Concept and mechanism
The identity lifecycle includes creation, role assignment, review, and access removal. A team move is a review event rather than merely an opportunity to add permissions. Confirm current need and remove what is no longer justified. Least privilege limits authority to what is needed; separation of duties addresses combinations that should not belong to one person. If an order requires different creator and approver, clicking twice or using a shared account does not satisfy the rule. Enforcement belongs in the workflow with attributable identities. RBAC organizes permissions through roles; attribute-based models can consider other characteristics and context according to design.
Guided application
In a fictional example, someone moves into APS while a reporting bot still uses their identity. Review human privileges and identify automation ownership, purpose, and dependencies before revocation or reassignment. A technical account also needs duration, control, and closure when it no longer serves a purpose. Do not solve continuity by sharing personal passwords. In authentication, count proof types rather than screens: a password and memorized PIN sent to the server are both knowledge. This differs from a local PIN activating a physical authenticator whose protocol can prove possession. The distinction prevents classifying any second field as MFA. At review closure, record what was removed, what remains, and its approved justification.
Role move: review need, remove old privilege, and handle dependent automation.
Common pitfalls
Two passwords as two factors; move as accumulated roles; ownerless bot; logs as self-approval prevention.
Related topics: Security principles and conduct · Governance, continuity, and awareness · Networks, cloud, and boundaries
Keep identity, need, and responsibility aligned throughout the lifecycle.
Reference: Security and privacy controls · CC examination outline effective 2026-09-01; PDF v01/2026