Skip to content
Mike Reams
← Diagrams

DGM · Technical Architecture

Identity Lifecycle Attribute Flow

An identity lifecycle flow lets HR events drive accounts: joiners get access, movers get updated and leavers get disabled, one source per attribute.

Data-flow diagram: the HR system sends worker events to an identity sync and governance engine that applies joiner, mover and leaver rules plus attribute mapping, precedence and scope. The engine provisions the directory (AD DS or Entra ID) and SaaS apps over SCIM; the directory writes email and username back to HR.Data-flow diagram: the HR system sends worker events to an identity sync and governance engine that applies joiner, mover and leaver rules plus attribute mapping, precedence and scope. The engine provisions the directory (AD DS or Entra ID) and SaaS apps over SCIM; the directory writes email and username back to HR.

What it is

An identity lifecycle flow makes the HR system the source of truth for who works here, and lets everything else follow. When HR records a hire, a role change or a departure, an identity engine turns that event into accounts, attribute updates and access changes in the directory and the applications downstream. Nobody types the same person into five systems.

Joiner, mover, leaver

  • Joiner: create the account and grant the base access the role needs, ideally before the first day.
  • Mover: update title, department and manager, and adjust group membership, removing access the old role needed.
  • Leaver: disable at once and remove on a schedule, so a mistaken termination can be undone and audits still find the account.

Rules worth writing down

  • One authoritative source per attribute. HR owns name, title and manager; the directory might own the email address.
  • Precedence. When two sources disagree, the rule decides, not whoever synced last.
  • Scope. Which workers are in: employees, contractors, interns, rehires.
  • Formats. How usernames and email addresses are built, and what happens on a collision.

Writeback and downstream apps

The identifiers the directory creates, usually the username and email address, are written back to HR so both systems agree. SaaS applications receive accounts through SCIM provisioning where they support it; the ones that do not need a documented connector or manual process, or they become the leaver accounts nobody disabled.

Common mistakes

  • Deleting on day one of a departure instead of disabling first.
  • Letting application admins edit identity data that the next sync silently overwrites.
  • No rehire rule, so a returning employee gets a second identity.

Based on What is HR-driven provisioning? (Microsoft Entra); RFC 7644, SCIM Protocol. Drawn for this site; no client or employer material.