Papers
Frameworks built to be picked up and used.
Longer-form, citable work: named metrics, reference models, and methodology built to be reused. Published openly, and indexed on SSRN.
The tools handle granting and removing access. This framework covers everything around them: six layers in build order, forty-seven numbered decisions, the failure modes that show where a program is broken, and four metrics that read whether it responds. Versioned, open for review, and citable by decision identifier.
IAM teams cite ISO and NIST to defend their work, and the citations do not always match what the documents say. This reference maps the four ways a citation fails, the wrong concept, the wrong document, the stale edition, and the invented requirement, each worked against the primary source, with guidance on defending it to an auditor.
Operational IGA metrics measure whether governance work happened, not whether the program is keeping pace with how fast access changes. This paper proposes four named, program-level metrics for governance responsiveness, the way DORA metrics did for software delivery, applied to human and non-human identity alike.