What is IAM?
Identity and Access Management, told as a story about the castle's registry.
A castle holds a lot of people.Cooks, clerks, guests, fixers… someone joined today, someone left yesterday.
Without a registry it's a mess.Leavers keep their keys, joiners wait for theirs, and the gatekeeper can't tell anyone apart.
IAM is the castle's registry.Who belongs here, whether it's really them, and which doors they may open — all kept in one place.
The registry changes when people join, move, or leave.Erase the line on the day they leave and every door shuts at once — no hunting down keys one by one.
The registry isn't just people.Errand robots (service accounts) and next-town guests (partners) belong on it too — and they're the ones everyone forgets.
IAM = the registry that keeps, in one place, who belongs here, whether it's really them, and which doors they may open.
Identity and Access Management. The gatekeeper (MFA), the ring (passkeys), the pass (SSO), the hats (RBAC), the if-sentence (ABAC) and the vault (PAM) are all this registry's job. Think Okta, Microsoft Entra ID, AWS IAM.
When grown-ups say it
- Identity
- One line in the registry. Who this person (or robot) is to the castle.
- Authentication
- Is it really them? The gatekeeper's job. → the gatekeeper's three questions, the ring that knows the gate
- Authorization
- Which doors? The hats' and the if-sentence's job. → hats, if-sentences
- Lifecycle (Joiner · Mover · Leaver)
- Join · move · leave. The three moments the registry changes. Leaving day matters most.
- Provisioning
- Handing out hats and keys. Written in, the hat, ring and pass go out automatically; struck out, they all come back.
- Directory
- The book itself. Active Directory, LDAP — the big book the registry lives in.
- Service account
- The errand robot. Not a person, but it holds keys. Dangerous if nobody owns it. → the vault story
- Access review
- Registry inspection day. Every quarter, read it line by line: should they still be here, is that the right hat.