Joiners, movers and leavers
Access should follow the employee lifecycle. New joiners receive the access their role requires. When someone changes role, the access they no longer need is removed. When they leave, every account is disabled on the same day. Leftover accounts and accumulated permissions are among the most common audit findings.
Core principles
Least privilege gives each person only the access required for their job. Role based access control assigns permissions to roles rather than individuals, which makes changes easier. Privileged accounts, such as administrators, are kept separate from everyday accounts, protected with strong MFA and reviewed more often. Periodic access reviews confirm that what people have still matches what they need.
The tools
An identity provider such as Microsoft Entra ID, Google Workspace or Okta is usually the centre, with SSO connecting applications to it. A password manager covers applications that do not support SSO, and SaaS management finds the ones nobody connected. IAM is also the starting point of a Zero Trust approach.
Where it shows up in compliance
ISO 27001 covers access control, identity management, authentication information, access rights and privileged access (Annex A 5.15 to 5.18 and 8.2). The ENS, NIS2 and SOC 2 have equivalent requirements, and access reviews are among the first pieces of evidence auditors request.




