Skill registry
Identity & accessPublic skills

Identity & Access Management

Zero-trust identity governance for AI agents — user lookup, MFA verification, least-privilege access requests, emergency revocation, and lifecycle automation.

What this skill teaches

A reusable playbook for a specific kind of work.

An MCP server tells an agent which actions are available. A skill adds the judgment around those actions: how to recognize the job, which sequence to follow, what to avoid, and how to decide that the result is complete.

Orchestrate identity and access management — user lookup, group membership, MFA verification, entitlement management, access requests, and emergency revocation. Use when looking up users, checking permissions, managing group membership, verifying MFA status, processing access requests, or revoking access.

Architecture

How Identity & Access Management guides an ADK-Rust agent.

The skill stays readable and portable because it contains instructions rather than service credentials or business data. ADK-Rust supplies it to the agent, the agent chooses from its reviewed tool boundary, and the connected MCP server performs the authenticated operation.

01

User request

The agent receives a goal expressed in ordinary language.

02

Identity & Access Management skill

Matches intent, supplies the decision guide, and narrows the tool boundary.

03

ADK-Rust agent

Plans the workflow and streams each meaningful step through the runtime.

04

mcp-identity

Executes authenticated operations against the system that owns the capability.

05

Verified result

The skill's completion rules shape the evidence returned to the user.

Portable instructions: SKILL.md · Capability boundary: mcp-identity · Allowed tools: 8

Decision guide

How the agent turns a request into the right action.

These routes come directly from the skill instructions. They help the model recognize intent and select a focused tool or workflow instead of improvising across the entire capability surface.

01

"who is", "user", "lookup"?

lookup_user + list_user_groups

02

"access", "permission", "can they"?

list_entitlements

03

"MFA", "2FA", "security"?

check_mfa

04

"grant access", "request"?

request_access (requires approval)

05

"revoke", "remove access", "emergency"?

emergency_revoke

06

"onboard", "offboard", "transfer"?

lifecycle_task

07

"verify", "confirm identity"?

verify_user

Proven workflows

Repeatable sequences for useful outcomes.

A workflow joins several tool calls into a task the user actually recognizes. The skill explains the sequence and the intended result while ADK-Rust streams the agent's progress through the shared runtime.

013 calls

Access Request

Governed access with justification + time-bound

021 calls

Emergency Revoke

Instant access removal (sessions + tokens)

032 calls

Lifecycle (Onboard)

Full provisioning with MFA enforcement

042 calls

Lifecycle (Offboard)

Complete access removal + ownership transfer

052 calls

MFA Compliance

Audit enrollment across teams

Tool boundary

The skill may use 8 documented tools.

This allowlist is declared by the skill. It keeps the agent focused on the actions needed for this job while mcp-identity retains responsibility for authentication, validation, and the connected system.

lookup_user
list_user_groups
check_mfa
verify_user
list_entitlements
request_access
emergency_revoke
lifecycle_task

Working rules

What the agent should do.

  • Enforce least privilege — minimum access needed
  • Require MFA for all privileged access
  • Time-bound all access grants (no permanent elevation)
  • Log every access change with justification

Operating boundaries

What the agent should avoid.

  • NEVER grant permanent privileged access
  • Don't skip MFA verification for sensitive operations
  • Don't delay offboarding — stale access = security risk

Install and connect

Add the skill beside the capability it expects.

Install the repository where your ADK-Rust skill loader can discover it, connect mcp-identity, and confirm the declared tools are available before asking the agent to use the workflow.

Install the skill
git clone https://github.com/zavora-ai/skill-identity-access-management.git \
  ~/.skills/skills/identity-access-management
ADK-Rust loading shape
let skills = SkillLoader::from_dir("~/.skills/skills").await?;
let skill = skills.load("identity-access-management").await?;

let agent = LlmAgentBuilder::new("agent")
    .instruction(skill.instructions())
    .tools(skill.allowed_tools(toolset)?)
    .build()?;

The repository's compatibility statement: Requires mcp-identity server connected.

Official documentation

Read the complete skill package.

The repository remains authoritative for its exact instructions, examples, helper scripts, assets, MCP requirements, license, and later updates.

Source record

Repository metadata for this skill entry.

View public repository ↗
License
Apache-2.0
Allowed tools
8
References
3
Revision
fe844998ea5f
Updated
May 31, 2026