Why the identity management system, not the access control panel, is the true system of record for who should have access to what — HR-driven provisioning, credential issuance, modification, revocation, and the identity governance basics that keep a large deployment from drifting into unexplained access.
Every access control module in this program has treated the panel as the center of the system, but the panel only ever enforces what an upstream identity system tells it. This module builds the mental model this program has been assuming: the layered architecture of HRIS, IdM/IGA platform, and directory services that feeds a PACS its identity and entitlement data, the joiner-mover-leaver events that should drive every provisioning decision, and the full credential lifecycle from issuance through modification to revocation.
By the end of this module you should be able to explain why same-day deprovisioning has to be verified complete across every connected system — not just the primary PACS head-end — and why privilege creep and unexplained access grants are the predictable result of skipping periodic access certification.