In an interview for a new graduate DevOps role, I was asked: "Who typically owns access to corporate applications: IAM engineers, IT staff, application administrators, or Platform/DevOps engineers?" How would you answer?
4 Answers
I’d clarify the meaning of ownership before choosing a team. The application owner or business owner often approves who should have access, while IAM or IT provisions it. DevOps or platform engineers might manage access for infrastructure and deployment systems, but they usually aren’t responsible for every corporate application.
The best answer is that it depends on the organization, the application, and what “owns access” means. IAM may define policies and manage identity systems, application administrators may approve or handle day-to-day requests, and IT or platform teams may implement the access. In a larger company, those responsibilities are usually separated.
For a straightforward interview response, I’d say IAM typically governs access management, but it works with application owners and IT. A strong access-control model separates approval from implementation: one person or team authorizes access, and another provisions or removes it. That separation is especially important in regulated environments.
Company size and industry make a big difference. At a small startup, one DevOps engineer or even a QA engineer might manage nearly everything. At a large or regulated company, responsibilities are divided among business owners, application administrators, IAM, security, and infrastructure teams.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures