Observations from the field

Notes from real identity programmes

What actually works in delivery, what breaks, and why, written from the inside of live programmes rather than from a vendor datasheet. Some pieces go into detail we only share directly; those are marked.

What we see repeatedly

Independent assessments keep finding the same themes

Across organisations with nothing else in common (different sectors, different platforms, different maturity) the findings converge. Very few are technology problems.

  • Unclear ownership of identity data and process
  • Governance defined after the platform, not before it
  • Provisioning fragmented across teams and systems
  • Service accounts treated as an afterthought
  • Customisation that nobody remaining can explain
  • Undocumented integrations holding the estate together
  • Manual workarounds introduced as temporary, now permanent
  • No confident way to assess the impact of a change
IAM Architecture 9 min read

Authentication patterns: what belongs where

Most estates run a dozen authentication mechanisms and have never agreed which are strategic, which are tolerated, and which are on the way out. A reference model for deciding.

Read the piece →
Identity Data 7 min read

Why identity data matters more than the IAM tool

A platform does not clean your data: it industrialises whatever you already have, including the parts that are wrong. Why data quality predicts programme success better than product choice.

Read the piece →
Authentication 8 min read

Security Assertion Markup Language (SAML) and OAuth 2.0 are not alternatives

They answer different questions: one proves who a user is, the other delegates permission to act. Treating them as competing options is where most integration problems start.

Read the piece →
Identity Governance 6 min read

Why access certification campaigns fail

Most campaigns complete on time and change almost nothing. The problem is rarely the platform: it is what reviewers are actually being asked to decide.

Read the piece →
Identity Governance Tool 3 min read

Directory Hygiene: the missing precondition for access governance

A reviewer looking at "member of Group_X47" (no description, no owner, no stated purpose) has no real basis to approve or deny it. That's not reviewer laziness, and it's not only a certification problem. It's a data problem wearing a workflow costume.

Read the piece →
IAM Strategy 4 min read

The four pillars of an enterprise IAM strategy

Every enterprise IAM strategy we've built ends up organised around the same four capability areas. The platforms change; the shape of the strategy underneath them doesn't.

Read the piece →
IAM Architecture 4 min read

Most IAM problems are architecture problems, not platform problems

A roadmap is only as good as the architecture behind it. Most programmes skip straight to "which platform" and inherit whatever reference architecture the vendor ships with.

Read the piece →
IAM Strategy 4 min read

The Target Operating Model (TOM) most IAM roadmaps skip

A phased roadmap says what gets built and when. It doesn't say who runs it once it's live, or who's accountable when it starts to decay six months after go-live.

Read the piece →
Platform Internals 7 min read

SailPoint IdentityIQ: the lifecycle events nobody reads the docs for

There is no "Rehire" event in IdentityIQ, and an application never sent to SAP GRC can still wait on its verdict. Two real platform behaviours worth knowing before you scope a requirement against them.

Read the piece →
Identity Data Platform Internals 6 min read

What actually breaks in a Saviynt data pipeline

Saviynt's own UI rarely tells you why an import silently dropped rows. Real failure modes from the data pipeline underneath, and why they matter more than the access-request screen.

Read the piece →
Identity Governance 6 min read

The API parameter that makes a failed provisioning request look "Complete"

An IGA-to-ServiceNow integration closed tickets as Complete whether provisioning succeeded or failed entirely, because the default API response couldn't tell the difference. One parameter fixes it.

Read the piece →
Vendor Evaluation 5 min read

The vendor-scoring mistake that rewards whoever's researched the least

An early version of our own vendor-ranking formula let a thinly-checked vendor score 100% and outrank two competitors who'd been researched far more rigorously. Here's what we changed.

Read the piece →
Identity Governance Audit & Control 5 min read

The backdated HR date that made a compliant IAM team look 31 days late

A termination entered a month late, backdated to the real leaving date, turned a same-day access removal into what looked on paper like a 31-day compliance gap. The fix is which clock the audit trail trusts.

Read the piece →
Platform Comparison Restricted

Platform Comparison Reports: from the inside of real implementations

Configuration quirks, integration friction, and what the vendor documentation does not tell you: across the Identity Governance and Administration (IGA), Privileged Access Management (PAM), and cloud IAM platforms we have actually delivered. Shared directly rather than published.

Request access →

Working through something similar?

If a piece here matches a problem you are facing, a short conversation is usually more useful than another article.

Talk to us
Talk to us