- 01
Authoritative signal — HR feed, CSV, webhook, or test termination event
- 02
One Identity source — Okta, Entra, AD, Workday, etc.
- 03
One target system — AD, AWS, Salesforce, ServiceNow, legacy app, etc.
- 04
Outbound network path — approval for mTLS dial-out (zero inbound ports)
- 05
Test population — at least one leaver/test account + approver