Identity lifecycle
Joiner, Mover and Leaver runbooks driven by authoritative employment attributes, approvals, target validation and exception handling.
A fictional, sanitized identity operations system demonstrating automated request validation, explainable least-privilege and segregation-of-duties policy, standard access provisioning, human exception handling, operational notifications and audit-ready evidence.
Operational IAM work is more than creating accounts. The lab shows how access is validated, provisioned, investigated, reviewed and removed with evidence at every stage.
Joiner, Mover and Leaver runbooks driven by authoritative employment attributes, approvals, target validation and exception handling.
Structured investigation across account state, authentication, policy, authorization, synchronization, provisioning and the target application.
Role and entitlement mapping, segregation-of-duties controls, recurring access reviews, remediation and target-state confirmation.
A repeatable decision path keeps access restoration safe, reduces handoff time and preserves an audit trail.
Each case includes business impact, validation, sanitized evidence, root cause, resolution, closure criteria and preventive action.
Traced recurring failures to stale credentials stored in a mobile email profile.
AUTHENTICATIONCompared governance and target state to identify a provisioning connector timeout.
PROVISIONINGVerified that compliant-device policy correctly blocked a sensitive application.
CLOUD IDENTITYContained an active connected account after the application connector failed.
P1 SECURITYRemoved sensitive Finance access retained after a department transfer.
GOVERNANCERun lifecycle workflows, approve access, troubleshoot incidents, conduct reviews and inspect evidence using a safe fictional dataset.