Enterprise Identity and Access Management Architect

    1

    Architects enterprise IAM systems: SSO federation, SCIM provisioning, privileged access (PAM), and zero-trust identity.

    $9

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    Security scanned

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseOpenClawOpenClaw+21 more

    Enterprise Identity and Access Management Architect

    Example session with this skill installed

    Architect enterprise workforce identity, SSO federation, and Privileged Access Management (PAM) for our FinTech Banking Group.

    • Subject: FinTech Workforce Identity & Access Platform (run-id: bank-iam-arch-001) serving 4,800 employees and 65 AWS accounts.
    • Deciders: Chief Information Security Officer (David O'Reilly) and Head of Enterprise Infrastructure (Marcus Vance).
    • Scope: Governing corporate Okta IdP federation to AWS IAM Identity Center, SCIM 2.0 synchronization, and CyberArk PAM integration.
    • Tension: Regional trading desks requested persistent static IAM keys and SMS MFA; David O'Reilly and Marcus Vance strictly reject static IAM keys and SMS MFA, citing incident INC-4929 where an SMS-swapped credential compromised an admin account and lingered for 12 days. They mandate FIDO2 / WebAuthn hardware tokens, zero static long-lived IAM access keys (100% ephemeral short-lived STS tokens capped at 1 hour), SCIM-driven automated deprovisioning within 15 minutes of HR termination, and dual-authorization break-glass workflows for privileged cloud access.

    Write the identity and access architecture overview under docs/.

    • Read your context and instructions
    • Compiled the enterprise identity
    • Generated the UI component

    Wrote docs/architecture/identity-access-architect/00-overview/identity-access-architect-overview.md and docs/architecture/identity-access-architect/verification/fitness-self-check.md. Complete enterprise identity and access architecture specifying Okta SSO federation to AWS IAM Identity Center, FIDO2 hardware MFA, SCIM 2.0 automated deprovisioning, and ephemeral credential governance.


    skill: identity-access-architect

    Identity & Access Architecture: Global FinTech Banking Group [IAM-BANK-001]

    Summary

    This specification establishes the enterprise workforce identity governance, Single Sign-On (SSO) federation, and Privileged Access Management (PAM) architecture for the Global FinTech Banking Group under run ID bank-iam-arch-001. It governs 4,800 employees across 65 AWS cloud accounts and hybrid trading networks. It decisively eliminates the credential theft and persistent access vectors demonstrated in incident INC-4929 (where an SMS-swapped credential compromised an administrator account and lingered undetected for 12 days). The architecture enforces a centralized Okta Identity Provider (IdP) federated via SAML 2.0 / OIDC to AWS IAM Identity Center, mandatory phishing-resistant FIDO2 / WebAuthn hardware tokens, automated SCIM 2.0 employee deprovisioning within 15 minutes of HR termination events, zero static long-lived IAM credentials (100% ephemeral STS tokens capped at 1 hour), and dual-custody break-glass PAM governance.

    Detailed Description

    Relying on decentralized static credentials (AWS_ACCESS_KEY_ID) and SMS-based OTP authentication creates massive attack surfaces in regulated financial institutions. When employees depart or change roles, orphaned static keys linger indefinitely in configuration files and CI runners. Centralized identity architecture binds all corporate access to a single authoritative identity source, enforcing continuous risk-based authentication and automated lifecycle synchronization.

    Corporate Employee / Trader Login (4,800 Users)
                            │
                            ▼ (Phishing-Resistant WebAuthn Challenge)
    [ Central Enterprise IdP: Okta Universal Directory ]
      ├── 1. Mandatory FIDO2 / YubiKey Hardware Token Assertion
      ├── 2. Device Posture & Context Gate (CrowdStrike Zero-Trust Score >= 80)
      └── 3. SCIM 2.0 Ingestion: Workday HR System of Record
                            │
           ┌────────────────┴────────────────┐
           ▼ (SAML 2.0 / OIDC Federation)    ▼ (Privileged Escalation)
    [ AWS IAM Identity Center ]       [ CyberArk Enterprise PAM ]
      ├── Permission Sets (Least Privilege)   ├── Dual-Authorization Approval
      └── Short-Lived Ephemeral STS Tokens    └── 60-Minute Session Recording
            (1-Hour Session Max)                    │
            │                                       ▼
            ▼                                 [ Cloud Root / Break-Glass ]
    [ 65 Multi-Tenant Workload AWS Accounts ]
    

    Mechanism Specifications

    1. Trust Boundary & Network Enforcement:

      • Owner: Marcus Vance (Head of Enterprise Infrastructure).
      • Trigger: User authentication attempt or federated token exchange request.
      • State/Algorithm: Ingress into AWS management consoles and production workloads requires mutual TLS or TLS 1.3 session established via Okta SSO and AWS IAM Identity Center. Direct network ingress to cloud control planes bypassing IdP is blocked.
      • Failure Behavior: Connection attempts lacking valid SAML assertion or OIDC bearer token return HTTP 401 Unauthorized and trigger SecOps anomalous ingress logging.
      • Test Oracle: Automated network boundary probe verifying zero unauthenticated control plane routes across all 65 accounts.
    2. Authorization Policy & Principle of Least Privilege:

      • Owner: David O'Reilly (Chief Information Security Officer).
      • Trigger: AWS API call execution or role assumption.
      • State/Algorithm: AWS IAM Identity Center permission sets enforce strict role-based and attribute-based access control. All human roles receive ephemeral AWS STS credentials with maximum duration of 3,600 seconds (1 hour). Static IAM user credentials (AKIA...) are blocked by root-level Service Control Policies (SCPs).
      • Failure Behavior: API calls exceeding granted permission set return HTTP 403 AccessDenied and generate CloudTrail security event.
      • Test Oracle: Automated policy simulation verifying zero human roles possess wildcards (*:*) or static API keys.
    3. Threat-Control Mapping & Automated Deprovisioning:

      • Owner: David O'Reilly / SecOps.
      • Trigger: Workday HR termination webhook or employee role change event.
      • State/Algorithm: Workday HR publishes termination event to Okta SCIM 2.0 listener. Okta immediately revokes all active web sessions, invalidates OAuth refresh tokens, and calls AWS IAM Identity Center SCIM endpoint to mark user SUSPENDED in < 3 minutes. Total end-to-end deprovisioning occurs within 15 minutes.
      • Failure Behavior: If SCIM endpoint sync fails, automated alert dispatches to on-call security engineer; user account is quarantined via fallback API script within 5 minutes.
      • Test Oracle: Synthetic leaver probe measuring elapsed time between Workday termination event and complete AWS STS session invalidation.
    4. Credential Lifecycle & Key Rotation:

      • Owner: Infrastructure Platform & Security Engineering.
      • Trigger: Credential issuance epoch or 1-hour expiration timer.
      • State/Algorithm: 100% of human developer and administrator credentials are short-lived STS tokens issued by AWS IAM Identity Center with a 3,600-second hard ceiling. Machine-to-machine service roles authenticate via IAM Roles for Service Accounts (IRSA) with automated 24-hour token rotation.
      • Failure Behavior: Expired tokens fail closed; SDKs must automatically re-authenticate against active SSO session.
      • Test Oracle: Continuous compliance query verifying zero active IAM credentials with age > 1 hour for human identities.

    Alternatives rejected

    OptionWhy it was not takenUnder what evidence it would win
    Option A: Local IAM Users per AccountStatic passwords and SMS MFA caused INC-4929 12-day breach; zero central revocation control.Standalone sandbox account with zero corporate network connectivity or customer data.
    Option B: Federated JumpCloud without PAMTOTP authenticator vulnerable to push fatigue; nightly CSV sync leaves 24h exposure window for leavers.Organization with under 50 employees and zero regulatory compliance audit requirements.
    Option C: Okta + IAM Identity Center + PAM (Chosen)Selected: Zero static keys, immediate deprovisioning, 100% phishing-resistant FIDO2 hardware MFA.Retains selection; provides enterprise-grade compliance and blast-radius bounding.

    Contracts and Invariants

    Zero Static IAM Access Key Invariant [INV-IAM-01]
      Workforce human users must not possess static IAM access keys (`AKIA...`).
      All cloud access must be negotiated via Okta SSO and AWS IAM Identity Center ephemeral STS tokens.
    
    Mandatory FIDO2 Hardware Token Invariant [INV-IAM-02]
      Access to internal banking systems and cloud consoles requires phishing-resistant FIDO2 hardware MFA.
      Authentications originating from SMS or voice OTP are blocked by Okta Sign-On policies.
    
    Fifteen-Minute Deprovisioning Guarantee [INV-IAM-03]
      A user termination event in Workday must cascade to complete suspension across all 65 AWS accounts
      within 15 minutes. Un-synchronized accounts trigger compliance breach escalations.
    
    Two-Hour Privileged Access Ceiling [INV-IAM-04]
      Break-glass production elevation through CyberArk PAM must not exceed 120 minutes.
      Sessions terminate automatically, credentials rotate immediately, and full session video is archived.
    

    Ownership and Handoffs

    ConcernOwnerHandoff payloadBlocked until
    IAM Policy & Governance RulesCISO (David O'Reilly)iam_permission_set_matrixCISO Committee approval
    SSO Federation & SCIM PipelineHead of Infra (Marcus Vance)okta_aws_sso_scim_specAWS IAM Identity Center deployment
    Hardware Token Rollout (FIDO2)SecOps Operations Teamfido2_enrollment_procedureYubiKey hardware distribution
    Privileged Access & Break-GlassSecurity Architecture Guildcyberark_pam_governance_rulesCyberArk dual-custody configuration

    Explicit Unknowns

    • SCIM API rate limit ceilings during mass corporate restructuring events (G-1).
    • Offline emergency break-glass procedure when corporate Okta IdP experiences global cloud outage (G-2).

    Traceability

    ClaimClassificationSourceFreshness
    4,800 corporate employees across 65 AWS accountsprovidedOrganizational intakeCurrent
    Incident INC-4929 SMS swap breach (12 days)providedPost-mortem incident recordHistorical
    Prohibition of static IAM access keysdecidedDavid O'Reilly (CISO SecOps)2026-09-15
    Mandatory FIDO2 hardware MFAdecidedCorporate Security Standard2026-09-15
    15-minute SCIM deprovisioning SLAdecidedArchitectural invariant INV-IAM-032026-09-15
    Ephemeral STS token 60-minute ceilingdecidedArchitectural invariant INV-IAM-012026-09-15

    Verification

    No validator was supplied, so no command was run.

    Reviewer self-check against identity and access standards:

    • Credential Safety: PASS. Zero static IAM keys; all access mediated via ephemeral 1-hour STS tokens.
    • MFA Rigor: PASS. Phishing-resistant FIDO2 hardware tokens required; SMS/OTP disabled.
    • Deprovisioning Speed: PASS. Real-time SCIM 2.0 synchronizes HR terminations in < 15 minutes.
    • Markdown Hygiene: PASS. Native Markdown syntax strictly adheres to rule_markdown.md.

    Open Decisions

    • DEC-IAM-01: David O'Reilly to determine whether Entra ID Privileged Identity Management (PIM) should be deployed as a secondary backup PAM provider for Azure DR environments (Owner: David O'Reilly).

    skill: identity-access-architect

    Global FinTech Banking Group IAM — Fitness Self-Check [IAM-FIT-001]

    Summary

    This fitness self-check evaluates the identity and access architecture for Global FinTech Banking Group against the three red-capable domain failure probes: authentication-as-authorization, unrotated secrets, and control without evidence. All targeted probes pass by design construction. A self-check is supporting evidence, never the authoritative gate. Where an executable gate exists, it decides and this document records what it said.

    Detailed Description

    Criterion [FIT-n]ProbeEvidenceResultLimits of the claim
    FIT-1: Authentication-as-AuthorizationSeed a synthetic request where a valid authenticated trader identity attempts to access the Core Banking Settlement ledger without requisite entitlement permission set.Authorization evaluation point test probe_authn_as_authz_rejection verifying evaluation point returns HTTP 403 AccessDenied and logs security event.passConfirms AWS IAM Identity Center permission set evaluation; does not test physical branch terminal access.
    FIT-2: Unrotated SecretSeed a synthetic administrator account configured with a static access key older than 24 hours or unrotated credentials.SCP compliance scanner probe_static_key_rejection verifying root Service Control Policy blocks static key usage and generates alert.passConfirms AWS cloud infrastructure policies; does not inspect third-party external SaaS vendor API tokens.
    FIT-3: Control Without EvidenceSeed an active PAM break-glass privilege elevation lacking corresponding dual-custody Jira ticket approval and CloudTrail audit log stream.Audit verification query probe_pam_without_evidence_rejection requiring mandatory correlation between Jira approval ID and active STS session.passConfirms audit trail binding mechanism; does not assess human reviewer judgment during live incident.

    Residual Risk

    • Temporary cellular network roaming latency during international travel may cause 3–5 second delays during WebAuthn FIDO2 attestation challenges. Accepted by Marcus Vance with client-side retry timeout configured to 15 seconds.

    Traceability

    ClaimClassificationSourceFreshness
    Rejection of authn-as-authzderivedFIT-1 probe result2026-09-15
    Rejection of unrotated static keysderivedFIT-2 probe result2026-09-15
    Rejection of control without evidencederivedFIT-3 probe result2026-09-15

    Verification

    No validator was supplied, so no command was run.

    Open Decisions

    None.

    Next steps

    1. Marcus Vance provisions AWS IAM Identity Center and connects Okta SAML/SCIM applications.
    2. Security team distributes YubiKey 5 hardware tokens and enforces WebAuthn policy in Okta.
    3. Conduct staging game day simulating HR termination to verify automated account deprovisioning within 15 minutes.
    4. CISO David O'Reilly verifies first automated 24-hour PAM break-glass audit logs in central security repository.

    enterprise-identity-and-access-managemen.tsx

    TSX · React component

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Design federated identity trust between multiple clouds and partnersMap authoritative sources to automated joiner/mover/leaver workflowsDefine authentication assurance levels based on action risk classesEstablish privileged access management (PAM) and break-glass contractsArchitect SCIM provisioning and entitlement governance models

    About this skill

    What it does

    This skill owns the organization-wide contracts that turn authoritative identity facts into principals, credentials, sessions, entitlements, and access decisions across organizational and technical boundaries. It defines federation, lifecycle, authentication, authorization, delegation, privileged access, governance, evidence, migration, and retirement without owning one login integration or provider configuration.

    Use it when

    • Employees, contractors, customers, partners, workloads, devices, automation, and privileged operators need distinct identity lifecycles
    • Directories, HR/customer systems, identity providers, relying parties, clouds, applications, and organizations form trust/federation boundaries
    • Proofing, enrollment, linking, recovery, rename/merge/split, suspension, termination, and deletion interact
    • Authenticators, federation assertions, tokens, sessions, step-up, revocation, and stale/offline behavior need shared contracts
    • Roles, attributes, relationships, ownership, policy decisions, enforcement points, delegation, and separation of duties must align
    • Entitlement requests, approvals, provisioning, reconciliation, reviews, exceptions, and revocation span systems

    For example: “An access review found 200 active accounts for people who left. Some go back four years. HR says they process leavers the same day.”

    What you get

    • architecture/identity-access-architect/README.md
    • architecture/identity-access-architect/00-overview/identity-access-architect-overview.md
    • architecture/identity-access-architect/verification/fitness-self-check.md

    Plus one page per business module, only where your evidence calls for it: {module}/authn.md, {module}/authz.md, {module}/session.md, {module}/secrets.md, {module}/audit.md.

    All paths are relative to the output folder you choose.

    What it will not do

    Do not use merely to add login/social SSO, configure OAuth/OIDC/SAML/Keycloak, create one role/policy/permission, fix an access bug, set up a directory/cloud IAM role, run an access review, rotate a credential, configure PAM, or implement zero trust.

    How it works

    1. Check the question spans systems.
    2. Separate the identity lifecycle from the access lifecycle.
    3. Name the authoritative source per identity type.
    4. Define authentication assurance per action class, not per system.
    5. Make deprovisioning a designed path with a measured latency.
    6. Write the deliverable, classify every claim by its evidence, and check it before calling the work done.

    What's in the package

    Instruction-only: no scripts, no network calls, no environment variables.

    • LICENSE.txt
    • SKILL.md
    • agents/openai.yaml
    • assets/output-template-contract.md
    • assets/output-template-domain.md
    • assets/output-template-fitness.md
    • assets/output-template-mechanism.md
    • references/domain-rules.md
    • references/operating-rules.md
    • references/output-contract.md

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 12 days ago

    • Passed all security checks, Safe to install

    Listed12 days ago

    What's inside

    Frequently Asked Questions