Identity Lifecycle Control Pack
Continuously evaluate identity lifecycle governance — new hire provisioning, access baselines, dormant accounts, and offboarding completeness — and generate findings for any gaps.
Requires a Nuxari account. Installs as Draft — no changes until you enable it.
Back to templatesWhat this template does
This control pack continuously evaluates the controls that govern an identity's full lifecycle. It checks that new hires receive the correct baseline access, that mover access changes align with role transitions, that dormant accounts are detected, and that offboarded users have no residual access. Each control gap surfaces as a severity-ranked finding with a recommended remediation action.
When to use it
Use this template when you want a single, continuously-evaluated view of identity lifecycle health rather than running separate one-off scans. It is especially valuable during audit preparation, where you need to demonstrate that joiner-mover-leaver controls are operating effectively.
How it works
Lifecycle state collection
Nuxari collects identity state across connected systems — provisioning records, group memberships, activity signals, and offboarding status.
Control evaluation
Each lifecycle control is evaluated: baseline provisioning correctness, access drift, dormancy thresholds, and offboarding completeness.
Finding generation
Control gaps surface as severity-ranked findings, each describing the deviation and a recommended remediation path.
Continuous reassessment
The control pack re-evaluates on its configured schedule so findings reflect the current lifecycle state and resolved gaps close automatically.
What gets created in your tenant
Identity Lifecycle Controls
A set of continuously-evaluated controls covering joiner, mover, and leaver lifecycle stages.
Lifecycle Gap Findings
A findings queue populated by lifecycle control deviations across connected systems.
Lifecycle Health Overview
A summary widget showing control pass rates across each lifecycle stage.
What evidence it produces
- Identity lifecycle control assessment report
- New hire provisioning gap findings
- Access baseline deviation findings
- Dormant account detection report
- Offboarding completeness findings
Safety and approval model
Templates install as Draft / Disabled by default. No actions run until you explicitly enable the template after reviewing the configuration.
This template installs in Draft state and is read-only — it evaluates lifecycle controls and generates findings but does not modify any account or access. No controls run until you connect the required connectors and explicitly enable the pack. Remediation of findings is handled through separate approval-gated workflows, not by the control pack itself.
Customization options
- Baseline access definitions per role or department
- Dormancy threshold (days of inactivity)
- Offboarding completeness scope (which systems to check)
- Severity thresholds for each control
- Assessment frequency (continuous, daily, weekly)
- Notification routing for critical lifecycle gaps
Related templates
Access Drift Review
Compare approved access against observed access across connected systems and generate structured findings for any drift — access added, removed, or changed outside an approved workflow.
View templateDormant Account Review
Identify accounts with no sign-in or activity in a configurable window, generate a dormancy report, and route owner review tasks — without modifying any accounts automatically.
View templateScheduled Employee Offboarding
Plan, approve, and execute complete employee offboarding in advance. Revokes access across identity, SaaS, and cloud at the scheduled time and generates a full evidence package.
View templateUse this template
Install in your Nuxari tenant and run the full approval and evidence workflow from day one.
Build the operating layer
for governance work.
See how Nuxari Ops reduces manual IT work, eliminates access drift, and generates audit evidence automatically, across your entire enterprise.