Kean University Identity Lifecycle Automation Standard Operating Procedure (SOP 14)
Table of Contents
- About
- Scope
- Definitions
- Roles & Responsibilities
- Procedure Steps
- Related Policies & Standards
- Metrics & KPIs
- Records & Storage
- Revision History
About
This Standard Operating Procedure (SOP) defines how Kean University automates the identity lifecycle, including provisioning, updates, and deprovisioning of user accounts. The goal is to ensure that identities are created, maintained, and removed accurately and in a timely manner based on authoritative data sources.
This SOP supports compliance by ensuring that access is granted only after verification, updated based on role changes, and removed immediately when no longer required.
Scope
This SOP applies to all identity lifecycle automation processes and systems, including:
- Automated identity feeds from authoritative systems
- Identity platforms such as Active Directory and Microsoft Entra ID (Azure AD)
- HR systems, registrar systems, and vendor management systems
- Privileged Access Management (PAM) tools
Applies to all identity types:
- Faculty and staff
- Students
- Vendors and contractors
- Service accounts
- Privileged accounts
Automated lifecycle stages include:
- Provisioning (account creation)
- Attribute updates
- Access and role adjustments
- Deactivation
- Expiration (e.g., vendors)
- Reactivation (when justified)
Definitions
View Definitions
- System of Record (SOR): Authoritative data source used to validate identity eligibility (e.g., HR system, registrar, vendor system).
- Lifecycle Automation Engine: Automated workflows that create, update, or disable accounts based on SOR events.
- Provisioning: Automated creation of user accounts across systems.
- Deactivation: Automated disabling of accounts after termination or status changes.
Roles & Responsibilities
| Role | Responsibilities |
|---|---|
| Identity & Access Management (IAM) Lead | Owns automation workflows and ensures governance and accuracy |
| Human Resources (HR) | Maintains employee data and triggers lifecycle events |
| Registrar | Provides student lifecycle data and status changes |
| Vendor Management | Supplies contractor and vendor lifecycle data |
| System Owners | Validate proper access and lifecycle behavior in systems |
| Security Operations | Monitors automation outcomes and detects anomalies |
| Chief Information Security Officer (CISO) | Approves changes impacting privileged identities and lifecycle controls |
Procedure Steps
1. Authoritative Data Synchronization
- Ingest data from HR, registrar, and vendor systems
- Track hires, status changes, enrollments, and terminations
- Validate identity eligibility using system-of-record data
2. Identity Provisioning Automation
- Create identity records in directory systems
- Apply naming conventions and identity categories
- Enable authentication (MFA, credentials, policies)
- Assign role-based access (RBAC)
3. Attribute Change Automation
- Update identity attributes when roles or departments change
- Recalculate access permissions automatically
- Remove unnecessary access to maintain least privilege
4. Privileged Identity Lifecycle Automation
- Require approvals before provisioning privileged accounts
- Enforce session controls, logging, and MFA
- Deprovision privileged access immediately upon role change or termination
5. Automated Deactivation & Disablement
- Disable accounts based on termination or inactivity events
- Revoke tokens, sessions, and group membership
- Disable authentication and log all actions
6. Integration & Error Handling
- Monitor for feed failures and automation errors
- Trigger alerts and remediation workflows
- Re-run jobs and document corrections
7. Exception Handling
- Follow formal exception management procedures
- Require risk analysis and approval
- Ensure exceptions are documented and time-bound
8. Verification & Audit
- Conduct quarterly validation of automation accuracy
- Reconcile system-of-record data with IAM systems
- Perform annual review of automation rules and integrations
Related Policies & Standards
- Identity & Authentication Policy
- Access Control Policy
- Account Management Policy
- Privileged Access Management Policy
- Password & Authentication Standard
- Exception Management Policy
- Policy Governance & Precedence
Metrics & KPIs
- Provisioning SLA compliance
- Deactivation SLA compliance
- Identity feed error rate
- Number of orphaned accounts
- Privileged account lifecycle accuracy
- Access assignment accuracy (RBAC)
- Automation success and failure rates
Records & Storage
| Record | Location |
|---|---|
| Lifecycle synchronization logs | IAM system |
| Provisioning and deprovisioning logs | IAM platform and GRC repository |
| Attribute and change logs | IAM system |
| Exception records | GRC system |
| Error and alert logs | SIEM and IAM platform |
| Audit and verification reports | GRC repository |
Revision History
| Version | Date | Change | Author |
|---|---|---|---|
| 1.0 | February 13, 2026 | Initial SOP | IAM Lead |