Authoritative Source
An authoritative source is the trusted system that holds accurate, verified information about a person or thing and is treated as the definitive answer for that data. For example, an organization's HR system is often the authoritative source for who its employees are. Other systems rely on this source rather than making their own independent determination.
An authoritative source is the entity or system designated as the trusted origin of record for specific identity attributes or entitlement data, such that dependent systems accept its values with high confidence. In NIST terms, it is an entity that has access to, or verified copies of, accurate information from an issuing source so that a credential service provider (CSP) can rely on its accuracy. In IGA deployments it typically drives identity lifecycle processes: the HR system commonly serves as the authoritative source for workforce identities, feeding provisioning, deprovisioning, and access decisions downstream. Authoritativeness is scoped per attribute or data domain rather than absolute, so a given deployment may designate different authoritative sources for different attributes (for example, HR for employment status and a separate directory for contact data). This is a governance and data-integrity concept and does not by itself perform runtime authentication or authorization enforcement.
Why it matters
The authoritative source is the anchor of trust for identity data across an organization. When downstream systems accept a source's values with high confidence rather than making independent determinations, the accuracy of that source directly shapes the correctness of provisioning, access decisions, and eventual deprovisioning. If the designated authoritative source is wrong, stale, or compromised, those errors propagate to every dependent system, which is why establishing clear authoritative sources is foundational to sound identity governance.
A common and consequential example is the reliance on the HR system as the authoritative source for workforce identities. When HR records an employee's departure or role change, that event ideally triggers deprovisioning or entitlement adjustments downstream. Where an authoritative source is not clearly designated or its feed is delayed, orphaned accounts and lingering access can persist, expanding the attack surface and complicating access certification. Because authoritativeness is scoped per attribute rather than absolute, ambiguity about which system is definitive for a given attribute can produce conflicting data and reconciliation problems.
It is important to note that this is a governance and data-integrity concept. Designating an authoritative source improves the trustworthiness of the identity data feeding access processes, but it does not by itself perform runtime authentication or authorization enforcement. Those functions remain the responsibility of separate enforcement components, and treating an authoritative source as if it enforced access at runtime would misstate its role.
Who it's relevant to
Inside Authoritative Source
Common questions
Answers to the questions practitioners most commonly ask about Authoritative Source.
