The final step in this month’s activity is to implement the roles and clean up any extraneous access that’s left behind. As in the previous segment, the distinction between enterprise and IT roles doesn’t matter, so I will generalize. The reason for this is that what you implement depends on your strategy – as defined [...]
Role- and Rule-Basing Part 4: Documentation and Approval
Once all of the roles are defined, it’s time to document them and obtain approval for their use. We’re now past the point where the distinction between enterprise and IT roles matters, so in this segment I go back to the generic term, “role.” Documentation and approval Once testing is complete, the final roles should [...]
Role- and Rule-Basing Part 3: Designing and Testing IT Roles
Now that enterprise roles have been identified and prioritized, it’s time to tackle IT roles, and figuring out IT roles is where the rubber meets the road. Chances are, neither the department heads nor the HR team can help on this one. It’s up to the identity management team and business “power users” to determine [...]
Role- and Rule-Basing Part 2: Identifying & Prioritizing Enterprise Roles
The first step in role- and rule-basing is identifying and prioritizing the enterprise roles. This sets the direction for the entire effort, which – make no mistake – will be time consuming. Doing some thoughtful planning up-front is therefore imperative to ensuring that you don’t start out off-track. Identifying the roles in the organization is [...]
Role- and Rule-Basing Part 1: Introduction
At this point in the identity management process it is time to consider what access the company’s job functions should have to begin creating roles and rules. This is the first step in automating provisioning and de-provisioning. Even without automation, creating and managing the roles and rules will make manual provisioning (and auditing!) quite a [...]
HR as a Source of Record Part 5: Reliability and Accessibility
We’ve now gone through the employee’s full lifecycle and discussed how to interpret and manipulate HR data to facilitate automation in identity management for new hires, transfers, and terminations. We wrap up this this month with a focus on the accessibility and reliability of HR data. At a minimum, you should know what to expect [...]
HR as a Source of Record Part 4: Terminations
In the last article, we discussed how to identify access transfers from HR data. Now we’re in the home stretch: terminations. Compared to transfers, terminations are pretty easy, but there are a couple of gotchas, as mentioned in this month’s introduction. A termination in the HR system means the employee is no longer getting paid. [...]
HR as a Source of Record Part 3: Transfers
In the last article, we discussed the HR considerations for enabling auto-provisioning/auto-assignment of tasks for new hires. Now we’ll address transfers. Employees are, by definition, only hired and terminated once, but they can undergo many transfers during their employment at a company. Transfers are the biggest part of the employee lifecycle because a transfer can [...]
HR as a Source of Record Part 2: New Hires
In my last article, I introduced the importance of understanding the HR system and putting that into the context of using HR data to manage identities. This is a big challenge because while the HR system is a technology, it is rarely managed by IT – more typically it is managed by an HR-owned administration [...]
Building the Foundation for Successful Password Self-Service Part 5: User Training and Wrap-up
So far this month, we’ve updated the <password policy>, created appropriate <challenge questions>, and come up with a strategy for setting initial passwords. Now we are ready to start training the users and wrap up the month’s activity Developing user training Unless you’ve already worked with Michael, chances are that the users at your organization [...]

Engage with Michael