Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Consider "inactivity" in Identity Management requirements / levels #39

Open
ameyah opened this issue Jan 18, 2025 · 1 comment
Open

Comments

@ameyah
Copy link

ameyah commented Jan 18, 2025

"Staleness" of SaaS accounts (or entitlements / roles / privileges) may be helpful in lifecycle governance in an organization. Some apps offer this capability through custom APIs / native app portals, but is not consistent.

Proposal - app communicates "last use" timestamp to IdP per account / entitlement pair.

@dhs-BI
Copy link
Contributor

dhs-BI commented Jan 21, 2025

As we discussed on this morning's call, this is an interesting idea. The RP is the only system that would have a definitive "last used" date for a user.

Since IPSIE is trying to profile existing standards rather than create new standards, our charter says that we'll try to find a home for any non-standardized functionality before considering adding it to the IPSIE WG scope. Is there an existing standards WG where this kind of metadata and related APIs could be standardized?

This kind of signal might be appropriate for the SSF working group to consider. @openid/wg-sharedsignals-chairs can you please take a look at this issue and let us know if this fits in the SSF WG existing/future workstreams.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants