Virtus Group logo

Runbook - Identity and Access Operations

Runbook stub • Effective 26 Sep 2025 • Version v1.0

Scope

Operate identity lifecycle and access controls: joiner-mover-leaver, privileged access, Conditional Access templates, break-glass oversight.

In scope Operations, monitoring, reporting to SLAs/SLOs, continuous improvement (SIP).
Out of scope One-off projects/uplifts (CPS), custom application development, non-standard integrations unless agreed.

Dependencies

Standard Operating Procedures (SOPs)

Daily

Weekly

Monthly

Quarterly

SLAs and SLOs

MeasureTarget
Incident response (business hours)Ack within 30 minutes; priority-based resolution targets
Change records100 percent with rehearsal and rollback for high-risk changes
ReportingMonthly service review delivered within 5 business days of month end
Joiner mover leaverWithin defined windows
Privileged access reviewsMonthly

KPIs and Signals

KPIDefinition
Ticket SLA compliancePercent of incidents and requests meeting SLA
Backlog healthAged tickets over threshold
SIP closure ratePercent of improvement actions closed by due date
Break glass checksMonthly access and sign in test
Orphaned accountsCount and MTTR

Escalation

Functional SPOCService Lead (email/phone as per contact matrix)
Duty escalationService Manager → Account Lead → Executive Sponsor
Vendor escalationAs per vendor matrix; include ticket ref and evidence
Incident bridgeSpin up within 15 minutes for SEV1/SEV2; roles per playbook

Evidence and Records