Metadata is not just a buzz word
Describing IAM nouns—and describing them well—is one of the quiet difference-makers in designing an effective IAM control.
Take something as ordinary as a permission listed in a permission catalog. Described well, in business-friendly language, it tells end users exactly what they're requesting. Approvers can make the call without guessing, and certifiers have a reason not to rubber-stamp their reviews.
Tagging that permission with metadata does more than make it searchable. The metadata can drive the rules that govern how the permission gets handled—scoping rules that control who can see it or whether it lands in a given certification, matching rules that auto-assign it to users or bundle it into a role, and so on.
Poor descriptions do the opposite, and the damage can be serious. Where a business-friendly description should be, there's often a cryptic technical reference that no ordinary end user can decode. Approval and certification decisions then get made on incomplete information, which renders them close to meaningless and leaves users holding more access than they should have.
More advanced Identity-based automation also stays out of reach when there is no solid metadata to drive it. [Here is an interesting read on how metadata problems have plagued the music industry for decades to the point that musicians can't get paid for their work. The article makes the case for standards in how metadata is collected, verified, and distributed—the same three concerns we have in the IAM universe.]
Left unresolved, these problems tend to compound as the volume of business resources grows and an organization's IT footprint expands. It's one small example of how large organizations end up carrying correspondingly large amounts of IAM technical debt.
But don't be disheartened, reader. All of this is avoidable with one simple measure: describe your IAM nouns well. It really is that straightforward. More on this topic to come, so stay tuned!