{ "schemaVersion": "1.0", "title": "Identity and Access Management System", "lang": "en", "prd": { "oneLiner": "Connect users, roles and groups, access requests, approvals, provisioning, periodic reviews, and audit reporting.", "goal": "Process 90% of standard access requests within SLA and reduce unreviewed entitlements.", "whyNow": "Accounts and access requests are scattered across email and chat, making approval evidence and entitlement history hard to track.", "category": "Internal operations system", "platforms": [ "Web" ], "problem": "Accounts and access requests are scattered across email and chat, making approval evidence and entitlement history hard to track.", "solution": "Connect users, roles and groups, access requests, approvals, provisioning, periodic reviews, and audit reporting.", "alternatives": "Email, chat, spreadsheets, and manual ledgers", "differentiator": "Manage intake, processing, and operations data as one connected source of truth.", "targets": [ { "name": "Employee requesting access to a work system", "role": "Requester and operational user", "needs": "Quickly register needed work and know its status.", "pain": "Accounts and access requests are scattered across email and chat, making approval evidence and entitlement history hard to track." }, { "name": "IT security and identity administrator", "role": "Operations administrator", "needs": "Manage priority and history and review operations metrics.", "pain": "Accounts and access requests are scattered across email and chat, making approval evidence and entitlement history hard to track." }, { "name": "System and policy administrator", "role": "Operations and security administrator", "needs": "Manage access, policy, and audit history.", "pain": "Accounts and access requests are scattered across email and chat, making approval evidence and entitlement history hard to track." } ], "scenarios": [ { "text": "An operational user registers required work and checks its status.", "start": "P1" }, { "text": "An operator processes queued work and handles exceptions.", "start": "P5" }, { "text": "System and policy administrator reviews policy and access.", "start": "P9" }, { "text": "System and policy administrator reviews audit records and operating metrics.", "start": "P10" } ], "northStar": "Share of operations requests completed on time", "kpis": [ { "name": "On-time processing rate", "target": "Process 90% of standard access requests within SLA and reduce unreviewed entitlements.", "baseline": "Not measured", "method": "Monthly aggregation of state changes against target dates", "refs": [ "F6" ] }, { "name": "Operations visibility", "target": "100% of key work tracked", "baseline": "Not measured", "method": "Share of records connected to reporting", "refs": [ "F11" ] }, { "name": "Auditable operations rate", "target": "100% of key changes retained", "baseline": "Not measured", "method": "Monthly audit-log and change-history review", "refs": [ "F12" ] } ], "inScope": [ "Account creation and access-request submission", "User, role, group, and entitlement lookup", "Approval, provisioning, access change, and periodic-review handling", "Access request, approval lead-time, and unreviewed-entitlement reporting", "Account creation and access-request submission validation and duplicate prevention", "Search, filter, and history management", "Owner, priority, and SLA management", "Approval and policy review", "Exception, rejection, and reprocessing", "Notifications and subscriptions", "External integration and data synchronization", "Role, permission, and audit management" ], "nonGoals": [ "External customer portal", "Replacing adjacent systems such as accounting or payroll" ], "assumptions": [ "User and organization data are available through company SSO.", "Operators manage policy and classification criteria." ], "risks": [ "Weak initial classification can cause incorrect processing.", "Stale source data can reduce operational trust." ], "openQuestions": [ "What defines urgent processing and approval?", "What are the post-completion verification and reopen rules?" ], "constraints": [ "State, owner, and priority changes require audit logs.", "Access is limited by role.", "Permission, policy, and state changes require audit logs." ] }, "requirements": [ { "id": "R1", "title": "Intake and data quality", "desc": "Accounts and access requests are scattered across email and chat, making approval evidence and entitlement history hard to track.", "status": "todo", "priority": "high", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ], "features": [ { "id": "F1", "title": "Account creation and access-request submission", "desc": "Connect users, roles and groups, access requests, approvals, provisioning, periodic reviews, and audit reporting.", "status": "todo", "priority": "high", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ], "specs": [ { "title": "Account creation and access-request submission core processing rule", "desc": "Connect users, roles and groups, access requests, approvals, provisioning, periodic reviews, and audit reporting.", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ] }, { "title": "Account creation and access-request submission exception and audit handling", "desc": "Connect users, roles and groups, access requests, approvals, provisioning, periodic reviews, and audit reporting. Retain change, failure, and reprocessing conditions with history.", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ] } ] }, { "id": "F2", "title": "Account creation and access-request submission validation and duplicate prevention", "desc": "Accounts and access requests are scattered across email and chat, making approval evidence and entitlement history hard to track.", "status": "todo", "priority": "high", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ], "specs": [ { "title": "Account creation and access-request submission validation and duplicate prevention core processing rule", "desc": "Accounts and access requests are scattered across email and chat, making approval evidence and entitlement history hard to track.", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ] }, { "title": "Account creation and access-request submission validation and duplicate prevention exception and audit handling", "desc": "Accounts and access requests are scattered across email and chat, making approval evidence and entitlement history hard to track. Retain change, failure, and reprocessing conditions with history.", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ] } ] } ] }, { "id": "R2", "title": "Records and search", "desc": "Connect users, roles and groups, access requests, approvals, provisioning, periodic reviews, and audit reporting.", "status": "todo", "priority": "high", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ], "features": [ { "id": "F3", "title": "User, role, group, and entitlement lookup", "desc": "Process 90% of standard access requests within SLA and reduce unreviewed entitlements.", "status": "todo", "priority": "high", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ], "specs": [ { "title": "User, role, group, and entitlement lookup core processing rule", "desc": "Process 90% of standard access requests within SLA and reduce unreviewed entitlements.", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ] }, { "title": "User, role, group, and entitlement lookup exception and audit handling", "desc": "Process 90% of standard access requests within SLA and reduce unreviewed entitlements. Retain change, failure, and reprocessing conditions with history.", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ] } ] }, { "id": "F4", "title": "Search, filter, and history management", "desc": "Connect users, roles and groups, access requests, approvals, provisioning, periodic reviews, and audit reporting.", "status": "todo", "priority": "high", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ], "specs": [ { "title": "Search, filter, and history management core processing rule", "desc": "Connect users, roles and groups, access requests, approvals, provisioning, periodic reviews, and audit reporting.", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ] }, { "title": "Search, filter, and history management exception and audit handling", "desc": "Connect users, roles and groups, access requests, approvals, provisioning, periodic reviews, and audit reporting. Retain change, failure, and reprocessing conditions with history.", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ] } ] } ] }, { "id": "R3", "title": "Processing and ownership", "desc": "Process 90% of standard access requests within SLA and reduce unreviewed entitlements.", "status": "todo", "priority": "high", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ], "features": [ { "id": "F5", "title": "Approval, provisioning, access change, and periodic-review handling", "desc": "Accounts and access requests are scattered across email and chat, making approval evidence and entitlement history hard to track.", "status": "todo", "priority": "high", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ], "specs": [ { "title": "Approval, provisioning, access change, and periodic-review handling core processing rule", "desc": "Accounts and access requests are scattered across email and chat, making approval evidence and entitlement history hard to track.", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ] }, { "title": "Approval, provisioning, access change, and periodic-review handling exception and audit handling", "desc": "Accounts and access requests are scattered across email and chat, making approval evidence and entitlement history hard to track. Retain change, failure, and reprocessing conditions with history.", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ] } ] }, { "id": "F6", "title": "Owner, priority, and SLA management", "desc": "Process 90% of standard access requests within SLA and reduce unreviewed entitlements.", "status": "todo", "priority": "high", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ], "specs": [ { "title": "Owner, priority, and SLA management core processing rule", "desc": "Process 90% of standard access requests within SLA and reduce unreviewed entitlements.", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ] }, { "title": "Owner, priority, and SLA management exception and audit handling", "desc": "Process 90% of standard access requests within SLA and reduce unreviewed entitlements. Retain change, failure, and reprocessing conditions with history.", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ] } ] } ] }, { "id": "R4", "title": "Approval and exceptions", "desc": "Accounts and access requests are scattered across email and chat, making approval evidence and entitlement history hard to track.", "status": "todo", "priority": "high", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ], "features": [ { "id": "F7", "title": "Approval and policy review", "desc": "Connect users, roles and groups, access requests, approvals, provisioning, periodic reviews, and audit reporting.", "status": "todo", "priority": "mid", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ], "specs": [ { "title": "Approval and policy review core processing rule", "desc": "Connect users, roles and groups, access requests, approvals, provisioning, periodic reviews, and audit reporting.", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ] }, { "title": "Approval and policy review exception and audit handling", "desc": "Connect users, roles and groups, access requests, approvals, provisioning, periodic reviews, and audit reporting. Retain change, failure, and reprocessing conditions with history.", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ] } ] }, { "id": "F8", "title": "Exception, rejection, and reprocessing", "desc": "Accounts and access requests are scattered across email and chat, making approval evidence and entitlement history hard to track.", "status": "todo", "priority": "mid", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ], "specs": [ { "title": "Exception, rejection, and reprocessing core processing rule", "desc": "Accounts and access requests are scattered across email and chat, making approval evidence and entitlement history hard to track.", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ] }, { "title": "Exception, rejection, and reprocessing exception and audit handling", "desc": "Accounts and access requests are scattered across email and chat, making approval evidence and entitlement history hard to track. Retain change, failure, and reprocessing conditions with history.", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ] } ] } ] }, { "id": "R5", "title": "Notifications and integrations", "desc": "Connect users, roles and groups, access requests, approvals, provisioning, periodic reviews, and audit reporting.", "status": "todo", "priority": "mid", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ], "features": [ { "id": "F9", "title": "Notifications and subscriptions", "desc": "Process 90% of standard access requests within SLA and reduce unreviewed entitlements.", "status": "todo", "priority": "high", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ], "specs": [ { "title": "Notifications and subscriptions core processing rule", "desc": "Process 90% of standard access requests within SLA and reduce unreviewed entitlements.", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ] }, { "title": "Notifications and subscriptions exception and audit handling", "desc": "Process 90% of standard access requests within SLA and reduce unreviewed entitlements. Retain change, failure, and reprocessing conditions with history.", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ] } ] }, { "id": "F10", "title": "External integration and data synchronization", "desc": "Connect users, roles and groups, access requests, approvals, provisioning, periodic reviews, and audit reporting.", "status": "todo", "priority": "high", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ], "specs": [ { "title": "External integration and data synchronization core processing rule", "desc": "Connect users, roles and groups, access requests, approvals, provisioning, periodic reviews, and audit reporting.", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ] }, { "title": "External integration and data synchronization exception and audit handling", "desc": "Connect users, roles and groups, access requests, approvals, provisioning, periodic reviews, and audit reporting. Retain change, failure, and reprocessing conditions with history.", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ] } ] } ] }, { "id": "R6", "title": "Insights and controls", "desc": "Process 90% of standard access requests within SLA and reduce unreviewed entitlements.", "status": "todo", "priority": "mid", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ], "features": [ { "id": "F11", "title": "Access request, approval lead-time, and unreviewed-entitlement reporting", "desc": "Accounts and access requests are scattered across email and chat, making approval evidence and entitlement history hard to track.", "status": "todo", "priority": "high", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ], "specs": [ { "title": "Access request, approval lead-time, and unreviewed-entitlement reporting core processing rule", "desc": "Accounts and access requests are scattered across email and chat, making approval evidence and entitlement history hard to track.", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ] }, { "title": "Access request, approval lead-time, and unreviewed-entitlement reporting exception and audit handling", "desc": "Accounts and access requests are scattered across email and chat, making approval evidence and entitlement history hard to track. Retain change, failure, and reprocessing conditions with history.", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ] } ] }, { "id": "F12", "title": "Role, permission, and audit management", "desc": "Process 90% of standard access requests within SLA and reduce unreviewed entitlements.", "status": "todo", "priority": "mid", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ], "specs": [ { "title": "Role, permission, and audit management core processing rule", "desc": "Process 90% of standard access requests within SLA and reduce unreviewed entitlements.", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ] }, { "title": "Role, permission, and audit management exception and audit handling", "desc": "Process 90% of standard access requests within SLA and reduce unreviewed entitlements. Retain change, failure, and reprocessing conditions with history.", "acceptance": [ { "text": "Required context, changes, ownership, and status are retained in an auditable record.", "done": false } ] } ] } ] } ], "ia": { "sections": [ { "id": "S1", "title": "Intake and data quality", "pages": [ { "id": "P1", "title": "Operations dashboard", "type": "top", "refs": [ "F1", "F1:0", "F3", "F4:0", "F7:1", "F11" ], "children": [] }, { "id": "P2", "title": "Work list", "type": "page", "refs": [ "F3", "F3:0", "F4", "F1:0", "F4:1", "F8", "F11:0" ], "children": [] }, { "id": "P3", "title": "Create record", "type": "page", "refs": [ "F1", "F1:1", "F2", "F5", "F8:0", "F11:1" ], "children": [] } ] }, { "id": "S2", "title": "Records and search", "pages": [ { "id": "P4", "title": "Record detail", "type": "page", "refs": [ "F3:1", "F4:1", "F11", "F2", "F5:0", "F8:1", "F12" ], "children": [] }, { "id": "P5", "title": "Processing workspace", "type": "page", "refs": [ "F5", "F5:0", "F6", "F2:0", "F5:1", "F9", "F12:0" ], "children": [] } ] }, { "id": "S3", "title": "Processing and ownership", "pages": [ { "id": "P6", "title": "Approval and exception queue", "type": "page", "refs": [ "F7", "F7:0", "F8", "F2:1", "F6", "F9:0", "F12:1" ], "children": [] }, { "id": "P7", "title": "Notifications and integrations", "type": "page", "refs": [ "F9", "F9:0", "F10", "F3", "F6:0", "F9:1" ], "children": [] } ] }, { "id": "S4", "title": "Insights and controls", "pages": [ { "id": "P8", "title": "Operations reports", "type": "page", "refs": [ "F11", "F11:0", "F3:0", "F6:1", "F10" ], "children": [] }, { "id": "P9", "title": "Policy and access settings", "type": "page", "refs": [ "F10:1", "F12", "F3:1", "F7", "F10:0" ], "children": [] }, { "id": "P10", "title": "Audit log", "type": "page", "refs": [ "F8:1", "F12:0", "F12:1", "F4", "F7:0", "F10:1" ], "children": [] } ] } ] }, "flow": { "start": "P1", "transitions": [ { "from": "P1", "to": "P2", "ref": "F1" }, { "from": "P2", "to": "P3", "ref": "F2" }, { "from": "P3", "to": "P4", "ref": "F3" }, { "from": "P4", "to": "P5", "ref": "F4" }, { "from": "P5", "to": "P6", "ref": "F5" }, { "from": "P6", "to": "P5", "ref": "F8" }, { "from": "P5", "to": "P7", "ref": "F6" }, { "from": "P7", "to": "P8", "ref": "F9" }, { "from": "P8", "to": "P9", "ref": "F10" }, { "from": "P9", "to": "P10", "ref": "F12" }, { "from": "P10", "to": "P4", "ref": "F11" }, { "from": "P4", "to": "P1", "label": "Refresh operations status" }, { "from": "P5", "to": "P6", "ref": "F7" } ] } }