Automating Identity Governance and Entitlement Lifecycle Management at Enterprise Scale

Authors

  • Kishore Vadla

Keywords:

identity governance; entitlement lifecycle management; role-based access control; attribute-based access control; access certification; segregation of duties; enterprise identity management

Abstract

Enterprise access complexity has outpaced what manual identity governance can sustain: role-based access control, the dominant model for securing large organizations, was never designed for the scale at which modern enterprises now operate, and its own literature has long documented the resulting "role explosion" problem (Elliott & Knight, 2015; Sandhu et al., 1996). This article argues that Joiner-Mover-Leaver (JML) automation, SCIM-based provisioning, and continuous access certification only address entitlement sprawl sustainably when they are unified around shared entitlement metadata and explicit ownership, rather than operated as separate compliance tools bolted onto a role model that was never built to scale this far. Drawing on foundational role-based access control theory (Sandhu et al., 1996), its documented scalability limits (Elliott & Knight, 2015), and the hybrid and attribute-based models developed in response (Hu et al., 2014; Aftab et al., 2022), the article proposes a lifecycle framework that treats provisioning, ownership, certification, and privileged access governance as one continuously governed process. The discussion addresses integration challenges specific to hybrid enterprise identity ecosystems, including legacy application onboarding and metadata quality dependencies, and positions entitlement ownership - not tooling - as the binding constraint on governance sustainability at scale.

Downloads

Download data is not yet available.

References

Aftab, M. U., Hamza, A., Oluwasanmi, A., Nie, X., et al. (2022). Traditional and hybrid access control models: A detailed survey. Security and Communication Networks, 2022, Article 1560885. https://doi.org/10.1155/2022/1560885

Elliott, A., & Knight, S. (2015). Towards managed role explosion. In Proceedings of the 2015 New Security Paradigms Workshop (pp. 100-111). ACM. https://www.nspw.org/papers/2015/nspw2015-elliott.pdf

Glockler, J., Sedlmeir, J., Frank, M., & Fridgen, G. (2023). A systematic review of identity and access management requirements in enterprises and potential contributions of self-sovereign identity. Business & Information Systems Engineering, 66(4), 421-440. https://doi.org/10.1007/s12599-023-00830-x

Hewett, R., Kijsanayothin, P., & Thipse, A. (2008). Security analysis of role-based separation of duty with workflows. In 2008 Third International Conference on Availability, Reliability and Security (pp. 765-770). IEEE.

Hu, V., Ferraiolo, D., Kuhn, R., Schnitzer, A., Sandlin, K., Miller, R., & Scarfone, K. (2014). Guide to attribute based access control (ABAC) definition and considerations (NIST Special Publication 800-162). National Institute of Standards and Technology.

Internet Engineering Task Force. (2015a). System for Cross-domain Identity Management: Core schema (RFC 7643). https://datatracker.ietf.org/doc/html/rfc7643

Internet Engineering Task Force. (2015b). System for Cross-domain Identity Management: Protocol (RFC 7644). https://www.rfc-editor.org/info/rfc7644/

Internet Engineering Task Force. (2015c). System for Cross-domain Identity Management: Definitions, overview, concepts, and requirements (RFC 7642). https://datatracker.ietf.org/doc/html/rfc7642

Nassif, A. B., Talib, M. A., Nasir, Q., Albadani, H., & Dakalbab, F. M. (2021). Machine learning for cloud security: A systematic review. IEEE Access, 9, 20717-20735.

Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero trust architecture (NIST Special Publication 800-207). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207

Sandhu, R. S., Coyne, E. J., Feinstein, H. L., & Youman, C. E. (1996). Role-based access control models. IEEE Computer, 29(2), 38-47. https://doi.org/10.1109/2.485845

Syed, N. F., Shah, S. W., Shaghaghi, A., Anwar, A., Baig, Z., & Doss, R. (2022). Zero trust architecture (ZTA): A comprehensive survey. IEEE Access, 10, 57143-57179. https://doi.org/10.1109/ACCESS.2022.3174679

Thurupati, S. C. (2026). Federated identity security: Challenges in SAML and OIDC implementations. International Journal of Intelligent Systems and Applications in Engineering, 14(1s), 1244-1256. https://ijisae.org/index.php/IJISAE/article/view/8337

Downloads

Published

31.08.2026

How to Cite

Kishore Vadla. (2026). Automating Identity Governance and Entitlement Lifecycle Management at Enterprise Scale. International Journal of Intelligent Systems and Applications in Engineering, 14(1s), 2361–2366. Retrieved from https://www.ijisae.org/index.php/IJISAE/article/view/8540

Issue

Section

Research Article