Skip to main content

References

Shared language

Find the NIM objects and identity concepts you need to understand a guide or plan an automation workflow.

Glossary hints throughout the documentationHighlighted glossary terms show a definition when you hover, focus with the keyboard, or select them. The popover identifies whether the term is NIM-specific or industry standard.

NIM terminology

How NIM describes automation

Configuration scenario

A managed set of connector configuration choices used to control how a system is configured or operated.

Connector

The NIM component that connects to an external system to read, create, update, or remove data.

Data model

The NIM schema that defines how a system’s entities, attributes, and relationships are interpreted.

Event

A NIM occurrence that can trigger automated actions, such as notifications or follow-up processing.

Filter

A SQL-like query in NIM that selects a subset of data for use in mappings, roles, jobs, or apps.

Inter-system relation

A configured relationship between data models that lets NIM correlate and exchange data across systems.

Job

A reusable collection of mappings and/or role operations that NIM executes together.

Mapping

A rule that applies filter output to a create, read, update, or delete operation in a target system.

NIM App

A customizable NIM web form that lets users complete approved identity-management tasks, such as onboarding, password reset, or access requests.

Role

A NIM object that manages group memberships or other target entitlements for correlated accounts.

Sync task

A scheduled or manually run task that executes one or more NIM jobs.

System

A connected source, target, or internal data source that NIM uses in an automation workflow.

Vault

NIM’s internal store of collected and processed identity data used by filters and automations.

Industry standard terminology

Identity and access vocabulary

Authentication

Verifying that a user, service, or device is who it claims to be before granting access.

Authorization

Deciding what an authenticated user or service is allowed to access or do.

Birthright access

Baseline access assigned automatically because of a person’s role, location, employment type, or other authoritative attribute.

Deprovisioning

Removing, disabling, or revoking accounts and access when it is no longer appropriate.

Entitlement

A specific permission, group membership, role, license, or access right granted in a target system.

HRIS

Human Resources Information System: a system of record for employee and employment data that commonly drives identity lifecycle events.

Identity and access management (IAM)

The processes and controls used to manage identities and their access to systems and data.

Identity governance and administration (IGA)

Managing identity lifecycles and entitlements with policies, reviews, and evidence of access decisions.

Joiner

A person entering an organization or changing into a covered population; identity processes create the required accounts, access, and equipment.

Least privilege

Giving an identity only the access needed for its work, for only as long as it is needed.

Leaver

A person leaving an organization or covered population; identity processes remove or disable access according to policy.

Mover

A person whose role, department, location, manager, or other employment attribute changes and requires access to be adjusted.

Multi-factor authentication (MFA)

Requiring two or more distinct types of evidence to verify a user during sign-in.

Provisioning

Creating or updating accounts, entitlements, and related access in a target system.

Role-based access control (RBAC)

Assigning access through roles that represent responsibilities instead of granting every permission individually.

SCIM

System for Cross-domain Identity Management: an open standard for automated user and group provisioning between identity systems.

Segregation of duties

A control that prevents conflicting privileges from being assigned to the same person or account.

Single sign-on (SSO)

Using one sign-in session to access more than one application without signing in separately to each one.

Put these terms to workDirect link to Put these terms to work