Identity Governance Glossary
Definitions for the terms that come up when a growing company has to govern access: IGA, SCIM, joiner-mover-leaver, access reviews, just-in-time access, non-human identity. Each entry says what the term means, where it breaks in a stack where most applications have no SCIM, and which audit control it maps to.
A
- Access certification
- Access certification is the formal process of confirming that each user's access is still appropriate, with a reviewer signing off per entitlement and revocations executed for anything rejected.Also: Certification campaign, Recertification, Entitlement certification
- Agent offboarding
- Agent offboarding is the removal of what an AI agent, integration or token can reach when its task ends, its owner leaves, or it is no longer justified.Also: Agent deprovisioning, Non-human offboarding, Integration offboarding
- Agentic IGA
- Agentic IGA is identity governance in which AI does the governance work across the whole lifecycle, connecting applications, provisioning, reviewing, revoking, recommending and producing evidence, and in which the AI agents themselves are governed as identities, each with an owner, a scope, an expiry, a review and an audit trail.Also: Agentic identity governance, Agentic IAM
- AI agent identity
- An AI agent identity is the identity an AI agent authenticates and acts with: an account or set of credentials, a scope of systems and actions, a named human owner, and a record of what it did and on whose behalf.Also: Agent identity, Agentic identity, AI agent access
- Attestation
- Attestation is the formal statement by an accountable person that a set of access is correct as of a point in time.Also: Access attestation, Sign-off
B
- Birthright access
- Birthright access is the set of applications and permissions a person receives automatically because of their role, granted on their first day without anyone asking for it.Also: Birthright provisioning, Default access, Role-based bundle
D
- Deprovisioning
- Deprovisioning is the removal of a user's access across every app and system when they leave, change roles, or no longer need it.Also: Access revocation, Offboarding
I
- Identity Governance and Administration (IGA)
- Identity governance and administration (IGA) is the discipline of controlling who has access to what across an organization's apps and systems, and proving it.Also: IGA, Identity Governance, Identity Administration
J
- Joiner-mover-leaver (JML)
- Joiner-mover-leaver (JML) is the model for managing a worker's access across their time at a company.Also: JML, Joiner mover leaver, Identity lifecycle
- Just-in-time access (JIT)
- Just-in-time access (JIT) grants a permission only when it is needed, for a defined window or task, and revokes it automatically when the window closes, so access exists while in use and not in between.Also: JIT access, Just-in-time privileged access, Time-bound access
M
- Machine identity
- A machine identity is the credential a workload, service or device proves itself with: an X.509 certificate, a SPIFFE ID, or a cloud role assumed at runtime.Also: Workload identity, Service identity, Machine-to-machine identity
N
- Non-human identity (NHI)
- A non-human identity (NHI) is any account or credential that acts without a person signing in: a service account, an API key, an OAuth app an employee authorized, a bot, or an AI agent.Also: NHI, Non-human identities, Machine identity (the infrastructure subset)
O
- OAuth grant
- An OAuth grant is a standing delegation of one person's access to a third-party application, created when they approve a consent screen.Also: OAuth consent, Third-party app access, Connected app
- Orphaned account
- An orphaned account is an active account with no valid owner: the person left, changed roles, or never should have had it, but the account still exists and often still works.Also: Orphan account, Ownerless account
S
- SCIM (System for Cross-domain Identity Management)
- SCIM (System for Cross-domain Identity Management) is the industry-standard protocol for automated user provisioning.Also: SCIM, System for Cross-domain Identity Management, SCIM 2.0
- SCIM provisioning
- SCIM provisioning is automated user provisioning done over the SCIM protocol: an identity provider creates, updates, and deactivates accounts in an app, and syncs group memberships, without manual work.Also: Automated provisioning, SCIM sync
- SCIM tax
- The SCIM tax is the price of unlocking SCIM provisioning in a SaaS application: vendors gate the protocol behind their enterprise plan, so a company that wants automated user provisioning has to upgrade every seat, whether or not it needs anything else in that tier.Also: SCIM paywall, SSO tax (the parent pattern)
- SCIM vs SAML
- SCIM and SAML solve different problems.Also: SAML vs SCIM, Provisioning vs authentication
- Service account
- A service account is an account created for a system, application or automated process to authenticate and act, rather than for a person to sign in.Also: System account, Application account, Integration account
U
- User access review
- A user access review is a periodic check of who has access to what, where a reviewer decides per entitlement whether each grant is still appropriate and revokes what is not.Also: UAR, Access review, Access recertification
Z
- Zombie account
- A zombie account is an active account that nobody uses: dormant, forgotten, but still enabled and still consuming a license.Also: Dormant account, Stale account, Inactive account
By category
Access control models
Access reviews and evidence
Core concepts
Identity lifecycle
Birthright access · Deprovisioning · Joiner-mover-leaver (JML)
Non-human identities and AI agents
Agent offboarding · Agentic IGA · AI agent identity · Machine identity · Non-human identity (NHI) · Service account
Provisioning and protocols
OAuth grant · SCIM (System for Cross-domain Identity Management) · SCIM provisioning · SCIM tax · SCIM vs SAML
Risks and cleanup
How this glossary is written
Nobody signs these entries; the team at Iden writes them and stands behind them. Every definition is checked against the primary text where there is one: the SCIM RFCs, the SOC 2 criteria, ISO 27001, PCI DSS and the HIPAA Security Rule. Where an entry describes what a vendor's plan includes, it leans on the vendor's own documentation and on the SCIM Tax Index. The "In practice" scenarios are composites, typical of what IT teams at that size run into, with no single real company behind any of them. The date on an entry is the day its words last changed, read from the page's own history, so it moves only when the content does. Iden never appears in a definition and shows up at most once in the body. If a definition is wrong, tell us at hello@idenhq.com and we will fix it.