Skip to main content
Category: Access and Security

Identity and Credential Management

Also known as: ICM, Identity, Credential, and Access Management, ICAM, Credential Management
Simply put

Identity and credential management refers to the policies, programs, and technologies used to create, secure, and eventually retire the digital identities and credentials that people and systems use to access resources. An identity is the enduring description of a user or entity within a system, such as a name, employee number, or role, while a credential is the movable evidence, such as a password or token, presented to prove that identity when access is requested. Together these practices help organizations control who or what may access systems and information.

Formal definition

Identity and credential management is a domain of policies, programs, and technologies concerned with the lifecycle management of digital identities and the credentials associated with them, for both human users and non-human identities. It encompasses the creation and maintenance of identities (typically enduring attributes such as name, identifier, and role) and the creation, securing, and retirement of credentials (the evidence presented at each authentication event). In practice it is often described as a component of the broader Identity, Credential, and Access Management (ICAM) framework, which also addresses authentication, authorization, privileges, and secure access to resources across systems and platforms. As a distinct concept, identity and credential management should not be conflated with access management or authorization decisions themselves, which govern what an authenticated identity is permitted to do. Its scope, implementation, and applicable requirements vary by organization, sector, and jurisdiction.

Why it matters

For records and information governance professionals, identity and credential management underpins the trustworthiness of the access controls that protect records throughout their lifecycle. The authenticity and integrity of a record depend in part on being able to establish who created, modified, or accessed it, and on preventing unauthorized parties from doing so. Where identities are poorly managed or credentials are weakly secured, the evidential value of records may be undermined, since it becomes harder to demonstrate reliably that a record was handled only by authorized individuals or systems.

Because identity and credential management often forms part of the broader Identity, Credential, and Access Management (ICAM) framework, it is closely tied to organizational cybersecurity and to the secure access of resources across existing and emerging systems. Effective management of the identity and credential lifecycle, from creation through securing to retirement, helps reduce the risk that dormant accounts or unretired credentials remain available for misuse. This is relevant not only to human users but also to non-human identities, such as service accounts and automated processes, which may also require access to records and information.

The specific obligations surrounding identity and credential management vary by organization, sector, and jurisdiction. Depending on applicable requirements, organizations may need to demonstrate that access to sensitive or regulated records is appropriately controlled and auditable. As a matter of scope, identity and credential management concerns establishing and proving identity rather than determining what an authenticated identity is permitted to do; the latter falls to access management and authorization, which are distinct concerns.

Who it's relevant to

Records managers
Records managers rely on sound identity and credential management to help ensure that access to records is limited to authorized identities, supporting the authenticity and integrity of records as evidence of activity. Understanding where identity and credential management ends and access authorization begins helps clarify which controls govern who can reach a record and which govern what they may do with it.
Information governance officers
Because information governance spans policy, risk, privacy, and security, officers in this role may treat identity and credential management as one element within a broader accountability framework. It is often positioned within the wider ICAM framework, and its scope and requirements typically vary by organization, sector, and jurisdiction.
Security and IT professionals
Identity and credential management is frequently described as an important cybersecurity domain that supports secure access to resources across existing systems and emerging platforms. Security and IT staff are commonly responsible for the technologies that create, secure, and retire credentials for both human users and non-human identities.
Compliance leads
Compliance leads may need to consider how identity and credential management supports demonstrable, auditable control over access to regulated or sensitive information. The applicable obligations depend on jurisdiction and sector, so requirements should be assessed against the organization's specific operating context rather than a single universal standard.

Inside ICM

Identity
The set of attributes that distinguishes an individual, system, or service acting within an information environment. In recordkeeping contexts, identity underpins accountability by linking actions such as creation, capture, or disposition of records to a specific actor.
Credential
An artifact, such as a password, token, certificate, or biometric factor, that is used to assert or verify a claimed identity. Credentials are the means by which an identity is authenticated, and their reliability affects the trustworthiness of any actions attributed to that identity.
Authentication
The process of verifying that a claimed identity is genuine, typically by validating one or more credentials. Authentication supports the authenticity and reliability properties expected of records by confirming who performed a given recordkeeping action.
Authorization
The determination of what an authenticated identity is permitted to do, often expressed through access rights or roles. Authorization is distinct from authentication; the former concerns permitted actions while the latter concerns proof of identity.
Provisioning and Deprovisioning
The lifecycle activities of creating, modifying, and removing identities and their associated credentials and access rights. Timely deprovisioning is often important to prevent unauthorized access to records once an individual's role or relationship changes.
Access Control
The mechanisms that enforce authorization decisions, governing which identities may view, alter, or dispose of records. Access control contributes to the integrity and usability of records by limiting actions to authorized parties.
Audit and Accountability Trails
Records of authentication and access events that link actions to identities over time. These trails support the evidential value of recordkeeping systems by demonstrating who did what and when, though their own reliability depends on how they are protected.

Common questions

Answers to the questions practitioners most commonly ask about ICM.

Is identity and credential management the same as authentication and access control?
Not exactly. Identity and credential management concerns the establishment, verification, maintenance, and eventual retirement of identities and their associated credentials. Authentication and access control are related processes that consume those identities and credentials to confirm a claimed identity and to determine what actions are permitted. In a recordkeeping context, credential management is often a prerequisite for access control rather than being identical to it. The distinction matters because identity assurance underpins the trustworthiness of the audit trail, while access control governs the permitted interactions with records. Depending on organizational policy, these functions may be delivered by the same system or by separate components.
Does managing credentials on its own guarantee the authenticity of a record?
No. Robust credential management can strengthen the evidence that a particular identity performed an action, which supports assessments of a record's authenticity and reliability. However, authenticity as a recordkeeping property also depends on integrity controls, reliable capture, accurate metadata, and defensible processes across the record's lifecycle. Credential management contributes to, but does not by itself establish, that a record is what it purports to be. Overreliance on credential controls alone, without corresponding integrity and metadata safeguards, may leave gaps that undermine the evidential value of records.
How should identity and credential events be captured for recordkeeping purposes?
In many organizations, significant identity and credential events, such as the creation, modification, suspension, or revocation of credentials, are logged so that actions affecting records can be attributed to a responsible identity. Whether these logs are themselves treated as records subject to retention and disposition typically depends on organizational policy, applicable standards, and jurisdictional or sector requirements. It is generally advisable to define which events warrant capture, the metadata to be retained, and how those logs relate to the audit trails of the records they support.
What happens to attribution when a person leaves and their identity is deprovisioned?
When an identity is deprovisioned, the credentials are typically disabled to prevent further access, but the historical association between that identity and past actions on records often needs to be preserved to maintain the integrity of the audit trail. Reassigning or reusing identifiers can create ambiguity about who performed earlier actions. Depending on organizational policy, practices such as retaining unique identifiers, avoiding reuse, and preserving relevant identity metadata are commonly used so that attribution remains defensible after an individual departs.
How do retention obligations apply to credential and identity records?
Records relating to identities and credentials may be subject to retention requirements that differ from those governing the substantive records they help control. Retention periods and disposition treatment often depend on jurisdiction, sector, and the purpose the identity records serve, such as security, accountability, or privacy compliance. It is worth noting that retention is not the same as indefinite storage; disposition of identity records may involve transfer, permanent preservation, or destruction according to an approved schedule. Privacy obligations in many jurisdictions may also constrain how long personal identity data can be kept.
How does identity and credential management support legal holds and disposition freezes?
Where a legal hold or disposition freeze is in effect, the ability to attribute actions reliably to identities can be important for demonstrating who accessed or altered records during the relevant period. Credential and identity logs may fall within the scope of a hold if they constitute relevant evidence, though whether they do depends on the matter and the applicable jurisdiction. Coordinating credential management with hold processes typically helps ensure that identity-related information is not deprovisioned or purged in ways that would compromise a defensible position, subject to organizational policy and legal advice.

Common misconceptions

Authenticating a user is the same as controlling what they can do with records.
Authentication and authorization are distinct. Authentication verifies a claimed identity, while authorization determines the actions that identity may perform. A system may correctly authenticate an individual yet still need separate controls to constrain their access to particular records.
Strong identity and credential controls make a captured item an authoritative record by themselves.
Identity and credential management supports properties such as authenticity and reliability, but it does not on its own make something a record. Whether an item is an authoritative record, a copy, a draft, or transitory information depends on additional recordkeeping factors beyond who accessed or created it.
Once an identity is provisioned and authenticated, ongoing management is unnecessary.
Identity and credential management is a lifecycle activity. Roles change, relationships end, and credentials can be compromised, so provisioning, modification, and timely deprovisioning are typically ongoing responsibilities rather than one-time steps.

Best practices

Distinguish authentication from authorization in policy and system design, so that verifying identity and granting access to records are handled as separate, deliberate controls.
Review provisioning and deprovisioning processes regularly to ensure that credentials and access rights are removed promptly when an individual's role or relationship changes.
Protect audit and accountability trails so that the record of who accessed or acted on records retains its own integrity and can support evidential needs.
Align access controls with the recordkeeping principle of least necessary access, limiting actions on records to identities that are authorized for them.
Treat credentials as sensitive artifacts whose compromise can undermine the authenticity and reliability attributed to recordkeeping actions, and manage them accordingly.
Document identity and credential management responsibilities within broader information governance policy, recognizing that requirements may vary depending on jurisdiction, sector, and organizational policy.