Home/Glossary/Identity and Access Management (IAM)

Identity and Access Management (IAM)

The policies and technologies used to verify identities, govern permissions, and log access across systems.

Identity & Access ManagementAlso called: "IAM program"

IAM unifies how people and services prove who they are and what they can do.

Building blocks

  • Central directory of users, groups, and service principals.
  • Authentication flows such as single sign-on (SSO) and multi-factor authentication (MFA).
  • Authorization policies enforced through roles, attributes, or context.
  • Audit trails and attestation workflows for compliance.

Maturity cues

  • Automated provisioning and deprovisioning linked to HR events.
  • Periodic access reviews with approval trails.
  • Fine-grained policies that adapt to device health and location.