External and Workload Identities¶
Atlanta, USA
Last updated: 2026-08-04
Objective¶
Establish secure and governed access patterns for partner, customer, and workload identities in addition to employee identities.
Identity categories¶
| Identity type | Typical controls |
|---|---|
| External collaboration identities | Invitation, conditional access, periodic review, and lifecycle removal |
| Customer identities | Registration, authentication journey, and application policy controls |
| Workload identities | App registration governance, credential hygiene, and scoped permissions |
| Agent identities | Sponsor ownership, policy inheritance, and lifecycle controls |
Setup priorities¶
- Define identity inventory and ownership model.
- Apply access package or request workflow where possible.
- Require periodic access reviews for external and privileged pathways.
- Enforce nonhuman identity credential and permission standards.
Risk patterns¶
- Orphaned external users with stale access.
- Workload identities with broad, long-lived permissions.
- Missing accountability for autonomous or semi-autonomous agents.