The Identity Blueprint
Enterprise identity and access management isn't a product you buy — it's a program you build. The Identity Blueprint covers the full spectrum: seven-phase IAM frameworks, zero trust architecture, JIT access, FIDO2 passkeys, identity governance, and the operational models that hold up at enterprise scale. Built for practitioners who are past the basics. Hosted by Ernie and Josée.
The Identity Blueprint
Identity Program Operations and Metrics
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Your dashboard says everything is fine. Intrusion detection normal. Firewall active. MFA compliance at 98%. Meanwhile, somewhere in your environment right now, credentials are being harvested and nobody's metric is moving. That is not a security program. That is an expensive illusion of one.
In this episode, Ernie and Josée decode Phase 7 of the IAM engagement blueprint: operationalization and metrics. Drawing from SailPoint, CyberArk, Ping Identity, Okta, NIST, and CISA — this is the episode that defines what a living, breathing IAM operating model actually looks like in production. The four-tier human architecture, JML velocity metrics, the psychology of the access review rubber stamp, and the KPI dashboard that tells you whether you are mathematically secure or just compliant on paper.
You'll leave knowing the difference between believing you are secure and being able to prove it — and exactly which dials to watch to know when something is wrong before your auditors find it first.
If you are responsible for an identity program that is already live — this episode is not optional.
Connect with Ernie Prescott on LinkedIn at linkedin.com/in/ernieprescott
Welcome back to the Identity Blueprint, where enterprise identity and access management gets the depth it deserves. I'm Ernie Prescott, Principal IAM Architect, and in episodes one through seven, Jose and I took you from strategy through architecture, governance, lifecycle design, and implementation. Today we tackle the question most programs never get around to asking. How do you actually know if any of it is working? Episode eight. Phase seven of the IAM engagement blueprint, the operating model, the KPI dashboard, and the telemetry that separates organizations that believe they are secure from those that can mathematically prove it. We're drawing from SailPoint, CyberArc, Ping Identity, Okta, NIST, and CISA to break down the four-tier human architecture, JML velocity metrics, the psychology of the Access Review rubber stamp, and what a living IAM operating model actually looks like in production. If you've ever presented a compliance report and secretly wondered whether the numbers were telling the real story, this episode is for you. Let's get into it.
SPEAKER_01You know, usually when we talk about a medical diagnosis, there's um there's this expectation of clinical precision.
SPEAKER_02Right, absolutely.
SPEAKER_01Like you fall, your arm sells up, you go to the hospital, and the X-ray shows that stark, jagged white line across the bone. The doctor points to it, and you both know exactly what's wrong. It's binary.
SPEAKER_02Broken or not broken.
SPEAKER_01Exactly. It's visible, it's categorized, and honestly, even if it hurts, it's comforting because you know the exact state of the system.
SPEAKER_02We really crave that visibility. Yeah. You know, we want a dashboard that says healthy or failing in bright, undeniable colors.
SPEAKER_01Aaron Powell But then you step into the world of enterprise security, specifically identity governance, and suddenly that X-ray machine is just printing static. We're looking at a diagnostic landscape that is incredibly murky. I mean, you've got tens of thousands of employees, hundreds of applications, non-human service accounts, overlapping permission structures, trying to diagnose the health of an identity and access management program, what we in the industry call IAM, is just a massive ongoing undertaking.
SPEAKER_02It really is. It's never finished.
SPEAKER_01So today we are going to completely demystify phase seven of the IAM program engagement blueprint, which covers operationalization and metrics. And we aren't just reading one manual for this deep dive. We are synthesizing the core blueprint with tactical telemetry from Sailpoint, CyberArc, Ping Identity, and Okta while, you know, mapping it all against the government frameworks from NIST and CISA.
SPEAKER_02Phase seven is really where the rubber meets the road. If you don't have this phase locked down, I mean you don't have a security program, you have a very expensive illusion of security.
SPEAKER_01Yeah. Think about it like designing a state-of-the-art nuclear submarine, going through phases one through six of this blueprint, the strategy, the policy framework, the technology architecture, the deployment that's building the vessel.
SPEAKER_02Right, the construction phase.
SPEAKER_01Yeah. You buy the finest steel, you integrate the best nuclear reactor, you wire up the command center, and you can step back and admire this multi-million dollar feat of engineering sitting safely in dry dock. But phase seven is what happens when you actually put a human crew inside, seal the hatch, submerge under a crushing ocean of daily cyber threats, and run the thing.
SPEAKER_02And if your crew doesn't know how to read the pressure dials, or even worse, if the dials are lying to them, that submarine isn't just going to drift, it's going to implode.
SPEAKER_01The pressure is entirely unforgiving.
SPEAKER_02It is. And to put hard numbers on the cost of that submarine sinking, the latest strategic intelligence reports from the Identity Management Institute show the average cost of a data breach has hit $4.45 million.
SPEAKER_01Wow. Over four million.
SPEAKER_02Yeah. But the crucial data point for us here is that nearly a third of those breaches involve stolen credentials. They don't hack in, they log in.
SPEAKER_01They just walk right through the front door.
SPEAKER_02Exactly. So phase seven is the operational shield against that exact disaster. It's the transition from a perfectly designed static architecture to a living, breathing, continuously validating defense system.
SPEAKER_01Aaron Powell Okay, so before we can even begin to measure the health of the system, before we look at the dials, we need to know who is actually sitting at the controls. The blueprint explicitly outlines an IAM operating model to manage this transition from build to run, and it structures the human element into a four-tier hierarchy.
SPEAKER_02Aaron Powell Right. And this four-tier support model is designed to isolate specific types of operational friction so that they don't drag down the entire security apparatus.
SPEAKER_01Aaron Powell Let's unpack this. Tier one is the service desk. Now we all know they handle the immediate high-volume issues like password resets and MFA enrollments.
SPEAKER_02The frontline stuff.
SPEAKER_01Yeah. But the blueprint highlights a massive governance risk here. If tier one lacks strict identity-proofing protocols, they become the soft underbelly of the organization. They are the absolute prime target for social engineering.
SPEAKER_02Oh, absolutely. I mean, attackers aren't always trying to brute force a password anymore. That's too hard. They're calling the service desk at 2.0 AM on a Friday, sounding panicked.
SPEAKER_01Right, claiming they have a huge deadline.
SPEAKER_02Exactly. And maybe they're even using AI-generated deepfake audio of an executive claiming they lost their phone and need their MFA token reset to a new device.
SPEAKER_01Aaron Powell, which is terrifying.
SPEAKER_02It is, because if Tier 1 doesn't have a rigid, mathematically verifiable way to prove the person on the phone is who they claim to be like, sending a push notification to a pre-registered secondary device or requiring verification from a direct manager, the attacker bypasses your entire multimillion dollar infrastructure with a five-minute phone call.
SPEAKER_01Yeah, all that fancy crypto just bypassed by a polite IT guy trying to be helpful.
SPEAKER_02Precisely.
SPEAKER_01Which brings us to tier two, IAM operations. These are the specialists managing the deviations from the standard process. They handle provisioning exceptions, manage the sprawl of active directory groups, and you know, troubleshoot the integrations when your HR system refuses to sync with your downstream cloud apps.
SPEAKER_02Yeah, they are basically the containment field for technical debt. When an automated workflow breaks, tier two steps in so the business doesn't grind to a halt. But their real job is to fix the immediate issue within the bounds of governance, document the failure, and pass the systemic issue up the chain.
SPEAKER_01Up to tier three, IAM engineering. These are the builders maintaining the engine while it's running at a thousand RPM.
SPEAKER_02Right, the heavy lifters.
SPEAKER_01They manage the complex conditional access policies, tune the lifecycle workflows, and build the actual API integrations. And then sitting above them is tier four, IAM architecture. The visionary is ensuring the technology aligns with the multi-year business strategy, overseen governance, and assessing the overall risk posture against frameworks like CISA's zero trust model.
SPEAKER_02That's the ideal structure, yes.
SPEAKER_01Okay, but hold on. Let me play devil's advocate here. Looking at this four-tier structure, it just screams corporate bureaucracy to me.
SPEAKER_02I hear that a lot.
SPEAKER_01Right, because we're layering management on top of management, siloing tasks into these rigid buckets. Isn't this like a hospital triage system gone wrong? Like if your organization is burning down because of a massive access failure and your top brain surgeon, your tier four architect, is barred from jumping into the ER to fix a routing issue because it's a tier two responsibility, doesn't the whole hospital fail? Why do we need to force engineers into these rigid tiers?
SPEAKER_02It seems counterintuitive when you're in a crisis. I'll give you that. Yeah. But what's fascinating here is that without this specific tiered model, programs inevitably experience what the blueprint terms a decay back to ad hoc operations.
SPEAKER_01Ad hoc operations in chaos.
SPEAKER_02Complete chaos. It is incredibly dangerous to collapse these tiers. And um here is the exact mechanism of why. If your tier three engineer, the person whose sole job is to write the automation scripts that govern thousands of access points, is constantly pulled away to manually provision an account for a frustrated vice president, they aren't just losing productivity.
SPEAKER_01Introducing vulnerabilities.
SPEAKER_02Exactly. Because they take shortcuts.
SPEAKER_01Walk me through what that shortcut actually looks like. Paint that picture for me.
SPEAKER_02Okay, let's say a senior marketing director complains they can't access a new cloud-based analytics platform. They need it for a board meeting in 10 minutes. They're panicking.
SPEAKER_01They've all been there.
SPEAKER_02Right. So the ticket bypasses tier one and two, landing directly on the desk of a tier three engineer. Now the engineer knows the proper way is to add the user to the correct role in the identity governance platform, wait for the approval workflow to trigger, let the system generate the audit log, and then automatically provision the account via the API.
SPEAKER_01Which is safe and auditable.
SPEAKER_02Yes. But that takes 20 minutes, and the meeting isn't 10. The engineer wants to be helpful and fast. So they open up the back-end database or they go directly into the administrative console of the analytics app and they manually flip the user's access switch to true.
SPEAKER_01Oh wow. They bypass the governor entirely.
SPEAKER_02They bypass the entire governance framework. The user is happy, the board meeting goes well, and the engineer closes the ticket. But they have just created undocumented shadow IT access.
SPEAKER_01Because the main system doesn't know about it.
SPEAKER_02Exactly. The central identity system, the brain of your submarine, thinks that user does not have access to the analytics platform. But in reality, they have native administrative rights. When the auditors arrive and demand a report of everyone who can access customer data, that user will not be on a list.
SPEAKER_01That's a huge compliance violation right there.
SPEAKER_02It gets worse. When that user leaves the company, the automated deprovisioning system will delete their core accounts, like their email, but it won't touch the analytics app because it doesn't know the connection exists.
SPEAKER_01Oh man.
SPEAKER_02You now have an active, highly privileged account floating in the wild tied to a former employee.
SPEAKER_01That is terrifying. So the bureaucracy isn't there to slow the business down. It's there to prevent invisible doors from being hard-coded into the hull of the submarine.
SPEAKER_02Precisely.
SPEAKER_01The sources actually give a name to the operational breakdown when this deprovisioning fails. They call it lever latency in the phase one discovery sources, and it's heavily monitored in phase seven.
SPEAKER_02Yeah, the deprovisioning gap is arguably the most critical metric on any auditor's clipboard.
SPEAKER_01Let's trace the anatomy of this failure for you, the listener. Imagine your HR department terminates an employee at 9 near 0 a.m. on a Monday for misconduct.
SPEAKER_02The high risk termination.
SPEAKER_01Yeah. In a mature phase seven environment, the HR information systems say workday updates their status to terminated. That status change triggers an API call to the identity platform, which instantly reaches out to every connected application and revokes the session tokens. Access is gone by 9.01 AM.
SPEAKER_02That's the ideal state.
SPEAKER_01But if your operating model is decayed, let's look at what happens. HR sends an email to the IT service desk to disable the account. Tier 1 gets the email, but maybe the employee has specialized access to a legacy mainframe that tier one doesn't have the rights to touch.
SPEAKER_02So they escalate it.
SPEAKER_01Right, they escalate the ticket to tier three. But tier three is currently fighting a server outage, so the ticket just sits in the queue. It takes until Friday afternoon for an engineer to manually go into the mainframe and kill the access. You now have a four-day window of catastrophic exposure.
SPEAKER_02A four-day window where a hostile former employee who already knows the internal network topology, who knows where the sensitive data is stored, and who possesses valid credentials can log in remotely. They can exfiltrate intellectual property, sabotage systems, or deploy ransomware.
SPEAKER_00And all of it looks legitimate.
SPEAKER_02That's the scariest part. Because they are using valid credentials, your standard threat detection tools might not even flag it as an anomaly. To the system, it just looks like an authorized user doing their job. This is why orphaned accounts and delayed revocations are the absolute holy grail for threat actors. They don't have to break your cryptography, they just walk through a door you forgot to lock.
SPEAKER_00That is such a chilling thought.
SPEAKER_01Okay, so moving from the human element, the crew managing the tiers, we need to look at the actual telemetry. What are the specific dials on the dashboard that tell us if the submarine is structurally sound?
SPEAKER_02The metrics.
SPEAKER_01Right. This transitions us deeply into the core lifecycle KPIs. We are shifting from the people running the program to the data tracking the flow of every single identity in the ecosystem. The sources refer to this as the JML life cycle. Joiner, mover, lever.
SPEAKER_02He is the absolute heartbeat of identity security. If your JML telemetry is irregular, your organization is suffering from a massive operational arrhythmia.
SPEAKER_01I love that comparison. The blueprint doesn't just offer suggestions here, it dictates very specific service level agreements or SLAs for this life cycle. Let's start with the joiner process. The target metric here is brutal. It should take less than four hours from the authoritative HR event to an active, fully provisioned account.
SPEAKER_02Under four hours.
SPEAKER_01The document literally mandates that day one access must be a reality, not an aspirational goal. But why is speed so critical here from a security perspective? We usually think of speed as a business enabler, not a security control.
SPEAKER_02Aaron Powell Well, think about human nature. If it takes two weeks for a new hire to get their official corporate email, access to the CRM, and entry to the code repositories, the business doesn't stop.
SPEAKER_01People still have to do their jobs.
SPEAKER_02Exactly. Employees want to be productive, so they work around you. The manager will say, hey, just use your personal Gmail account to view these documents for now. Or here, just log in using my credentials so you can get started.
SPEAKER_01Ah, the classic copy user anti-pattern.
SPEAKER_02Precisely. You immediately fracture your security perimeter because IT failed to deliver the service. By enforcing a strict four-hour SLA on joiner provisioning, you eliminate the operational desperation that drives employees toward insecure workarounds. You keep them inside the governed environment from minute one.
SPEAKER_01That makes total sense. Then we have the lever process, which we touched on with the 900 AM termination scenario. The KPIs here are completely unforgiving. Deprovisioning time must be less than one hour for an involuntary termination.
SPEAKER_0260 minutes, max.
SPEAKER_01If someone is fired, their access must evaporate before they are even escorted out of the building. Now, for a voluntary resignation, say someone giving two weeks' notice, you have slightly more breathing room with a target of less than eight hours. The ultimate goal is to get your orphaned account count to absolute zero.
SPEAKER_02Or as close as mathematically possible.
SPEAKER_01Right. The blueprint allows a tolerance of strictly less than 0.5% of total accounts, purely to account for highly complex technical edge cases, but zero is the mandate. But what about the middle of the life cycle?
SPEAKER_02The movers.
SPEAKER_01Yes. We covered joiners coming in and levers going out. But what about the movers? The people who get promoted or shift from one department to another or take on temporary cross-functional projects. Here's where it gets really interesting. The blueprint sources explicitly state that mover is where organizations fail the most spectacularly.
SPEAKER_02It's the biggest blind spot.
SPEAKER_01Why is an internal transfer fundamentally more dangerous than just bringing someone in or kicking them out?
SPEAKER_02Because of privilege creep.
SPEAKER_01Privilege creep.
SPEAKER_02Yes. The industry also calls it access accumulation. It is a silent systemic rot within enterprise security. Let's build a scenario. You have an employee who starts in the finance department as a junior analyst. The joiner process provisions them perfectly. They get access to the general ledger, payroll databases, and financial forecasting tools.
SPEAKER_01Everything they need.
SPEAKER_02Right. They spend three years in finance doing a fantastic job.
SPEAKER_01Yeah.
SPEAKER_02Then they get promoted and transferred to lead a new product marketing initiative. The joiner aspect of that move kicks in nicely. The system sees their new title and provisions access to the marketing automation platforms, the social media management tools, and the public relations shared drives.
SPEAKER_00So they can do their new job.
SPEAKER_02But now nobody remembers to trigger the lever process for their old role. Nobody takes away the finance access.
SPEAKER_01Because subtracting access requires someone to make a definitive decision that the access is no longer needed, and people are terrified of breaking a workflow. It's infinitely easier to just stack new permissions on top.
SPEAKER_02Exactly. Fast forward another five years, maybe they move to IT or operations. They're dragging a massive, invisible tail of accumulated privileges behind them. They now possess an entirely toxic combination of access.
SPEAKER_01Toxic combination, meaning they have too much power across too many silos.
SPEAKER_02Exactly. They can view the raw financial data, they have the keys to the public-facing marketing channels, and maybe they have administrative rights to certain IT systems. If that one single account is compromised via a phishing attack, the blast radius is exponential. The attacker doesn't just get access to a marketing director's inbox, they get the keys to the kingdom.
SPEAKER_01Okay, so how do we fix this? Because the blueprint demands a very specific operational mitigation for this, utilizing a mover workflow driven by something called delta analysis. How does the delta analysis mechanically solve the privilege creep problem?
SPEAKER_02Well, it removes human hesitation from the equation. When the HR system registers the job change, say moving from cost center A to cost center B, it sends a webhook to the identity governance and administration platform, like SalePoint's identity IQ.
SPEAKER_01Okay.
SPEAKER_02SalePoint looks at the user's new role and calculates the delta. It mathematically compares what permissions the user needs for the new marketing role against the inventory of permissions they currently hold from the finance role.
SPEAKER_01Ah, so it identifies the overlap and more importantly, the excess.
SPEAKER_02Yes. It isolates the excess, but it doesn't always cut the excess off instantly because sometimes transitions take a few weeks. You have to hand over projects to your replacement.
SPEAKER_01Sure, you don't want to completely cut someone off while they're training their backfill.
SPEAKER_02Right. So the blueprint suggests implementing a 30-day grace period for the Delta. The system automatically flags the old finance access for removal and alludes the new marketing manager and the old finance manager. We are automatically revoking this legacy access in 30 days unless you explicitly provide a business justification for why it must be retained.
SPEAKER_01Well, that's brilliant. That shifts the burden of proof. You don't have to ask permission to remove it, you have to fight to keep it.
SPEAKER_02And if nobody responds to the alert, the system executes an auto-revocation. The access is severed. This entirely neutralizes privilege creep, but and this is a big bud, it requires extreme operational maturity. The sources emphasize that this delta analysis cannot rely on an email from a manager saying, hey, Bob moved to my team today. It must be triggered by an authoritative source.
SPEAKER_01Meaning the HR platform, systems like workday or SAP success factors.
SPEAKER_02The HR system is the single source of truth for the human being's status. When the record changes in workday, it must cascade automatically via API into the IGA platform, which then acts as the central brain, orchestrating the exact provisioning and deprovisioning commands across all the downstream applications: Salesforce, AWS, Active Directory.
SPEAKER_01So no more IT tickets for job changes.
SPEAKER_02If your organization relies on human communication, a JIRA ticket, or an email to trigger a mover process, your phase seven operationalization has already failed.
SPEAKER_01Wow. Okay, so speed and accuracy in the JML lifecycle are fantastic for productivity. It makes the business agile, but speed is the enemy of security if it isn't continuously validated. Exactly. Like if we are granting day one access in under four hours, how do we mathematically prove that access isn't being abused six months later? We have to transition from operational velocity to security depth. And this brings us to the security and governance metrics outlined in the blueprint. We need to confront the reality of how human psychology actually undermines security controls.
SPEAKER_02We are moving from the logistics of managing accounts to the actual governance of risk.
SPEAKER_01Let's dissect the primary security KPIs. First is multi-factor authentication. Now the dashboard target is greater than 99% adoption across all employees. But the blueprint and the specialized Okto white papers are very clear. Simply having MFA turned on is no longer sufficient.
SPEAKER_02Not anymore, no.
SPEAKER_01You cannot just check a compliance box. The actual metric you must track in phase seven is the adoption rate of phishing resistant MFA. The goal is to hit over 80% initially and aggressively scale to over 95%. Why is the blueprint essentially deprecating traditional MFA? I feel like we've been told for a decade that any MFA is good in MFA.
SPEAKER_02We were told that, but the threat landscape evolved and traditional MFA didn't. Not all factors are created equal. If your organization relies on SMS text messages for the second factor, or even simple push notifications where a user just taps approve on their smartphone screen, you are highly vulnerable to modern adversary tactics.
SPEAKER_01We're talking about MFA fatigue attacks and adversary in the middle attacks, right?
SPEAKER_02Precisely. Let's look at MFA fatigue, or MFA bombing as some call it. An attacker buys valid username and password credentials off the dark web. They try to log in at 3.m. Okay. The system sends a push notification to the sleeping employee's phone. The phone buzzes, the employee wakes up, looks at it, and ignores it. But the attacker sends another one and another. They send 50 push notifications in 10 minutes.
SPEAKER_01Just relentlessly buzzing.
SPEAKER_02Right. Eventually the employee, half asleep and frustrated by the constant buzzing, taps approve just to make it stop so they can go back to sleep. The attacker is in.
SPEAKER_01That's so simple but so effective. And what about adversary in the middle?
SPEAKER_02ATM attacks using tools like EvilJinks. The attacker sends a highly convincing phishing email with a link to a fake login page that looks exactly like your corporate Microsoft 365 portal. The user enters their password.
SPEAKER_01And the proxy captures it.
SPEAKER_02Yes. It forwards the password to the real Microsoft site, which triggers the real SMS code to the user's phone. The user types the code into the fake site. The proxy captures that too, logs into the real site, and steals the session cookie. They bypass your SMS MFA entirely because the user willingly handed over the code.
SPEAKER_01Unbelievable. So how does phishing resistant MFA actually stop a user from being tricked?
SPEAKER_02It removes the human's ability to give away the secret.
SPEAKER_01What do you mean?
SPEAKER_02Phishing resistant MFA relies on asymmetric cryptography and specific protocols like WebAuthan and FIDO2. This usually takes the form of hardware security keys like a YubiKey or platform authenticators like Windows Hello or OctaFastPass, which integrate biometric device context.
SPEAKER_01So no codes to type in.
SPEAKER_02Right. When you use a Phyto II key, the authentication is cryptographically bound to the specific domain you are visiting. If a user is tricked into visiting Microsoft-login-secure.com instead of the real Microsoft.com, the hardware key mathematically verifies the domain mismatch and simply refuses to authenticate. The user couldn't give the attacker the code even if they wanted to, because there is no code to give. Tracking the deployment of use cryptographic factors is the only way to measure true authentication resilience in phase seven.
SPEAKER_01That is a massive paradigm shift. Next up on the security dashboard is standing privilege access. The target here is trending toward absolute zero. The blueprint mandates that all administrative access should be just in time or JIT.
SPEAKER_02This connects deeply to the cyber arc architecture documentation we are pulling from. The historical model of IT administration is built on standing privileges. You have an IT engineer and they have an account called domain admin.
SPEAKER_01The Godmode account.
SPEAKER_02Exactly. That account possesses the power to create, delete, or modify anything on the network. And it holds that power 24 hours a day, seven days a week, 365 days a year.
SPEAKER_01It's an always-on skeleton key.
SPEAKER_02And if an attacker compromises that specific account, maybe the admin logged into a compromise server or fell for a spear phishing attack, the attacker instantly inherits that always-on power. It's game over.
SPEAKER_01So how does just in time access fix that?
SPEAKER_02Just in time access? Utilizing privileged access management tools like CyberArc or Microsoft intra-privileged identity management fundamentally changes the architecture. It means the admin account has zero standing power. No.
SPEAKER_00Right. None at all.
SPEAKER_02None. When the engineer logs in on Tuesday morning, they have the same baseline privileges as a marketing intern.
SPEAKER_01Okay, but they still need to do their jobs.
SPEAKER_02Right. When they actually need to perform an administrative task, say patching a production database, they must request temporary elevation. They log into the PAM vault, select the system they need to access, provide a ticketing system justification, and check out the privilege. The PAM system dynamically provisions the necessary administrative rights to their account, or injects a set of managed credentials into their session for a strictly defined time window, say two hours.
SPEAKER_01And when the two hours are up.
SPEAKER_02The PAM system revokes the rights, rotates the underlying passwords in the vault, and severs the connection. The admin returns to being a standard user.
SPEAKER_01That's incredible.
SPEAKER_02Even if an attacker steals the admin session token after the window closes, it's useless. The privilege simply doesn't exist anymore. You shrink the attack surface from 22040 Sevic exposure to a tiny, tightly monitored two-hour window.
SPEAKER_01This brings us to a metric I really want to dig into because it highlights the friction between governance theory and human reality perfectly. The access review completion rate. The blueprint target is greater than 95% completion within the defined SLA.
SPEAKER_02A controversial metric for sure.
SPEAKER_01Look, I've lived through these and I know exactly what happens. Access reviews are the enterprise equivalent of clicking agree on the terms and conditions of a new software update. Nobody reads them.
SPEAKER_02Oh, absolutely not.
SPEAKER_01An engineering manager gets an automated email saying it's time for the quarterly access review. They log into the portal and are confronted with a spreadsheet containing 500 rows of cryptic IT jargon. Things like uh CN AppFind B, B prod RW, OU groups, DC Corp, DC Comm.
SPEAKER_02Complete alphabet suit.
SPEAKER_01Exactly. They have 10 other urgent projects competing for their attention. They don't know what that string of text means. They know their team is currently working fine, and they don't want to accidentally break anything. So they just highlight all 500 rows, click approve, and get back to their real job.
SPEAKER_02The classic rubber stamp.
SPEAKER_01Yes. So how on earth does slapping a KPI target of 95% completion on a dashboard actually fix human nature? You aren't measuring security, you're just measuring how fast managers can rubber stamp a form.
SPEAKER_02You're entirely right. A 95% completion rate of bad, unverified reviews is completely worthless.
SPEAKER_01Right.
SPEAKER_02It is the definition of compliance theater. You look great to the auditors, but your actual risk posture hasn't improved an inch.
SPEAKER_00So what's the solution?
SPEAKER_02The blueprint heavily anticipates this exact failure mode, which is why the operationalization phase demands two massive structural changes to how reviews are conducted. First, you must implement non-response auto-revocation.
SPEAKER_01Auto-revocation.
SPEAKER_02Yes. Historically, if a manager ignored the review campaign, the IT department would just assume the access was still needed to avoid causing disruptions, and they would manually extend it. The blueprint flips that.
SPEAKER_01Wow. That is going to cause immense pain the first time it happens.
SPEAKER_02Oh, there will be screaming. But pain is an incredibly effective operational motivator. The moment an entire team loses access to Salesforce because their director ignored the compliance emails, that director will never ignore an access review again. You force engagement through operational consequence.
SPEAKER_01That's a tough love approach. What's the second structural change?
SPEAKER_02You have to fix the data you are presenting to the reviewer. You cannot hold a manager accountable for rubber stamping a decision they literally do not understand. You pointed out the Active Directory jargon earlier.
SPEAKER_01How does the system translate the technical debt into plain English?
SPEAKER_02Through aggressive metadata tagging and business context mapping within the IGA platform. Instead of presenting that raw CN string to the manager, SailPoint correlates that group back to the application owner, the data classification, and the plain text description.
SPEAKER_01So it looks like a real sentence.
SPEAKER_02Exactly. The manager sees a clean, business readable prompt. Does Sarah still require read-write access to the production financial database, which contains highly confidential Tier 1 data?
SPEAKER_01That makes it so much easier to evaluate.
SPEAKER_02Furthermore, the blueprint requires shifting the burden of review away from just direct line managers. Direct managers only know what their employees are doing generally. The blueprint mandates holding the application owners accountable. The executive who owns the financial database should be certifying who has access to it because they understand the inherent risk of the data much better than a mid-level manager in a different department.
SPEAKER_01That contextualization is brilliant. It turns an IT chore into an actual business risk decision. And speaking of risk decisions, you mentioned exceptions earlier. The blueprint has a specific KPI for policy exceptions. The target is to maintain exceptions at less than 5% of all total access, with a hard rule that absolutely no exception can be older than 90 days.
SPEAKER_02Yeah. Exceptions are basically the technical debt of the identity world. In a complex enterprise, you will inevitably encounter a legacy application, maybe a 15-year-old inventory system, that simply cannot integrate with modern SSO or MFA. It requires a hard-coded shared password.
SPEAKER_01And you can't just turn it off.
SPEAKER_02Right. The business needs the application to survive, so you have to grant an exception to your security policy.
SPEAKER_01But if you just document it and walk away, it becomes permanent.
SPEAKER_02Exactly. An exception that persists indefinitely isn't an exception. It's a permanent, ungoverned workaround. It's a gaping hole in the submarine. The 90-day clock forces accountability. You document the shared password risk, but the system alerts the application owner at day 60 and day 80.
SPEAKER_01Ticking clock.
SPEAKER_02When the clock runs out at day 90, the exception expires. The business must either present a funded, actionable plan to modernize or replace that legacy app, or the security team revokes the access and shuts it down. The KPI ensures that exceptions are painful. Temporary life support, not a lifestyle choice.
SPEAKER_01I love that. Temporary life support, not a lifestyle choice. So if we step back, these metrics, the joiner lever times, the MFA quality, the JIT adoption, the exception aging, they give us a highly detailed point-in-time snapshot. We know exactly what the dials say today. But a true phase seven operational program isn't a photograph, it is a motion picture.
SPEAKER_02It's constantly moving.
SPEAKER_01Right. How does an organization use these metrics to continuously evolve, especially when the technological landscape is being completely disrupted underneath them? We can't just operationalize for the threats of 2024. We have to govern the chaos of what's coming. This leads us into the final frontier of the blueprint, the continuous improvement cycle and future-proofing. We have to talk about zero trust architecture and the absolute tidal wave of agentic AI.
SPEAKER_02You cannot submerge a submarine, sail it for five years, and never upgrade the sonar. The threat actors are evolving their tactics daily, so your operational model must iterate to survive.
SPEAKER_00And the blueprint dictates a very specific, relentless cadence for this evolution, right?
SPEAKER_02Yes. Monthly, the tactile working groups meet to review the granular KPIs and triage the 90-day exceptions. Quarterly, the Executive Steering Committee reviews the aggregated program metrics to assess the macro risk posture. Semi-annually, the organization must run a brutally honest reassessment of the program's maturity against a one-to-five capability scale. And annually, there's a full strategy and budget refresh to align with new business goals.
SPEAKER_01And what is the ultimate North Star they are steering toward? The CISA Zero Trust Maturity Model.
SPEAKER_02The Cybersecurity and Infrastructure Security Agency maps this transition out beautifully. The industry is moving from a traditional state to an optimal state of zero trust.
SPEAKER_01Give me a quick breakdown of the traditional state.
SPEAKER_02In the traditional state, identity is static. You present your username, password, and MFA token at the front door of the VPN. The system checks the list, says you are authenticated, and lets you in. Once you are inside the network perimeter, you are implicitly trusted. You can roam around for the next 12 hours and the system never questions you again.
SPEAKER_01It's the Castle and Moat architecture. Once you cross the drawbridge, you have the run of the courtyard.
SPEAKER_02Exactly. And attackers love that. If they hijack your session token after you cross the moat, they have free reign. But in the optimal state of zero trust, identity is continuously validated. It is never static. The perimeter isn't a firewall, the perimeter is the identity itself.
SPEAKER_01So it's constantly checking you.
SPEAKER_02Every single time a user requests a piece of data, not just when they log in, but every time they click a link, open a file, or query a database, the policy engine evaluates a massive array of telemetry. It looks at the user's current behavioral risk score, it looks at the health of the device. Is the endpoint running the latest patched OS? Is the firewall active?
SPEAKER_01That's a lot of checks.
SPEAKER_02It even evaluates the network context. Is this request coming from a known corporate IP or an anonymous VPN exit node in a high-risk country? If any of those signals drop below the required threshold, the session is instantly severed, or the user is prompted to step up their authentication with a biometric scan.
SPEAKER_01It's exhausting just thinking about the computational power required to validate every single action, but I guess it's the only way to contain a breach locally.
SPEAKER_02It's the only way.
SPEAKER_01But then, and here's where things get wild. We throw a massive wrench into this carefully governed human ecosystem, agentic AI readiness. We are pulling heavily from the ping identity framework for securing AI agents here, and honestly, this completely breaks my mental model of IAM.
SPEAKER_02It's breaking everyone's model right now.
SPEAKER_01We just spent 50 minutes detailing how to govern human employees, the JML life cycles, the HR triggers, the access reviews. How on earth do you govern a digital worker? Like if I deploy an autonomous AI agent to work on my behalf, an agent that reads my emails, parses incoming vendor invoices, and autonomously negotiates and executes contracts in the CRM, how do these human metrics apply? Does an algorithm have a lever process? Do you fire an AI?
SPEAKER_02That is the exact frontier the industry is violently grappling with right now. Organizations are rushing to deploy these autonomous agents to gain a competitive edge, completely bypassing the governance models. Ping identity outlines a critical 90-day plan to scale AI security because right now most companies are treating these highly capable AI agents like simple static service accounts.
SPEAKER_01What's the danger in treating them like a service account?
SPEAKER_02Well, a traditional service account, you say the account a web server uses to talk to a database, does exactly one predictable thing millions of times a day. You give it a long-lived credential, lock it down to a single IP address, and it's fine.
SPEAKER_01It's deterministic.
SPEAKER_02Yes. But an agentic AI is non-deterministic. It reasons, it makes decisions, it interacts with unpredictable external data. If you give an AI agent a static, highly privileged token to access your CRM, and that AI suffers a prompt injection attack from a malicious email it reads, it can be hijacked to autonomously exfiltrate your entire customer database.
SPEAKER_01And because it's a non-human identity, there is no HR department to fire it. The traditional JML lifecycle doesn't exist. There's no workday record for the marketing bot.
SPEAKER_02Exactly.
SPEAKER_01So how do the phase seven metrics evolve to capture this?
SPEAKER_02Ping's framework insists on two major structural shifts. First, high-risk agent actions must be gated by human in the loop approvals or HITL.
SPEAKER_01Human in the loop.
SPEAKER_02Right. If your AI agent decides, based on this analysis, to execute a $50,000 add by or bulk delete 500 records in the CRM, it shouldn't possess the autonomy to just execute that API call. The AI must be forced to trigger an out-of-band flow. Ping refers to this utilizing SIBA client-initiated back channel authentication.
SPEAKER_01Okay, unpack the mechanics of a SIBA flow for me. What does that actually look like for the human supleiser?
SPEAKER_02The AI agent initiates the high-risk action. The IAM policy engine intercepts the request and pauses the AI's workflow. It then opens a completely separate out-of-band communication channel to the human owner of that agent. Your phone buzzes.
SPEAKER_00Another push notification.
SPEAKER_02But a very specific one. You receive a rich context push notification that says Agent MarketingBot Zero O is attempting to execute a $50K ad buy via the Google Ads API. Do you authorize this? You review the context, authenticate with your face it or fingerprint to prove you are present, and hit approve. The policy engine receives the cryptographically signed approval and releases a single use token to the AI to complete that specific transaction.
SPEAKER_01Your phase 7 dashboard now has to track an entirely new metric, HITL approval quality. Are the human supervisors actually reviewing these AI actions, or are they just rubber stamping the bot prompts exactly like they rubber stamp their quarterly access reviews?
SPEAKER_02It's the exact same human behavioral flaw ported over to a hyperspeed technology. If humans rubber stamp AI actions, the governance fails.
SPEAKER_00Right. And what about firing the AI?
SPEAKER_02Right. To address your question about how you fire an AI, you rely on machine speed automated threat detection. You cannot give these agents static passwords. You scope incredibly short-lived just-in-time tokens for them. If an AI goes rogue, whether it's hallucinating or it's been hijacked via an adversary in the middle attack, you need telemetry to catch it.
SPEAKER_00How fast are we talking?
SPEAKER_02Milliseconds. Okta's behavioral analytics engine, for example, baselines the normal operating behavior of the agent. If the AI normally processes five vendor invoices an hour and suddenly attempts to download 50,000 sensitive employee records in two minutes, the analytics engine detects the massive deviation in velocity and volume.
SPEAKER_01And it triggers the lever process.
SPEAKER_02Instantly, the system executes a global token revocation. It doesn't wait for a human to review a ticket. The AI is immediately stripped of all access rights across every single connected platform. It is a machine speed termination triggered by behavioral anomaly detection, not a human manager.
SPEAKER_01That paints an incredible, almost intimidating picture of where this discipline is heading. The ultimate phase seven deliverables, the living IAM operating model document detailing the human tiers, the real-time KPI dashboard tracking JML velocity, the continuous improvement plan plotting the course to zero trust, and the annual program report. The sources make it undeniably clear.
SPEAKER_02No, not at all.
SPEAKER_01They are the literal pulse of the organization. They are the sonar pinging in the dark water.
SPEAKER_02And if you aren't obsessively watching those dials and constantly recalibrating them against new threats, you are sailing blind in incredibly hostile territory.
SPEAKER_01Let's bring this all the way back to the surface and recap this massive journey for you. Phase seven isn't an administrative afterthought. It is the central operating system of the entire enterprise security apparatus.
SPEAKER_02The engine of the whole thing.
SPEAKER_01We unpack the friction within the four-tier human architecture, realizing that you need the rigid governance of the service desk and operations just as much as the architects to prevent engineers from building shadow IT shortcuts. We dissected the critical JML joiner, mover, lever telemetry, discovering that the mover process, with its terrifying potential for privilege creep, is the most dangerous transition of all, requiring automated delta analysis to neutralize.
SPEAKER_02It's all connected.
SPEAKER_01We tackled the psychological fight against the access review rubber stamp, proving that you need business readable contextual data and the pain of auto-revocation to change how managers behave. And finally, we looked at how this entire massive apparatus must scale up to handle the continuous behavioral validation of zero trust and the wild west of autonomous agentic AI.
SPEAKER_02It's a lot to monitor, but it's essential.
SPEAKER_01So, my call to action for you, the listener, is this when you log back into your corporate network tomorrow, take a hard look at your own organization's reality. Do you actually know your joiner and lever times, or are you relying on anecdotal guesswork? Are you tracking the true cryptographic quality of your MFA, or are you resting on the false comfort of compliance boxes while your users get spammed with fishable push notifications?
SPEAKER_02It really is the stark difference between believing you are secure and mathematically knowing you are secure. And as we look toward the immediate future, I want to leave you with this final thought to dissect. We discussed how rapidly the perimeter is dissolving into identity. Imagine if your company deployed a highly capable autonomous AI agent tomorrow morning, an agent programmed to optimize workflows, capable of independently requesting its own elevated access to your core customer database in order to do its job better.
SPEAKER_01A scary thought.
SPEAKER_02That's a wrap on season one of the identity blueprint. Thank you for joining us on this journey through the full IAM engagement blueprint, from discovery and strategy all the way through to operations and metrics. We hope it changed how you see this discipline. Season two is coming. Stay tuned. It's going to be worth the wait. Connect with me on LinkedIn at LinkedIn.com forward slash IN slash Ernie Prescott. And subscribe now so you're first to know when we're back. Until next time.