Our Approach

A practical path, not a 200-page strategy deck

We work in four focused phases so you see progress and reduced risk from week one. Here's exactly what happens in each one.

This is the full journey. Most engagements start or stay at just one phase. See how each maps to a commercial model.

Step 1 · Typically 2–4 weeks

Discover

Before we recommend anything, we find out what's actually true about your identity estate, not what the org chart or the last vendor deck says. This phase is about facts, not assumptions.

  • Structured stakeholder interviews with security, IT, HR, and business application owners
  • Current-state identity and access assessment across applications, directories, and HR source systems
  • Entitlement and account inventory: including dormant, orphaned, and over-privileged access
  • Segregation-of-duties conflict scan for audit-critical applications
  • Risk-prioritised findings report, mapped to your existing compliance obligations

You get: a clear, evidence-based picture of your identity risk, in plain terms your board can act on.

Step 2 · Typically 3–6 weeks

Design

Discovery tells us where the risk is. Design decides how to fix it, in a way that fits how your organisation actually operates, not a platform's default configuration.

  • Target operating model: who owns access decisions, and how they get made
  • Role design workshops: a Role-Based (RBAC) baseline with Attribute-Based (ABAC) exceptions where they're genuinely needed, not by default
  • Platform and architecture recommendation: vendor-neutral, unless you've already selected one
  • Phased delivery roadmap, sequenced by risk reduction and effort, not vendor convenience
  • Business case and stakeholder sign-off pack, ready for a board or steering committee

You get: a target architecture and roadmap you can actually defend to a steering committee, and start delivering against immediately.

Step 3 · Varies by scope: phased in 6–12 week increments

Deploy

This is where the roadmap becomes something that actually runs in production. We deliver hands-on: we don't hand a design document to your team and step back.

  • Hands-on platform implementation: governance workflows, Privileged Access Management (PAM) vaulting, cloud IAM, or all three
  • Joiners/Movers/Leavers (JML) automation build and testing
  • Access certification campaign configuration and rollout
  • Integration with HR, IT Service Management (ITSM), directory, and Security Information and Event Management (SIEM) / Security Orchestration, Automation and Response (SOAR) tooling
  • User acceptance testing and a controlled go-live, phased to avoid business disruption

You get: a working platform in production, not a proof of concept that stalls, with your team trained to run it.

See our full services →
Step 4 · Ongoing

Sustain

IAM is never "done." Controls that looked clean at go-live decay quietly as the business changes: new joiners, new applications, new leavers nobody remembered to offboard. We stay accountable for it not happening.

  • Scheduled access reviews and certification campaigns that actually get completed
  • Quarterly identity risk reporting to security leadership
  • Policy and control tuning as the business and platform evolve
  • Day-two operational support: incident response, access changes, platform health
  • Continuous monitoring so controls don't quietly decay after go-live

You get: an identity programme that's still clean at next year's audit, not just at go-live.

See Access Management →

Ready to start with Discover?

Take the free 2-minute IAM Health Check, or talk to us directly about where your programme should begin.

Talk to us
Talk to us