A practical path, not a 200-page strategy deck
We work in four focused phases so you see progress and reduced risk from week one. Here's exactly what happens in each one.
This is the full journey. Most engagements start or stay at just one phase. See how each maps to a commercial model.
Discover
Before we recommend anything, we find out what's actually true about your identity estate, not what the org chart or the last vendor deck says. This phase is about facts, not assumptions.
- Structured stakeholder interviews with security, IT, HR, and business application owners
- Current-state identity and access assessment across applications, directories, and HR source systems
- Entitlement and account inventory: including dormant, orphaned, and over-privileged access
- Segregation-of-duties conflict scan for audit-critical applications
- Risk-prioritised findings report, mapped to your existing compliance obligations
You get: a clear, evidence-based picture of your identity risk, in plain terms your board can act on.
Design
Discovery tells us where the risk is. Design decides how to fix it, in a way that fits how your organisation actually operates, not a platform's default configuration.
- Target operating model: who owns access decisions, and how they get made
- Role design workshops: a Role-Based (RBAC) baseline with Attribute-Based (ABAC) exceptions where they're genuinely needed, not by default
- Platform and architecture recommendation: vendor-neutral, unless you've already selected one
- Phased delivery roadmap, sequenced by risk reduction and effort, not vendor convenience
- Business case and stakeholder sign-off pack, ready for a board or steering committee
You get: a target architecture and roadmap you can actually defend to a steering committee, and start delivering against immediately.
Deploy
This is where the roadmap becomes something that actually runs in production. We deliver hands-on: we don't hand a design document to your team and step back.
- Hands-on platform implementation: governance workflows, Privileged Access Management (PAM) vaulting, cloud IAM, or all three
- Joiners/Movers/Leavers (JML) automation build and testing
- Access certification campaign configuration and rollout
- Integration with HR, IT Service Management (ITSM), directory, and Security Information and Event Management (SIEM) / Security Orchestration, Automation and Response (SOAR) tooling
- User acceptance testing and a controlled go-live, phased to avoid business disruption
You get: a working platform in production, not a proof of concept that stalls, with your team trained to run it.
See our full services →Sustain
IAM is never "done." Controls that looked clean at go-live decay quietly as the business changes: new joiners, new applications, new leavers nobody remembered to offboard. We stay accountable for it not happening.
- Scheduled access reviews and certification campaigns that actually get completed
- Quarterly identity risk reporting to security leadership
- Policy and control tuning as the business and platform evolve
- Day-two operational support: incident response, access changes, platform health
- Continuous monitoring so controls don't quietly decay after go-live
You get: an identity programme that's still clean at next year's audit, not just at go-live.
See Access Management →