The authoritative source contract
Automation begins with a reliable trigger. The HR system is normally authoritative for employees, but contractors, interns, service partners and machine identities each need their own authoritative source with a defined owner. Every source needs a data contract: which attributes are supplied, what they mean, how quickly changes propagate, and what happens on a null value.
Pre-hire records deserve particular attention. Provisioning on the start date leaves the new joiner idle; provisioning on the offer date with a scheduled activation gets them productive on day one without granting access early.
Birthright access and the role model
Birthright access — email, collaboration, the intranet, baseline security tooling — should be granted automatically to everyone. Beyond that, a role model maps job attributes to entitlement bundles. Mining existing entitlement data reveals natural clusters, but roles must be validated with business owners rather than derived purely statistically, because existing access already contains the drift you are trying to remove.
Keep the model coarse. Hundreds of narrow roles become unmaintainable; a moderate number of well-owned roles plus a request workflow for exceptions is far more durable.
Movers: the hardest of the three
Joiners and leavers are conceptually simple. Movers are where privilege accumulates, because organisations add the new department's access and quietly leave the previous department's access in place. Every transfer should recalculate entitlements and revoke what no longer applies.
Where an immediate revocation would break a handover, use a time-boxed grace period with an explicit expiry rather than an open-ended exception. Notify the previous manager so the removal is visible and can be challenged if genuinely needed.
Deprovisioning that actually completes
Termination should disable authentication, revoke active sessions and tokens, and trigger downstream deprovisioning across every connected application. SCIM handles the modern estate; the legacy tail needs scripted connectors or a monitored manual task with an SLA.
Reconciliation is what makes the process trustworthy. A scheduled job comparing active accounts in every target system against the authoritative source will surface orphans, missed revocations and unmanaged local accounts — and that report, more than any diagram, is what convinces an auditor the process works.
Key takeaways
- Define an authoritative source and data contract for every identity population.
- Keep the role model coarse and business-validated; handle exceptions through requests.
- Recalculate and revoke on every transfer — movers are where privilege accumulates.
- Run continuous reconciliation to prove deprovisioning actually completed.
Hiring or being hired in IAM?
TagWin Recruiting places Okta, Ping, SailPoint and CyberArk specialists with enterprises that cannot afford an identity gap.
Start an intake