Skip to content
Boston Identity

Governance

Identity Governance

Access requests, approvals, certifications and the joiner, mover and leaver process, designed so that who has access to what has a ready answer.

How it works

A joiner, provisioned by policy

A joiner, provisioned by policyA hire in the HR system reaches identity governance, which assigns birthright roles by policy, creates the account in the directory, and provisions access to each application over SCIM or a connector.HRsystemIGADirectoryApplicationsgoverned1. Hire eventnew worker, start date2. Birthright rolesassigned by policy3. Create accountidentity and groups4. Provision accessSCIM or a connector
Joiner, mover and leaver all run from the HR system of record. A mover re-runs the same policy; a leaver removes access everywhere it was provisioned.

The problem

  • Access is granted quickly and removed slowly, so it accumulates.
  • Certification campaigns ask managers to approve lists they cannot interpret.
  • An auditor asks who can reach a system, and answering takes weeks.

What we do

Identity governance decides who should have access; authentication only checks who someone is. Governance is the half an audit asks about, and the half that decays fastest when nobody owns it.

Most of the work is not about the tool but about the decisions it records: who may approve what, and when access should end. Our explainer below sets out the concepts in plain language, without a vendor's vocabulary.

What you get

  • A role and entitlement model built from the access people actually have.
  • Joiner, mover and leaver processes driven by the HR system of record.
  • Access reviews scoped so that a reviewer can make a real decision.
  • Reports that answer an auditor's question from the system rather than from a spreadsheet.

How it is usually shaped

Usually follows a workforce identity program, once authentication is in place.

Talk to us

Tell us where your Identity Governance work stands, and we will reply within one business day.

Talk to us about Identity Governance