Skip to main content

Governance intelligence for access, cloud, and SaaS. Now in early access

Nuxari
Control PackAccess Governancemedium risk

Identity Lifecycle Control Pack

Continuously evaluate identity lifecycle governance — new hire provisioning, access baselines, dormant accounts, and offboarding completeness — and generate findings for any gaps.

Identity governance teamsSecurity teams managing joiner-mover-leaver processesCompliance teams preparing for access control auditsIT operations standardizing lifecycle controls
Use template

Requires a Nuxari account. Installs as Draft — no changes until you enable it.

Back to templates
~25 min setup
Required
Entra ID

What this template does

This control pack continuously evaluates the controls that govern an identity's full lifecycle. It checks that new hires receive the correct baseline access, that mover access changes align with role transitions, that dormant accounts are detected, and that offboarded users have no residual access. Each control gap surfaces as a severity-ranked finding with a recommended remediation action.

When to use it

Use this template when you want a single, continuously-evaluated view of identity lifecycle health rather than running separate one-off scans. It is especially valuable during audit preparation, where you need to demonstrate that joiner-mover-leaver controls are operating effectively.

How it works

01

Lifecycle state collection

Nuxari collects identity state across connected systems — provisioning records, group memberships, activity signals, and offboarding status.

02

Control evaluation

Each lifecycle control is evaluated: baseline provisioning correctness, access drift, dormancy thresholds, and offboarding completeness.

03

Finding generation

Control gaps surface as severity-ranked findings, each describing the deviation and a recommended remediation path.

04

Continuous reassessment

The control pack re-evaluates on its configured schedule so findings reflect the current lifecycle state and resolved gaps close automatically.

What gets created in your tenant

Control Pack

Identity Lifecycle Controls

A set of continuously-evaluated controls covering joiner, mover, and leaver lifecycle stages.

Findings Pipeline

Lifecycle Gap Findings

A findings queue populated by lifecycle control deviations across connected systems.

Dashboard Widget

Lifecycle Health Overview

A summary widget showing control pass rates across each lifecycle stage.

What evidence it produces

  • Identity lifecycle control assessment report
  • New hire provisioning gap findings
  • Access baseline deviation findings
  • Dormant account detection report
  • Offboarding completeness findings

Safety and approval model

Templates install as Draft / Disabled by default. No actions run until you explicitly enable the template after reviewing the configuration.

This template installs in Draft state and is read-only — it evaluates lifecycle controls and generates findings but does not modify any account or access. No controls run until you connect the required connectors and explicitly enable the pack. Remediation of findings is handled through separate approval-gated workflows, not by the control pack itself.

Customization options

  • Baseline access definitions per role or department
  • Dormancy threshold (days of inactivity)
  • Offboarding completeness scope (which systems to check)
  • Severity thresholds for each control
  • Assessment frequency (continuous, daily, weekly)
  • Notification routing for critical lifecycle gaps

Use this template

Install in your Nuxari tenant and run the full approval and evidence workflow from day one.

Use template
Get started

Build the operating layerfor governance work.

See how Nuxari Ops reduces manual IT work, eliminates access drift, and generates audit evidence automatically, across your entire enterprise.