Identity Lifecycle Management
Identity lifecycle management (often part of identity governance and administration, IGA) keeps access aligned with a person's or workload's current relationship to the organization. It covers initial access when someone joins, changes when they move roles, temporary assignments, periodic reviews, and removal when they leave — plus the evidence that every downstream system actually reached the intended state.
Most access-related breaches and audit findings trace back to lifecycle gaps: former employees with working accounts, contractors whose access never expired, or people who accumulated permissions across five role changes. Automating the lifecycle from an authoritative source closes most of those gaps.
TL;DR
- Drive identities from an authoritative source (usually the HR system) using a stable identifier, not an email address.
- Model joiner, mover, and leaver events explicitly; movers must lose old access, not just gain new access.
- Give birthright access automatically from attributes; require approval for sensitive access.
- Provision downstream with SCIM or supported connectors, then reconcile actual state.
- Revoke sessions, tokens, and local accounts, not just the central login.
- Run access reviews that owners can actually understand, and time-limit exceptions.
Quick Example
A mover event handled as a desired-state calculation:
And a SCIM request the identity provider sends to deactivate a user in a SaaS app:
Core Concepts
Authoritative Sources and Correlation
For employees, the HR system is normally the source of truth for who works here, in what role, and until when. Contractors, vendors, guests, service accounts, and AI agents may have different sources and owners. Correlate accounts across systems with stable identifiers; names and email addresses change (marriage, rebranding) and can be reused, which leads to access leaking to the wrong person.
Joiner, Mover, Leaver
Authentication vs Provisioning
Single sign-on proves identity at sign-in. Provisioning creates, updates, and deactivates accounts and entitlements inside target systems, typically through SCIM (System for Cross-domain Identity Management) or vendor APIs. Disabling SSO blocks new sign-ins but doesn't necessarily end existing sessions, API tokens, or local accounts.
Access Models
Role-based access control (RBAC) is the usual starting point; attribute-based access control (ABAC) adds context such as location or data classification. Keep the role catalog small enough that people can understand it — "role explosion" defeats the purpose.
Access Reviews (Certification)
Periodic reviews ask managers or resource owners to confirm that each person still needs each entitlement. They work only when reviewers see meaningful descriptions ("Can approve payments up to $50k in ERP") rather than raw group names, and when unanswered reviews default to removal.
Non-Human Identities
Service accounts, API keys, CI/CD credentials, and workload identities often outnumber humans. They need owners, purposes, rotation, and removal when the service is retired. Prefer short-lived workload identity federation over long-lived secrets. See Privileged Access Management and Secrets Management.
Best Practices
Make Lifecycle Events Idempotent
Repeated or duplicated HR events should converge on the same desired state, never create duplicate accounts or broaden access twice.
Recompute Access on Every Move
Calculate desired access from the new role and remove anything no longer justified. Time-limit any handover overlap with a named owner.
Separate Revocation From Deletion
On departure, immediately block sign-in, revoke sessions and tokens, and remove privileged access. Delete or archive accounts later, after data ownership and records are transferred.
Reconcile Target State
Read back effective permissions from target systems and alert on differences. A successful workflow submission is only an intermediate signal.
Cover Every Identity Type
Guests need sponsors and expiry; contractors need end dates from their contracts; workloads need owners. Include them all in reviews.
Measure the Lifecycle
Track time from HR effective date to access granted or removed, orphaned accounts, review completion rates, and the share of access assigned by policy versus by request.
Common Mistakes
Using Email as the Identity Key
Email changes and reuse cause mismatched accounts and access for the wrong person.
Additive-Only Moves
Adding finance permissions during a transfer while leaving all sales permissions indefinitely creates toxic combinations and audit findings.
Closing Leaver Tickets After Disabling Only the Central Account
App-local accounts, API tokens, shared passwords, OAuth grants, and mailbox delegations survive. Verify each system.
Rubber-Stamp Access Reviews
Reviews that show hundreds of cryptic group names get approved wholesale. Summarize entitlements and focus reviewers on risky access.
Orphaned Service Accounts
Service accounts created for a project and never retired accumulate privileges nobody monitors.
FAQ
What is identity lifecycle management?
It's the automated process of creating, changing, reviewing, and removing digital identities and their access as people join, move within, and leave an organization, and as workloads are deployed and retired.
What is SCIM?
SCIM is an open standard (RFC 7643/7644) for provisioning users and groups between an identity provider and applications through a REST API, so account creation and deactivation happen automatically.
Should all access be automatic?
No. Automate well-defined baseline access. Require contextual approval for sensitive entitlements, exceptions, and privileged roles.
How do guests differ from employees?
Guests need a sponsor, a business purpose, an expiry date, and regular review, even when they sign in through their own organization's identity provider.
What if a connector can't revoke access?
Escalate to a named system owner, apply an approved compensating control such as blocking sign-in, and track the gap until access in the target system is removed.
Related Topics
- Single Sign-On (SSO) — Central authentication for workforce apps
- Directory Services — Where identities and groups are stored
- Privileged Access Management — Extra controls for high-impact access
- SaaS Management — Governing access across cloud applications
- Identity & Access Management — The wider IAM discipline