August 7, 2026

Identity Management: Definition, Scope, and Best Practices

Selina Trummer

By Selina Trummer

Product Marketing Manager

Geschäftsfrau mit Mitarbeiterausweis am Eingang eines Bürogebäudes — kontrollierter Zugriff im Identity Management

16 min read

Share this post

Anyone reading this article will understand what identity management is, how it differs from IAM, IGA, and PAM, and why it is a core security discipline. You’ll learn about the identity lifecycle—from onboarding to offboarding—understand the four root causes of identity chaos, and gain access to a proven framework, best practices, a real-world example, and an FAQ for security professionals.

Key Points

  • Definition: Identity Management manages digital identities and their access rights throughout their entire lifecycle—from onboarding to offboarding.

  • Distinction: Identity Management is the umbrella term; IAM covers access control, IGA covers governance, and PAM covers privileged accounts.

  • Stolen credentials are a top attack vector: According to the Verizon DBIR 2026, stolen login credentials are the second-most common initial attack vector.

  • Data breaches remain costly: According to IBM's 2025 report, a data breach costs an average of $4.44 million; identity-based attacks cost even more, at $4.67 million.

  • The identity lifecycle is key: Joiner-Mover-Leaver processes determine security—orphaned accounts are an underestimated risk.

  • The real problem lies in identity data: No access system is better than the employee and organizational master data on which it is based.

  • Goldright provides the foundation: The Identity Manager delivers unique employee identities as a single source of truth—the basis for automated, auditable user management.

What Is Identity Management? The Definition

Identity management refers to the totality of all processes, policies, and technologies that a company uses to manage digital identities and their access rights. A digital identity can be an internal employee, an external service provider, a partner, or, increasingly, a technical account (service or machine identity).

At its core, identity management answers three questions:

  • Who is the person or entity?

  • What are they authorized to access?

  • And is this access still justified?

This encompasses unique identification, the granting and revocation of permissions, and comprehensive documentation throughout the entire lifecycle of an identity.

The terms “identity management,” “identity and access management” (IAM), and “user management” are often used interchangeably. Strictly speaking, identity management is the umbrella term for managing the identity itself, while IAM additionally encompasses technical access control (authentication and authorization). Traditional user management is an operational subset of this.

A digital identity is more than just a login. It brings together all the attributes that uniquely describe a person or entity: name, role, organizational unit, employment type, and the permissions derived from them. Depending on the context, this is also referred to as identity management, access management, or permission management—but the concept always refers to the controlled management of identities and their rights.

Crucial—and often overlooked—is the data foundation. Every digital identity is based on user master data: name, role, department, cost center, start date, and contract type. If this employee master data is incorrect or contradictory, even the most sophisticated access control is worthless. This is exactly where Goldright’s Identity Manager comes in: It creates unique employee identities as a single source of truth.

The Core Components of Identity Management

A comprehensive identity management system consists of several building blocks. It is only through their interaction that a collection of user accounts becomes a secure, manageable system. Understanding these terms allows you to evaluate solutions more effectively.

Authentication — Who Are You?

Authentication verifies whether an identity is who it claims to be. Modern methods go beyond passwords: Multi-factor authentication (MFA) combines multiple forms of verification, such as a password plus a one-time code or a biometric feature. MFA is considered one of the most effective individual measures against the misuse of stolen login credentials.

Authorization — What Can You Access?

Authorization determines which resources an authenticated identity is permitted to use. Ideally, it is based on roles (Role-Based Access Control, RBAC): permissions are tied to the role, not to the individual. This ensures that permission assignment remains traceable and can be automated.

Single Sign-On and Federation

Single Sign-On (SSO) allows users to log in once and then access multiple applications without having to log in again. Federation enables identities to be exchanged reliably across systems—including between organizations. Both enhance convenience and security but require a unique identity.

Provisioning and Deprovisioning

Provisioning automatically creates accounts and permissions in the target systems, while deprovisioning revokes them. When these processes are linked to a central database, access is granted and revoked automatically based on the role—the key to a secure identity lifecycle.

Why Is Identity Management So Important?

Identity management has evolved from an IT administrative task into a core security discipline. Four documented trends explain why identities are now the most critical line of defense. The common thread: Attackers no longer break in; they log in—using stolen or over-privileged identities.

1. Identity Is the New Perimeter—and the Most Common Point of Entry

In the cloud and remote world, no firewall protects the corporate boundary anymore—identity is the new perimeter. According to the Verizon Data Breach Investigations Report 2026, stolen credentials are the second-most common initial attack vector and are involved in 22% of all analyzed security incidents. For attacks on web applications, this percentage rises to over 80%.

2. Data breaches are costly

The IBM Cost of a Data Breach Report 2026 estimates the average cost of a data breach at $4.44 million worldwide. Attacks in which compromised credentials served as the entry point are even higher, at $4.67 million. Every poorly managed identity thus poses a direct financial risk.

Add to that the time factor: The longer a compromised account remains undetected, the more expensive the damage becomes. A well-managed identity lifecycle with a comprehensive overview shortens precisely this detection and response time—and thus directly reduces the cost of an incident.

3. Cybercrime Reaches Record Levels

The Bitkom study “Economic Protection 2025” estimates the total annual damage to the German economy at 289.2 billion euros; 87% of companies were affected by theft, espionage, or sabotage. A large portion of these attacks begins with compromised identities.

4. Regulations Make Identity Management Mandatory

The EU NIS2 Directive (Directive (EU) 2022/2555) requires a broad range of companies to implement strict access controls, multi-factor authentication, and verifiable identity processes. Together with the GDPR, this makes auditable identity management a regulatory requirement.

Identity Management vs. IAM vs. IGA vs. PAM

Hardly any other subject area has as many acronyms as identity management. The following table clearly distinguishes between the four core disciplines—which is crucial for selecting the right solution for the right purpose.

Criterion

Identity Management

IAM

IGA

PAM

Focus

Identity & Master Data

Access (AuthN/AuthZ)

Governance & Compliance

Privileged Accounts

Key Question

Who is the user?

How do they access the system?

Are they (still) allowed to do that?

Who has admin rights?

Typical Function

Unique Identity, Lifecycle

SSO, MFA, Provisioning

Access Reviews, Recertification

Password Vault, Session Control

Key Benefits

Data Repository & Consistency

Secure Login

Auditability

Protection of Critical Access Points

Typical Providers

Goldright Identity Manager

Microsoft Entra, Okta

SailPoint, Omada

CyberArk, Delinea

The key message of the table: These disciplines are not competing but complementary. IAM controls access, IGA ensures governance, and PAM protects the most critical accounts. However, all three rely on a clean identity database—and that is precisely the blind spot in many security architectures.

The Identity Lifecycle: Joiner, Mover, Leaver

At the heart of every identity management system is the identity lifecycle—the life cycle of a digital identity from creation to deactivation. In practice, it follows the Joiner-Mover-Leaver (JML) model.

Joiner — Onboarding

Beim Onboarding entsteht eine neue Identität. Idealerweise erhält der neue Mitarbeiter bereits am ersten Tag automatisch alle Zugriffsrechte, die seine Rolle erfordert — nicht mehr und nicht weniger. Manuelle Anlage führt hier zu Verzögerungen und Überberechtigung.

Mover — the change

A new identity is created during onboarding. Ideally, the new employee automatically receives all the access rights required for their role on the very first day—no more and no less. Manual creation leads to delays and excessive permissions.

Leaver — Departure

If an employee changes roles, departments, or locations, their permissions must be adjusted. The most common mistake: new permissions are added, but old ones are never revoked. Over the years, this results in a dangerous accumulation of permissions—known as “privilege creep.” An employee who has worked in three different departments often ends up with the combined permissions of all three—an ideal target for attackers.

 

Phase

Trigger

Security Risk in Case of Errors

Goal

Joiner

Onboarding

Delayed Access, Excessive Privileges

Access from Day 1,
Least Privilege

Mover

Role/
Department Change

Privilege Creep,
Accumulation of Permissions

Permissions Follow the Role

Leaver

Termination / Offboarding

Orphaned Accounts, Data Leakage

Immediate,
Complete Deactivation

The Four Root Causes of Identity Chaos

Before a company invests in new security tools, it should understand the actual causes of its identity problem. In practice, four recurring root causes emerge—and they are rarely technical in nature; they are mostly data-driven.

Root Cause 1: Scattered Identity Sources Without a Master System

Employee data resides in the HR system, Active Directory, ERP, CRM, and countless cloud applications—each source with its own version. Without a master system for identity data, no one can reliably know who is currently with the company and what role they hold. Access decisions are then based on conflicting data.

This becomes particularly critical with external identities. Service providers, temporary workers, and partners often do not appear in any master system at all but are created on an ad hoc basis. As a result, there is a lack of visibility precisely for the highest-risk identities.

Root Cause 2: Manual Provisioning and Lack of Automation

When access rights are granted via support tickets and email, the process is slow, error-prone, and opaque. Onboarding takes days, and offboarding is often forgotten. Manual user management does not scale—and every forgotten deactivation is an open security risk. With every reorganization and every system change, the gap between the actual state and what the systems reflect widens.

Root Cause 3: No Clear Role Model

Without a well-thought-out role model (RBAC), each authorization is granted individually. The result is an opaque web of individual rights that cannot be verified or recertified. Authorization management thus becomes a black box. This will come back to haunt you by the next audit at the latest: No one can explain why a specific person has a specific permission.

Root Cause 4: Lack of Historical Record-Keeping and Traceability

If it isn’t documented who had which permissions and when, every audit becomes a Herculean task. Systems without audit-proof historical record-keeping simply cannot provide the regulatory evidence required—for example, under the GDPR or NIS2. Traceability is not an option—it’s a requirement.

Machine and Service Identities: The Invisible Majority

Identity management is usually associated with people. But in modern IT landscapes, technical identities have long made up the majority: service accounts, API keys, bots, containers, and automated processes. These so-called non-human identities (NHI) outnumber human users many times over in many companies.

The problem: machine identities are often created and never cleaned up. They frequently have extensive privileges, run under generic accounts, and fall outside traditional onboarding processes. Gartner identifies the governance of non-human identities as one of the key areas of focus in identity management for the coming years.

Modern identity management considers human and technical identities together. Service accounts also need an owner, a lifecycle, and recertification—otherwise, they become a prime, unsupervised target for attackers.

Not an access problem, but an identity data problem

The most common misdiagnosis in identity management: Security vulnerabilities are treated as purely an access problem, leading to investments in more and more tools—single sign-on, multi-factor authentication, new IAM suites. These tools are important, but they only treat the symptoms.

The root cause lies one level deeper: in the identity data. An access control system can only make decisions as effectively as the employee and organizational master data on which it is based. Conflicting roles, outdated department assignments, and duplicate entries inevitably lead to incorrect permissions.

Incorrect Framing

Correct Framing

“We have an access problem.”

“We have an identity data problem.”

“We need another security tool.”

“We need a clean database.”

“IAM solves our identity issue.”

“IAM relies on clean identity data.”

“Offboarding is an IT task.”

“Offboarding is a data-driven process.”

“We assign permissions individually.”

“Permissions automatically follow the role.”

 

This shift in perspective has practical implications. Those who view identity management as a data issue start with the fundamentals: unique identities, clean organizational structures, and a central, leading system. This is precisely the domain of master data management—and the reason why Goldright’s Organizational Data Manager and Identity Manager are so closely intertwined.

Solution Approach: Six Steps to Clean Identity Management

Robust identity management isn’t achieved simply by purchasing software, but through a combination of a clean data foundation, clear processes, and automation. The following framework outlines the proven path.

Step 1 — Inventory Identity Sources

First, it must be clear where identity data resides: HR, Active Directory, ERP, cloud services. Which system is the primary source for which attribute? This inventory forms the foundation for any consolidation.

Step 2 — Create a Unique Identity as the Single Source of Truth

A unique, consolidated employee identity—a “golden record” for identities—is created for each person from the various sources. Duplicates are identified, inconsistencies are resolved, and a master data model is established. From this point on, there is exactly one reliable answer to the question of who a person is and what role they hold.

Step 3 — Define the Role Model and Authorization Logic

A role model (RBAC) is established based on clean organizational data: Which role requires which access rights? Authorizations are no longer granted individually but rather based on rules via roles—following the principle of least privilege.

Step 4 — Automate the Lifecycle (Joiner-Mover-Leaver)

Onboarding, role changes, and offboarding are automatically linked to the database. If a role changes in the leading system, permissions are automatically adjusted—including immediate deactivation upon departure.

Step 5 — Integrate Provisioning with Target Systems

The calculated access rights are provisioned to target systems via configurable, bidirectional interfaces—from OneDrive and SharePoint to line-of-business applications and licenses. Approval occurs via defined workflows. Even temporary or additional permissions—such as for substitutes—can be granted in a controlled manner and expire automatically.

Step 6 — Logging, Monitoring, and Recertification

Every change is stored with a timestamp in an audit-proof manner. Regular access reviews and recertifications ensure that permissions remain up to date—and provide complete documentation for any audit.

Where does your identity database stand?

The first step is to clearly assess your current situation: Through direct discussion, we’ll evaluate your starting point and identify where the greatest opportunities for improvement lie.

Best Practices for Effective Identity Management

Six principles can be derived from successful identity projects that distinguish between true control and a false sense of security.

1. Consistently Implement Least Privilege

Each identity is granted only the permissions that are strictly necessary for its role. The principle of least privilege drastically reduces the attack surface and forms the foundation of any zero-trust architecture. When in doubt, it’s better to grant too few privileges and add them selectively later than to grant too many across the board.

2. Automate the Offboarding Process

Offboarding is the most frequently neglected process—and the most dangerous. The automatic, immediate deactivation of all access upon departure prevents orphaned accounts and protects against data leaks by former employees. Instead of deleting accounts, it’s recommended to deactivate them while retaining the full access history: This preserves traceability for audits while immediately terminating access.

3. Roles Instead of Individual Permissions

A clean, well-maintained role model makes permissions verifiable and automatable. Individually assigned permissions, on the other hand, grow into an unmanageable tangle that turns every recertification into a guessing game.

4. Regular Access Reviews

Access permissions are not permanent. Periodic recertifications—on a quarterly basis for critical systems—ensure that no one has more access than they currently need. They are also at the heart of any compliance documentation requirement.

5. Consider Internal and External Identities Together

Service providers, partners, and temporary staff pose a particularly high risk because their access rights are often poorly managed. Effective identity management encompasses both internal and external employee identities equally—including temporary access rights.

6. Ensuring Data Quality as the Foundation

No role model or automation is better than the underlying master data. Ensuring the quality of employee and organizational data lays the actual foundation for secure identity management.

Practical Example: Automated User Management in a Corporate Group

The following case study has been anonymized for data protection reasons and is based on a real project.

Initial Situation

An international company with approximately 2,000 internal and external employees managed access rights largely manually. Onboarding took several days on average, during which new employees were unable to work. During offboarding, accounts regularly remained active—an internal audit uncovered several hundred orphaned accounts, some of which had extensive permissions.

Challenge

The root cause was not the access control system itself, but the data landscape: employee data was maintained inconsistently across HR, Active Directory, and several line-of-business systems. There was no single, authoritative identity and no consistent role model. Every audit turned into a manual reconciliation process lasting weeks.

Particularly problematic: There was no structured process at all for external employees. They were manually created at the start of a project and simply forgotten at the end. This is precisely where the orphaned accounts with the most extensive permissions accumulated.

Approach

Using the Identity Manager, a unique employee identity was established for each person as the single source of truth. Based on clean organizational data, a role model was created that automatically calculates permissions. Onboarding, role changes, and offboarding were integrated with the target systems via bidirectional interfaces.

Result

  • Onboarding time: reduced from several days to Day 1 — access granted from the first day of work

  • Orphaned accounts: virtually eliminated through automatic deactivation upon departure

  • Audit effort: reduced from weeks to hours thanks to audit-proof logging

  • Manual authorization assignment: drastically reduced through the rule-based role model

Lessons from the case: The security gains did not come from a new access tool, but from a clean, unambiguous identity database and its automation.

Pitfalls: What Often Goes Wrong in Identity Management Projects

Identity projects rarely fail because of the technology—they usually fail due to avoidable organizational mistakes. These are the most common pitfalls.

  • Neglecting offboarding: Orphaned accounts are one of the biggest—and most underestimated—security risks.

  • Tool over database: An IAM system built on inaccurate identity data simply automates errors more quickly.

  • No role-based model: Permissions granted on an individual basis cannot be reviewed or recertified.

  • Ignoring privilege creep: If old permissions aren’t revoked during role changes, dangerous over-privileges accumulate.

  • Forgetting external identities: Service providers and partners are often managed less effectively than in-house employees—and pose a particularly high risk.

  • No audit trail: Without audit-proof documentation, regulatory compliance under the GDPR and NIS2 cannot be demonstrated.

Identity Management as the Foundation of Zero Trust

Hardly any security concept shapes the current discussion as much as Zero Trust. The basic principle: No identity is trusted by default—every single access attempt is verified, regardless of whether it comes from the internal network or from outside. The former principle of “safe on the inside, dangerous on the outside” is thus obsolete.

However, Zero Trust only works with reliable identity management. If every access attempt is to be continuously evaluated based on identity, role, and context, this information must be accurate at all times. An inconsistent or outdated identity database undermines any Zero Trust model—because verification is then based on incorrect assumptions.

This brings us full circle: Zero Trust is not a product you buy, but an architecture built on clean identity data. Anyone who invests in Zero Trust without first getting their identity management in order is building on shaky ground.

Do you know which of your accounts are orphaned?

Most companies don’t know how many active accounts without active employees exist in their systems. In a joint discussion, we can determine:

  • Where your biggest identity risks lie

  • How secure your joiner, mover, and leaver processes are

  • What the next logical step is

Conclusion: Identity Management Is a Matter of Data Quality

The core message of this article can be summarized in one sentence: Identity management is the central security discipline—and its effectiveness depends on the quality of identity data.

Stolen credentials are one of the most common attack vectors, data breaches cost millions, and regulations require verifiable controls. Those who respond by constantly introducing new access tools are merely treating the symptoms. The sustainable solution lies in the foundation: unique identities, a clean role model, an automated identity lifecycle, and audit-proof historical logging.

This is exactly where Goldright excels. As a provider of multidimensional master data management, the Identity Manager establishes a single, reliable source of truth for every employee identity—and makes user management automatable, auditable, and secure. The first step is a clear assessment of the current situation.

Frequently asked Questions about Identity Management

Identity management is the centralized management of digital identities and their access rights throughout their entire lifecycle—from onboarding through role changes to offboarding. The goal is to ensure that each person has exactly the permissions they need and that all access remains traceable and auditable at all times.
Identity management manages identities themselves—who exists, what role a person has, and what their status is. Access management controls specific access to systems and data. IAM combines both disciplines: identities and their access rights are managed centrally, based on rules, and throughout their entire lifecycle.
IAM controls access (who is allowed to log in and how). Identity Governance and Administration (IGA) complements the governance layer: access reviews, recertification, and verification that permissions comply with policies. IGA ensures that access not only works but is also verifiably correct.
PAM protects privileged accounts with extensive permissions—such as administrator or service accounts. Since these accounts are particularly attractive to attackers, PAM secures them using password vaults, session control, and additional authorizations. PAM complements identity management for the most critical access points.
The identity lifecycle describes the life cycle of an identity in three phases: Joiner (onboarding, access from Day 1), Mover (role change, adjustment of permissions), and Leaver (departure, immediate deactivation). Errors in this cycle—such as forgotten deactivations—are the most common cause of security vulnerabilities.
Orphaned accounts are active user accounts that no longer correspond to an active employee—typically as a result of improper offboarding. They serve as unmonitored entry points for attackers and are a key audit criterion in any identity audit.
Because identity is the new perimeter. According to the Verizon DBIR 2026, stolen login credentials are one of the most common initial attack vectors. Failing to properly manage identities and permissions opens the easiest door into the company for attackers.
Zero Trust assumes that no identity is trusted by default—every access attempt is verified. This only works with a reliable identity management system that knows at all times who an identity is and what role they have. Accurate identity data is therefore a prerequisite for Zero Trust.
Both the GDPR and the NIS2 Directive require controlled access and traceable processes. An identity management system with audit-proof logging provides the required evidence of who had which permissions and when—and thus becomes a regulatory requirement.
Every digital identity is based on user and organizational master data. If this data is incorrect or inconsistent, permissions will also be assigned incorrectly. Clean identity management therefore begins with clean master data—the domain of master data management.
Yes. If user management is linked to a single, authoritative identity database and a role model, onboarding, role changes, and offboarding can be fully automated. This reduces errors, speeds up processes, and ensures complete documentation for audits.
Traditional IAM providers focus on access control. Goldright starts one level deeper: at the foundation of identity data. The Identity Manager creates unique employee identities as a single source of truth—the clean database on which IAM, IGA, and PAM can function reliably in the first place.

Sources

Verizon: "2026 Data Breach Investigations Report" - https://www.verizon.com/business/resources/reports/dbir/

IBM: "Cost of a Data Breach Report 2026" - https://www.ibm.com/reports/data-breach

Bitkom e.V.: "Wirtschaftsschutz 2025" - https://www.bitkom.org/Bitkom/Publikationen/Wirtschaftsschutz

Gartner: "Identity Governance and Administration (IGA), Market/Reviews" - https://www.gartner.com/reviews/market/identity-governance-administration

Gartner: "Identity and Access Management (IAM), Glossary-Definition" - https://www.gartner.com/en/information-technology/glossary/identity-and-access-management-iam

NIST: "SP 800-63 Digital Identity Guidelines" - https://pages.nist.gov/800-63-3/

Europäische Kommission: NIS2, Regulation (EU) 2022/2555 - https://eur-lex.europa.eu/eli/dir/2022/2555/oj

Europäische Kommission: DSGVO, Regulation (EU) 2016/679 - https://eur-lex.europa.eu/eli/reg/2016/679/oj