Identity and Access Management (IAM) is a conceptual framework for centralized management of digital identities, authentication and access controls. It defines processes, roles, policies and technical mechanisms for provisioning, single sign-on, authorization and auditing to ensure security and compliance across distributed IT landscapes.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What you need to understand to reason about a domain.
Identity and access management (IAM) controls which digital identities authenticate and what resources they may use.
IAM connects identity administration with security and organizational processes. It covers the identity lifecycle, policies, roles, and technical enforcement.
Think in four steps: create identity, authenticate sign-in, authorize access by policy, then log use and revoke privileges when responsibility changes. Roles express need; policies decide; enforcement points apply the decision.
A person or service receives a managed digital representation with verifiable attributes.
A method checks whether a requester belongs to that identity.
Policies and roles determine which action is allowed on which resource.
Creation, change, review, and revocation keep privileges aligned with responsibility.
IAM underpins zero-trust architectures, cloud operations, and compliance. Pay attention to privileged access, separation of duties, service identities, logging, and timely offboarding.
Where this building block is located in the topic model.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.