What is Identity and Access Management (IAM)?
Identity and access management (IAM) is the set of governance rules, processes, and technologies used to establish digital identities and control their access to resources. It covers account and authenticator lifecycle, authentication, authorization, provisioning, access review, revocation, and audit. IAM applies to people, services, workloads, and devices. Authentication establishes confidence in an identity; authorization decides what that identity can do.
Why it matters
An organization must change access when a person joins, changes roles, or leaves, and when a workload or device changes state. A managed identity lifecycle reduces stale accounts, excessive access, and weak audit records.
How it works
- Establish an identity record, bind approved authenticators, and maintain the attributes needed for access decisions.
- Authenticate the principal, then evaluate authorization policy for the requested resource and action.
- Update, review, suspend, and remove access as identity state changes, and retain useful audit records.
Example
An engineer moves from the support team to the platform team. The identity system removes the old group, adds the new group, and the access layer uses the current group data for the next request.
Pomerium boundary
Pomerium is an identity-aware access proxy, not a complete IAM system or identity provider. It authenticates users through an OIDC-compatible identity provider and applies identity and context policy to protected routes. The external identity system remains responsible for account, group, and authenticator lifecycle.
Limits and non-claims
- IAM does not make identity data accurate or current without a controlled lifecycle and trusted data sources.
- Successful authentication does not authorize every resource or action.
- A central identity service can affect many applications, so its administration, recovery, and availability need strong controls.
Evaluation checklist
- Which people, services, workloads, devices, agents, accounts, and authenticators are in scope?
- How do authentication, authorization, provisioning, sessions, and evidence protect each resource action?
- Do joiner, mover, leaver, recovery, and emergency processes remove obsolete authority?
