Notes from real identity programmes
What actually works in delivery, what breaks, and why, written from the inside of live programmes rather than from a vendor datasheet. Some pieces go into detail we only share directly; those are marked.
Independent assessments keep finding the same themes
Across organisations with nothing else in common (different sectors, different platforms, different maturity) the findings converge. Very few are technology problems.
- Unclear ownership of identity data and process
- Governance defined after the platform, not before it
- Provisioning fragmented across teams and systems
- Service accounts treated as an afterthought
- Customisation that nobody remaining can explain
- Undocumented integrations holding the estate together
- Manual workarounds introduced as temporary, now permanent
- No confident way to assess the impact of a change
No pieces match that filter yet.
Authentication patterns: what belongs where
Most estates run a dozen authentication mechanisms and have never agreed which are strategic, which are tolerated, and which are on the way out. A reference model for deciding.
Read the piece →Why identity data matters more than the IAM tool
A platform does not clean your data: it industrialises whatever you already have, including the parts that are wrong. Why data quality predicts programme success better than product choice.
Read the piece →Security Assertion Markup Language (SAML) and OAuth 2.0 are not alternatives
They answer different questions: one proves who a user is, the other delegates permission to act. Treating them as competing options is where most integration problems start.
Read the piece →Why access certification campaigns fail
Most campaigns complete on time and change almost nothing. The problem is rarely the platform: it is what reviewers are actually being asked to decide.
Read the piece →Directory Hygiene: the missing precondition for access governance
A reviewer looking at "member of Group_X47" (no description, no owner, no stated purpose) has no real basis to approve or deny it. That's not reviewer laziness, and it's not only a certification problem. It's a data problem wearing a workflow costume.
Read the piece →The four pillars of an enterprise IAM strategy
Every enterprise IAM strategy we've built ends up organised around the same four capability areas. The platforms change; the shape of the strategy underneath them doesn't.
Read the piece →Most IAM problems are architecture problems, not platform problems
A roadmap is only as good as the architecture behind it. Most programmes skip straight to "which platform" and inherit whatever reference architecture the vendor ships with.
Read the piece →The Target Operating Model (TOM) most IAM roadmaps skip
A phased roadmap says what gets built and when. It doesn't say who runs it once it's live, or who's accountable when it starts to decay six months after go-live.
Read the piece →SailPoint IdentityIQ: the lifecycle events nobody reads the docs for
There is no "Rehire" event in IdentityIQ, and an application never sent to SAP GRC can still wait on its verdict. Two real platform behaviours worth knowing before you scope a requirement against them.
Read the piece →What actually breaks in a Saviynt data pipeline
Saviynt's own UI rarely tells you why an import silently dropped rows. Real failure modes from the data pipeline underneath, and why they matter more than the access-request screen.
Read the piece →The API parameter that makes a failed provisioning request look "Complete"
An IGA-to-ServiceNow integration closed tickets as Complete whether provisioning succeeded or failed entirely, because the default API response couldn't tell the difference. One parameter fixes it.
Read the piece →The vendor-scoring mistake that rewards whoever's researched the least
An early version of our own vendor-ranking formula let a thinly-checked vendor score 100% and outrank two competitors who'd been researched far more rigorously. Here's what we changed.
Read the piece →The backdated HR date that made a compliant IAM team look 31 days late
A termination entered a month late, backdated to the real leaving date, turned a same-day access removal into what looked on paper like a 31-day compliance gap. The fix is which clock the audit trail trusts.
Read the piece →Platform Comparison Reports: from the inside of real implementations
Configuration quirks, integration friction, and what the vendor documentation does not tell you: across the Identity Governance and Administration (IGA), Privileged Access Management (PAM), and cloud IAM platforms we have actually delivered. Shared directly rather than published.
Request access →