Join our Newsletter — 33% off our NHI Course
Home› Glossary› NHI Lifecycle Management› Identity Sunset
NHI Lifecycle Management

Identity Sunset

← Back to Glossary
By NHI Mgmt Group Updated September 25, 2026 Domain: NHI Lifecycle Management

Identity sunset is the practice of disabling or retiring an identity instead of deleting it outright when a person leaves. The record remains available for future reactivation or lifecycle continuity, which supports compliance, auditability, and cleaner re-entry when the same individual returns in a new capacity.

What Identity Sunset Means in Identity Lifecycle

Identity sunset is not the same as immediate deletion. It preserves the identity record in a disabled or retired state so the organisation can prove what existed, when access ended, and whether the same person later returned.

The operational value is lifecycle continuity: teams can re-enable the record if business rules allow, preserve historical linkage for audits, and avoid creating duplicate identities that fragment history across HR, IAM, and access review records.

Why Identity Sunset Exists

The term reflects a practical compromise between disposal and retention. If an identity is deleted too aggressively, organisations can lose the audit trail that explains prior access, ownership, entitlements, approvals, and separation events. If it is left active, it creates unnecessary exposure.

Used well, identity sunset supports joiner-mover-leaver discipline, especially where employees, contractors, or consultants may return later. That continuity also helps reconcile rehire cases, preserve reporting lineage, and keep identity governance cleaner over time. For broader non-human lifecycle patterns, NHIMG’s Ultimate Guide to NHIs covers the same lifecycle logic in adjacent identity contexts.

Identity Sunset vs Deletion

Deletion is irreversible account disposal. Identity sunset is a controlled retirement state that removes standing access while retaining the record for governance, investigation, and reactivation decisions. That distinction matters because identity records often anchor approvals, access history, and entitlement evidence.

The strongest versions of the practice keep the record non-usable but recoverable, with clear ownership over whether reactivation is allowed and under what conditions. In modern cloud and service environments, the same pattern appears in machine and workload identity governance, where re-entry, rotation, and historical traceability all matter. The broader NHI lifecycle view is described in OWASP Non-Human Identity Top 10 and in the NIST SP 800-63 Digital Identity Guidelines for identity lifecycle and assurance concepts.

Where Identity Sunset Fits in Governance

Identity sunset sits inside identity governance, not just offboarding. It affects retention policy, record ownership, reactivation criteria, access review closure, and how evidence is preserved for compliance or internal investigation.

It also reduces the chance that retired identities are confused with active ones. That matters when auditors, managers, or automation later need to answer whether a person still had an organisational relationship, whether prior access was appropriately terminated, and whether a rehire should inherit any legacy state. In practice, it is a lifecycle control with governance consequences, not simply a cleanup task.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5PS-4 — Personnel TerminationIdentity sunset retains terminated-user records while disabling access and preserving evidence.
AC-2 — Account ManagementIdentity sunset is an account lifecycle state change governed by provisioning, disablement, and reactivation.
AU-11 — Audit Record RetentionSunset identities are kept for traceability, so related audit evidence must remain available.
Recommendation — Retain terminated identities in a disabled state and preserve separation evidence for review. Use account lifecycle controls to disable, retain, and re-enable identities under defined approval rules. Retain audit records that link retired identities to prior access and lifecycle events.
ISO/IEC 27001:2022A.5.18 — Access rightsIdentity sunset supports controlled removal, retention, and review of access rights across the identity lifecycle.
A.5.33 — Protection of recordsIdentity sunset keeps records available for auditability and later reactivation decisions.
Recommendation — Review and revoke access rights while preserving the identity record needed for lifecycle governance. Protect retired identity records so they remain trustworthy and retrievable for governance purposes.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 25, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org