Identity Lifecycle Management

Identity lifecycle management (often part of identity governance and administration, IGA) keeps access aligned with a person's or workload's current relationship to the organization. It covers initial access when someone joins, changes when they move roles, temporary assignments, periodic reviews, and removal when they leave — plus the evidence that every downstream system actually reached the intended state.

Most access-related breaches and audit findings trace back to lifecycle gaps: former employees with working accounts, contractors whose access never expired, or people who accumulated permissions across five role changes. Automating the lifecycle from an authoritative source closes most of those gaps.

TL;DR

Quick Example

A mover event handled as a desired-state calculation:

And a SCIM request the identity provider sends to deactivate a user in a SaaS app:

Core Concepts

Authoritative Sources and Correlation

For employees, the HR system is normally the source of truth for who works here, in what role, and until when. Contractors, vendors, guests, service accounts, and AI agents may have different sources and owners. Correlate accounts across systems with stable identifiers; names and email addresses change (marriage, rebranding) and can be reused, which leads to access leaking to the wrong person.

Joiner, Mover, Leaver

Authentication vs Provisioning

Single sign-on proves identity at sign-in. Provisioning creates, updates, and deactivates accounts and entitlements inside target systems, typically through SCIM (System for Cross-domain Identity Management) or vendor APIs. Disabling SSO blocks new sign-ins but doesn't necessarily end existing sessions, API tokens, or local accounts.

Access Models

Role-based access control (RBAC) is the usual starting point; attribute-based access control (ABAC) adds context such as location or data classification. Keep the role catalog small enough that people can understand it — "role explosion" defeats the purpose.

Access Reviews (Certification)

Periodic reviews ask managers or resource owners to confirm that each person still needs each entitlement. They work only when reviewers see meaningful descriptions ("Can approve payments up to $50k in ERP") rather than raw group names, and when unanswered reviews default to removal.

Non-Human Identities

Service accounts, API keys, CI/CD credentials, and workload identities often outnumber humans. They need owners, purposes, rotation, and removal when the service is retired. Prefer short-lived workload identity federation over long-lived secrets. See Privileged Access Management and Secrets Management.

Best Practices

Make Lifecycle Events Idempotent

Repeated or duplicated HR events should converge on the same desired state, never create duplicate accounts or broaden access twice.

Recompute Access on Every Move

Calculate desired access from the new role and remove anything no longer justified. Time-limit any handover overlap with a named owner.

Separate Revocation From Deletion

On departure, immediately block sign-in, revoke sessions and tokens, and remove privileged access. Delete or archive accounts later, after data ownership and records are transferred.

Reconcile Target State

Read back effective permissions from target systems and alert on differences. A successful workflow submission is only an intermediate signal.

Cover Every Identity Type

Guests need sponsors and expiry; contractors need end dates from their contracts; workloads need owners. Include them all in reviews.

Measure the Lifecycle

Track time from HR effective date to access granted or removed, orphaned accounts, review completion rates, and the share of access assigned by policy versus by request.

Common Mistakes

Using Email as the Identity Key

Email changes and reuse cause mismatched accounts and access for the wrong person.

Additive-Only Moves

Adding finance permissions during a transfer while leaving all sales permissions indefinitely creates toxic combinations and audit findings.

Closing Leaver Tickets After Disabling Only the Central Account

App-local accounts, API tokens, shared passwords, OAuth grants, and mailbox delegations survive. Verify each system.

Rubber-Stamp Access Reviews

Reviews that show hundreds of cryptic group names get approved wholesale. Summarize entitlements and focus reviewers on risky access.

Orphaned Service Accounts

Service accounts created for a project and never retired accumulate privileges nobody monitors.

FAQ

What is identity lifecycle management?

It's the automated process of creating, changing, reviewing, and removing digital identities and their access as people join, move within, and leave an organization, and as workloads are deployed and retired.

What is SCIM?

SCIM is an open standard (RFC 7643/7644) for provisioning users and groups between an identity provider and applications through a REST API, so account creation and deactivation happen automatically.

Should all access be automatic?

No. Automate well-defined baseline access. Require contextual approval for sensitive entitlements, exceptions, and privileged roles.

How do guests differ from employees?

Guests need a sponsor, a business purpose, an expiry date, and regular review, even when they sign in through their own organization's identity provider.

What if a connector can't revoke access?

Escalate to a named system owner, apply an approved compensating control such as blocking sign-in, and track the gap until access in the target system is removed.

Related Topics

References