Close former-user access within 24 hours
Access controls can appear complete while identity changes arrive too late.
The tension is between preserving customer-controlled identity models and limiting avoidable residual access.
“Our auditors see the account still active; they don’t care which system was late.”
Haslina Susanto · Identity Governance Lead
Owns deprovisioning controls for an enterprise analytics environment connected to the company warehouse.
What pulls against what
- rapid deprovisioning vs. workflow continuity
- platform safeguards vs. customer identity ownership
- uniform policy vs. risk-tiered controls
What is at stake
Residual access can convert an identity-sync delay into a customer audit finding
Why Sigma Computing
At Sigma Computing, governed access often depends on how faithfully external identity systems carry customer intent.
Written for
This is the setup. The work is inside.
Running it puts you in the room: the full situation and its constraints, stakeholders who push back in their own words, and the decisions that are yours to make. What you produce becomes a Day One Plan — work you can show someone instead of describing.