Skip to content
Back to skills

Iam Pro

ASecurity

Build identity and access management — lifecycle, privileged access, governance, and continuous access review.

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 29, 2026
ai-agentsgogitapisecurity

Works with

  • api

Security analysis

A100/100

Scanned September 29, 2026

npx -y skills add aicodedecode/awesome-muse-skills --skill iam-pro --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Iam Pro?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Iam Pro
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/aicodedecode-iam-pro/badge)](https://www.skillsdirectory.com/skills/aicodedecode-iam-pro)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: iam-pro
description: Build identity and access management — lifecycle, privileged access, governance, and continuous access review.
category: security
---

## Overview

Identity is the primary security perimeter: nearly every modern attack involves compromised credentials or abused permissions. IAM is the discipline of ensuring the right identities have the right access at the right time — and nothing more. It spans human lifecycle (joiner/mover/leaver), non-human identities, privileged access, and governance.

This skill covers building IAM as a program: lifecycle automation, privileged access management, access reviews, and the metrics that show it working.

IAM is the operating system of enterprise security — every access decision in the organization flows through it. Programs fail when treated as IT plumbing; they succeed when treated as a product with users (employees want fast access), customers (auditors want evidence), and a roadmap (lifecycle automation, PAM, governance). Fund and staff it accordingly.

## When to use

- Standing up or maturing IAM: SSO, lifecycle automation, privileged access.
- Fixing audit findings on orphaned accounts, excessive privilege, or missing reviews.
- Reducing standing privilege (the #1 identity risk).
- Governing non-human identities: service accounts, API keys, workload identities.

## Core concepts

- **Lifecycle (JML):** joiner (provisioning from HR source of truth), mover (access changes with role changes — the most neglected), leaver (deprovisioning within hours, not weeks). Automate from the HR system; manual processes rot.
- **Least privilege, continuously:** grant minimum necessary, default-deny, and re-validate. Privilege accumulates like plaque — reviews are the cleaning.
- **Privileged Access Management (PAM):** vault privileged credentials, require checkout with approval and session recording, eliminate standing admin rights via just-in-time elevation.
- **Non-human identities:** service accounts, API keys, OAuth apps, workload identities — inventory them like humans, give them owners, rotate them, and apply least privilege. They are often the weakest link.
- **Access reviews (certification):** periodic attestation by managers/system owners that access is still needed. Make them meaningful: show last-used data, pre-flag anomalies, keep scope tight.
- **Segregation of duties (SoD):** conflicting permissions (e.g., create vendor + approve payment) must not sit with one identity. Define SoD rules and enforce at provisioning time.

- **Access request workflows.** Self-service requests with manager approval and automatic provisioning beat ticket queues — speed of legitimate access is a security feature (it kills shadow IT).
- **Privileged session management.** Recording and proxying admin sessions gives you both deterrence and forensic evidence for the highest-risk activity in the estate.
- **Identity threat detection.** Impossible travel, token replay, and privilege-escalation patterns in identity logs deserve dedicated detections — the identity plane is now the primary battleground.

## Practical workflow

1. **Establish the identity source:** HR system as the authoritative source for humans; a registry (CMDB/IdP) for non-human identities with mandatory owners.
2. **Automate JML:** provisioning on hire, role-based access changes on transfer (remove old, grant new — movers are where privilege accumulates), deprovisioning within 24 hours of termination, including SaaS and shared mailboxes.
3. **Deploy PAM:** vault all privileged credentials; just-in-time elevation instead of standing admin; session monitoring for the most sensitive systems; break-glass with sealed, audited procedures.
4. **Rationalize access:** role mining — build roles from actual usage patterns, not org charts; remove unused entitlements (last-used data is your best friend); kill orphaned and dormant accounts.
5. **Run meaningful reviews:** quarterly for privileged/sensitive access, annual for standard; arm reviewers with usage data and anomaly flags; track remediation of revoked access to completion.
6. **Measure:** time-to-provision, time-to-deprovision, % privileged access via JIT, orphaned-account count, review completion and revocation rates, SoD violations. Report trends, not snapshots.

### IAM health checklist

- [ ] HR-driven automated provisioning/deprovisioning live
- [ ] Mover process removes old access (verified by sampling)
- [ ] Standing privileged accounts minimized; JIT elevation in use
- [ ] Non-human identity inventory with owners and rotation
- [ ] Access reviews run on schedule with usage data; revocations completed
- [ ] SoD rules defined and enforced at provisioning
- [ ] Dormant/orphaned account cleanup automated

### Sustaining the practice

- Publish IAM metrics monthly to engineering and business leadership
- Re-certify privileged access quarterly without exception
- Hunt for orphaned and dormant accounts continuously, not just at review time
- Test the leaver process with spot audits — sample terminations and verify deprovisioning

### Metrics that prove it works

- Time to deprovision after termination (target: hours)
- Orphaned and dormant account counts, trended down
- % of privileged access via just-in-time elevation
- Access-review completion and revocation-follow-through rates

## Common pitfalls

- **Manual JML.** Spreadsheets and tickets cannot keep up with hiring velocity. Automate from HR or accept the orphan accounts.
- **Ignoring movers.** Joiners get attention, leavers get compliance pressure, movers quietly accumulate every permission from every past role. Fix movers.
- **Standing admin everywhere.** "Everyone in IT is a domain admin" is the fastest path to total compromise. JIT elevation exists for a reason.
- **Non-human identity sprawl.** Service accounts created in 2019 with domain-admin-equivalent rights and no owner. Inventory them ruthlessly.
- **Rubber-stamp reviews.** Certifying 500 entitlements in 10 minutes helps nobody. Scope tightly, provide usage data, sample-verify.
- **SoD as an afterthought.** Discovering toxic permission combinations during fraud investigation is too late. Enforce at grant time.
- **SaaS sprawl outside the IdP.** Shadow SaaS with standalone credentials bypasses every IAM control. Discover, federate, or shut down.
- **Contractor lifecycle gaps.** Contractors with no HR record keep access indefinitely. Every non-employee needs an owner and an expiry.
- **Treating IAM as a one-time project.** 'We deployed SSO' is the beginning. Lifecycle, governance, and PAM are ongoing operations that need permanent ownership.
- **Over-centralizing without delegation.** Business units need controlled self-service for their apps, or they will route around central IAM entirely.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…