Practical field guide
Identity & Access Field Guide
Identity & Access Field Guide organizes the decisions that matter for organizations controlling accounts, roles, permissions, sign-in, and staff access: the current workflow, ownership, implementation choices, rollout risk, and acceptance evidence.
Working artifact
Identity & Access implementation-path comparison
Compare the smallest responsible paths before treating replacement as the default.
| Path | Best fit | Watch closely |
|---|---|---|
| Repair | The core of authentication, invitation, and account-lifecycle systems remains sound | Former staff or vendors retain unnecessary access |
| Extend | OAuth, OIDC, SAML, passkeys, and MFA has a stable, understood boundary | Users cannot recover accounts without manual intervention |
| Replace | Ownership or architecture prevents a responsible repair | Permissions are inconsistent across connected systems |
Read the situation before naming the solution
Former staff or vendors retain unnecessary access. Confirm who encounters it, where it occurs, and what changed before it appeared. Then distinguish the visible symptom from dependencies such as oAuth, OIDC, SAML, passkeys, and MFA.
- Former staff or vendors retain unnecessary access
- Users cannot recover accounts without manual intervention
- Permissions are inconsistent across connected systems
Map the operating boundary
For Identity & Access Management, confirm account ownership, current exports or backups, recovery options, and recent changes before touching production. Preserve exact errors and timestamps that may disappear after a restart or update.
- People and roles
- Systems and vendors
- Records and data
- Known deadlines
Choose the smallest useful first result
Frame the first scope around authentication, invitation, and account-lifecycle systems and one observable acceptance journey. Treat role, permission, SSO, and MFA implementation as a later phase unless the evidence shows it is a true dependency.
- Authentication, invitation, and account-lifecycle systems
- Role, permission, SSO, and MFA implementation
- Access review, recovery, audit, and migration workflows
Protect working assets
Repair fits when the core remains sound. Extension fits when the boundary around oAuth, OIDC, SAML, passkeys, and MFA is understood. Replacement fits when ownership, architecture, or operating risk prevents a responsible change.
- Current backup
- Restore method
- Access owner
- Change evidence
Verify the lived result
Sequence work around role and attribute-based authorization models. Protect the people affected by “Former staff or vendors retain unnecessary access,” and define the point where rollback is safer than continuing.
- Acceptance evidence
- Failure-path check
- Ownership record
- Next-step backlog