Automating Identity Governance and Entitlement Lifecycle Management at Enterprise Scale
Keywords:
identity governance; entitlement lifecycle management; role-based access control; attribute-based access control; access certification; segregation of duties; enterprise identity managementAbstract
Enterprise access complexity has outpaced what manual identity governance can sustain: role-based access control, the dominant model for securing large organizations, was never designed for the scale at which modern enterprises now operate, and its own literature has long documented the resulting "role explosion" problem (Elliott & Knight, 2015; Sandhu et al., 1996). This article argues that Joiner-Mover-Leaver (JML) automation, SCIM-based provisioning, and continuous access certification only address entitlement sprawl sustainably when they are unified around shared entitlement metadata and explicit ownership, rather than operated as separate compliance tools bolted onto a role model that was never built to scale this far. Drawing on foundational role-based access control theory (Sandhu et al., 1996), its documented scalability limits (Elliott & Knight, 2015), and the hybrid and attribute-based models developed in response (Hu et al., 2014; Aftab et al., 2022), the article proposes a lifecycle framework that treats provisioning, ownership, certification, and privileged access governance as one continuously governed process. The discussion addresses integration challenges specific to hybrid enterprise identity ecosystems, including legacy application onboarding and metadata quality dependencies, and positions entitlement ownership - not tooling - as the binding constraint on governance sustainability at scale.
Downloads
References
Aftab, M. U., Hamza, A., Oluwasanmi, A., Nie, X., et al. (2022). Traditional and hybrid access control models: A detailed survey. Security and Communication Networks, 2022, Article 1560885. https://doi.org/10.1155/2022/1560885
Elliott, A., & Knight, S. (2015). Towards managed role explosion. In Proceedings of the 2015 New Security Paradigms Workshop (pp. 100-111). ACM. https://www.nspw.org/papers/2015/nspw2015-elliott.pdf
Glockler, J., Sedlmeir, J., Frank, M., & Fridgen, G. (2023). A systematic review of identity and access management requirements in enterprises and potential contributions of self-sovereign identity. Business & Information Systems Engineering, 66(4), 421-440. https://doi.org/10.1007/s12599-023-00830-x
Hewett, R., Kijsanayothin, P., & Thipse, A. (2008). Security analysis of role-based separation of duty with workflows. In 2008 Third International Conference on Availability, Reliability and Security (pp. 765-770). IEEE.
Hu, V., Ferraiolo, D., Kuhn, R., Schnitzer, A., Sandlin, K., Miller, R., & Scarfone, K. (2014). Guide to attribute based access control (ABAC) definition and considerations (NIST Special Publication 800-162). National Institute of Standards and Technology.
Internet Engineering Task Force. (2015a). System for Cross-domain Identity Management: Core schema (RFC 7643). https://datatracker.ietf.org/doc/html/rfc7643
Internet Engineering Task Force. (2015b). System for Cross-domain Identity Management: Protocol (RFC 7644). https://www.rfc-editor.org/info/rfc7644/
Internet Engineering Task Force. (2015c). System for Cross-domain Identity Management: Definitions, overview, concepts, and requirements (RFC 7642). https://datatracker.ietf.org/doc/html/rfc7642
Nassif, A. B., Talib, M. A., Nasir, Q., Albadani, H., & Dakalbab, F. M. (2021). Machine learning for cloud security: A systematic review. IEEE Access, 9, 20717-20735.
Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero trust architecture (NIST Special Publication 800-207). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207
Sandhu, R. S., Coyne, E. J., Feinstein, H. L., & Youman, C. E. (1996). Role-based access control models. IEEE Computer, 29(2), 38-47. https://doi.org/10.1109/2.485845
Syed, N. F., Shah, S. W., Shaghaghi, A., Anwar, A., Baig, Z., & Doss, R. (2022). Zero trust architecture (ZTA): A comprehensive survey. IEEE Access, 10, 57143-57179. https://doi.org/10.1109/ACCESS.2022.3174679
Thurupati, S. C. (2026). Federated identity security: Challenges in SAML and OIDC implementations. International Journal of Intelligent Systems and Applications in Engineering, 14(1s), 1244-1256. https://ijisae.org/index.php/IJISAE/article/view/8337
Downloads
Published
How to Cite
Issue
Section
License

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
All papers should be submitted electronically. All submitted manuscripts must be original work that is not under submission at another journal or under consideration for publication in another form, such as a monograph or chapter of a book. Authors of submitted papers are obligated not to submit their paper for publication elsewhere until an editorial decision is rendered on their submission. Further, authors of accepted papers are prohibited from publishing the results in other publications that appear before the paper is published in the Journal unless they receive approval for doing so from the Editor-In-Chief.
IJISAE open access articles are licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. This license lets the audience to give appropriate credit, provide a link to the license, and indicate if changes were made and if they remix, transform, or build upon the material, they must distribute contributions under the same license as the original.


