Notes from real identity programmes
What actually works in delivery, what breaks, and why — written from the inside of live programmes rather than from a vendor datasheet. Some pieces go into detail we only share directly; those are marked.
Independent assessments keep finding the same themes
Across organisations with nothing else in common — different sectors, different platforms, different maturity — the findings converge. Very few are technology problems.
- Unclear ownership of identity data and process
- Governance defined after the platform, not before it
- Provisioning fragmented across teams and systems
- Service accounts treated as an afterthought
- Customisation that nobody remaining can explain
- Undocumented integrations holding the estate together
- Manual workarounds introduced as temporary, now permanent
- No confident way to assess the impact of a change
Authentication patterns: what belongs where
Most estates run a dozen authentication mechanisms and have never agreed which are strategic, which are tolerated, and which are on the way out. A reference model for deciding.
Read the piece →Why identity data matters more than the IAM tool
A platform does not clean your data — it industrialises whatever you already have, including the parts that are wrong. Why data quality predicts programme success better than product choice.
Read the piece →Security Assertion Markup Language (SAML) and OAuth 2.0 are not alternatives
They answer different questions — one proves who a user is, the other delegates permission to act. Treating them as competing options is where most integration problems start.
Read the piece →Why access certification campaigns fail
Most campaigns complete on time and change almost nothing. The problem is rarely the platform — it is what reviewers are actually being asked to decide.
Read the piece →Platform Notes — from the inside of real implementations
Configuration quirks, integration friction, and what the vendor documentation does not tell you — across the Identity Governance and Administration (IGA), Privileged Access Management (PAM), and cloud IAM platforms we have actually delivered. Shared directly rather than published.
Request access →