Access and identity management
Grants permissions based on role and necessity, periodically reviews who can access what and withdraws rights on change or departure.
How hrmforce measures this
- Assessment method
- Work sample test · rho 0.33 (SD 0.09)
- hrmforce instrument
- Knowledge test (client-specific), Work sample test
- Competency (50-framework)
- Accuracy
- Trainability
- high
- Demand outlook 2026 to 2030
- rising
The candidate performs a representative work sample under standardised conditions.
Behavioural anchors
| Level | Behaviour at this level |
|---|---|
| N1 Guided | Processes access requests according to the established role scheme and records every change. works under supervision and follows instruction · routine, one variable at a time · own task |
| N3 Proficient | Designs roles and permissions for an application, carries out the periodic review and corrects excessive access. sets own approach and seeks input proactively · several variables, some ambiguity · own team or process |
| N5 Leading | Sets the organisation's access policy and accounts for the control of permissions in audits. sets the standard and the policy · strategic, under high uncertainty · organisation, value chain or profession |
N2 and N4 are deliberately not anchored. Raters place them between the anchors, following the O*NET convention.
Underlying skills
These skills inherit the assessment route and the behavioural anchors of this construct.
| T | Skill | Definition | Demand outlook 2026 to 2030 |
|---|---|---|---|
| V | Setting up identity and access management Identity and access management · IAM | Sets up how identities are created, changed and terminated and which permissions are linked to them. | rising |
| V | Setting up role based access Role based access control · RBAC | Bundles permissions into roles per job so assignment is uniform and individual exceptions stay visible. | rising |
| V | Managing privileged access Privileged access management · PAM | Limits administrator rights to what is needed, grants them temporarily and records what was done with them. | rising |
| V | Performing an access review Access review · Access recertification | Has managers periodically confirm who keeps which permissions and withdraws unconfirmed rights. | rising |
| K | Applying zero trust Zero trust | Verifies identity, device and context at every access attempt instead of trusting the network. | rising |
| V | Handling joiner and leaver authorisations Joiner mover leaver | Ensures new employees receive permissions on time and that rights disappear on the day of departure. | rising |
| V | Applying segregation of duties Segregation of duties | Prevents one person completing a process alone by distributing permissions across roles. | stable |
| V | Rolling out multi factor authentication MFA rollout | Rolls out a second verification step for all users, arranges exceptions and supports recovery after loss. | rising |
| V | Managing guest and external accounts Guest accounts | Gives externals temporary access with limited rights and an end date and checks that it actually expires. | rising |