Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
daemon-blockint-tech avatar

Iam Specialist

  • 27 installs
  • 7 repo stars
  • Updated May 20, 2026
  • daemon-blockint-tech/agentic-enteprises-skill

Guides identity and access management: workforce/machine identity lifecycle, RBAC/ABAC/PBAC design, access reviews, SSO federation, PAM/JIT, and cloud IAM least privilege.

About

Guides IAM work across identity lifecycle, entitlement modeling, access reviews, SSO/SAML/OIDC federation, privileged access, and cloud IAM least privilege. A developer uses it when designing RBAC/ABAC, running recertification campaigns, or authoring cloud IAM policies.

  • Least-privilege RBAC/ABAC/PBAC entitlement modeling
  • Separation-of-duties matrices with toxic-combination detection

Iam Specialist by the numbers

  • 27 all-time installs (skills.sh)
  • Ranked #1,533 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Jul 29, 2026 (Skillselion catalog sync)
npx skills add https://github.com/daemon-blockint-tech/agentic-enteprises-skill --skill iam-specialist

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs27
repo stars7
Last updatedMay 20, 2026
Repositorydaemon-blockint-tech/agentic-enteprises-skill

What it does

Guides identity and access management: workforce/machine identity lifecycle, RBAC/ABAC/PBAC design, access reviews, SSO federation, PAM/JIT, and cloud IAM least privilege.

Files

SKILL.mdMarkdownGitHub ↗

IAM Specialist

When to Use

  • Design workforce and machine identity lifecycle — joiner/mover/leaver, contractors, service principals
  • Model RBAC, ABAC, or PBAC entitlements, roles, and permission sets with least privilege
  • Run access reviews and recertification — campaigns, risk-based sampling, manager attestation
  • Architect SSO federation — SAML, OIDC, SCIM provisioning, app onboarding patterns
  • Implement privileged access — PAM vaulting, JIT elevation, session recording, break-glass policy
  • Author cloud IAM roles, policies, permission boundaries, trust relationships (AWS/GCP/Azure)
  • Govern service accounts and secrets — naming, rotation, no human keys, workload identity
  • Define separation of duties matrices and toxic-combination detection
  • Align IAM controls to audit and risk narratives (with GRC partners)

When NOT to Use

  • Multi-BU landing zone, CCoE, EA, or executive cloud governance → enterprise-cloud-architect
  • Org SCPs, CSPM, network segmentation, KMS program, detective controls → cloud-security-engineer
  • Access ticket fulfillment, key rotation runbooks, patching, restores → cloud-system-administrator
  • VPC/RDS/serverless build without IAM as primary deliverable → cloud-engineer
  • SIEM/EDR deployment, WAF, broad security tooling → information-security-engineer
  • SOC 2 evidence pipelines and automated control checks → compliance-engineer
  • CI OIDC and pipeline scan gates only → devsecops
  • Inherent/residual risk scoring and risk register → security-risk-analyst
  • Authorized exploitation or pentest validation → penetration-tester
  • Legal interpretation, employment policy, or contract redlines → commercial-counsel

Related skills

NeedSkill
Cloud org guardrails, CSPM, network/KMS securitycloud-security-engineer
Cloud resource build and workload identity wiringcloud-engineer
Day-2 IAM tickets, rotation, break-glass executioncloud-system-administrator
Enterprise landing zone and CCoE governanceenterprise-cloud-architect
SIEM, EDR, encryption, security-as-code guardrailsinformation-security-engineer
GRC program, framework scope, audit coordinationcompliance-specialist
Audit evidence automation from IdP and cloud APIscompliance-engineer
CI/CD OIDC federation and pipeline least privilegedevsecops
Risk register, treatment, and executive heat mapssecurity-risk-analyst
Cloud framework evidence and residency packagescloud-compliance-specialist
Security program strategycybersecurity

Core Workflows

1. Scope and governance model

Identity domains, RACI, and boundaries vs cloud security and ops.

See `references/iam_specialist_scope.md`.

2. Identity lifecycle and access governance

Joiner/mover/leaver, provisioning, reviews, and exceptions.

See `references/identity_lifecycle_and_governance.md`.

3. Entitlements and authorization models

RBAC/ABAC/PBAC design, role engineering, and SoD.

See `references/rbac_abac_and_entitlements.md`.

4. Federation and SSO protocols

SAML, OIDC, SCIM, and SaaS onboarding.

See `references/federation_sso_and_protocols.md`.

5. Privileged access and PAM

JIT, vaulting, break-glass, and session controls.

See `references/privileged_access_and_pam.md`.

6. Cloud IAM and least privilege

Cross-cloud IAM patterns, policy review, and machine identity.

See `references/cloud_iam_and_least_privilege.md`.

Outputs

  • Entitlement catalog — roles, permissions, owners, review cadence
  • Access review campaign — scope, attestations, remediation tracker
  • Federation design — trust, claims, MFA, provisioning flow
  • PAM policy — elevation paths, approval, monitoring, break-glass
  • Cloud IAM policy set — least-privilege JSON with trust boundaries documented
  • SoD matrix — incompatible duties, compensating controls, exceptions
  • Service account standards — creation, rotation, audit queries

Principles

  • Identity is the perimeter — authenticate strongly; authorize minimally
  • No standing privilege — prefer JIT and time-bound elevation for admin
  • Prove every grant — reviews, logs, and SoD checks on sensitive entitlements
  • Humans ≠ machines — separate lifecycle, credentials, and audit trails
  • Federation fails closed — misconfigured trust denies access; monitor sync errors
  • Break-glass is rare, logged, and reviewed — not a daily admin shortcut

Related skills

Securitysecretsaudit

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.