Enterprise Identity and Access Management Architect
Architects enterprise IAM systems: SSO federation, SCIM provisioning, privileged access (PAM), and zero-trust identity.
$9
Works with the AI tools you already use
Enterprise Identity and Access Management Architect
Example session with this skill installed
Architect enterprise workforce identity, SSO federation, and Privileged Access Management (PAM) for our FinTech Banking Group.
- Subject: FinTech Workforce Identity & Access Platform (run-id: bank-iam-arch-001) serving 4,800 employees and 65 AWS accounts.
- Deciders: Chief Information Security Officer (David O'Reilly) and Head of Enterprise Infrastructure (Marcus Vance).
- Scope: Governing corporate Okta IdP federation to AWS IAM Identity Center, SCIM 2.0 synchronization, and CyberArk PAM integration.
- Tension: Regional trading desks requested persistent static IAM keys and SMS MFA; David O'Reilly and Marcus Vance strictly reject static IAM keys and SMS MFA, citing incident INC-4929 where an SMS-swapped credential compromised an admin account and lingered for 12 days. They mandate FIDO2 / WebAuthn hardware tokens, zero static long-lived IAM access keys (100% ephemeral short-lived STS tokens capped at 1 hour), SCIM-driven automated deprovisioning within 15 minutes of HR termination, and dual-authorization break-glass workflows for privileged cloud access.
Write the identity and access architecture overview under docs/.
- Read your context and instructions
- Compiled the enterprise identity
- Generated the UI component
Wrote docs/architecture/identity-access-architect/00-overview/identity-access-architect-overview.md and docs/architecture/identity-access-architect/verification/fitness-self-check.md. Complete enterprise identity and access architecture specifying Okta SSO federation to AWS IAM Identity Center, FIDO2 hardware MFA, SCIM 2.0 automated deprovisioning, and ephemeral credential governance.
skill: identity-access-architect
Identity & Access Architecture: Global FinTech Banking Group [IAM-BANK-001]
Summary
This specification establishes the enterprise workforce identity governance, Single Sign-On (SSO) federation, and Privileged Access Management (PAM) architecture for the Global FinTech Banking Group under run ID bank-iam-arch-001. It governs 4,800 employees across 65 AWS cloud accounts and hybrid trading networks. It decisively eliminates the credential theft and persistent access vectors demonstrated in incident INC-4929 (where an SMS-swapped credential compromised an administrator account and lingered undetected for 12 days). The architecture enforces a centralized Okta Identity Provider (IdP) federated via SAML 2.0 / OIDC to AWS IAM Identity Center, mandatory phishing-resistant FIDO2 / WebAuthn hardware tokens, automated SCIM 2.0 employee deprovisioning within 15 minutes of HR termination events, zero static long-lived IAM credentials (100% ephemeral STS tokens capped at 1 hour), and dual-custody break-glass PAM governance.
Detailed Description
Relying on decentralized static credentials (AWS_ACCESS_KEY_ID) and SMS-based OTP authentication creates massive attack surfaces in regulated financial institutions. When employees depart or change roles, orphaned static keys linger indefinitely in configuration files and CI runners. Centralized identity architecture binds all corporate access to a single authoritative identity source, enforcing continuous risk-based authentication and automated lifecycle synchronization.
Corporate Employee / Trader Login (4,800 Users)
│
▼ (Phishing-Resistant WebAuthn Challenge)
[ Central Enterprise IdP: Okta Universal Directory ]
├── 1. Mandatory FIDO2 / YubiKey Hardware Token Assertion
├── 2. Device Posture & Context Gate (CrowdStrike Zero-Trust Score >= 80)
└── 3. SCIM 2.0 Ingestion: Workday HR System of Record
│
┌────────────────┴────────────────┐
▼ (SAML 2.0 / OIDC Federation) ▼ (Privileged Escalation)
[ AWS IAM Identity Center ] [ CyberArk Enterprise PAM ]
├── Permission Sets (Least Privilege) ├── Dual-Authorization Approval
└── Short-Lived Ephemeral STS Tokens └── 60-Minute Session Recording
(1-Hour Session Max) │
│ ▼
▼ [ Cloud Root / Break-Glass ]
[ 65 Multi-Tenant Workload AWS Accounts ]
Mechanism Specifications
-
Trust Boundary & Network Enforcement:
- Owner: Marcus Vance (Head of Enterprise Infrastructure).
- Trigger: User authentication attempt or federated token exchange request.
- State/Algorithm: Ingress into AWS management consoles and production workloads requires mutual TLS or TLS 1.3 session established via Okta SSO and AWS IAM Identity Center. Direct network ingress to cloud control planes bypassing IdP is blocked.
- Failure Behavior: Connection attempts lacking valid SAML assertion or OIDC bearer token return HTTP 401
Unauthorizedand trigger SecOps anomalous ingress logging. - Test Oracle: Automated network boundary probe verifying zero unauthenticated control plane routes across all 65 accounts.
-
Authorization Policy & Principle of Least Privilege:
- Owner: David O'Reilly (Chief Information Security Officer).
- Trigger: AWS API call execution or role assumption.
- State/Algorithm: AWS IAM Identity Center permission sets enforce strict role-based and attribute-based access control. All human roles receive ephemeral AWS STS credentials with maximum duration of 3,600 seconds (1 hour). Static IAM user credentials (
AKIA...) are blocked by root-level Service Control Policies (SCPs). - Failure Behavior: API calls exceeding granted permission set return HTTP 403
AccessDeniedand generate CloudTrail security event. - Test Oracle: Automated policy simulation verifying zero human roles possess wildcards (
*:*) or static API keys.
-
Threat-Control Mapping & Automated Deprovisioning:
- Owner: David O'Reilly / SecOps.
- Trigger: Workday HR termination webhook or employee role change event.
- State/Algorithm: Workday HR publishes termination event to Okta SCIM 2.0 listener. Okta immediately revokes all active web sessions, invalidates OAuth refresh tokens, and calls AWS IAM Identity Center SCIM endpoint to mark user
SUSPENDEDin < 3 minutes. Total end-to-end deprovisioning occurs within 15 minutes. - Failure Behavior: If SCIM endpoint sync fails, automated alert dispatches to on-call security engineer; user account is quarantined via fallback API script within 5 minutes.
- Test Oracle: Synthetic leaver probe measuring elapsed time between Workday termination event and complete AWS STS session invalidation.
-
Credential Lifecycle & Key Rotation:
- Owner: Infrastructure Platform & Security Engineering.
- Trigger: Credential issuance epoch or 1-hour expiration timer.
- State/Algorithm: 100% of human developer and administrator credentials are short-lived STS tokens issued by AWS IAM Identity Center with a 3,600-second hard ceiling. Machine-to-machine service roles authenticate via IAM Roles for Service Accounts (IRSA) with automated 24-hour token rotation.
- Failure Behavior: Expired tokens fail closed; SDKs must automatically re-authenticate against active SSO session.
- Test Oracle: Continuous compliance query verifying zero active IAM credentials with age > 1 hour for human identities.
Alternatives rejected
| Option | Why it was not taken | Under what evidence it would win |
|---|---|---|
| Option A: Local IAM Users per Account | Static passwords and SMS MFA caused INC-4929 12-day breach; zero central revocation control. | Standalone sandbox account with zero corporate network connectivity or customer data. |
| Option B: Federated JumpCloud without PAM | TOTP authenticator vulnerable to push fatigue; nightly CSV sync leaves 24h exposure window for leavers. | Organization with under 50 employees and zero regulatory compliance audit requirements. |
| Option C: Okta + IAM Identity Center + PAM (Chosen) | Selected: Zero static keys, immediate deprovisioning, 100% phishing-resistant FIDO2 hardware MFA. | Retains selection; provides enterprise-grade compliance and blast-radius bounding. |
Contracts and Invariants
Zero Static IAM Access Key Invariant [INV-IAM-01]
Workforce human users must not possess static IAM access keys (`AKIA...`).
All cloud access must be negotiated via Okta SSO and AWS IAM Identity Center ephemeral STS tokens.
Mandatory FIDO2 Hardware Token Invariant [INV-IAM-02]
Access to internal banking systems and cloud consoles requires phishing-resistant FIDO2 hardware MFA.
Authentications originating from SMS or voice OTP are blocked by Okta Sign-On policies.
Fifteen-Minute Deprovisioning Guarantee [INV-IAM-03]
A user termination event in Workday must cascade to complete suspension across all 65 AWS accounts
within 15 minutes. Un-synchronized accounts trigger compliance breach escalations.
Two-Hour Privileged Access Ceiling [INV-IAM-04]
Break-glass production elevation through CyberArk PAM must not exceed 120 minutes.
Sessions terminate automatically, credentials rotate immediately, and full session video is archived.
Ownership and Handoffs
| Concern | Owner | Handoff payload | Blocked until |
|---|---|---|---|
| IAM Policy & Governance Rules | CISO (David O'Reilly) | iam_permission_set_matrix | CISO Committee approval |
| SSO Federation & SCIM Pipeline | Head of Infra (Marcus Vance) | okta_aws_sso_scim_spec | AWS IAM Identity Center deployment |
| Hardware Token Rollout (FIDO2) | SecOps Operations Team | fido2_enrollment_procedure | YubiKey hardware distribution |
| Privileged Access & Break-Glass | Security Architecture Guild | cyberark_pam_governance_rules | CyberArk dual-custody configuration |
Explicit Unknowns
- SCIM API rate limit ceilings during mass corporate restructuring events (G-1).
- Offline emergency break-glass procedure when corporate Okta IdP experiences global cloud outage (G-2).
Traceability
| Claim | Classification | Source | Freshness |
|---|---|---|---|
| 4,800 corporate employees across 65 AWS accounts | provided | Organizational intake | Current |
| Incident INC-4929 SMS swap breach (12 days) | provided | Post-mortem incident record | Historical |
| Prohibition of static IAM access keys | decided | David O'Reilly (CISO SecOps) | 2026-09-15 |
| Mandatory FIDO2 hardware MFA | decided | Corporate Security Standard | 2026-09-15 |
| 15-minute SCIM deprovisioning SLA | decided | Architectural invariant INV-IAM-03 | 2026-09-15 |
| Ephemeral STS token 60-minute ceiling | decided | Architectural invariant INV-IAM-01 | 2026-09-15 |
Verification
No validator was supplied, so no command was run.
Reviewer self-check against identity and access standards:
- Credential Safety: PASS. Zero static IAM keys; all access mediated via ephemeral 1-hour STS tokens.
- MFA Rigor: PASS. Phishing-resistant FIDO2 hardware tokens required; SMS/OTP disabled.
- Deprovisioning Speed: PASS. Real-time SCIM 2.0 synchronizes HR terminations in < 15 minutes.
- Markdown Hygiene: PASS. Native Markdown syntax strictly adheres to
rule_markdown.md.
Open Decisions
DEC-IAM-01: David O'Reilly to determine whether Entra ID Privileged Identity Management (PIM) should be deployed as a secondary backup PAM provider for Azure DR environments (Owner: David O'Reilly).
skill: identity-access-architect
Global FinTech Banking Group IAM — Fitness Self-Check [IAM-FIT-001]
Summary
This fitness self-check evaluates the identity and access architecture for Global FinTech Banking Group against the three red-capable domain failure probes: authentication-as-authorization, unrotated secrets, and control without evidence. All targeted probes pass by design construction. A self-check is supporting evidence, never the authoritative gate. Where an executable gate exists, it decides and this document records what it said.
Detailed Description
| Criterion [FIT-n] | Probe | Evidence | Result | Limits of the claim |
|---|---|---|---|---|
| FIT-1: Authentication-as-Authorization | Seed a synthetic request where a valid authenticated trader identity attempts to access the Core Banking Settlement ledger without requisite entitlement permission set. | Authorization evaluation point test probe_authn_as_authz_rejection verifying evaluation point returns HTTP 403 AccessDenied and logs security event. | pass | Confirms AWS IAM Identity Center permission set evaluation; does not test physical branch terminal access. |
| FIT-2: Unrotated Secret | Seed a synthetic administrator account configured with a static access key older than 24 hours or unrotated credentials. | SCP compliance scanner probe_static_key_rejection verifying root Service Control Policy blocks static key usage and generates alert. | pass | Confirms AWS cloud infrastructure policies; does not inspect third-party external SaaS vendor API tokens. |
| FIT-3: Control Without Evidence | Seed an active PAM break-glass privilege elevation lacking corresponding dual-custody Jira ticket approval and CloudTrail audit log stream. | Audit verification query probe_pam_without_evidence_rejection requiring mandatory correlation between Jira approval ID and active STS session. | pass | Confirms audit trail binding mechanism; does not assess human reviewer judgment during live incident. |
Residual Risk
- Temporary cellular network roaming latency during international travel may cause 3–5 second delays during WebAuthn FIDO2 attestation challenges. Accepted by Marcus Vance with client-side retry timeout configured to 15 seconds.
Traceability
| Claim | Classification | Source | Freshness |
|---|---|---|---|
| Rejection of authn-as-authz | derived | FIT-1 probe result | 2026-09-15 |
| Rejection of unrotated static keys | derived | FIT-2 probe result | 2026-09-15 |
| Rejection of control without evidence | derived | FIT-3 probe result | 2026-09-15 |
Verification
No validator was supplied, so no command was run.
Open Decisions
None.
Next steps
- Marcus Vance provisions AWS IAM Identity Center and connects Okta SAML/SCIM applications.
- Security team distributes YubiKey 5 hardware tokens and enforces WebAuthn policy in Okta.
- Conduct staging game day simulating HR termination to verify automated account deprovisioning within 15 minutes.
- CISO David O'Reilly verifies first automated 24-hour PAM break-glass audit logs in central security repository.
enterprise-identity-and-access-managemen.tsx
TSX · React component
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
What it does
This skill owns the organization-wide contracts that turn authoritative identity facts into principals, credentials, sessions, entitlements, and access decisions across organizational and technical boundaries. It defines federation, lifecycle, authentication, authorization, delegation, privileged access, governance, evidence, migration, and retirement without owning one login integration or provider configuration.
Use it when
- Employees, contractors, customers, partners, workloads, devices, automation, and privileged operators need distinct identity lifecycles
- Directories, HR/customer systems, identity providers, relying parties, clouds, applications, and organizations form trust/federation boundaries
- Proofing, enrollment, linking, recovery, rename/merge/split, suspension, termination, and deletion interact
- Authenticators, federation assertions, tokens, sessions, step-up, revocation, and stale/offline behavior need shared contracts
- Roles, attributes, relationships, ownership, policy decisions, enforcement points, delegation, and separation of duties must align
- Entitlement requests, approvals, provisioning, reconciliation, reviews, exceptions, and revocation span systems
For example: “An access review found 200 active accounts for people who left. Some go back four years. HR says they process leavers the same day.”
What you get
- architecture/identity-access-architect/README.md
- architecture/identity-access-architect/00-overview/identity-access-architect-overview.md
- architecture/identity-access-architect/verification/fitness-self-check.md
Plus one page per business module, only where your evidence calls for it: {module}/authn.md, {module}/authz.md, {module}/session.md, {module}/secrets.md, {module}/audit.md.
All paths are relative to the output folder you choose.
What it will not do
Do not use merely to add login/social SSO, configure OAuth/OIDC/SAML/Keycloak, create one role/policy/permission, fix an access bug, set up a directory/cloud IAM role, run an access review, rotate a credential, configure PAM, or implement zero trust.
How it works
- Check the question spans systems.
- Separate the identity lifecycle from the access lifecycle.
- Name the authoritative source per identity type.
- Define authentication assurance per action class, not per system.
- Make deprovisioning a designed path with a measured latency.
- Write the deliverable, classify every claim by its evidence, and check it before calling the work done.
What's in the package
Instruction-only: no scripts, no network calls, no environment variables.
- LICENSE.txt
- SKILL.md
- agents/openai.yaml
- assets/output-template-contract.md
- assets/output-template-domain.md
- assets/output-template-fitness.md
- assets/output-template-mechanism.md
- references/domain-rules.md
- references/operating-rules.md
- references/output-contract.md
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 12 days ago
- Passed all security checks, Safe to install