بدون IAM منسجم، هر سامانه حساب جدا، نقش مبهم و دسترسی فراموششده دارد. این پروژه لایهٔ هویت مرکزی ساخت: تعریف کاربر، نقش، دسترسی، تأیید، بازبینی دورهای و قطع خودکار هنگام خروج از سازمان.Without coherent IAM, every system has separate accounts, fuzzy roles and forgotten access. This project built a central identity layer: users, roles, entitlements, approvals, periodic access reviews and automatic offboarding.
چه مشکلی را حل کردیم؟What problem did we solve?
- حسابهای یتیم پس از جابهجایی یا ترک نیروOrphan accounts after transfers or exits
- اعطای دستی و کند دسترسی در سامانههای متعددSlow manual provisioning across many systems
- نبود مدل نقش استاندارد (RBAC/ABAC)No standard role model (RBAC/ABAC)
چه پیادهسازی شد؟What was implemented?
- منبع حقیقت هویت و همگامسازی با HR / DirectoryIdentity source of truth synced with HR / directory
- مدل نقشها، گروهها و سیاست حداقل دسترسیRoles, groups and least-privilege policies
- Provisioning / Deprovisioning خودکار به اپهای کلیدیAutomated provisioning and deprovisioning to key apps
- بازبینی دسترسی دورهای برای مدیران و ممیزیPeriodic access reviews for managers and auditors
- داشبورد مالکیت دسترسی و هشدار انحراف از سیاستAccess-ownership dashboards and policy-drift alerts
نتیجه برای سازمانBusiness outcome
آنبوردینگ سریعتر، خروج امنتر، و برای امنیت دیدی واحد از «چه کسی به چه چیزی دسترسی دارد» ایجاد شد.Faster onboarding, safer offboarding, and one clear view for security of who can reach what.