A firefighter separates from the department but still can open mutual-aid apps through federation. What lifecycle control is missing?
Select an answer to reveal the explanation.
Short Explanation
When the firefighter turns in the gear, federated app access has to end the same day—not linger as a courtesy or wait for them to tidy up partner accounts. Hook revocation into the HR/identity lifecycle. Shared generic logins after exit just rename the orphan problem.
Full Explanation
Federated access must follow joiner–mover–leaver processes: termination disables the home identity and propagates logout, assertion denial, and entitlement removal at relying parties. Courtesy windows and voluntary self-deletion leave dangerous residual access. Converting individual accounts into shared generics destroys accountability and complicates future revocation. Lifecycle-aligned deprovisioning is essential for mutual-aid and other cross-org IAM.