"who is", "user", "lookup"?
lookup_user + list_user_groups
Zero-trust identity governance for AI agents — user lookup, MFA verification, least-privilege access requests, emergency revocation, and lifecycle automation.
What this skill teaches
An MCP server tells an agent which actions are available. A skill adds the judgment around those actions: how to recognize the job, which sequence to follow, what to avoid, and how to decide that the result is complete.
Orchestrate identity and access management — user lookup, group membership, MFA verification, entitlement management, access requests, and emergency revocation. Use when looking up users, checking permissions, managing group membership, verifying MFA status, processing access requests, or revoking access.
Architecture
The skill stays readable and portable because it contains instructions rather than service credentials or business data. ADK-Rust supplies it to the agent, the agent chooses from its reviewed tool boundary, and the connected MCP server performs the authenticated operation.
The agent receives a goal expressed in ordinary language.
Matches intent, supplies the decision guide, and narrows the tool boundary.
Plans the workflow and streams each meaningful step through the runtime.
Executes authenticated operations against the system that owns the capability.
The skill's completion rules shape the evidence returned to the user.
Decision guide
These routes come directly from the skill instructions. They help the model recognize intent and select a focused tool or workflow instead of improvising across the entire capability surface.
"who is", "user", "lookup"?
lookup_user + list_user_groups
"access", "permission", "can they"?
list_entitlements
"MFA", "2FA", "security"?
check_mfa
"grant access", "request"?
request_access (requires approval)
"revoke", "remove access", "emergency"?
emergency_revoke
"onboard", "offboard", "transfer"?
lifecycle_task
"verify", "confirm identity"?
verify_user
Proven workflows
A workflow joins several tool calls into a task the user actually recognizes. The skill explains the sequence and the intended result while ADK-Rust streams the agent's progress through the shared runtime.
Governed access with justification + time-bound
Instant access removal (sessions + tokens)
Full provisioning with MFA enforcement
Complete access removal + ownership transfer
Audit enrollment across teams
Tool boundary
This allowlist is declared by the skill. It keeps the agent focused on the actions needed for this job while mcp-identity retains responsibility for authentication, validation, and the connected system.
Working rules
Operating boundaries
Install and connect
Install the repository where your ADK-Rust skill loader can discover it, connect mcp-identity, and confirm the declared tools are available before asking the agent to use the workflow.
git clone https://github.com/zavora-ai/skill-identity-access-management.git \
~/.skills/skills/identity-access-managementlet skills = SkillLoader::from_dir("~/.skills/skills").await?;
let skill = skills.load("identity-access-management").await?;
let agent = LlmAgentBuilder::new("agent")
.instruction(skill.instructions())
.tools(skill.allowed_tools(toolset)?)
.build()?;The repository's compatibility statement: Requires mcp-identity server connected.
Official documentation
The repository remains authoritative for its exact instructions, examples, helper scripts, assets, MCP requirements, license, and later updates.
Source record
Repository metadata for this skill entry.