Identity lifecycle management requires a verifiable audit trail for every account modification to satisfy NIST SP 800-53 AC-2. The gap here is that SCIM-driven user deletions aren’t surfacing in the audit query results.
| Attempt | Endpoint | Result |
|---|---|---|
| Audit Query | POST /api/v2/audits/query |
No events for SCIM DELETE |
| Service Map | GET /api/v2/audits/query/servicemapping |
Service ID present, no logs |
RFC 7643 defines the SCIM core schema for identity propagation, yet the platform isn’t logging the deprovisioning trigger. Documentation (Audit API) implies all security-relevant changes are captured.