Purpose
The Identity Pattern defines the approved reference architecture for integrating identity and access capabilities with University-managed technology environments.
This pattern describes how human identities, workload identities, authentication services, authorization services, privileged-access services, identity-governance services, and identity-audit services fit together to support University workloads.
The pattern applies across workload classifications. Applicable standards, workload classifications, data classifications, and obligations determine the requirements implemented through this architecture.
Use Cases
This pattern applies when:
- Integrating an application, service, platform, or infrastructure environment with enterprise identity services
- Implementing workforce or administrative access to a workload
- Implementing application-to-application or service-to-service authentication
- Implementing identities for automation, integration, orchestration, or deployment processes
- Implementing external or federated access
- Implementing identity capabilities within a Landing Zone or hosting product
- Integrating identity activity with monitoring and audit services
- Integrating a workload with identity-governance and lifecycle-management services
This pattern does not define:
- Application-specific business roles or permissions
- Detailed authentication requirements
- Detailed authorization requirements
- Detailed privileged-access requirements
- Access-review frequency or procedures
- Credential, secret, certificate, or key-management requirements
- Identity lifecycle procedures
- Obligation-specific identity requirements
- Physical identity or facility-access architecture
Design Principles
Centralized Enterprise Identity
Enterprise identity services provide the common identity foundation used by University workloads.
Workloads integrate with shared identity capabilities rather than duplicating common identity services within each workload environment.
Separation of Authentication and Authorization
Enterprise identity services establish and authenticate identities.
Platform and application authorization services determine the resources and functions available to an authenticated identity.
Role-Based Authorization
Roles, groups, policies, claims, and application entitlements provide the primary architectural mechanisms for connecting authenticated identities to authorized workload capabilities.
Workload Identity
Applications, services, integrations, and automation use non-human identity capabilities to establish trust and access protected resources.
Individual Accountability
Human access is associated with identifiable human identities, while non-human activity is associated with identifiable workload identities.
Identity Auditability
Identity services integrate with monitoring and audit services to make identity-related activity available to operational, governance, security, and audit functions.
Logical Architecture
Human Identity
|
v
Enterprise Identity Platform
|
+-- Identity Provider Service
+-- Federation Service
+-- Authentication Service
+-- Identity Governance Service
|
v
Authorization Layer
|
+-- Platform Authorization
+-- Application Authorization
+-- Privileged Access
|
v
University Workload
|
+-- Applications
+-- APIs
+-- Databases
+-- Data Platforms
+-- Integration Services
+-- Platform Services
+-- Infrastructure
|
+-------------------------------+
| |
v v
Workload Identity Automation Identity
| |
+---------------+---------------+
|
v
Protected Resources
|
v
Monitoring and Audit Services
Identity Types
Human Identities
Human identities represent individuals interacting with applications, platforms, infrastructure, services, or data.
Human identity scenarios include:
- Workforce access
- Administrative access
- Operational access
- Support access
- Student or affiliate access
- External or guest access
Workload Identities
Workload identities represent applications, services, integrations, platform components, and other non-human technology actors.
Workload identity scenarios include:
- Application-to-application access
- Application-to-service access
- Application-to-data access
- Service-to-service access
- Integration access
- Platform service access
Automation Identities
Automation identities represent deployment, orchestration, configuration-management, scheduled, recovery, and operational processes.
Automation identity scenarios include:
- Infrastructure deployment
- Application deployment
- Configuration management
- Operational automation
- Data movement
- Integration workflows
- Recovery automation
Emergency Identities
Emergency identities support approved continuity, recovery, and emergency-access scenarios when normal identity capabilities are unavailable or insufficient.
Identity Architecture Services
Identity Provider Service
The Identity Provider Service establishes authoritative identity information and provides identity services to applications, platforms, infrastructure, and shared services.
The service supports:
- Human identities
- External identities
- Application identities
- Service identities
- Automation identities
- Device identities when applicable
Federation Service
The Federation Service establishes identity trust between enterprise identity services and applications, platforms, cloud services, partners, and external organizations.
Authentication Service
The Authentication Service verifies identities and provides authenticated identity context to downstream authorization services.
Authorization Service
The Authorization Service connects authenticated identities to roles, groups, policies, claims, entitlements, and other access decisions.
Authorization may occur at multiple architecture layers:
- Enterprise identity layer
- Platform layer
- Infrastructure layer
- Application layer
- Data layer
Privileged-Access Service
The Privileged-Access Service provides the architectural integration point for elevated platform, infrastructure, application, database, and service administration.
Workload Identity Service
The Workload Identity Service provides identities and trust relationships for applications, services, integrations, automation, and platform components.
Identity Governance Service
The Identity Governance Service provides integration with identity provisioning, access governance, role management, identity lifecycle management, and access-review capabilities.
Identity Audit Service
The Identity Audit Service collects or routes identity-related activity to approved monitoring, audit, reporting, investigation, and governance capabilities.
Authorization Model
Enterprise Authorization
Enterprise authorization connects identities to centrally managed roles, groups, policies, claims, and entitlements.
Platform Authorization
Platform authorization maps identities to administrative, operational, resource, and service-access roles provided by the target platform.
Application Authorization
Application authorization maps authenticated identities to application functions, business roles, records, transactions, and data.
Workload Authorization
Workload authorization maps application, service, integration, and automation identities to protected services and resources.
Identity Boundaries
Enterprise Identity Boundary
Enterprise identity services operate as shared capabilities that may support multiple workloads, platforms, hosting environments, and workload classifications.
Workload Boundary
The workload boundary contains the applications, services, infrastructure, data, and workload-specific authorization capabilities associated with a technology solution.
Use of shared enterprise identity services does not eliminate the workload boundary.
Application Authorization Boundary
The application authorization boundary contains the roles, permissions, entitlements, and access decisions specific to an application or service.
Platform Authorization Boundary
The platform authorization boundary contains the roles and permissions used to administer and operate infrastructure, cloud resources, data platforms, integration platforms, and shared services.
External Trust Boundary
The external trust boundary represents federation and identity relationships with partners, vendors, guests, collaborators, cloud services, and other external organizations.
Identity Integration
Application Integration
Applications integrate with enterprise authentication services and use application authorization to map authenticated identities to application capabilities.
Platform Integration
Platforms integrate enterprise identities with platform roles and administrative capabilities.
Workload Identity Integration
Applications, services, integrations, and automation integrate with workload-identity capabilities provided by enterprise identity services or supported platforms.
Identity Governance Integration
The Identity Pattern integrates with identity-governance, lifecycle-management, role-management, and access-governance services.
Monitoring Integration
Identity services integrate with approved monitoring and audit platforms to provide visibility into authentication, authorization, privileged-access, workload-identity, and identity-management activity.
Landing Zone Integration
Landing Zone and hosting products use this pattern to connect workload environments to enterprise identity, authorization, privileged-access, governance, and monitoring services.
Operational Responsibilities
Enterprise Identity Services
Enterprise Identity Services owns:
- Enterprise identity architecture
- Enterprise identity platforms
- Identity-provider services
- Federation services
- Enterprise authentication services
- Enterprise identity integration capabilities
Platform Engineering
Platform Engineering owns:
- Reusable identity-integration components
- Platform authorization integration
- Workload-identity deployment components
- Landing Zone identity integration
- Identity onboarding automation
Information Security
Information Security provides:
- Security requirements consumed by the pattern
- Architecture and security review
- Identity monitoring requirements
- Investigation support
Workload Teams
Workload teams own:
- Application authorization architecture
- Application-role integration
- Workload-identity integration
- Application identity telemetry
- Workload-specific identity configuration
Business and Data Owners
Business and data owners provide the business-role, access, data-use, and ownership information consumed by application authorization and identity-governance capabilities.
Automation Pattern
Identity integration should be implemented through approved platform automation whenever practical.
Automation may support:
- Enterprise identity integration
- Federation configuration
- Platform role assignment
- Workload identity deployment
- Privileged-access integration
- Identity-governance integration
- Monitoring and audit integration
- Landing Zone integration
- Workload onboarding
Identity Integration Definition
|
+-- Enterprise Identity Integration
+-- Authorization Integration
+-- Privileged-Access Integration
+-- Workload Identity Integration
+-- Governance Integration
+-- Monitoring Integration
|
v
Reusable Automation Components
|
v
Landing Zone or Workload Deployment
|
v
Integrated Identity Architecture
Automation components should be reusable across supported workload and hosting products.
Product-specific implementations may extend the common automation pattern to support platform, workload, or obligation-specific architecture.
Reference Architecture Outcomes
A workload implementing this pattern should provide:
- Integration with enterprise identity services
- Separation of authentication and authorization responsibilities
- Enterprise, platform, and application authorization layers
- Human identity support
- Workload identity support
- Automation identity support
- Privileged-access integration
- Identity-governance integration
- Identity monitoring and audit integration
- Defined enterprise, workload, platform, application, and external trust boundaries
- Reusable identity-integration components
- Repeatable identity onboarding
- Support for workload and obligation-specific extensions
Exceptions
Exceptions to this pattern must follow approved architecture governance and information security exception processes.
Approved exceptions must be periodically reviewed and must not be treated as permanent architecture patterns.