3.4. Identity Protection and Governance Capabilities
💡 First Principle: Granting the right access once isn't enough — access rights drift over time as people change roles, projects end, and risk conditions change — so governance capabilities exist to periodically re-verify that existing access is still appropriate, and protection capabilities exist to detect when an identity itself looks compromised.
Why care: without governance, "temporary" access silently becomes permanent, and nobody notices until an audit or a breach. Without protection, a compromised account can be used for weeks before anyone realizes the sign-in pattern looks wrong. These four capabilities work together to keep access both current and safe over time, not just at the moment it was first granted.
⚠️ Common Misconception: Assuming these are one-time setup tasks. Every capability in this section is designed to run continuously or periodically — reviews recur, PIM activations expire, and risk detection runs constantly.