DRAFT: Identity Practice

Summary

Provides architecture guidance for digital identity, authentication, authorization, account lifecycle management, and access control. The Identity Practice helps the university apply consistent identity patterns while keeping access decisions and operational service ownership with the appropriate stakeholders.

Body

Purpose

The Identity Practice is an Enterprise Architecture practice that helps the University of Arkansas manage digital identities and access through shared knowledge, documented patterns, and reusable architecture guidance.

The Identity Practice exists to help the university learn from identity implementations and apply those lessons broadly rather than repeatedly solving the same problems.


Mission

Provide practical architecture guidance that helps university units manage identity and access in a consistent, supportable, and sustainable manner.

The practice supports identity and access management by documenting standards, patterns, decisions, lessons learned, and reference architectures.


Why the Identity Practice Exists

Identity is a shared foundation for university technology.

People, applications, services, devices, and automated processes require identities and permissions to access university systems and data. These identities may span multiple platforms, services, departments, and stages of the university relationship.

Identity decisions affect access to university resources, the protection of university data, and the ability to determine who or what performed an action.

The challenge is not whether identity and access decisions will be made.

The challenge is ensuring that the university can:

  • Apply consistent identity and access patterns
  • Use individual and accountable identities
  • Manage access throughout the identity lifecycle
  • Limit access to what is needed
  • Support appropriate authentication methods
  • Manage privileged and administrative access
  • Connect applications and services to university identity capabilities
  • Document ownership and operational responsibilities
  • Reduce duplicate and inconsistent identity solutions

What the Practice Does

The Identity Practice serves three functions.

Curate

Maintain reusable identity knowledge, including:

  • Standards
  • Patterns
  • Reference Architectures
  • Architectural Decision Records (ADRs)
  • Lessons Learned
  • Roadmaps

Connect

Connect identity consumers with:

  • Existing identity services
  • Application and service owners
  • Data owners and stewards
  • Subject matter experts
  • Architecture guidance
  • Institutional requirements

Accelerate

Help teams move from identity requirements to implementation by providing:

  • Proven approaches
  • Reusable patterns
  • Architecture guidance
  • Integration recommendations
  • Early identification of identity dependencies

The goal is to reduce friction, improve consistency, and make appropriate access easier to implement and support.


Scope

The Identity Practice focuses on architecture and guidance related to:

  • Digital identity architecture
  • Authentication
  • Authorization
  • Single sign-on
  • Multi-factor authentication
  • Account and identity lifecycle management
  • Role and group management
  • Access provisioning and removal
  • Privileged access
  • Service and application identities
  • Workload and agent identities
  • External and guest identities
  • Federated identity
  • Identity integration patterns
  • Access logging and auditability
  • Identity ownership and accountability

Out of Scope

The Identity Practice does not:

  • Operate all identity services
  • Provision or remove every account
  • Approve every access request
  • Determine who has a business need for data
  • Own university data
  • Own application permissions
  • Replace service owners or system administrators
  • Replace human resources, student, affiliate, or other source-system processes
  • Replace security, privacy, compliance, or policy authorities

The practice provides architecture guidance and stewardship.

Access decisions, data decisions, policy decisions, and operational ownership remain with the appropriate stakeholders.


Deliverables

Standards

Examples:

  • Authentication standards
  • Identity integration standards
  • Privileged identity standards
  • Service identity standards
  • Identity logging standards
  • Account lifecycle standards

Patterns

Examples:

  • Single sign-on pattern
  • Multi-factor authentication pattern
  • Role-based access pattern
  • Privileged access pattern
  • Service identity pattern
  • Application identity pattern
  • External user access pattern
  • Workload identity pattern

Reference Architectures

Examples:

  • Enterprise identity architecture
  • Application authentication architecture
  • Privileged access architecture
  • External identity architecture
  • Hybrid identity architecture

Architecture Decision Records

Examples:

  • Authentication method decisions
  • Authorization model decisions
  • Identity source decisions
  • Service account decisions
  • Federation decisions
  • Privileged access decisions

Roadmaps

Examples:

  • Identity platform evolution
  • Authentication capability maturity
  • Identity lifecycle improvements
  • Privileged access improvements
  • Strategic identity capabilities

Relationship to Services

The Identity Practice and identity services are related but distinct.

The Identity Practice stewards architecture knowledge.

Services provide operational capabilities.

Identity Practice Identity Service
Authentication standards Authentication Service
Single sign-on patterns Single Sign-On Service
Multi-factor authentication patterns Multi-Factor Authentication Service
Account lifecycle guidance Account Provisioning Services
Directory architecture guidance Directory Services
Privileged access patterns Privileged Access Services
External identity guidance Guest and External Access Services

A practice may inform one or more services.

A service may be influenced by multiple practices.

Practice stewardship does not imply operational ownership of an identity service.

Operational ownership of an identity service does not automatically imply stewardship of the Identity Practice.

The same individual may participate in both.


Relationship to Other Practices

The Identity Practice works across other Enterprise Architecture practices.

Practice Relationship to Identity
Cloud Practice Uses identity guidance for cloud access, privileged roles, service identities, and workload identities.
AI Practice Uses identity guidance for users, applications, agents, data access, and accountable actions.
Integration Practice Uses identity guidance for API authentication, service authorization, credentials, and system-to-system access.

The Identity Practice does not replace these practices. It provides shared identity guidance that they can apply within their respective areas.


Stewardship

The Identity Practice is maintained through the Enterprise Architecture stewardship model.

The practice may include:

  • A Practice Steward
  • Practice Contributors

Contributors may be drawn from teams responsible for identity services, enterprise applications, cloud platforms, infrastructure, integration, security, support, and other relevant capabilities.

The practice may be active, emerging, or unassigned depending on organizational need.

Participation does not require a dedicated team or full-time role.

The Identity Practice may be established before a permanent steward is assigned. An unassigned practice makes the need for identity architecture stewardship visible without transferring operational ownership from existing teams.


Success Measures

The Identity Practice is successful when:

  • Identity and access decisions become easier to make.
  • Teams can find clear guidance for common identity needs.
  • Reusable patterns reduce repeated effort.
  • Identity integrations become more consistent.
  • Access is connected to identifiable users, applications, services, or processes.
  • Identity lifecycle responsibilities become clearer.
  • Privileged access is easier to identify and manage.
  • Teams engage the appropriate stakeholders earlier.
  • Lessons learned are documented and reused.
  • Identity capabilities are easier to support and evolve.

Details

Details

Article ID: 2230
Created
Wed 9/30/26 5:57 PM
Audience
Staff