Architecture & control · reference function

Identity & Access Management Interface

Connect enterprise identity authority with cloud access patterns and privileged-operation controls.

Reference mandate

Own the cloud-facing identity and access interface, including approved patterns, role boundaries, lifecycle integration, privileged access requirements and escalation to enterprise identity authority.

Short

Connect enterprise identity authority with cloud access patterns and privileged-operation controls.

Standard

Own the cloud-facing identity and access interface, including approved patterns, role boundaries, lifecycle integration, privileged access requirements and escalation to enterprise identity authority.

Detailed

Own the cloud-facing identity and access interface, including approved patterns, role boundaries, lifecycle integration, privileged access requirements and escalation to enterprise identity authority. The function maintains explicit decision boundaries, measurable outcomes, governed interfaces and a documented improvement loop for its scope.

Scope in

  • Cloud identity patterns
  • Role and privilege boundaries
  • Joiner-mover-leaver integration
  • Privileged access requirements

Scope out

  • Enterprise identity-platform ownership
  • Application authorization design
  • Approving business access without an owner

Responsibilities

  • Cloud identity patterns
  • Role and privilege boundaries
  • Joiner-mover-leaver integration
  • Privileged access requirements

Services

  • Cloud identity patterns service
  • Role and privilege boundaries service
  • Joiner-mover-leaver integration service
  • Privileged access requirements service

Required capabilities

  • Cloud IAM Architect capability
  • Access Governance Lead capability
  • Platform IAM Engineer capability

Roles

  • Cloud IAM Architect
  • Access Governance Lead
  • Platform IAM Engineer

Decision rights

  • Approve a cloud access pattern
  • Approve a privileged access exception
  • Set cloud role-separation requirements

Key interfaces

  • Cloud Security & Assurance
  • Cloud Architecture
  • Platform Engineering

Inputs

  • Requirements from Cloud Security & Assurance
  • Requirements from Cloud Architecture

Outputs

  • Governed output to Cloud Architecture
  • Governed output to Platform Engineering

Governance forums

  • Identify design review
  • Cloud operating-model review

Measures

  • Automated lifecycle coverage
  • Privilege age
  • Access exception age

Dependencies

  • Cloud Security & Assurance
  • Cloud Architecture
  • Platform Engineering

Sourcing options

  • Retained internal
  • Shared
  • MSP-supported

Organizational placements

  • Central cloud organization
  • Federated domain
  • Shared technology function

Decisions owned

  • Approve a cloud access pattern
  • Approve a privileged access exception
  • Set cloud role-separation requirements

Decisions contributed to

  • Contribute to decisions owned by Cloud Security & Assurance
  • Contribute to decisions owned by Cloud Architecture
  • Contribute to decisions owned by Platform Engineering
Design boundary

Common failure modes

  • Cloud roles drift from enterprise identities
  • Privilege is granted without time bounds
  • Platform teams become the access authority
Sourcing principle

Engineering may be shared; identity authority and approval policy must remain accountable internally.

Minimum retained capability

Engineering may be shared; identity authority and approval policy must remain accountable internally.

Maturity guidance

Begin with named ownership and one measurable outcome; add delegation and automation only when evidence and capability are reliable.

Reference note

Vendor-neutral practitioner reference pattern; validate against organizational, regulatory and sourcing context.

Version 2026.3 · reviewed 8 September 2026