Applicant
In the general sense, an applicant is a person who applies or signs up for something, such as a job or a service. In identity systems specifically, an applicant is a person who is going through the process of proving their identity before they can be granted an account or credential.
In common usage, an applicant is simply an individual who expresses interest in or applies for something, for example a job applicant who completes an application form. In the IAM and digital-identity context, the term typically denotes the subject undergoing identity proofing and enrollment prior to becoming an enrolled subscriber or account holder; the provided evidence, however, only supports the general-language definition, and the identity-proofing usage aligns with digital-identity guidance rather than any source in this evidence packet. This term describes a lifecycle/enrollment role and does not by itself imply any authentication or authorization outcome; whether an applicant ultimately receives credentials or access depends on the enrollment, proofing, and provisioning processes applied.
Why it matters
The applicant role marks the entry point of the identity lifecycle, before any account, credential, or access exists. Getting this stage right is foundational: every downstream authentication and authorization decision inherits the assurance, or the weakness, of how well the applicant's claimed identity was established. If proofing is weak or skipped, an attacker can enroll as a legitimate subject and inherit trust that no runtime control can later fully undo, because the credential itself will validate correctly even though it was issued to the wrong person.
Distinguishing the applicant from the enrolled subscriber also matters for governance and accountability. An applicant has expressed interest or begun a process but has not yet been granted anything; conflating the two can lead to premature provisioning, orphaned records, or audit gaps around who was proofed, when, and to what level of confidence. Keeping the applicant a distinct lifecycle role clarifies that being an applicant carries no authentication or authorization outcome by itself, those depend entirely on the proofing, enrollment, and provisioning processes that follow.
In digital-identity practice, the applicant stage is where identity proofing standards and regulatory expectations apply. Because the outcome of this stage determines the identity assurance associated with the eventual account, treating the applicant as a deliberately scoped role helps organizations map their enrollment controls to the assurance levels their use cases require, rather than assuming trust that was never actually established.
Who it's relevant to
Inside Applicant
Common questions
Answers to the questions practitioners most commonly ask about Applicant.
