Skip to content

Home Expertise / Identity & access

IAM / IAM-01

Identity lifecycle and role management

Organising account creation, changes and removal so each person receives the right access at the right time for the right duration.

WHEN IT HELPS

A focused response
to a defined need.

IT, HR or business owners; slow onboarding, incomplete offboarding or accumulated access after role changes.

AT A GLANCE

Family
Identity & access

Engagement
Implementation

Reference
IAM-01

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Authoritative identity source
  • business roles and approvals
  • automate or formalise joiner, mover and leaver processes

Deliverables

  • Role matrix
  • included processes and connectors
  • lifecycle tests and operating guide

Acceptance evidence

A test user is created, moved and removed; resulting access matches approved rules.

DELIVERY

How the work is structured.

Approach

Inventory identities and applications; define roles and policies; pilot with one group; test allow/deny/recovery paths; roll out and hand over.

Prerequisites & responsibilities

Customer: application owners, HR, administrators, pilot groups and emergency accounts. Provider: design, integration and testing within agreed permissions.

Scope factors

Users, directories, applications, protocols, privileged accounts, compatibility and migration. Licenses, physical keys and recurring operations are separate.

Questions to clarify

Who confirms arrivals and departures? Which systems must follow? Which access requires business approval?

IMPORTANT BOUNDARIES

Automation depends on HR data quality and available interfaces; not all applications support the same provisioning capabilities.

Recovery and emergency access are tested before rollout. Authentication, authorisation and privileged-access management are complementary layers.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

A 300-person company shares leaver information through informal messages. Project: define a departure event and tracked actions. Target outcome: controlled revocation, access handover and exception tracking.

Scenario 02

An employee moves between subsidiaries but retains old access. Project: define roles and mover rules. Target outcome: remove former permissions after checking legitimate transitional duties.

Technology and reference context

Customer directories, IAM/IGA and connectors; SCIM where available and compatible.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.