Our Approach

A practical path, not a 200-page strategy deck

We work in four focused phases so you see progress — and reduced risk — from week one. Here's exactly what happens in each one.

Step 1 · Typically 2–4 weeks

Discover

Before we recommend anything, we find out what's actually true about your identity estate — not what the org chart or the last vendor deck says. This phase is about facts, not assumptions.

  • Structured stakeholder interviews with security, IT, HR, and business application owners
  • Current-state identity and access assessment across applications, directories, and HR source systems
  • Entitlement and account inventory — including dormant, orphaned, and over-privileged access
  • Segregation-of-duties conflict scan for audit-critical applications
  • Risk-prioritised findings report, mapped to your existing compliance obligations

You get: a clear, evidence-based picture of your identity risk — in plain terms your board can act on.

Step 2 · Typically 3–6 weeks

Design

Discovery tells us where the risk is. Design decides how to fix it — in a way that fits how your organisation actually operates, not a platform's default configuration.

  • Target operating model — who owns access decisions, and how they get made
  • Role design workshops — a Role-Based (RBAC) baseline with Attribute-Based (ABAC) exceptions where they're genuinely needed, not by default
  • Platform and architecture recommendation — vendor-neutral, unless you've already selected one
  • Phased delivery roadmap, sequenced by risk reduction and effort — not vendor convenience
  • Business case and stakeholder sign-off pack, ready for a board or steering committee

You get: a target architecture and roadmap you can actually defend to a steering committee — and start delivering against immediately.

Step 3 · Varies by scope — phased in 6–12 week increments

Deploy

This is where the roadmap becomes something that actually runs in production. We deliver hands-on — we don't hand a design document to your team and step back.

  • Hands-on platform implementation — governance workflows, Privileged Access Management (PAM) vaulting, cloud IAM, or all three
  • Joiner / mover / leaver automation build and testing
  • Access certification campaign configuration and rollout
  • Integration with HR, IT Service Management (ITSM), directory, and Security Information and Event Management (SIEM) / Security Orchestration, Automation and Response (SOAR) tooling
  • User acceptance testing and a controlled go-live, phased to avoid business disruption

You get: a working platform in production, not a proof of concept that stalls — with your team trained to run it.

See our full services →
Step 4 · Ongoing

Sustain

IAM is never "done." Controls that looked clean at go-live decay quietly as the business changes — new joiners, new apps, new leavers nobody remembered to offboard. We stay accountable for it not happening.

  • Scheduled access reviews and certification campaigns that actually get completed
  • Quarterly identity risk reporting to security leadership
  • Policy and control tuning as the business and platform evolve
  • Day-two operational support — incident response, access changes, platform health
  • Continuous monitoring so controls don't quietly decay after go-live

You get: an identity programme that's still clean at next year's audit, not just at go-live.

See Access Management →

Ready to start with Discover?

Take the free 2-minute IAM Health Check, or talk to us directly about where your programme should begin.

Talk to us