Inspect the team before use
Active database publicationIdentity Access Governance
Identity lifecycle, account-entitlement, access-control and certification evidence joined for qualified governance review.
Opens the installed OpenCorvus desktop app. The client re-downloads and re-verifies this exact revision, then asks you for an install scope. No desktop app yet? Install OpenCorvus first
Bound execution graph
Workflow and handoffs
The graph shows who owns each step and which earlier result it depends on. It explains the team's collaboration contract; it is not live task progress and does not schedule Agents from the page.
0f3a05b65 nodes- 01authoritative-identity-lifecycle-analystReconciles authoritative identity populations and Joiner-Mover-Leaver events.
root - 02account-entitlement-correlation-analystCorrelates identities, accounts, groups, roles and effective entitlements.
root - 03access-request-role-sod-control-analystTests access-request, role and segregation-of-duties evidence.
root - 04access-certification-orphan-review-analystReviews certification populations, dormant and orphaned account evidence.
root - 05identity-access-governance-review-ownerJoins lifecycle, entitlement, control and certification evidence without deciding access.
← access-certification-orphan-review-analyst + access-request-role-sod-control-analyst + account-entitlement-correlation-analyst + authoritative-identity-lifecycle-analyst
Intended scope
Use for bounded identity-governance evidence without provisioning or access decisions.
- Product pillarscode + work
- Agent roster5 declared roles
- Declared workflows1 complete responsibility and dependency graphs
- Full capability projection1 Skills · 3 tools · 0 MCP refs
Roles and ownership
This roster comes from the exact package. Agent identity and base role participate in the real runtime; avatars, ratings, and personas do not influence selection.
- Authoritative Identity Lifecycle Analyst
exploreReconciles authoritative identity populations and Joiner-Mover-Leaver events. - Account and Entitlement Correlation Analyst
delegated-workerCorrelates identities, accounts, groups, roles and effective entitlements. - Access Request, Role and SoD Control Analyst
delegated-workerTests access-request, role and segregation-of-duties evidence. - Access Certification and Orphan Review Analyst
delegated-workerReviews certification populations, dormant and orphaned account evidence. - Identity Access Governance Review Owner
delegated-workerJoins lifecycle, entitlement, control and certification evidence without deciding access.
Workflow and handoffs
The graph shows who owns each step and which earlier result it depends on. It explains the team's collaboration contract; it is not live task progress and does not schedule Agents from the page.
identity-access-governance-review
Identity Access Governance Review
Four independent professional evidence branches converge into Identity Access Governance Review Owner.
- 01authoritative-identity-lifecycle-analystReconciles authoritative identity populations and Joiner-Mover-Leaver events.depends_on: []
- 02account-entitlement-correlation-analystCorrelates identities, accounts, groups, roles and effective entitlements.depends_on: []
- 03access-request-role-sod-control-analystTests access-request, role and segregation-of-duties evidence.depends_on: []
- 04access-certification-orphan-review-analystReviews certification populations, dormant and orphaned account evidence.depends_on: []
- 05identity-access-governance-review-ownerJoins lifecycle, entitlement, control and certification evidence without deciding access.depends_on: access-certification-orphan-review-analyst, access-request-role-sod-control-analyst, account-entitlement-correlation-analyst, authoritative-identity-lifecycle-analyst
Capability scope
The full projection includes built-in, default, and package-owned references. The package-owned subset is disclosed separately and never presented as the complete permission surface.
- Full Skill projection1 unique references; 1 are the package-owned subset
- Full tool projection3 unique references; 0 are the package-owned subset
- Full MCP projection0 server/tool/prompt/resource references; 0 are the package-owned subset
- Configuration0 fields · 0 required
Version and provenance
During publication import, the website reconstructs the canonical file tree and complete display facts from the exact ZIP referenced by the signed catalog. The local Manager validates shape, identity, topology, and digest again during install.
- Identitybuiltin/identity-access-governance
- Version2026.08.13.1
- Package SHA-2560f3a05b610af45c89e828164cf8c48bda814305da4bff9be0686572a55bc7b29
This record belongs to the active database publication. The importer checked it field by field against the OpenCorvus-signed catalog, exact ZIP, and content digest. The signing private key never reaches the production server; third-party publisher identity and independent review services are not open yet.
Install boundary
The page can hand this exact revision to an installed OpenCorvus client, or stream its content-addressed ZIP. Neither path installs or activates a team from the web: the client re-downloads the archive, re-verifies its bytes, digest, and shape, and requires an explicit scope.
- 01Resolve the exact revision in the website database, verify ZIP bytes and SHA-256, then hand it to the client or start the download response
- 02Recompute the digest and strictly validate the selected package during client import
- 03Require the operator to choose project or user-global scope
- 04Import atomically through the Manager and return a mutation receipt
- 05Select the installed Squad separately before the active profile changes