The Identity Blueprint
Enterprise identity and access management isn't a product you buy — it's a program you build. The Identity Blueprint covers the full spectrum: seven-phase IAM frameworks, zero trust architecture, JIT access, FIDO2 passkeys, identity governance, and the operational models that hold up at enterprise scale. Built for practitioners who are past the basics. Hosted by Ernie and Josée.
The Identity Blueprint
Securing Identities from Hire to Fire
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Your employee submitted their resignation on Friday. By Monday morning their access was still fully active. Every system. Every application. Every privilege they ever accumulated.
In this episode, Ernie and Josée go deep on Phase 4 of the IAM engagement blueprint: process and lifecycle design. The joiner, the mover, the leaver — every transition point in the human identity lifecycle where access gets granted, recalculated, and revoked. From birthright provisioning on day one, to separation of duties enforcement when someone changes roles, to the instant revocation mechanisms that close the latency window the moment someone walks out the door.
You'll leave knowing exactly how a minor paperwork delay in HR becomes a fired employee with full access to your financial systems on a Friday night — and how to engineer that window permanently shut.
If identity lifecycle is your responsibility — or it should be and nobody has claimed it yet — this episode is not optional.
Connect with Ernie Prescott on LinkedIn at linkedin.com/in/ernieprescott
Welcome back to the Identity Blueprint, where enterprise identity and access management gets the depth it deserves. I'm Ernie Prescott, Principal IAM architect, and today Jose and I are taking everything we've built so far and putting it into motion. In Episode 5, Securing Identities from Hire to Fire, we go deep on phase four of the IAM engagement blueprint, process and lifecycle design. This is where the philosophy ends and the operational reality begins. The joiner, the mover, the lever, every transition point in the human life cycle where access gets granted, recalculated, and revoked. We're talking birthright access, separation of duties, the latency window between termination and deprovisioning, zero standing privilege, and the break glass account that wakes the CISO at three in the morning. If you've ever wondered how a minor paperwork delay in HR becomes a fired employee draining your financial systems on a Friday night, this episode is for you. Let's get into it.
SPEAKER_02Usually when you talk about um a medical diagnosis, there's this really comforting expectation of precision, right?
SPEAKER_00Yeah, it feels very much like engineering.
SPEAKER_02Exactly. I mean you fall off your bike, your arm hurts, you go to the hospital, and the x-ray shows that like jagged white line right across the radius bone.
SPEAKER_00Right. And the doctor just points at the screen and says, Well, there it is. That's the problem.
SPEAKER_02Aaron Powell It's binary. The bone is broken or the bone is not broken. You put a cast on it, and the path forward is visible, it's categorized, and it's contained.
SPEAKER_00Aaron Ross Powell But then, you know, you step into the world of enterprise security.
SPEAKER_02Oh, yeah.
SPEAKER_00Specifically identity and access management, and suddenly that X-ray machine is just completely broken.
SPEAKER_02Aaron Powell You are no longer looking at a clean fracture. We're talking about a diagnostic landscape that is just incredibly murky.
SPEAKER_00Aaron Powell Oh, absolutely. You've got overlapping permissions, legacy systems that honestly probably haven't been updated since like 2015. Trevor Burrus, Jr.
SPEAKER_02Right. And those shadow IT projects that nobody ever bothered to document, plus thousands of employees shifting roles every single year.
SPEAKER_00Aaron Powell Yeah. So you're looking at an entire digital nervous system where the signals are crossing in ways they were just never originally architected to handle.
SPEAKER_02Aaron Powell Right. You can't just point to a single broken bone anymore.
SPEAKER_00Aaron Ross Powell No, not at all. You're basically looking for a microscopic pathogen in the bloodstream of the organization.
SPEAKER_02Aaron Powell Which is exactly why we're pulling you into this specific deep dive today. We are taking you right into the heart of the IAM program engagement blueprint.
SPEAKER_00Aaron Powell Unpacking the Machinery of Phase 4, which is process and life cycle design.
SPEAKER_02Now I know process and lifecycle design sounds like uh the title of a very dry seminar under buzzing fluorescent lights.
SPEAKER_00It really does.
SPEAKER_02But this is actually about preventing catastrophic digital disasters. You know, it's the literal difference between a secure corporate network and, say, a fired employee siphoning funds out of your financial systems on a Friday night.
SPEAKER_00Aaron Powell Right. And all because of a minor paperwork delay over an HR.
SPEAKER_02Exactly. So in the earlier phases of this blueprint, organizations are essentially doing like philosophy. Trevor Burrus, Jr.
SPEAKER_00Yeah, they're designing policies. They're writing down what should happen in a perfect world.
SPEAKER_02But phase four is where those theoretical security policies are forced to actually turn into operational reality.
SPEAKER_00Aaron Powell It's the engine that runs an organization's identity security. I mean, if your corporate policy dictates that nobody should have inappropriate access to sensitive data, which obviously every policy does. Right. Then phase four is the actual mathematical machinery that adds, moves, and removes that access in real time across thousands of applications.
SPEAKER_02And if that machinery is missing even a single gear, the whole philosophy just falls apart.
SPEAKER_00Completely.
SPEAKER_02So let's look at the starting line of this whole apparatus. The journey of an identity from the exact moment someone signs an offer letter.
SPEAKER_00Historically, integrating a new human into a corporate network was just absolute chaos.
SPEAKER_02A manual, heavily siloed nightmare.
SPEAKER_00Yeah, the old way relied on what we call the frantic help desk ticket. Right. A hiring manager would send an email to IT on a Friday afternoon saying, Hey, we just hired a new guy, Dave. He starts Tuesday. Give him the same access as Sarah.
SPEAKER_02Which, you know, seems innocent enough to a hiring manager, but from a security perspective, make him look like Sarah is a terrifying instruction.
SPEAKER_00It really is. Because Sarah might have been with the company for five years.
SPEAKER_02Right. She might have accumulated dozens of special exception-based access permissions for projects that ended three years ago.
SPEAKER_00Exactly. So if you just clone Sarah's profile for Dave, you are cloning a massive security vulnerability.
SPEAKER_02Aaron Powell, you are institutionalizing privilege creep on Dave's very first day.
SPEAKER_00And that is exactly why the phase four blueprint dictates a complete architectural shift. The onboarding process, what we call the joiner process, it must never start with an email or a phone call or an IT ticket.
SPEAKER_02Aaron Powell It has to start with an authoritative HR trigger.
SPEAKER_00Precisely.
SPEAKER_02Meaning the system of record for human beings has to talk directly to the system of record for digital identities. Aaron Powell Right.
SPEAKER_00So you have an HR information system and HRAS, like workday or SEP success factors, that is where the official employee record is born.
SPEAKER_02Aaron Powell And when HR finalizes that hiring paperwork and clicks create, that software generates an event.
SPEAKER_00Aaron Powell Yeah. And through API connection or a specific protocol called SCEAM, which is the system for cross-domain identity management, that creation event acts like a digital flair.
SPEAKER_02Trevor Burrus It's the authoritative trigger for the identity and access management system. Let's pause on SDM for a second, actually, because that's a concept that bridges a massive historical gap. Aaron Powell Oh, for sure. Trevor Burrus Before SCDUM, HR systems spoke French and IT directories spoke German. You had to write custom, incredibly fragile scripts just to get a user's last name to port over correctly.
SPEAKER_00Aaron Powell It was a mess. So SCGIM essentially acts as a universal translator.
SPEAKER_03Aaron Powell Got it.
SPEAKER_00It standardizes identity attributes into a clean, readable data payload. So when the IM system, whether that's a platform like SailPoint or Microsoft under ID governance, sees that SEM payload, it doesn't need a human to interpret it.
SPEAKER_02It reads the core attributes directly.
SPEAKER_00Aaron Powell Right. It sees Dave's department, his specific job code, his physical office location, and who his manager is.
SPEAKER_02And this is where the automation engine kicks in to calculate what the blueprint calls birthright access.
SPEAKER_00Yeah, and the hotel analogy you used earlier is perfect for this.
SPEAKER_02Aaron Powell Right. Think of it like checking into a highly optimized futuristic hotel. In a traditional hotel, you get a physical key to your room. But if you want to use the gym, you have to walk back down to the lobby and ask the front desk for a temporary gym pass.
SPEAKER_00Aaron Powell And if you want into the executive lounge, you have to find a manager to authorize it.
SPEAKER_02Exactly. You are constantly asking for permission at every single door.
SPEAKER_00Which is a deeply inefficient way to operate a business, resulting in just hours of lost productivity.
SPEAKER_02Aaron Powell But with automated birthrate access, it's as if the hotel already knows you booked the executive wellness package.
SPEAKER_01Yeah.
SPEAKER_02Before you even walk through the sliding glass doors, your digital key card is mathematically pre-programmed based on your reservation attributes. It automatically unlocks your room on the fifth floor, the gym turnstiles, the pool gate, and the executive lounge.
SPEAKER_00You don't ask anyone for anything. You just begin your stay.
SPEAKER_02Right. When we map that analogy to the corporate environment, we're talking about dynamic provisioning.
SPEAKER_00Exactly. The IAM system looks at Dave's attributes, say he's a financial analyst in the London office. Without any human IT intervention, the system automatically creates his Active Directory account.
SPEAKER_03Wow, okay.
SPEAKER_00It provisions a Microsoft 365 E5 license, drops him into the London Office VPN security group, and grants him read-only access to the base level financial reporting dashboards.
SPEAKER_02And the blueprint outlines a very strict service level agreement or SLA for this exact process, doesn't it?
SPEAKER_00It does. That entire provision cascade has to happen, and the account must be fully active with all birthright access within four hours of the HR trigger.
SPEAKER_02Four hours. That ensures that when Dave actually sits down at his desk at 9 a.m. on his first day, he can immediately begin adding value to the company.
SPEAKER_00Because the legacy era of a new hire sitting in the break room for three days, just waiting for the IT help desk to manually create an email inbox is unacceptable in a modern enterprise.
SPEAKER_02Oh, it's a massive drain on operational capital.
SPEAKER_00Absolutely.
SPEAKER_02Now there is a fascinating detail buried in the blueprint regarding how we actually handaved the keys on that first day. The credentialing mechanism has entirely shifted.
SPEAKER_00Yeah. We're no longer printing out a default password on a piece of paper and leaving it on his keyboard.
SPEAKER_02Or emailing a temporary password to his personal Gmail account, right?
SPEAKER_00Right. Because emailing a static temporary password like Welcome2026 is a glaring vulnerability.
SPEAKER_02Aaron Powell Yeah, I'd imagine threat actors actively scan personal email accounts for those exact strings.
SPEAKER_00Aaron Powell They do. So the modern onboarding standard utilizes passwordless flows from minute one.
SPEAKER_02Aaron Powell Which relies on something called a temporary access pass or a tap.
SPEAKER_00Exactly. Instead of a password, the IAM system generates a short-lived, single-use cryptographic code.
SPEAKER_02Aaron Powell And how does Dave get that?
SPEAKER_00Well, it might send this securely to Dave's hiring manager to hand over in person, or maybe route it via SMS to the mobile device Dave registered during his background check.
SPEAKER_02Okay, so Dave uses that tape to initiate his very first login session.
SPEAKER_00Right, but the critical architectural control here is that the system immediately consumes that tate and forces Dave into a registration loop for a strong phishing resistant credential.
SPEAKER_02Like a Phyto II security key or setting up a biometric PASCE on his corporate smartphone.
SPEAKER_00Precisely. We are establishing a zero trust baseline immediately. A Phyto II PASCI uses public key cryptography. Dave's device generates a mathematical pair.
SPEAKER_02A private key that never leaves his phone's secure hardware enclave and a public key that gets sent to the corporate identity provider.
SPEAKER_00Exactly, which completely neutralizes phishing.
SPEAKER_02Because if a hacker sends Dave a fake login page that looks exactly like his corporate portal, the PASCI mechanism just won't work, right?
SPEAKER_00Yeah, the fake website can't send the correct cryptographic challenge to Dave's phone, so D's phone refuses to authenticate.
SPEAKER_02That's wild. Dave couldn't give the hacker his password even if he wanted to, because Dave literally doesn't know his own password. He doesn't have one.
SPEAKER_00He is operating in a cryptographically secure paradigm from his very first keystroke.
SPEAKER_02And to close the loop on this entire joiner phase, the system enforces a transparency mandate, right?
SPEAKER_00Yes. The IAM engine sends an automated notification to Dave's manager detailing the exact access Dave was just granted.
SPEAKER_02Like your new hire is fully provisioned with these specific roles. Please validate.
SPEAKER_00Exactly. It forces the business side of the house to acknowledge and own the risk of their employees on day one.
SPEAKER_02Which perfectly sets the stage for the next phase of the human life cycle. Because, you know, onboarding a brand new employee is relatively straightforward.
SPEAKER_00It's a clean slate. You're building a house on an empty lot.
SPEAKER_02But humans are dynamic. They do not stay in the same role sitting at the same desk for 10 years.
SPEAKER_00No, they get promoted, they transfer from marketing to product development, they move from the London office to the New York office.
SPEAKER_02Aaron Powell And every time an employee moves, their risk profile fundamentally shifts. This brings us to the mover process. And frankly, this is where the diagnostic X-ray of an organization usually looks the most terrifying.
SPEAKER_00Without a doubt. From a security architecture standpoint, the mover phase is the single most dangerous point in the identity life cycle.
SPEAKER_02Aaron Powell Really. More than leaving.
SPEAKER_00Yes, because it is the primary vector for what we call privilege creep.
SPEAKER_02Aaron Ross Powell Right, because just like joining, moving triggers an HR event. The HR system updates Dave's record to show he is no longer in marketing. He's now a senior analyst in product development.
SPEAKER_00Aaron Powell And the IAM system catches that XCIM payload. It sees the change.
SPEAKER_02And this is where the mathematical engine performs a delta analysis.
SPEAKER_00Exactly. The system looks at Dave's new attributes and calculates the new birthright access he requires for product development. He needs access to the engineering wikis, the product roadmaps, the JIRA boards.
SPEAKER_02But calculating what he needs is only half the equation, isn't it?
SPEAKER_00Right. The system also has to look at the massive list of permissions Dave already possesses from his time in marketing.
SPEAKER_02The delta. The mathematical difference between what he currently holds and what his new role justifies.
SPEAKER_00And that delta dictates the automated response. The system provisions the new engineering tools, but it must systematically flag every single legacy marketing entitlement for immediate review or removal.
SPEAKER_02Because without that automated delta analysis, employees become digital pack rats. I love that term from the source material.
SPEAKER_00It's incredibly accurate.
SPEAKER_02If you spend 15 years at a massive corporation, moving from the help desk to systems administration to finance to HR, and your old access is never actively stripped away, you accumulate a wildly toxic combination of permissions.
SPEAKER_00You end up with a mid-level HR manager who secretly retains the ability to execute root-level commands on the legacy database servers simply because they worked in IDE a decade ago.
SPEAKER_02It's the equivalent of a tenant keeping the physical front door key to every apartment they have ever rented in a city.
SPEAKER_00Yes. There is zero justifiable reason for them to have those keys.
SPEAKER_02It makes that individual a walking security liability. I mean, if an external attacker manages to compromise that HR manager's passkey, the attacker doesn't just gain access to the HR department.
SPEAKER_00They instantly inherit the keys to the database servers.
SPEAKER_02The blast radius of that single compromised account expands exponentially.
SPEAKER_00And that lateral movement is the ultimate goal of every advanced persistent threat group. They look for the digital pack rats.
SPEAKER_02So the Delta Analysis engine must actively strip away what is no longer justified. However, the blueprint introduces a human governance element here that often causes intense debate during implementation.
SPEAKER_00Oh, it causes huge argument.
SPEAKER_02I noticed this in the Mover workflow documentation, and honestly, it seems entirely backward at first glance.
SPEAKER_00Let me guess the manager review.
SPEAKER_02Yes. When the Delta analysis flags Dave's old marketing access for removal, the workflow sends a notification to his new manager in product development to review that legacy access during a 30-day grace period. Right. Wait, hold on. The new manager reviews the old access. That makes zero intuitive sense. The new manager has no idea what Dave was doing in marketing. Why wouldn't the old manager in marketing do the review to see if Dave still needs it?
SPEAKER_00I know. It is a counterintuitive mechanism until you view it through the lens of strict risk accountability.
SPEAKER_02Okay, unpack that for me.
SPEAKER_00The moment HR updates that record, Dave's old manager is legally and operationally absolved of all responsibility for Dave. They do not own his risk anymore.
SPEAKER_03Ah.
SPEAKER_00The new manager in product development is now 100% accountable for Dave's overall threat profile.
SPEAKER_02So the new manager has to look at the total aggregate picture of what Dave is capable of doing on the network.
SPEAKER_00Exactly. The new manager needs to make two distinct determinations. First, does Dave need a brief, say, 14-day extension of his old marketing email groups simply to finish handing off a transition project?
SPEAKER_02Okay. That's common. Hence the grace period. You don't want to break active business workflows.
SPEAKER_00Right. But what is the second determination? The new manager must actively ensure that Dave's legacy access does not violate separation of duties or SA within his new context.
SPEAKER_02Aaron Ross Powell Separation of Duties. This goes all the way back to the Enron era, Sarbanne's Oxley regulations, right?
SPEAKER_00Aaron Ross Powell Precisely. Preventing a single human from having enough power to commit fraud and hide it simultaneously.
SPEAKER_02Give me a classic Shusothi conflict so we can visualize this.
SPEAKER_00Okay, imagine Sarah moves from the accounts payable department to accounts receivable. The Delta analysis flags her accounts payable access for removal, but gives a 30-day grace period.
SPEAKER_03Right.
SPEAKER_00If her new manager blindly approves her keeping that legacy access, Sarah now possesses the digital authority to both write a corporate check and receive a corporate check.
SPEAKER_02Wow. She can generate a fraudulent invoice, pay it to a dummy corporation she owns, and then reconcile the ledger to hide the missing funds.
SPEAKER_00Exactly. She possesses both halves of the fraud triangle.
SPEAKER_02So the new manager is required to view her total AXI package, recognize that toxic Susodi conflict, and immediately override the grace period to terminate the legacy access.
SPEAKER_00It is not about knowing what the old access was for, it is about owning the risk of what that access is right now.
SPEAKER_02That makes total sense now. But let's be realistic about human behavior and corporate environments. Managers are overwhelmed. They suffer from a light fatigue.
SPEAKER_00Oh, massively.
SPEAKER_02What happens if this new manager just ignores the email notification? If they don't click approve or deny, does the grace period just stay open forever?
SPEAKER_00No. The architecture is designed to assume human failure.
SPEAKER_02Thank goodness.
SPEAKER_00If the legacy access remains unconfirmed by the manager at the end of that 30-day grace period, the system's SLA dictates an automatic revocation.
SPEAKER_02It defaults to a state of leased privilege.
SPEAKER_00Right. The access drops, and if Dave actually needed it, he has to formally request it again.
SPEAKER_02It forces active engagement rather than passive accumulation. I love that. So we've joined, we've moved. But eventually the relationship between the human and the corporation ends.
SPEAKER_03Yes.
SPEAKER_02We are pivoting from employees changing desks to employees leaving the building entirely. Segment three of this life cycle is the lever process. And the blueprint makes it unequivocally clear this is where the stakes reach their absolute peak.
SPEAKER_00The lever process is the ultimate stress test of an IAML program. I mean, if your joiner process is slow, your company loses a bit of productivity. But if your lever process fails, you are exposing the organization to immediate, highly exploitable, catastrophic vulnerabilities.
SPEAKER_02It all comes down to a metric called lever latency, doesn't it?
SPEAKER_00Yes. This is the temporal gap between reality and the digital reflection of reality.
SPEAKER_02Meaning the exact time delay between the moment an employee officially terminates their relationship with the company and the precise millisecond their digital access is completely severed across every single platform.
SPEAKER_00Exactly. Let's run a scenario. HR sits down with an employee on a Monday morning at 900 AM. Things have not worked out. It's an involuntary termination.
SPEAKER_03Right. They're fired.
SPEAKER_00HR updates the workday system. But because the company doesn't have an automated phase four pipeline, HR just sends an email to the IT help desk saying, please offboard this user.
SPEAKER_02And the IT guy is swamped with server updates, so he doesn't actually log into the directory to manually disable the Active Directory account until Friday afternoon.
SPEAKER_00You have just created a massive 100-hour window of extreme risk.
SPEAKER_02For four entire days, you have a disgruntled former employee sitting at home, potentially furious, who still possesses perfectly valid authenticated credentials to your virtual private network, your customer relationship databases, and your proprietary source cloud repositories.
SPEAKER_00And the statistics surrounding this latency gap are horrifying.
SPEAKER_02Yeah. Based on the sale point research in our source stack, over 70% of surveyed companies report instances of employees retaining inappropriate access days, weeks, or even months after their formal departure.
SPEAKER_00Wait, 70%. And an orphaned account is basically a digital ghost.
SPEAKER_02Right.
SPEAKER_00It is an active identity profile floating in your network that no longer has a legally binding, valid human owner tied to it in the central HR system. And it represents a dual vector threat.
SPEAKER_02The first vector is obvious. The insider threat. The furious former employee downloading the entire Salesforce client list on a Tuesday night to take to their new job at a direct competitor.
SPEAKER_00Or worse, a systems engineer deciding to detonate a logic bomb on their way out the door, wiping production servers in retaliation.
SPEAKER_02But I imagine the insider threat is only half the battle. If I am an external ransomware operator and advanced persistent threat group, an orphaned account looks like a ghost ship.
SPEAKER_00Oh, it's the perfect vessel for them to board because they know for a fact that absolutely nobody is at the helm.
SPEAKER_02Because if a hacker attempts to hijack the active account of your current CFO, the CFO is going to notice.
SPEAKER_00Right. The CFO will get unexpected multi-factor authentication prompts on their phone or notice emails marked as red that they haven't seen.
SPEAKER_02They will alert the security operations center. The active human acts as an organic intrusion detection system.
SPEAKER_00Aaron Powell But if the account belongs to a marketing contractor whose contract ended six months ago.
SPEAKER_02There is no human checking that inbox.
SPEAKER_00Exactly. There is no human to hit deny on the MFA prompt if the hacker bypasses it.
SPEAKER_02The external attacker can slip into that orphaned account, assume the identity of the former employee, and quietly begin exploring the network architecture.
SPEAKER_00They can map out the active directories, search for privilege escalation paths, and slowly exfiltrate data for months without ever tripping the behavioral analytics alarms that monitor active users. It is the ultimate camouflage.
SPEAKER_02So how does the blueprint eradicate the ghost ships? What is the technical mechanism to drive lever latency down to zero?
SPEAKER_00The SLA for the lever process removes human intervention entirely. For involuntary terminations firings, the SLA is immediate automated disablement within one hour of the HR trigger firing.
SPEAKER_02Wow, one hour. And for voluntary resignations.
SPEAKER_00It is same day disablement, usually triggered at 5 0 p.m. on their final day. The HR API communicates directly to the IAM engine, which instantly executes a revocation playbook.
SPEAKER_02But let's look at the actual plumbing of that revocation playbook because this is where legacy IT mindsets completely. Completely fail in the cloud era.
SPEAKER_00Aaron Powell They really do.
SPEAKER_02Ten years ago, if you fired someone, you went into the on-premise server, you right-clicked their Active Directory account, you hit disable, and you physically escorted them out of the building. Problem solved. They couldn't log in.
SPEAKER_00But in a modern distributed cloud architecture, killing the Active Directory account does not instantly kill their access.
SPEAKER_02Aaron Powell That is a critical vulnerability that many organizations fail to grasp. The difference between authentication and authorization.
SPEAKER_00Exactly. When a user logs into a cloud application like Salesforce or Amazon Web Services, the central identity provider, say NTRA ID or Okta, authenticates them and issues a session token.
SPEAKER_02An O or small L token.
SPEAKER_00Right. That token is essentially a digital passport stamped with an expiration time, often valid for 12, 24, or even 48 hours.
SPEAKER_02So if the user is sitting at a coffee shop on their personal laptop and they are already logged into Salesforce with a valid token, and HR fires them at 10.0 AM and disables their central Active Directory account, what happens to the Salesforce session?
SPEAKER_00In a legacy setup, absolutely nothing.
SPEAKER_02Nothing.
SPEAKER_00Nothing. The central directory is disabled, meaning the user can't log in again, but the Active Salesforce session doesn't know that.
SPEAKER_02Because the token is still valid.
SPEAKER_00Yes. The user can continue downloading customer data for the next 23 hours until that specific token naturally expires and asks the disabled central directory for a renewal.
SPEAKER_02That is terrifying. You think you've locked the front door, but they are already inside the house and all the interior doors are still open.
SPEAKER_00Exactly.
SPEAKER_02How does phase four architect a solution to sever those acta sessions?
SPEAKER_00The modern IAM framework mandates the use of continuous access evaluation or CAE. This is a massive architectural upgrade.
SPEAKER_02Okay, how does CAE work?
SPEAKER_00When the termination trigger hits the IAM system, it doesn't just passively flip a status bit from active to disabled in a database. It actively generates a cryptographic revocation event.
SPEAKER_02It goes on the offensive.
SPEAKER_00Exactly. The identity provider broadcasts a universal webhook signal out to every single cloud application integrated into the environment.
SPEAKER_02It pushes a message to Salesforce, to AWS, to Microsoft 365, to the VPN gateway.
SPEAKER_00Explicitly stating, session revoked, invalidate all existing tokens for this specific user immediately.
SPEAKER_02A universal kill switch. The user could be mid-keystroke in a spreadsheet, and the browser simply kicks them back to the login screen permanently.
SPEAKER_00It closes the latency gap across the entire cloud perimeter in milliseconds.
SPEAKER_02Amazing. However, the automated lever process is not solely about destruction, is it? It also has to handle business continuity.
SPEAKER_00Aaron Powell Right. Because if you instantly nuke a high-level manager's access, what happens to the infrastructure they were managing?
SPEAKER_02Right. If Dave was the sole owner of a critical project's shared SharePoint drive, or he managed the primary info at company.com distribution list, if his account vanishes, does that shared drive just become locked in a digital vault?
SPEAKER_00Aaron Powell Does the business process grind to a halt? No. This is where resource reassignment protocols engage.
SPEAKER_02Okay, so what does the system do before deleting him?
SPEAKER_00Before the IAM system fully disables Dave's account, it scans the environment for any shared resources where Dave is listed as the sole proprietor. Shared mailboxes, calendar delegations, external guest network sponsorships, cloud infrastructure resource groups.
SPEAKER_02And it automatically bridges the gap.
SPEAKER_00It mathematically reassigns ownership of those assets up the organizational chart to Dave's immediate manager. Ah, that's smart. The manager receives an automated briefing. Dave's access has been terminated. You have automatically been assigned ownership of the following four shared drives and two distribution lists to ensure continuous business operations.
SPEAKER_02It is the difference between taking a sledgehammer to the departing employee's desk versus using a scalpel to carefully untangle their threads from the network.
SPEAKER_00That's a great way to put it.
SPEAKER_02And what is the final disposition of the account itself? Does the IAM system just instantly delete Dave from the server entirely to save database space?
SPEAKER_00Never. Immediate deletion is a severe compliance violation.
SPEAKER_02Really? Why?
SPEAKER_00Because if you delete the account object, you destroy the cryptographic anchor for all of Dave's historical audit trails.
SPEAKER_03Oh, I see.
SPEAKER_00Furthermore, if Dave decides to sue the company for wrongful termination three weeks later, the legal department will immediately issue an e-discovery hold requiring all of Dave's emails and chat logs.
SPEAKER_02And if you deleted the account, that data is gone and the company is liable for spoiliation of evidence.
SPEAKER_00Exactly. So it goes into a freezer.
SPEAKER_02The blueprint specifies a compliance hold.
SPEAKER_00Yes. The account is cryptographically disabled, stripped of all group memberships, hidden from the global address book, and placed in the suspended organizational unit for a retention period, typically 30 to 90 days.
SPEAKER_02And only after the legal and compliance windows expire does the automated lifecycle script permanently purge the digital identity from the directory.
SPEAKER_00Correct.
SPEAKER_02All right, let's step back and look at the whole board here. We have covered the foundational baseline, the JML lifecycle. Joiner, mover, lever.
SPEAKER_00Core pillars.
SPEAKER_02We have automated the birthright access upon entry, we've dynamically recalculated the risk delta during internal movement, and we've deployed the universal kill switch upon departure.
SPEAKER_00But that baseline is rigid.
SPEAKER_02Right. It only covers what a user needs simply by existing in their role. What happens when a user needs more? What happens when work requires them to step outside their birthright boundaries?
SPEAKER_00This brings us to the governance engine access requests and certifications.
SPEAKER_02Segment four. Because, you know, birthright access is strategically designed to get an employee about 80% of the way to productivity.
SPEAKER_00Yeah, it covers the ubiquitous tools, email, intranet basic department folders. But modern enterprise work is highly dynamic and fluid.
SPEAKER_02Aaron Powell Right. Like Dave is in marketing, but suddenly he gets pulled into a cross-functional tiger team evaluating a merger, and he desperately needs read access to a highly secure European financial projections database.
SPEAKER_00And his birthright doesn't cover that.
SPEAKER_02In the legacy model, Dave would submit an IT help desk ticket requesting access.
SPEAKER_00Aaron Ross Powell And this is exactly the paradigm the phase four blueprint actively dismantles.
SPEAKER_02It says the IT department should never be in the business of approving access requests, which, I mean, sounds completely contradictory at first. Isn't IT the department in charge of network security? Why wouldn't they approve who gets onto the network?
SPEAKER_00Aaron Powell Because IT is in charge of securing the infrastructure of the network. They build the roads and the fences. But the IT help desk analyst sitting in a cubicle has absolutely zero business context regarding the data itself.
SPEAKER_03Ah, okay.
SPEAKER_00If Dave submits a ticket asking for European financials, the IT analyst looks at it, shrugs, assumes Dave knows what he's doing, and clicks approve.
SPEAKER_02They are essentially flying blind. They don't know if Dave is actually on the merger committee or if Dave is just being nosy and wants to look at executive salaries.
SPEAKER_00Exactly. IT does not own the data risk. Therefore, phase four shifts the entire access request workflow out of IT ticketing systems and into self-service portals powered by identity governance and administration platforms.
SPEAKER_02IGA tools. So how does a self-service portal change the fundamental dynamic of approval?
SPEAKER_00It shifts the decision-making authority directly to the data or application owners.
SPEAKER_02So when Dave realizes he needs the financial data, he logs into a clean web-based internal catalog. It looks like an internal app store.
SPEAKER_00Right. He searches for European financial projections and clicks request. The IGA platform knows, via its metadata tags, that the authoritative owner of that specific database is the VP of finance in Europe.
SPEAKER_02And the system automatically routes the request directly to her smartphone or email?
SPEAKER_00Yes. And she possesses the critical business context. She's running the merger committee, she knows exactly why Dave needs it, and more importantly, she knows exactly what level of access he requires.
SPEAKER_02She makes the approval decision, completely bypassing the IT department. That aligns the approval authority with the actual risk owner.
SPEAKER_00But there is a crucial guardrail highlighted in the blueprint regarding these manual requests.
SPEAKER_02Yeah, by default, any access granted outside of the automated birthright must be strictly time-bound and require a logged business justification.
SPEAKER_00Permanent exception access is the archenemy of identity governance. If Dave requests access for the Q3 merger project, the self-service portal will not allow him to submit the request without answering two forced parameters.
SPEAKER_02Why do you need this? And how long do you need it?
SPEAKER_00Right. If he types in merger due diligence and selects a 60-day window, the system provisions the access. But on day 61, the access evaporates automatically.
SPEAKER_02There is no manual cleanup required.
SPEAKER_00And that typed justification is cryptographically hashed and permanently logged in the governance database.
SPEAKER_02Aaron Powell So when the external auditors arrive at the end of the year, they can see exactly who asked for the data, who approved it, and the precise business rationale behind it.
SPEAKER_00Aaron Powell It's totally transparent.
SPEAKER_02Okay. Time-bound requests solve the problem for new exceptions. But let's look at the reality of an enterprise that is implementing phase four for the very first time.
SPEAKER_00Aaron Powell Oh, this is the messy part.
SPEAKER_02Aaron Powell Right. They already have thousands of employees who have been accumulating permanent access for a decade. Even with automated movers and time bound requests, the baseline is already polluted.
SPEAKER_00Heavily polluted.
SPEAKER_02How do you clean up the historical mess that is already in the system?
SPEAKER_00That requires the heavy machinery of the governance engine. Access reviews and certifications. This is the recertification protocol.
SPEAKER_02Let's unpack the mechanics of a certification campaign. What actually happens?
SPEAKER_00A certification campaign is a periodic, mandatory, system-wide validation event. The blueprint dictates that organizations must run these sweeps on a rigid schedule.
SPEAKER_02Usually quarterly for highly privileged or sensitive access and semi-annually for standard user application access, right?
SPEAKER_00Exactly. So mechanically, the IGA platform wakes up on the first of the quarter. It generates a massive personalized compliance report for every single manager across the entire company.
SPEAKER_02The manager logs into their dashboard and sees an alert like here are your seven direct reports. Here are the 85 unique applications, databases, and security groups they currently hold access to.
SPEAKER_00And they are required to review this entire matrix and actively certify whether each entitlement is still required for their current job duties or they must explicitly revoke it.
SPEAKER_02This used to be a notorious compliance nightmare in the old days of massive Excel spreadsheets.
SPEAKER_00Managers would get a spreadsheet with 10,000 rows, sigh heavily, and just reply to the email saying, Looks good to me. It was just a rubber stamping exercise.
SPEAKER_02But modern IAM systems change the psychological enforcement mechanism. Think of it like a consumer subscription model.
SPEAKER_00Yeah, that's a perfect analogy.
SPEAKER_02If you sign up for a basic streaming service, it operates on an auto-renewing contract. You put your credit card in once, and if you forget about it, they will happily charge you $5 a month for the next 20 years.
SPEAKER_00Which is exactly how legacy IT environments operated. Once a user got access, it auto-renewed forever unless someone actively fought to stop it.
SPEAKER_02But the modern certification engine treats access like a subscription that auto-cancels.
SPEAKER_01Right.
SPEAKER_02Imagine if Netflix emailed you on the 25th of every month and said, please click the secure link to confirm you actively want to watch Netflix next month. If you do not click approve within five days, we are permanently deleting your account and wiping your watch history.
SPEAKER_00I mean, that is precisely the enforcement mechanism here. The SLA for a certification campaign includes a strict, non-negotiable deadline for the manager.
SPEAKER_02And if the manager experiences alert fatigue and simply ignores the certification campaign, if they fail to actively click approve for Dave's access to the Salesforce database.
SPEAKER_00The IGA platform does not assume the access is fine. It assumes the manager's silence means the access is no longer justified.
SPEAKER_03It defaults to denial. The access is automatically revoked at the deadline.
SPEAKER_00It forces aggressive engagement. You cannot passively allow privilege to accumulate. The manager has to consciously put their digital signature on the line, certifying that the access is required.
SPEAKER_02And modern systems actually combat the rubber stamping problem by using machine learning analytics, don't they?
SPEAKER_00They do. If a manager goes in and just highlights all 85 entitlements and tries to click approve all, the system will intervene.
SPEAKER_02It will flag high-risk outliers like, wait, Dave is the only person in his department with access to this specific financial server? Are you absolutely certain you want to approve this?
SPEAKER_00It adds intelligent friction to the process. And again, this creates a pristine, mathematically verifiable audit trail.
SPEAKER_02So when the external auditors come in to do an SOX compliance check, you aren't just showing them a static list of who happens to have access today.
SPEAKER_00You are showing them the immutable log of exactly which human manager certified that specific access, on what exact date, and passing the liability entirely to the business.
SPEAKER_02Incredible. So we have now established tight control over the general population. But everything we have discussed in the JML lifecycle, the requests and the certifications, all of that primarily governs standard users.
SPEAKER_00The regular employees doing their daily business tasks.
SPEAKER_02Right. We now have to pivot to the final and arguably most critical pillar of phase four. We are talking about privileged access management, or PAM.
SPEAKER_00Segment five, the keys to the kingdom.
SPEAKER_02We are shifting focus from the standard population to the superusers, the IT administrators, the database engineers, the senior network architects.
SPEAKER_00These are the people whose credentials do not just grant access to data. Their credentials grant the ability to alter, dismantle, or destroy the fundamental infrastructure of the network itself.
SPEAKER_02And the stakes in this specific arena are just astronomically high. The statistical reality is chilling. Our sources cite that a staggering 80% of all successful corporate data breaches involve the explicit compromise and exploitation of privileged credentials.
SPEAKER_00Because if an attacker compromises Dave in marketing, they can read some confidential emails, maybe steal a client list. It's a localized breach.
SPEAKER_02But if an attacker compromises a domain administrator, they own the entire corporate reality.
SPEAKER_00A domain admin can silently alter the central directory. They can grant themselves access to every inbox in the company.
SPEAKER_02They can deploy a ransomware payload to 5,000 endpoint servers simultaneously with a single command.
SPEAKER_00They can delete the backups and then wipe the centralized logging servers and no one can figure out how they did it.
SPEAKER_02It is the ultimate prize for a threat actor. So how does the phase four blueprint handle these superusers? Because obviously, a senior network architect still needs to do their job. They need high-level access to maintain the systems.
SPEAKER_00The blueprint introduces a radical paradigm shift in how we conceptualize administrative power. Historically, a systems administrator essentially possessed two separate identities. Right. They had their standard account for reading email and browsing the internet, and they were issued a secondary permanent admin account with globally elevated privileges that they could log into whenever they wanted. We call this architecture standing privileges.
SPEAKER_02Standing privileges, meaning the godlike power is always turned on, 24 hours a day, seven days a week, 365 days a year.
SPEAKER_00Exactly. Always on, always sitting in the directory, and therefore always vulnerable to theft.
SPEAKER_02If the admin goes on a two-week vacation to the mountains, that high-level account is still sitting there, fully active, waiting for someone to guess the password or steal the session token.
SPEAKER_00It's an unnecessarily massive attack surface. So the modern blueprint mandates a concept called just-in-time access or JIT, combined with zero standing privileges, ZSP.
SPEAKER_02Zero standing privileges is exactly what it sounds like, I imagine. It dictates that in the default resting state of the network, absolutely no user possesses active administrative rights. Zero.
SPEAKER_00Exactly.
SPEAKER_02Okay, but let's look at the practical mechanics of that. If the senior database administrator doesn't have a permanent admin account, how on earth do they perform maintenance on a production server at 2.0 pm on a Tuesday?
SPEAKER_00They are no longer granted the persistent account. Instead, they are granted eligibility to assume a specific role.
SPEAKER_03Okay.
SPEAKER_00When the engineer needs to perform maintenance, they log into a specialized PAM platform tools like CyberArc, Beyond Trust, or Intra-privileged Identity Management.
SPEAKER_02But at the moment they log in, they are still just a normal user. They do not have the power yet.
SPEAKER_00Right. They must actively initiate a workflow to request temporary elevation, like I am mathematically eligible to be a database admin. I need to do my job now. Please elevate my session.
SPEAKER_02They submit the digital request through the PAMI interface. They are required to provide a valid ticketing number from the IT service desk system, proving there is an authorized change order for the work.
SPEAKER_00And crucially, they must specify a highly constrained timeframe. They request the elevated role for exactly two hours.
SPEAKER_02Depending on the sensitivity of the target server, I imagine that request might automatically ping another senior engineer for a secondary real-time approval.
SPEAKER_00Often, yes. Doll control workflows for critical infrastructure. Once the request clears the policy gates, the PAM system acts.
SPEAKER_02It dynamically provisions the necessary administrative credentials on the back end, or it attaches the elevated role directly to the engineer's current session token.
SPEAKER_00The engineer steps into the superuser role, performs the database upgrade, and completes the work.
SPEAKER_02And here is the defining boundary of the just-in-time architecture. When that requested two-hour window expires, the access doesn't just ask to be renewed, it violently evaporates.
SPEAKER_00The elevated role is mathematically stripped from the session. The engineer instantly reverts to a standard user.
SPEAKER_02The standing privilege returns to zero. This shrinks the attack surface to a microscopic window.
SPEAKER_00An advanced threat actor cannot compromise an administrative credential on a Saturday night if the administrative credential literally does not exist in the environment on a Saturday night.
SPEAKER_02It's brilliant. It turns a static target into a hyperkinetic vanishing target. But the phase four blueprint doesn't stop at just limiting the time the access exists. It goes significantly further with a concept called session monitoring.
SPEAKER_00Right. Because even if that window is only two hours long, you are still handing someone the keys to the kingdom for two hours.
SPEAKER_02You need absolute unblinking visibility and control over what happens inside that window. What if the authorized engineer decides to go rogue during those two hours?
SPEAKER_00Aaron Powell Or what if an attacker managed to hijack the session at the exact moment the engineer elevated their privileges.
SPEAKER_01How do you monitor that at a granular level?
SPEAKER_00This relies on an architecture where the PM platform acts as an impenetrable proxy. Platforms like CyberArx Privileged Session Manager, or PSM, sit directly in the middle of the connection path.
SPEAKER_02Unpack the mechanics of a proxy for us. How does that change the workflow?
SPEAKER_00Normally an administrator would sit at their laptop, open a secure shell or remote desktop protocol window, type in the IP address of the target server, and connect directly to it point-to-point. In a proxied PAM environment, that direct connection is physically blocked by network firewalls. The administrator is not allowed to touch the server directly.
SPEAKER_02Instead, they log into the centralized CyberArc web portal, they find the target server in a list, and they click connect.
SPEAKER_00So they are connecting to CyberArc, not the server.
SPEAKER_02Aaron Powell Exactly. CyberArc receives that command. CyberArc then turns around, opens a secure connection to the target server on the back end, retrieves a heavily randomized, complex credential from its encrypted vault, and injects that credential into the server connection.
SPEAKER_00It then stitches the administrator's web interface to that back-end session.
SPEAKER_02Wait, if the proxy is injecting the credential from a vault, the human administrator never actually sees or types the password for the production server.
SPEAKER_00Aaron Powell The human never sees it. They never type it on their keyboard. And therefore, they can never write it down on a sticky note, they can never reuse it on another system, and a keylogger malware infection on their laptop cannot steal it.
SPEAKER_02Aaron Powell The credential remains entirely hermetically sealed within the proxy architecture. That eliminates an entire class of credential theft vulnerabilities.
SPEAKER_00Aaron Powell But the proxy serves a second, equally vital purpose. Yeah. Because 100% of the administrative traffic is forced to flow through that central proxy choke point, the PAM system acts as a surveillance camera. Trevor Burrus, Jr.
SPEAKER_02It records the entire administrative session from start to finish.
SPEAKER_00Yes. It captures a highly compressed searchable video file of the administrator's screen. It logs every single individual keystroke typed. It logs the title of every window that opens and every mouse click.
SPEAKER_02So if a production database mysteriously goes offline at 3.0 PM, the security team doesn't have to guess what happened. They pull up the literal DVR recording of the engineer session and watch the exact command being typed.
SPEAKER_00It is irrefutable forensic evidence. It makes post-incident analysis incredibly fast.
SPEAKER_02However, modern phase four paym systems are not just passive recording devices. They employ real-time threat analytics engines that constantly monitor the stream of data flowing through the proxy. Give us a concrete example of what the analytics engine is scanning for in real time.
SPEAKER_00Let's say an engineer legally elevates their privileges to perform a routine software patch on a Windows server. But five minutes into the session, the analytics engine detects the engineer opening a command prompt and typing a command designed to dump the local system registry ashes or attempting to download a known penetration testing tool like Mimicats.
SPEAKER_02That is highly anomalous, inherently malicious behavior that has nothing to do with the software patch. What does the proxy do? Does it just flag the video for someone to review tomorrow?
SPEAKER_00No. A mature PAM deployment is configured for automated termination. The system doesn't wait.
SPEAKER_02It cuts them off.
SPEAKER_00The millisecond, it detects the forbidden command string right in the middle of the keystroke. It instantly severs the back-end connection. It suspends the session entirely, locking the user out of the proxy, and immediately fires a critical alert to the security operations center.
SPEAKER_02It stops the breach while it is actively occurring. That is an incredibly aggressive security posture. It takes no prisoners.
SPEAKER_00But given that 80% of breaches rely on these accounts, aggressive intervention is clearly necessary.
SPEAKER_02Now I do have to ask one highly practical worst-case scenario question. We have built this incredibly complex, highly automated, heavily proxied GIT architecture. Okay. What happens if the PAM system itself crashes? What if the identity provider goes offline or there is a massive internal network outage, and the entire just-in-time approval workflow is completely inaccessible? Does the IT department just lose the ability to control its own data centers?
SPEAKER_00That is the ultimate resilience question, and the blueprint accounts for it. Every phase four design requires the implementation of a break glass emergency access procedure.
SPEAKER_01Break glass, like the little red hammer sitting next to the fire alarm in a hallway.
SPEAKER_00Precisely. Break glass accounts are highly secured, extremely privileged credentials that are intentionally designed to bypass all the normal JIT proxies, MFA requirements, and approval workflows.
SPEAKER_02They exist completely outside the automated machinery.
SPEAKER_00Sometimes there are physical passwords split into two halves and stored in physical safes in different geographic locations. Sometimes they are highly monitored digital vault accounts.
SPEAKER_02But they are only to be used when the primary identity infrastructure suffers a catastrophic failure. And I imagine utilizing a break glass account is not something you do quietly.
SPEAKER_00Using a break glass account is the digital equivalent of pulling the fire alarm in a crowded theater. The moment that credential authenticates, it triggers massive, unignorable, screeching alarms across the entire security organization, up to and including waking up the chief information security officer in the middle of the night.
SPEAKER_02And the post-use process involves intense mandatory audits where the engineers who broke the glass have to legally justify exactly why the normal procedures failed and why emergency access was required.
SPEAKER_00It is truly a mechanism of absolute last resort.
SPEAKER_02All right, we have covered an immense, complex landscape today. Let's pull the camera back and summarize this journey. We started this deep dive looking at a murky, chaotic, diagnostic landscape of identity.
SPEAKER_00We saw the legacy systems riddled with overlapping permissions, manual help desk errors, and toxic privilege creep.
SPEAKER_02And we've mapped out exactly how phase four of the I am blueprint brings mathematical engineering precision to that chaos. It turns identity into an automated, highly governed machine.
SPEAKER_00It systematically tightens the security controls at every single transition point in the human lifecycle.
SPEAKER_02It seamlessly integrates the HR authoritative trigger to perfectly control the exact moment you join the organization with birthright access.
SPEAKER_00It dynamically recalculates your risk delta the day you move roles, enforcing separation of duties.
SPEAKER_02It deploys continuous access evaluation webhooks to instantly sever your access the hour you leave, permanently closing the latency window.
SPEAKER_00It forces managers to actively certify your access rather than passively ignore it.
SPEAKER_02Aaron Powell And for every elevated administrative action taken in between, it enforces zero standing privileges, proxies the connection, and records every single keystroke.
SPEAKER_00It takes the philosophical concept of zero trust and turns it into tangible operational reality.
SPEAKER_02Aaron Powell It really does. But before we wrap up, I want to leave you, the listener, with one final highly provocative thought to mull over. Something that builds on everything we just discussed, but points toward a very strange future.
SPEAKER_00Aaron Powell This is where it gets interesting.
SPEAKER_02We have spent this entire deep dive mapping out the human life cycle, the joiners, movers, and leavers. We are talking about flesh and blood employees, contractors, and human administrators.
SPEAKER_00But there is a glaring statistic buried in the Okta research sources we reviewed that points to a radically different paradigm.
SPEAKER_02You are referring to the explosive rise of non-human identity. Right now, according to Okta survey data, 91% of enterprise organizations are actively deploying autonomous AI agents. Now, we are not talking about simple chatbots that answer customer questions.
SPEAKER_00We are talking about sophisticated pieces of code operating autonomously with valid API keys. They are making independent decisions, pulling massive data sets, writing to databases, and executing complex tasks deep inside the corporate network.
SPEAKER_02And historically, service accounts and API keys have been managed horribly, operating almost entirely outside the strict human governance structures we just spent an hour detailing.
SPEAKER_00Exactly.
SPEAKER_02So here is the question you need to ask your own security teams. Do we need a joiner-moverlever process for a piece of code?
SPEAKER_00Because if an autonomous AI agent dynamically changes its function, say it optimizes itself and moves from executing a marketing task to analyzing a financial task, how do you perform a delta analysis on its permissions?
SPEAKER_02Who is the manager that certifies an AI's access? And most terrifyingly of all, if that AI agent hallucinates, goes rogue, or has its API key compromised by a threat actor, how quickly can your IAM architecture trigger an agent universal logout?
SPEAKER_00Because if you think a disgruntled human employee can do a lot of damage in a four-day latency window, an autonomous script running at machine speed with an administrative API key can dismantle a corporation in four seconds.
SPEAKER_02It is undeniably the next great frontier of identity security. The phase four blueprint is going to have to rapidly evolve to govern the machines with the exact same rigor, if not more, than it currently governs the humans.
SPEAKER_00It is a wild, slightly terrifying thought to end on.
SPEAKER_02But that is why we do this. Thank you for joining us on this incredibly deep dive into the machinery of identity. Take these concepts back to your own organizations, keep questioning the legacy systems around you, keep looking for those hidden latency windows, and we will see you on the next one.
SPEAKER_00That's a wrap on securing identities from higher to fire. We mapped the entire human life cycle today. Joiners, movers, leavers, flesh and blood employees, and administrators. But here's the thought I want to leave you with. Right now, 91% of enterprise organizations are deploying autonomous AI agents, code operating with valid API keys, making independent decisions deep inside the corporate network. A disgruntled employee can do damage in a four-day latency window. An autonomous script with an administrative key can dismantle a corporation in four seconds. Do you need a joiner mover lever process for a piece of code? Who certifies an AI's access? That's where we're heading next. Connect with me on LinkedIn at LinkedIn.com forward slash IN forward slash Ernie Prescott and subscribe now so you don't miss it. Until next time.