Identity Lifecycle Management Overview

Clear Skye identity governance and administration software

Your team members need access to the applications and data needed to complete their jobs.  No more, no less.  As people move around during their careers with the organization, this becomes more difficult. Often, team members ‘collect’ permissions as they move from role to role, ending up with access to more things than their current role demands. This flies against the principles of least privilege access and can increase security and compliance risk.

Clear Skye Identity Lifecycle Management

Identity Lifecycle Management sits firmly at the intersection of productivity and security.  Clear Skye provides all the controls you need to effectively manage the key aspects of an effective lifecycle management program.

User Onboarding

The Joiner Process

As new employees, contractors, and vendors are onboarded, Clear Skye Identity Lifecycle Management provides a robust and flexible user provisioning engine that can leverage any attribute within Clear Skye or the rest of your ServiceNow instance to define clearly what systems and associated permissions a new user needs to have to waiting for them on the first day they start.  For example, a new employee starting in the sales department will need to be provisioned with access to email, customer relationship management applications, and the order management system. This is called either Role Based Access Control (RBAC) or Attribute Based Access Control (ABAC) and is a critical component of modern identity security hygiene.

Most SaaS Identity solutions are limited in the flexibility of the workflows available to lifecycle actions, requiring organizations to circumvent current processes. Clear Skye leverages the flexible, no-code Flow Designer ensuring we can easily meet any required business process for lifecycle events.

User Transfers

The Mover Process

It’s common for people to take on many roles during their tenure at the company, and at each change, access must be reevaluated.  Not only will new permissions need to be provisioned to satisfy new role requirements, but existing permissions need to be reviewed to ensure that you are deprovisioning permissions that are no longer needed in support of least privileged access.  

Clear Skye Identity Lifecycle Management provides the controls needed to:

  • Detect when identity attributes change that would require a transfer action (Manager, Department, Cost Center are good examples).
  • Reevaluate the RBAC or ABAC policies to give newly needed access rights
  • Route access certification to both old and new managers to ensure that permissions that are no longer required are removed
  • Define a transition period where old and new access overlap for a period of time, ensuring a clean transition as roles are changed.

User Offboarding

The Leaver Process

As someone leaves the organization, their access is revoked.  While exceedingly simple in concept, stories of disgruntled ex-employees using their access to inflict damage, and outside bad actors exploiting the attack surface provided by no-longer needed access for an attack remain commonplace.  Clear Skye Identity Lifecycle Management provides controls that give leaver actions the highest priority in the system, ensuring that permissions are disabled or removed as soon as possible, reducing risk for the organization. Clear Skye also provides the ability to delegate access to managers or colleagues to prevent key projects or customers from being negatively affected as persons leave the organization.While the above are the three main lifecycle use cases, Clear Skye Identity Lifecycle Management also provides the means to address less common use cases like Leave of Absence, Rehire and change from contractor to employee.

Key Components of Identity Lifecycle Management

Clear Skye Identity Lifecycle Management comprises:

  • ACCESS POLICIES
    These policies contain the condition (Employee in Cost Center 112, Location is Australia) and the entitlements or roles that this type of person should be granted. They are evaluated during both the joiner and the mover processes.
  • APPLICATION ROLES
    Application roles are a grouping of environments (applications) and entitlements (permissions) that should be given to identities that meet certain criteria.
  • REQUEST VARIABLES
    Request variables are functions that can define how an account attribute is calculated.  For example, a single request variable can be defined that decides which Active Directory Organizational Unit an account is created in.  These greatly reduce the number of access policies needed to provisioning requirements.
  • CONNECTOR FRAMEWORK
    Clear Skye IGA provides its own connector framework and out-of-the-box  application connectors. These ensure our ability to automate any changes in critical downstream systems. This includes a facility for disconnected systems, where CSV files may be uploaded on a regular basis instead of a direct connection.
  • NATIVE ALIGNMENT WITH ITSM PROCESS
    For disconnected systems, changes are made through traditional ITSM processes.  Because Clear Skye is built natively on ServiceNow, these applications have the same visibility and control as those we are connecting to directly.

Identity Lifecycle Management Summary

Every Identity Security solution will provide the means to manage joiner / mover / leaver  use cases.  Clear Skye’s native to ServiceNow approach provides significant benefits over stand-alone solutions:

Clear Skye - Identity Security and Governance Administration

Richer data to make informed lifecycle decisions leveraging data points from the CSDM, HRIS, and SIR sources of record.

Clear Skye - Identity Security and Governance Administration

No need to change your business processes as Clear Skye uses the same powerful, flexible workflow automation engine you are already using.

Clear Skye - Identity Security and Governance Administration

A single point of control for all applications with visibility into the lifecycle of both connected and disconnected systems .

Clear Skye IGA

Clear Skye, a better way to IGA™

Schedule a DemoContact Us
Update cookies preferences