ITSM
Operates joiner/mover/leaver, request, approval, provisioning, change, incident, remediation, vendor, and lifecycle work.
Explore ITSM →ThreatKrusher Pillar 04 · Identity and controlled authority
ThreatKrusher Access governs human, administrator, contractor, service, workload, application, and AI-agent identities across authentication, authorization, privilege, lifecycle, review, exception, and revocation.
Supported identity platforms, systems, users, authentication methods, privileged-access functions, lifecycle workflows, review cadence, monitoring, and exclusions must match the current executed agreement and implementation.
The access problem
Access risk accumulates when identity sources, approvals, roles, privilege, service accounts, external users, applications, and offboarding are managed as separate technical tasks.
Scope boundary
Access governance system
Person or system, owner, sponsor, role, status, purpose, organization, sensitivity, and lifecycle source.
Approved factors, device and location context, session conditions, recovery, enrollment, exceptions, and signals.
Role, resource, entitlement, data, operation, condition, environment, business need, approval, and duration.
Named administrators, dedicated identities, just-in-time or time-bound access, approvals, monitoring, emergency use, and review.
Owner, purpose, workload, secret or credential, permission, rotation, dependency, activity, expiry, and revocation.
Access certification, exception, stale-account action, risky-event response, remediation, revocation, evidence, and next review.
Conceptual capability model. Exact platforms, methods, automation, integrations, authentication strength, privileged controls, and review cadence require current technical and contractual evidence.
People · process · system
Executive, manager, HR or worker source, sponsor, data owner, system owner, access approver, identity administrator, security reviewer, service owner, vendor, and eTrepid roles remain distinct.
Request, verify, approve, provision, authenticate, authorize, elevate, monitor, review, change, suspend, recover, revoke, validate, and preserve evidence through defined workflows.
Authoritative identity source, directory, identity provider, devices, applications, cloud, privileged tooling, secrets, service desk, monitoring, logging, automation, and evidence systems exchange bounded records.
Identity and access lifecycle
Capture identity, sponsor, resource, business purpose, role, data, entitlement, duration, and urgency.
Confirm identity, worker or service status, authoritative facts, eligibility, conflicts, and request integrity.
Obtain accountable owner approval, apply role and separation rules, and document exception or risk decisions.
Create or update the identity, factors, groups, roles, privileges, conditions, expiry, and supporting records.
Revalidate status, need, use, ownership, privilege, risk, exceptions, inactivity, and anomalous conditions.
Remove access, terminate sessions, rotate secrets, recover assets, preserve records, validate closure, and address dependencies.
Evidence produced
Type, source, owner, sponsor, role, status, purpose, systems, start, change, end, and review dates.
Request, business need, resource, entitlement, approver, rules, conflicts, exception, duration, and conditions.
Account, factors, groups, roles, privilege, configuration, administrator, system result, validation, and timestamp.
Population, scope, reviewer, decision, stale or risky access, remediation, revocation, residual exception, and next review.
Access records support evaluation; they do not independently prove that every entitlement is appropriate, every identity is legitimate, or misuse cannot occur.
Responsibility boundary
Critical dependencies
Operates joiner/mover/leaver, request, approval, provisioning, change, incident, remediation, vendor, and lifecycle work.
Explore ITSM →Monitors authentication, risky identity conditions, privilege activity, anomalies, incidents, and validation evidence.
Explore Trust →Connects identity obligations, policies, control owners, review requirements, exceptions, evidence, and risk decisions.
Explore Comply →Cloud supplies tenant and application controls; Command extends Access to AI-agent identity and authority; Continuity governs emergency access and recovery dependencies within scope.
Identity proof gate
Public proof should use approved, redacted joiner/mover/leaver records, MFA or conditional-access evidence, privileged-access records, service-account governance, access reviews, revocation validation, or metrics with defined scope and limitations.
No current supported-platform list, MFA coverage, privileged-access capability, lifecycle target, access-review result, service-account metric, or client outcome is approved for this page. Reconcile service schedules, tenant configuration, platform records, workflow definitions, measurement sources, and delivery ownership first.
Any zero-trust, passwordless, phishing-resistant, privileged-access, full-coverage, automated-provisioning, or rapid-offboarding claim requires exact current evidence and scope.
Common questions
MFA can materially strengthen authentication, but access governance also depends on identity source, enrollment and recovery, factor strength, session controls, authorization, privilege, device and location context, monitoring, exceptions, and timely revocation.
eTrepid can operate approved workflows and perform technical administration within scope. The client’s accountable resource, data, system, or business owner must authorize business need and risk unless a documented delegation expressly says otherwise.
They require the same core principles—identity, owner, purpose, least privilege, authorization, monitoring, review, and revocation—but their credentials, workload context, rotation, dependencies, actions, and failure modes need specialized controls.
No. It means access decisions should not rely solely on network location or a one-time implicit trust assumption. Identity, device, context, resource, policy, risk, and session conditions are evaluated according to the implemented architecture.
Identity and access briefing
Provide only non-sensitive context about identity platforms, user and non-human identity types, applications, current ownership, business trigger, recurring pain, and desired operating model.
Do not submit credentials, recovery codes, personal data, CUI, access lists, privileged-account names, service-account secrets, security findings, logs, or confidential architecture through a public form.