Identity through its lifecycle.
WHAT THE LIFECYCLE IS
Creation on joining Modification on role change Removal on leaving
WHAT TO DEFINE
Standard access by role.
WHY
So access is granted consistently, and can be reviewed.
WHAT TO RECORD ON CREATION
Every system granted, and why.
WHY
That record is what you work through on departure.
WHAT TO DO ON ROLE CHANGE
Adjust access to the new role.
Not add to it.
WHY
Access accumulates otherwise, and nobody notices.
WHAT TO DO ON DEPARTURE
Disable everything, the same day Change shared credentials they knew Recover equipment Transfer ownership of their files
WHAT TO VERIFY
That removal actually took effect.
WHAT TO REVIEW PERIODICALLY
Every account, against current staff.
WHAT YOU WILL FIND
Accounts for people who left, and access nobody can justify.
WHAT TO RESTRICT MOST TIGHTLY
Administrative access, and anything touching money or customer data.