Just-in-Time Provisioning
Just-in-Time Provisioning is the creation of an account or identity record only when access is actually requested or first used.
- Acronym
- JIT
- Synonym
- JIT Provisioning
Definition
Just-in-Time Provisioning, often abbreviated JIT Provisioning, is a model in which a user account, local identity record, or target system profile is created dynamically at the moment of first successful access or federation event instead of being pre-created administratively. This model is common in SaaS, B2B federation, and modern workforce identity scenarios where users are trusted through an upstream identity provider and provisioned locally only when needed. JIT can reduce unused accounts and accelerate onboarding, but it requires careful design around attribute mapping, default access, lifecycle ownership, and deprovisioning behavior. It also raises governance questions when accounts appear without explicit prior approval in the target system.
Why it matters
JIT Provisioning supports agility and integration efficiency, especially in federated and distributed environments.
The Ariovis perspective
Ariovis promotes automation that remains explainable and recoverable: explicit rules, approvals where needed, logs, error handling and recovery mechanisms.
Related services
Common pitfalls
- A common pitfall is enabling JIT without controlling what default access is granted, who owns the resulting accounts, and how they are later cleaned up.
Standards and protocols
- SAML
- OIDC
Related terms
Explore this category
These concepts matter most inside a real project.
The first conversation helps establish your context, the systems involved and the next useful decision.