iam-specialist

Design identity lifecycle, entitlements, and access review programs for enterprise IAM.

7|1|Updated May 19, 2026
One-click install
npx skills add https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill --skill iam-specialist-daemon-blockint-tech
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: iam-specialist
Source: https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill/tree/main/iam-specialist
Command: npx skills add https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill --skill iam-specialist-daemon-blockint-tech

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Guides identity and access management—workforce and machine identity lifecycle, RBAC/ABAC/PBAC entitlement design, access reviews and recertification, SSO/SAML/OIDC federation, privileged access (PAM/JIT), cloud IAM least privilege (AWS/GCP/Azure concepts), service accounts and secrets hygiene, and separation of duties. Use for IAM, identity governance, access review, RBAC, least privilege, SSO federation, PAM, privileged access, cloud IAM policy, service account, or SoD—not full cloud landing zone architecture (enterprise-cloud-architect), broad cloud security controls (cloud-security-engineer), day-2 break-glass ticket execution only (cloud-system-administrator), pentest (penetration-tester), or legal/HR policy drafting only.

Core Features & Use Cases

  • Identity lifecycle design for workforce and machine identities (Joiner/Mover/Leaver)
  • RBAC/ABAC/PBAC entitlement modeling with least privilege enforcement
  • Access reviews, recertification campaigns, and SoD governance
  • Federation patterns for SSO/SAML/OIDC and PAM/JIT break-glass

Quick Start

Outline an initial IAM governance plan with lifecycle, entitlements, federation, and reviews for a mid-sized organization.

Frequently Asked Questions about iam-specialist

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I design an IAM governance plan for a mid-sized organization?

To design an IAM governance plan, you must outline the identity lifecycle, model RBAC/ABAC entitlements, define federation patterns, and establish access review recertification campaigns. This creates a scalable baseline for workforce and machine identities across cloud and on-prem apps.

What is the best way to model least privilege entitlements using RBAC and ABAC?

Modeling least privilege entitlements requires mapping RBAC roles and ABAC attributes to enforce strict access boundaries. This approach minimizes excessive permissions by ensuring machine and workforce identities only receive access necessary for their specific functions.

How do I implement SSO federation and PAM break-glass procedures?

Implementing SSO federation and PAM break-glass procedures involves configuring SAML/OIDC protocols for standard authentication and defining Just-In-Time (JIT) privileged access policies. This secures emergency access while maintaining strict identity governance oversight.

Can I use this for cloud IAM policy design across multi-account environments?

Yes, you can use this for cloud IAM policy design across multi-account AWS, GCP, and Azure environments. It provides benchmarks for least privilege enforcement and service account secrets hygiene without covering full landing zone architecture.

When should I not use this approach for identity and access management?

You should not use this approach for broad cloud security controls, day-to-day break-glass ticket execution, penetration testing, or drafting legal and HR policies. It focuses specifically on IAM governance, entitlement catalogs, and SoD matrices rather than general security operations.