One Identity For Life is an identity governance approach that links every record associated with one person into a single authoritative identity. It gives security and IAM teams a persistent view of roles, access, and risk across systems, which helps reduce duplication, improve control decisions, and support lifecycle continuity.
What One Identity For Life Means in practice
One Identity For Life is best understood as an identity governance model, not a single database feature. The core idea is to keep one authoritative person record that can absorb many system-specific accounts, so security teams can reason about access, role changes, and risk against the same person over time.
This matters because most environments accumulate duplicate identities, stale entitlements, and inconsistent ownership as people move roles or systems. A persistent identity layer helps reduce ambiguity in approval, review, and remediation workflows, especially when a person appears in multiple business applications, directories, or SaaS platforms.
How the model changes identity governance
The governance value is continuity. Instead of treating each account as an isolated object, the model ties activity back to the person behind it, which makes access review, joiner-mover-leaver processing, and entitlement analysis more reliable. That is especially useful when access decisions need to account for historic roles, inherited access, or exceptional permissions.
It also creates a cleaner basis for control decisions. When one identity aggregates multiple records, teams can spot duplication, orphaned access, overlapping privileges, and lifecycle gaps more quickly. In practice, that supports stronger visibility across identity stores, target applications, and downstream workflows.
Why it matters for access control and lifecycle continuity
One Identity For Life is strongest where identity sprawl would otherwise weaken control. A persistent identity view supports least privilege by showing what a person should have now, what they had before, and what should be removed as their role changes. It also helps reduce the common problem where a new account is created while the old one remains active and forgotten.
The model is also useful for auditability. If access decisions are based on a stable identity, then reviews, certifications, and investigations can connect historical access to a single person rather than reconciling fragments across systems. For broader background on identity lifecycle and governance, see NHI Lifecycle Management Guide.
Where it fits in the wider identity stack
This approach sits above the individual accounts, credentials, and application permissions that people actually use. It does not replace authentication, access control, or directory services; it gives them a more coherent governance layer. That distinction matters because the value comes from identity correlation and decision support, not from changing how every downstream system authenticates users.
It is especially relevant in mixed environments with HR data, cloud apps, SaaS, and legacy systems, where one person may hold several identifiers. The model helps normalize those records into a single view for policy, reporting, and oversight. For a broader reference point on non-human identity governance patterns that overlap with identity lifecycle thinking, see Ultimate Guide to NHIs.
Risk and Threat Considerations
When identity records are fragmented, organisations lose visibility into who really has access and which permissions are still active. That creates a practical risk of duplicate entitlements, orphaned accounts, and delayed revocation, all of which can increase exposure during role changes, departures, or investigations.
Failure mechanism: Multiple records for the same person break the link between governance decisions and real access, so reviews miss stale accounts, excessive permissions, and incomplete offboarding.
Impact: Attackers and insiders can exploit leftover access paths, while defenders may misjudge privilege, ownership, or accountability during incident response and audit.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8, NIST CSF 2.0, NIST SP 800-53 Rev 5 and CSA Cloud Controls Matrix set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-5 — Account Management | Centralises account ownership and lifecycle control across duplicate records. |
| Recommendation — Inventory accounts and tie them to one governed identity record for review and removal. | ||
| NIST CSF 2.0 | ID.AM-01 — Identity Inventory | Supports maintaining an accurate inventory of identities and their relationships. |
| Recommendation — Keep a current inventory that maps each person to all associated accounts and entitlements. | ||
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Defines account lifecycle governance that benefits from one authoritative person record. |
| Recommendation — Link provisioning, review, and termination decisions to the authoritative identity record. | ||
| ISO/IEC 27001:2022 | A.5.16 — Identity Management | Requires governance of identity information that One Identity For Life consolidates. |
| Recommendation — Maintain a single governed identity record to support access and lifecycle control. | ||
| CSA Cloud Controls Matrix | IAM — Identity & Access Management | Directly covers identity lifecycle, access governance, and identity correlation. |
| Recommendation — Use a unified identity view to govern access reviews, lifecycle changes, and ownership. | ||
Practitioner Guidance
Governance implication: Treat the authoritative person record as a governed control object, not just a directory cleanup task. The practical question is whether every downstream account, entitlement, and exception can be reliably traced back to one current identity.
Practitioner takeaway: The model only works when identity correlation is maintained continuously, because a stale master record is just a more organised form of the same risk.