IAM delivery and operations

IAM Rollback

An IAM rollback is a back-out plan that restores an acceptable service state when an identity change produces unexpected effects.

Synonym
back-out planfallback plan

Definition

IAM rollback applies to a migration, a go-live, an access policy change, a new federation, a connector, an upgrade or a configuration change. What makes it specific is that an IAM change does not only alter the platform: it alters the state of the wider information system. Provisioning may have created accounts, deprovisioning may have removed them, an authorization rule may have withdrawn entitlements across several applications. Some changes are therefore not strictly reversible and require a compensation strategy: replay, reconciliation, targeted restore or break-glass procedure. A useful rollback plan states the point of no return, the trigger criteria, who decides and how long the plan stays valid.

Why it matters

Without a realistic back-out plan, an IAM go-live commits the organisation well beyond the risk it thought it was accepting.

The Ariovis perspective

"We will restore the backup" is not always an IAM rollback plan. Provisioning may have created accounts, deprovisioning may have deleted them, a policy may have changed entitlements in several applications. Backing out must therefore be designed around the functional state of the information system, not only the technical state of the IAM platform.

Common pitfalls

  • A common mistake is treating a platform backup as a rollback plan, when the effects of the change have already propagated into applications.

These concepts matter most inside a real project.

The first conversation helps establish your context, the systems involved and the next useful decision.