Identity Lifecycle
Identity lifecycle refers to the full span of a digital identity's existence within an organization, from the moment it is created through its various changes and until it is eventually retired. Managing this lifecycle typically involves creating accounts when a person joins, adjusting their access as their role changes, and removing access when they leave. The goal is to ensure that each person has appropriate access at each stage of their relationship with the organization.
Identity Lifecycle Management (ILM) is the framework and set of processes for governing a digital identity and its associated entitlements across all stages of its existence, typically spanning provisioning (creation), ongoing changes such as role transitions and entitlement adjustments, and de-provisioning (retirement). In most implementations, ILM is automated to enforce consistent joiner-mover-leaver handling and to align access with an individual's current affiliation and role. In a compliance context, ILM controls commonly support logical access management objectives; under the SOC 2 framework these relate to the Security (Common Criteria) category, and under ISO/IEC 27001 they are typically addressed by access-control-related Annex A reference controls selected via the Statement of Applicability. Note that ILM itself is a control domain rather than a framework requirement, and the specific controls, automation, and scope vary depending on the organization, applicable criteria, and the auditor or certification body.
Why it matters
Identity lifecycle management sits at the center of logical access control, which is one of the most scrutinized areas in both SOC 2 examinations and ISO/IEC 27001 certifications. When accounts are created, changed, and retired in a consistent and timely way, access remains aligned with each person's current role and affiliation. When the lifecycle breaks down, orphaned accounts that outlive an employee's tenure, entitlements that accumulate as people change roles, or provisioning that grants more than a role requires, the result is often excess or stale access that is difficult to justify to an auditor and risky to leave in place.
Because ILM directly supports the Security (Common Criteria) category under SOC 2 and access-control-related Annex A reference controls under ISO 27001, weaknesses in this domain frequently surface as findings. A SOC 2 Type II report, for example, attests to whether these controls operated effectively over the review period, so inconsistent joiner-mover-leaver handling can undermine an otherwise strong control environment. It is worth noting that neither framework guarantees freedom from breaches; ILM controls reduce the likelihood and impact of inappropriate access but do not eliminate risk, and the specific expectations vary with scope, applicable criteria, and the auditor or certification body.
Strong lifecycle management also builds the broader trust that identity systems are meant to support across transactions between individuals, identity providers, and the parties that rely on them. Automating and standardizing the lifecycle helps organizations demonstrate that access decisions are deliberate and reviewable rather than ad hoc, which is typically what compliance assessors look for when evaluating logical access management objectives.
Who it's relevant to
Inside ILM
Common questions
Answers to the questions practitioners most commonly ask about ILM.