Save this.
1. Provisioning
The process of creating and configuring a user account in a target system. When a new employee joins and their laptop account, email, and application access are set up, that is provisioning.
2. Deprovisioning
The reverse. Removing access when someone leaves or changes roles. The most common IAM failure point in most organisations.
3. Entitlement
A specific unit of access, a role, a group membership, a permission. When you talk about what a user has access to, you are talking about their entitlements.
4. Identity Governance
The discipline of making sure access is appropriate, reviewed, and auditable. Access certification campaigns, SoD policy enforcement, and audit reporting all fall under governance.
5. Target System
Any system that the IAM platform provisions accounts into, Active Directory, a cloud application, an HR platform, a database. Everything downstream of the IAM tool is a target system.
These five terms come up in every IAM role, every interview, and every client conversation. Knowing them precisely, not just roughly, is what separates someone who has read about IAM from someone who works in it.
Which of these was new to you? Let me know in the comments.