep 2026

J

JREV. 2026-09

Joiner

A person starting employment or a contract. The joiner event creates accounts and birthright access, ideally before the first working day.

Read more

JREV. 2026-09

Joiner-mover-leaver (JML)

The three HR events that should create, change and remove access.

Read more

JREV. 2026-09

Just-in-time (JIT) access

Access granted for a limited time when it is needed and removed automatically afterwards, instead of being held permanently.

L

LREV. 2026-09

Least privilege

The principle that a system should restrict the access privileges of users, or processes acting for them, to the minimum needed for their assigned tasks.

Source: NIST glossary · Reviewed Sep 2026

LREV. 2026-09

Leaver

A person whose employment or contract ends. The leaver event should disable every account the person holds, including local accounts in disconnected applications, within the period your policy sets.

Read more

LREV. 2026-09

Local account

An account created and stored inside an application rather than in the central directory.

Read more

M

MREV. 2026-09

Mover

A person who changes role, department, manager or location. The mover event should add the access the new role needs and remove what the old role granted.

Read more

N

NREV. 2026-09

Non-human identity (NHI)

An identity used by software rather than a person, such as a service account, API key, workload identity or AI agent. It has no HR record, so its lifecycle needs a named sponsor.

Read more

O

OREV. 2026-09

Orphan account

An active account with no current valid owner.

Read more

P

PREV. 2026-09

Privileged account

A system account with the authorizations of a privileged user, such as an administrator.

Source: NIST glossary · Reviewed Sep 2026

PREV. 2026-09

Provisioning

Creating accounts and granting access in applications, through a connector, SCIM, an API or a manual ticket.

Read more

R

RREV. 2026-09

RISC (Risk Incident Sharing and Coordination)

An OpenID Foundation profile of the Shared Signals Framework for account-level risk events shared between providers, such as account disabled or credential compromise.

Source: OpenID Foundation · Reviewed Sep 2026

RREV. 2026-09

Role-based access control (RBAC)

A model where permitted actions are attached to roles rather than to individual identities, and people receive access by holding a role.

Read more

Source: NIST glossary · Reviewed Sep 2026

RREV. 2026-09

Rubber-stamping

Approving every item in an access review without real examination, often because the list is long or the entitlements are unclear. Auto-certifying low-risk items and describing entitlements in plain language are the usual countermeasures.

Read more

S

SREV. 2026-09

SCIM

System for Cross-domain Identity Management, a standard protocol for provisioning users to applications. The protocol is defined in IETF RFC 7644 (September 2015).

Source: IETF RFC 7644 · Reviewed Sep 2026

SREV. 2026-09

Separation of duties (SoD)

A rule that one person should not hold two conflicting permissions, such as creating and approving a payment. NIST's glossary puts it as: no user should be given enough privileges to misuse the system on their own.

Source: NIST glossary · Reviewed Sep 2026

SREV. 2026-09

Service account

A non-human account that an application or script uses to run or to connect to another system. Service accounts often hold broad access and are a common source of orphan accounts when their owner leaves.

SREV. 2026-09

Shadow IT

Applications adopted by teams without going through IT or security, so they are missing from the application inventory and from identity governance. C1 and Lumos both describe detection of shadow applications.

Read more

Source: C1 · Reviewed Sep 2026

SREV. 2026-09

Shared Signals Framework (SSF)

An OpenID Foundation API that lets a transmitter send security events to receivers over a managed stream, so one system can tell another that something about a user or session changed.

Read more

Source: OpenID Foundation · Reviewed Sep 2026

SREV. 2026-09

Sponsor

The named person accountable for a non-human identity or an external user. When the sponsor leaves or changes role, the identities they sponsor need a new sponsor or a review.

T

TREV. 2026-09

Time to deprovision

The time between a leaver's termination date in the HR system and the moment each of their accounts is disabled. Measured per application, it shows where the leaver process is slow.

Read more

Z

ZREV. 2026-09

Zero standing privilege (ZSP)

An operating model in which no account holds privileged access permanently; admin rights are granted just in time and removed after use.