Provisioning and Deprovisioning
Provisioning is the process of creating user accounts and granting people the access they need to an organization's applications and systems, typically based on their role. Deprovisioning is the reverse: removing or disabling that access when it is no longer valid, such as when someone changes roles or leaves the organization. Together, these processes help keep digital identities consistent and appropriate across the many systems a person may use.
Provisioning and deprovisioning are the lifecycle processes that create, update, and remove user accounts and their associated entitlements across multiple applications and systems, ensuring consistency of digital identities. Provisioning creates and configures access based on role or policy and can propagate accounts across connected systems, often simultaneously; deprovisioning revokes that access when it is no longer valid, ideally at the moment of a role change or separation to limit lingering access. In practice these processes are typically driven by identity governance and administration tooling and coordinated with authoritative sources such as HR systems, though the specific automation, connectors, and provisioning rules vary by provider and platform. From a security leadership perspective, a virtual or fractional CISO would treat provisioning and deprovisioning as governance and access-control controls to be defined and overseen rather than operated hands-on, since account administration and tool configuration are generally out of scope for advisory engagements unless explicitly contracted; accountability for enforcing these controls remains with the client organization.
Why it matters
Provisioning and deprovisioning sit at the center of an organization's access-control posture. When these processes are inconsistent or manual, access tends to accumulate over time: users pick up entitlements as they change roles but rarely lose the ones they no longer need, and accounts belonging to departed employees or contractors may linger long after separation. These orphaned and over-privileged accounts expand the attack surface, and they are a common target because a dormant but still-active account often escapes routine monitoring. Timely deprovisioning at the moment of a role change or separation is one of the more direct ways to limit lingering access.
From a security leadership perspective, provisioning and deprovisioning are governance and risk questions before they are technical ones. A virtual or fractional CISO typically treats these as controls to be defined, documented, and overseen, establishing role-based access policies, identifying authoritative sources of truth such as HR systems, and setting expectations for how quickly access is revoked, rather than operating the tooling directly. Account administration and connector configuration are generally out of scope for an advisory engagement unless explicitly contracted, and accountability for enforcing these controls remains with the client organization and its officers.
The value of well-governed provisioning depends heavily on organizational context. It requires cooperation across HR, IT, and application owners, a defined joiner-mover-leaver process, and access to the stakeholders who own the connected systems. In organizations with low identity maturity, the primary gap is often the absence of an authoritative source and a documented offboarding workflow, not the absence of a tool. A security leader's contribution is frequently to surface these gaps and establish the governance that makes automation meaningful, rather than to assume that purchasing a platform resolves the underlying process weaknesses.
Who it's relevant to
Inside Provisioning and Deprovisioning
Common questions
Answers to the questions practitioners most commonly ask about Provisioning and Deprovisioning.