identity-access-governance

Diagnose and plan least-privilege access governance for human and machine identities.

Updated Aug 22, 2026
One-click install
npx skills add https://github.com/fritzgeraldz/Vibe-Managing --skill identity-access-governance-fritzgeraldz
Or copy as Structured Prompt for Agentβ–Ό
Please help me install this Agent Skill.
Skill: identity-access-governance
Source: https://github.com/fritzgeraldz/Vibe-Managing/tree/main/skills/security-privacy/identity-access-governance
Command: npx skills add https://github.com/fritzgeraldz/Vibe-Managing --skill identity-access-governance-fritzgeraldz

SYSTEM DOCUMENTATION & REQUIREMENTS

πŸ’‘ This Skill includes references (resource) components.

What problem does it solve? Founders and operators struggle to ensure every human and machine identity has only the minimum justified access, with timely approval, review, and removal. This Skill turns identity and access governance into an evidence-backed decision and operating plan instead of ad-hoc permission sprawl. ## Core Features & Use Cases - Identity & Entitlement Diagnosis: Inventories identities, maps roles and entitlements, and identifies toxic access combinations with evidence and confidence levels. - Least-Privilege Planning: Applies least privilege, schedules access reviews, and automates joiner-mover-leaver processes with risk-adjusted option ranking. - Governed Execution: Produces decision records, KPIs (excess privilege, orphaned accounts, review completion), monitoring cadences, and escalation routes with human approval gates. - Use Case: A founder asks whether contractor access is under control. The Skill inventories accounts, flags orphaned accounts and excess privilege, compares remediation options against hard constraints, and recommends a sequenced plan with owners and review dates. ## Quick Start Use identity access governance to audit our current user and service accounts and produce a least-privilege remediation plan with review cadences.

Frequently Asked Questions about identity-access-governance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I implement least privilege access in a small business?β–Ό

Start by inventorying all human and machine identities, then map roles to entitlements and remove access that lacks justification. This Skill walks through that framework step by step, producing a ranked remediation plan with owners, due dates, and review cadences.

How to find and remove orphaned accounts?β–Ό

Orphaned accounts are detected during the identity inventory step, which reconciles active accounts against current employees, contractors, and services. The Skill tracks orphaned accounts as a KPI with baseline, target, and trend, and recommends removal actions subject to human approval.

What is a toxic combination in access management?β–Ό

A toxic combination is a set of entitlements held by one identity that together enable fraud or material harm, such as creating and approving payments. The Skill identifies these combinations during role and entitlement mapping and flags them as decision-relevant findings.

Can this Skill change user access permissions automatically?β–Ό

No. Access changes require human approval under the Skill's governance rules. It can read and reconcile scoped records, calculate metrics, and draft plans at low autonomy levels, but it never executes access modifications without an authorized approver.

When should I not use an identity governance analysis?β–Ό

Do not use it during an active security emergency; invoke the incident response workflow first and operate within that command structure. Also avoid applying generic benchmarks before comparability is established, and escalate regulated interpretations to qualified specialists.