Questions worth answering upfront
The things prospective clients and procurement teams actually ask us — answered directly, including where the honest answer is "it depends" or "not us."
Working with us
Where to start, who does the work, and how we fit alongside what you already have.
We're a greenfield organisation with no IAM strategy or platform in place — where do you even start?
That's actually the cleanest starting point. For greenfield organisations, we run a full RFP across the whole IAM capability stack — identity governance, privileged access, and cloud IAM — evaluated together against your actual requirements, not platform by platform. We've taken organisations through this exact process before, from requirements workshops through to contract negotiation.
See Full RFP & Platform Selection →We don't have budget for a full transformation programme — can you help with something smaller?
Yes. Engagements range from a focused two-week assessment to a multi-year transformation programme. We would rather start small — a health check, a gap assessment, or a single high-priority fix — and earn the larger engagement than the other way round.
Who will actually be delivering our programme?
Engagements are delivered by experienced IAM specialists — project managers, solution architects, developers, business analysts, and test engineers — scaled to exactly what the programme needs rather than carrying people you don't require. Naveen, our founder, scopes the work directly with senior leadership and stays accountable for it landing, and you'll always know who is doing the work and why.
See how we deliver →What happens if someone working on our programme becomes unavailable?
We work so that no individual becomes a single point of failure. Design decisions, configuration, and process documentation are written down as we go and belong to you, not to us. If someone has to step away mid-programme, the next person picks it up from documentation rather than from memory — the same discipline we'd expect of any well-run identity programme.
Where a team member has to be replaced mid-engagement, we agree the replacement with you before they start, with a documented handover so the programme keeps its pace rather than restarting — never a silent swap.
Can you work alongside our existing IT team or Managed Service Provider (MSP)?
Yes — that's the norm, not the exception. Most engagements integrate directly with your internal team, existing vendors, and any managed service providers already in place. We scope around what's already there, not around replacing it.
Do you work with organisations outside the UK, or only on-site?
Both. We've delivered multi-country programmes for organisations with estates spanning Europe and beyond, combining remote delivery with on-site time where it genuinely adds value — workshops, go-live support, stakeholder sessions. We'll agree the right mix for your organisation upfront.
How quickly can you start?
For scoping conversations and initial assessments, typically within a week. Full delivery engagements depend on scope and current commitments — we'll always tell you honestly rather than overpromise a start date we can't hit.
Platforms & approach
Which technologies we work with, and how we stay honest about recommending them.
What platforms do you cover?
We have the deepest hands-on delivery experience with Saviynt (EIC & CPAM) and SailPoint, and have also delivered on Oracle IAM, CyberArk, Ping Identity, and Microsoft Entra ID.
If you run something we haven't delivered before, that isn't a barrier. Across 22+ years and 25+ go-lives, the hard part has consistently been the identity design — role and entitlement models, segregation of duties, Joiners/Movers/Leavers (JML), federation — and that transfers between products. Configuration is the part that changes. We come up to speed on an unfamiliar platform quickly for exactly that reason, and we'll tell you upfront where our product-specific experience starts and stops.
Every strategy engagement starts vendor-neutral — if a platform decision is on the table, we run a structured evaluation rather than defaulting to what we know best.
See our Expertise →How do you actually keep product recommendations vendor-agnostic?
Every scoring matrix is built from your specific requirements first — not a generic ranking we reuse across clients. Vendor responses and proof-of-concept results are scored against that matrix, not gut feel or familiarity. We also factor in independent analyst research, including Gartner and Forrester reports, as one input alongside your requirements and our own hands-on delivery experience — though the final weighting always comes back to what actually matters for your environment. We're not a Gartner or Forrester partner, and we don't claim to be; we simply read the same research a well-informed buyer would.
Request our restricted platform implementation notes →Do you only provide strategy advice, or do you design the architecture too?
Both — and architecture is a service in its own right, not an add-on to a strategy engagement. We design identity data flows, integration patterns, and role and policy models, and the same team that designs the architecture is available to build it rather than handing it off to another firm.
See Architecture & Design →We're on a legacy or in-house built identity system — can you help us move off it?
Yes — that's one of the more common starting points we see. We've migrated organisations off ageing on-premises platforms and bespoke, internally built identity systems onto modern, supported commercial platforms, without disrupting live services. We handle the entitlement and data migration strategy, run the new platform alongside the old one during cutover, and decommission the legacy system only once the new one is proven in production.
See a related case study →What frameworks and regulations do you have experience with?
ISO 27001, SOC 2, NIST CSF, GDPR, and DORA, among others — including hands-on ISO 27001 Lead Auditor certification held by Naveen Kumar, our founder. We map identity controls to whichever framework actually applies to your business.
See Compliance & Audit Readiness →Delivery & support
What happens once the work starts — and what happens after go-live.
Do you provide ongoing support after go-live, or just the initial implementation?
Both. Day-two support is one of our core capabilities precisely because IAM programmes decay without ongoing attention. It's expert-level support from the people who understand your platform — not a generic vendor ticket queue. We can hand back to your team fully, stay on for ongoing support, or anything in between.
See Managed Access Governance →Will we end up dependent on you?
No — and we'd treat it as a failure of the engagement if you did. Everything we build is documented as it's built: architecture decisions, role and policy models, and runbooks for the processes we put live. Your team is involved through delivery rather than handed a finished system at the end, and knowledge transfer happens before go-live, not after it.
When an engagement ends you can take it fully in-house, keep us on for day-two support, or anything in between. The deliverables, documentation, and platform configuration are yours — we hold nothing back to keep you tied in.
See how engagements are structured →Is the free IAM Health Check actually free, no strings attached?
Yes. It runs entirely in your browser, nothing you enter is transmitted anywhere unless you choose to email yourself the results, and there's no obligation to talk to us afterward.
Take the free health check →Your case studies don't name clients — can we speak to a reference?
Client engagements are described at the sector level and kept anonymous by design — the specifics of another organisation's identity risk aren't ours to publish. References can be arranged directly with a prospective client under the right context; just ask when we talk.
See our case studies →Commercial & procurement
The questions procurement, legal, and due diligence teams ask before an engagement starts.
How do you charge for engagements?
Whichever model fits the work — project-based, time & materials, retainer, or staff augmentation. We agree the model, rate, and scope upfront before any work begins, and we'll flag it clearly if scope looks likely to change.
See Engagement Models →Are you insured?
Yes. We carry professional indemnity insurance of £2 million for any one claim, together with public liability and employer's liability cover. We also operate IR35-compliant. Certificates are available on request as part of any procurement or due diligence process, and we can arrange additional or higher cover where a contract requires a specific limit.
Does your team hold UK security clearance?
Naveen, our founder, has previously held UK security clearance, which has since lapsed — as clearance does once you leave a cleared role. Where a project requires it, we're willing to put the team members on your programme through BPSS, SC, or any other vetting the client sponsors, and having been through the process before makes that straightforward.
Tell us early if clearance is a gate for your programme, so the lead time can be built into the plan rather than discovered late.
How do you handle our data and access information during an engagement?
IAM assessments inevitably touch sensitive entitlement, identity, and sometimes personal data. We work under mutual NDAs as standard, scope access to only what the engagement needs, and handle everything in line with UK GDPR. Nothing leaves the engagement beyond the agreed deliverables.
Read our privacy policy →