{
  "slug": "provision",
  "name": "Provisioning and invites",
  "category": "Identity",
  "summary": "Review invites, directory sync, and provisioning as high-authority lifecycle operations with tenant, role, and approval checks.",
  "scope": "Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question.",
  "inputs": [
    "Provisioning protocol configuration",
    "Organization and role model",
    "Approved lifecycle events"
  ],
  "review": [
    {
      "title": "Map ownership",
      "body": "Bind each provider, invitation, group mapping, and lifecycle event to a specific organization owner and approved administrator."
    },
    {
      "title": "Constrain role changes",
      "body": "Require explicit policy for role assignment, deprovisioning, and cross-organization moves; do not infer authority from profile edits."
    },
    {
      "title": "Review durable links",
      "body": "Validate that directory attributes and external identities retain provenance and cannot silently rebind an account."
    },
    {
      "title": "Verify revocation",
      "body": "Confirm disabled users, removed memberships, and revoked providers lose access across all active interfaces."
    }
  ],
  "outputs": [
    "Provisioning authority map",
    "Role-change policy",
    "Deprovisioning verification notes"
  ],
  "pitfalls": [
    "Treating an invite as blanket authority",
    "Allowing ownerless configuration",
    "Leaving stale group access after deprovisioning"
  ],
  "references": {
    "resources": [
      {
        "id": "better-auth-2026-scim-ownerless-provider-authority",
        "title": "Better Auth SCIM: absent ownership must not grant shared authority",
        "url": "https://vulns.co/research/resources/better-auth-2026-scim-ownerless-provider-authority/"
      },
      {
        "id": "n8n-2026-ldap-account-linking-authority",
        "title": "n8n: directory-attribute authority in durable account linking",
        "url": "https://vulns.co/research/resources/n8n-2026-ldap-account-linking-authority/"
      },
      {
        "id": "umbraco-2026-group-assignment-authority",
        "title": "Umbraco: editing an account does not authorize assigning every role",
        "url": "https://vulns.co/research/resources/umbraco-2026-group-assignment-authority/"
      }
    ],
    "diagrams": [
      {
        "id": "identity-claim-binding",
        "title": "An identity claim must belong to the user",
        "url": "https://vulns.co/research/diagrams/identity-claim-binding/"
      },
      {
        "id": "workload-identity-tenant-scope",
        "title": "Keep workload authority tenant-scoped",
        "url": "https://vulns.co/research/diagrams/workload-identity-tenant-scope/"
      }
    ],
    "reports": [
      {
        "id": "apple-sign-in-identity-claim-binding-2020",
        "title": "Sign in with Apple failed to bind identity claims to the authenticated user",
        "url": "https://vulns.co/research/reports/apple-sign-in-identity-claim-binding-2020/"
      },
      {
        "id": "github-oauth-method-semantics-2019",
        "title": "GitHub OAuth consent failed across request-method semantics",
        "url": "https://vulns.co/research/reports/github-oauth-method-semantics-2019/"
      },
      {
        "id": "meta-service-identity-secrets-trust-boundary-2026",
        "title": "Meta service-identity exposure amplified by excessive secret access",
        "url": "https://vulns.co/research/reports/meta-service-identity-secrets-trust-boundary-2026/"
      }
    ]
  },
  "provenance": {
    "publisher": "vulns.co / GK Data",
    "guide_updated": "2026-10-11",
    "library_as_of": "2026-10-04",
    "library_commit": "d5550c7891119cf1379e235721541c947850a3b3"
  },
  "url": "https://vulns.co/skills/provision/",
  "markdown_url": "https://vulns.co/skills/provision/SKILL.md"
}
