Resources  /  Glossary

Glossary

The acronyms, in English — for the half of the room who did not choose this topic.

Access recertification
Periodically confirming that the people who have access still need it — and keeping proof that you checked.
Identity governance (IGA)
The discipline of deciding who should have access, granting it, reviewing it and proving all three.
Privileged access (PAM)
Controlling the accounts that can change things: administrators, service accounts, anything holding the keys.
Just-in-time access
Granting elevated access for a specific task, which then expires on its own rather than sitting there forever.
Standing privilege
Administrative access that is always on, whether or not anyone is using it. The thing attackers hope to find.
Joiner-mover-leaver
Access following employment: granted on the first day, changed on a move, removed on exit.
Separation of duties
Making sure one person cannot hold a combination of access that lets them do something harmful unchecked.
Single sign-on (SSO)
One sign-in that opens the applications you are entitled to, instead of a password for each.
Multi-factor / passkeys
Proving identity with more than a password. Passkeys resist phishing rather than merely recording it.
Non-human identity
Anything that holds access but is not a person: service accounts, scripts and now AI agents.
Sovereign deployment
Running the system where the data is legally required to stay, under your control rather than a vendor’s.
Orphaned account
An account nobody owns, usually left behind by someone who moved on. Working access, no accountable human.