Term · 9. Business Processes & Methodology
Aggregation Aggr
Definition
Process of collecting account and entitlement data from target systems into the IGA platform. Foundation for reconciliation, correlation, certification, and compliance reporting. Frequency: typically nightly batch; modern deployments increasingly event-driven (real-time webhook).
- Application
- Performance-critical for large estates — IGA platforms tune aggregation schedules per system based on change rate. Failed aggregation = IGA platform view diverges from reality (security/compliance risk).
- Standards & regulations
-
- NIST SP 1800-35B (preliminary draft 3, 2023) «SailPoint connects to enterprise resources to **aggregate accounts** and correlate with authoritative records to build a foundational identity profile from which access and activity can be governed an»
- NIST SP 1800-35B (preliminary draft 2, 2022) «The IIQ IGA platform connects to enterprise resources to **aggregate accounts and entitlements** and correlate them with authoritative records to build a foundational identity profile for governance a»
- NIST SP 1800-35A (Zero Trust Architecture, Vol. A – Project Overview) «The IGA component ingests identity and account information from enterprise directories and applications, **aggregating accounts and entitlements** to support correlation, certification, and policy-bas»
Related terms
-
Approval Route
Defined sequence of approvers an access request must traverse before fulfillment — typically manager → role owner → secu …
-
Approval Timeout
Maximum time an approver has to respond before request escalates or auto-decides. Typical settings: 3-5 business days fo …
-
Birthright (BR)
Baseline access granted automatically to every identity of a specific type — typically minimal access required to functi …
-
Delegated Administration (DA)
Permission model where administrators delegate specific management functions to other users within scoped boundaries — t …
-
Deprovisioning (Deprov)
Removal of an identity's access from a target system — typically triggered by termination (Leaver), role change (Mover), …
-
Entitlement Creep
Gradual accumulation of access rights beyond what's needed for current job, as users change roles without losing prior a …