Identity lifecycle management glossary
Short definitions of the terms used across this reference, in alphabetical order. Where a term comes from a standard or regulator, the source is linked. Three terms have their own page.
A
AC-2 (account management)
The NIST SP 800-53 control for managing system accounts: defining account types, approving creation, monitoring use, reviewing accounts at a set frequency and disabling accounts that are no longer needed.
Source: NIST SP 800-53 Rev. 5 · Reviewed Sep 2026
Access certification
A scheduled review in which managers or app owners confirm or revoke each person's access.
Access package
A bundle of access (groups, application roles, sites) that people request or are assigned as one unit, with its own approval and expiry policy. The term is used in Microsoft Entra ID Governance entitlement management.
Source: Microsoft Learn · Reviewed Sep 2026
Access request
A request for access that is not granted automatically, routed for approval before it is provisioned. Okta Identity Governance and Microsoft Entra ID Governance both describe access requests with approval workflows.
Source: Okta · Reviewed Sep 2026
Account reconciliation
Matching the accounts that exist inside an application against the people and owners in your authoritative sources, so every account is either linked to a current owner or flagged for action.
Application owner
The person accountable for an application's access: approving requests, reviewing accounts in certifications and acting on leavers where the application is not connected to the IGA.
Attribute-based access control (ABAC)
An access control method where authorization is decided by evaluating attributes of the subject, the object, the requested operation and sometimes the environment against policy.
Source: NIST SP 800-162 · Reviewed Sep 2026
Authoritative source
The system trusted as the record of who a person is and whether they still work for you, usually the HR system for employees and a contract or vendor record for contractors. Lifecycle events start from changes in it.
AuthZEN
An OpenID Foundation working group defining a standard API between applications and authorization engines. Its Authorization API 1.0 was approved as a Final Specification on 12 January 2026.
Source: OpenID Foundation · Reviewed Sep 2026
B
Birthright access
Access granted automatically to everyone in a population on day one, such as email and HR self-service.
Break-glass account
An emergency account kept outside normal sign-in and approval flows so administrators can recover access when those flows fail. It needs a named owner, stored credentials and a review after every use.
C
CAEP (Continuous Access Evaluation Profile)
An OpenID Foundation profile of the Shared Signals Framework for events that affect an active session, such as Session Revoked and Credential Change.
Source: OpenID Foundation · Reviewed Sep 2026
D
Deprovisioning
Removing or disabling a person's accounts and access when they leave or no longer need it. In connected applications it runs through a connector or SCIM; in disconnected ones it is a manual task that needs a record.
Disconnected application
An application the identity provider or IGA cannot read from or write to.
Dormant account
An account with an owner that has not been used for a defined period.
E
Entitlement
A specific permission inside an application, such as a role, group or permission set. Access reviews are only as clear as the entitlement descriptions reviewers see.
Entitlement creep
The gradual build-up of access beyond what a role needs, usually because movers gain new access without losing the old. Also called privilege drift; Orchid Security lists privilege drift among the issues it detects inside applications.
Source: Orchid Security · Reviewed Sep 2026
H
Hardcoded credential
A username and password, token or key written into application code or configuration. It behaves like an account nobody reviews. Orchid Security lists hardcoded accounts and credentials among the issues it detects.
Source: Orchid Security · Reviewed Sep 2026
I
Identity Dark Matter
Identity Dark Matter is a trademark of Orchid Security. Orchid uses the term for identity activity and accounts inside applications that central IAM does not see; its home page states that identity dark matter hides in applications.
Source: Orchid Security · Reviewed Sep 2026
Identity observability
Continuous visibility into how identities actually authenticate and use access inside applications.
Identity provider (IdP)
The system that authenticates users and provides sign-on to connected applications through federation protocols. It controls sign-on, not the accounts an application keeps in its own user store.
IGA (identity governance and administration)
Software that automates provisioning, access reviews and access policy.
IT general controls (ITGC)
The controls auditors test over the IT environment that supports financial reporting, including who can access programs and data. PCAOB AS 2201 tells auditors to understand how IT affects the company's flow of transactions.
Source: PCAOB AS 2201 · Reviewed Sep 2026
J
Joiner
A person starting employment or a contract. The joiner event creates accounts and birthright access, ideally before the first working day.
Just-in-time (JIT) access
Access granted for a limited time when it is needed and removed automatically afterwards, instead of being held permanently.
L
Least privilege
The principle that a system should restrict the access privileges of users, or processes acting for them, to the minimum needed for their assigned tasks.
Source: NIST glossary · Reviewed Sep 2026
Leaver
A person whose employment or contract ends. The leaver event should disable every account the person holds, including local accounts in disconnected applications, within the period your policy sets.
Local account
An account created and stored inside an application rather than in the central directory.
M
Mover
A person who changes role, department, manager or location. The mover event should add the access the new role needs and remove what the old role granted.
N
Non-human identity (NHI)
An identity used by software rather than a person, such as a service account, API key, workload identity or AI agent. It has no HR record, so its lifecycle needs a named sponsor.
O
P
Privileged account
A system account with the authorizations of a privileged user, such as an administrator.
Source: NIST glossary · Reviewed Sep 2026
Provisioning
Creating accounts and granting access in applications, through a connector, SCIM, an API or a manual ticket.
R
RISC (Risk Incident Sharing and Coordination)
An OpenID Foundation profile of the Shared Signals Framework for account-level risk events shared between providers, such as account disabled or credential compromise.
Source: OpenID Foundation · Reviewed Sep 2026
Role-based access control (RBAC)
A model where permitted actions are attached to roles rather than to individual identities, and people receive access by holding a role.
Source: NIST glossary · Reviewed Sep 2026
Rubber-stamping
Approving every item in an access review without real examination, often because the list is long or the entitlements are unclear. Auto-certifying low-risk items and describing entitlements in plain language are the usual countermeasures.
S
SCIM
System for Cross-domain Identity Management, a standard protocol for provisioning users to applications. The protocol is defined in IETF RFC 7644 (September 2015).
Source: IETF RFC 7644 · Reviewed Sep 2026
Separation of duties (SoD)
A rule that one person should not hold two conflicting permissions, such as creating and approving a payment. NIST's glossary puts it as: no user should be given enough privileges to misuse the system on their own.
Source: NIST glossary · Reviewed Sep 2026
Service account
A non-human account that an application or script uses to run or to connect to another system. Service accounts often hold broad access and are a common source of orphan accounts when their owner leaves.
Shared Signals Framework (SSF)
An OpenID Foundation API that lets a transmitter send security events to receivers over a managed stream, so one system can tell another that something about a user or session changed.
Source: OpenID Foundation · Reviewed Sep 2026
Sponsor
The named person accountable for a non-human identity or an external user. When the sponsor leaves or changes role, the identities they sponsor need a new sponsor or a review.
T
Time to deprovision
The time between a leaver's termination date in the HR system and the moment each of their accounts is disabled. Measured per application, it shows where the leaver process is slow.
Z
Zero standing privilege (ZSP)
An operating model in which no account holds privileged access permanently; admin rights are granted just in time and removed after use.