Provisioning

Reconciliation

Reconciliation is the process of comparing expected identity and access state with the actual state observed in target systems.

Definition

Reconciliation is the control process by which an IAM platform collects data from connected systems and compares the observed accounts, entitlements, and attributes against the expected state defined by identity records, policies, approvals, and provisioning logic. It is used to detect drift, missing access, unauthorized changes, orphan accounts, failed deprovisioning, and inconsistent attribute values. Reconciliation may be periodic, event-driven, or targeted to sensitive systems. It is fundamental to closed-loop IAM because provisioning alone does not guarantee that the target system actually reflects the intended state.

Why it matters

Reconciliation is what allows organizations to verify that provisioning outcomes match governance intent and that unexpected access has not appeared.

The Ariovis perspective

Reliable lifecycle and access decisions depend on trusted identifiers, clearly owned sources and controlled data quality. Automation should not accelerate inconsistent data.

Related services

Common pitfalls

  • A common mistake is assuming connector success means the target state is correct, without independently reconciling the actual system data.

These concepts matter most inside a real project.

The first conversation helps establish your context, the systems involved and the next useful decision.