Short answer
Identity management controls digital access through accurate identities, appropriate permissions, and timely lifecycle changes. It gives managers observable evidence from approvals, access records, reviews, and resolved exceptions.
About Identity management
Controls digital access through accurate identities, appropriate permissions, and timely lifecycle changes. The competency focuses on identity and access decisions across the lifecycle, not broad security monitoring.
Use this competency for
- Roles that provision, change, review, or remove workforce and system access.
- Functions accountable for identity records, access models, approvals, or lifecycle controls.
Do not use this competency for
- Roles that consume access but do not administer or design identity controls.
Important distinctions
Security operations
Security operations detects and investigates security events. Identity management maintains identities, permissions, and lifecycle controls before and after events.
IT support
IT support may fulfill access requests. Identity management determines the records, approvals, access patterns, and review controls those requests follow.
Expectations by level
IC1
Processes identity changes
Completes well-defined identity and access changes with guidance, verifies required approvals, and leaves an accurate record of what changed.
Observable behaviors
- Matches each request to the approved identity and entitlement.
- Uses the current joiner, mover, and leaver procedure.
- Escalates mismatched or excessive access before fulfillment.
Examples
- Removed departing-worker access within the assigned window and attached completion evidence.
- Paused a role change when the requested entitlement did not match the recorded approval.
IC2
Owns access workflows
Independently manages identity workflows for a system or population, resolves ambiguous access cases, and improves controls using review and exception evidence.
Observable behaviors
- Investigates access discrepancies across source and target systems.
- Runs an access review and tracks unresolved decisions to closure.
- Updates role or workflow rules after documenting a recurring exception.
Examples
- Reconciled stale group membership against the source identity records and assigned corrections.
- Reworked a mover workflow after repeated role changes left conflicting permissions.
IC3
Designs identity controls
Defines identity and access standards across systems, frames complex lifecycle risks, and sets review and ownership patterns that multiple teams can operate.
Observable behaviors
- Defines shared identity attributes, ownership, and approval boundaries.
- Designs access models that separate routine grants from exceptions.
- Uses lifecycle and review evidence to prioritize control changes.
Examples
- Established a common role model for three systems with named owners for exceptional access.
- Changed the deprovisioning standard after cross-system evidence showed delayed removals.