Observations from the field

The four pillars of an enterprise IAM strategy

Every enterprise IAM strategy we've built ends up organised around the same four capability areas. The platforms change; the shape of the strategy underneath them doesn't.

Vision before pillars

A strategy document that starts with a platform comparison has already skipped a step. We start with a small number of principles the whole programme gets measured against — because a roadmap with no stated principles just becomes whatever the loudest stakeholder wants that quarter:

  • Least privilege, by default, not by exception.
  • Alignment with Zero Trust — identity is the perimeter now, not the network.
  • Automation-first, over building a bigger operations team to run manual processes.
  • As little platform customisation as the requirements genuinely allow.
  • Compliance by design, not bolted on before an audit.
  • A path toward passwordless authentication, not just more password policy.

The four pillars

Underneath the vision, we've found the same four capability areas do the actual work in every enterprise IAM strategy, regardless of sector or existing tooling:

A maturity model, not a wishlist

A strategy is only useful if it says where you actually stand today, not just where you'd like to end up. We assess each of the four pillars — plus authentication, authorisation, provisioning, audit, and user experience individually — against five maturity levels:

 Level 1Level 2Level 3Level 4Level 5
Maturity Initial / Ad hoc Repeatable / Basic Defined / Standardised Managed / Measured Optimized / Adaptive
What it looks like Manual provisioning, no central identity store, no governance Basic SSO, manual provisioning scripts, limited MFA Central identity store, defined RBAC, MFA everywhere Automated lifecycle, certification campaigns, PAM in place Just-in-Time access, full Zero Trust, behaviour-based policy

Most organisations aren't uniformly at one level. It's normal — and useful to know explicitly — that authentication might be well ahead of identity governance, or that provisioning is automated while access reviews are still a spreadsheet.

Worth asking before writing a roadmap: which of the four pillars is your organisation's actual weak point today? Most strategy conversations start with a platform decision instead of this question — and end up buying capability for a pillar that wasn't the real constraint.

A phased roadmap, not a big-bang programme

Once the maturity gaps are honest, the roadmap follows a consistent shape — the same Discover → Design → Deploy → Sustain model we use across every engagement, unpacked into five phases for a strategy programme specifically:

  • Foundation & assessment. Current-state maturity, governance model, stakeholders, and target platform selection — before anything gets built.
  • Quick wins & risk mitigation. MFA everywhere, SSO for critical applications, legacy authentication decommissioned, privileged accounts identified and secured — visible progress inside the first quarter.
  • Core enablement. The Identity Governance platform goes in, Joiner/Mover/Leaver is automated, role-based access control is implemented, and Privileged Access Management is deployed.
  • Governance & optimisation. Access reviews expand to every key system, segregation-of-duties is actively monitored, and Just-in-Time access replaces standing privilege.
  • Intelligent & adaptive. Risk-driven, behaviour-based access policies, and identity extended to non-human identities — service accounts, bots, and APIs — under the same governance discipline as everyone else.

A Target Operating Model sits alongside the roadmap, not after it — who owns the strategy, who runs day-to-day operations, who's accountable for application-level access decisions, and where HR's data stops being HR's problem and starts being identity's. Getting that governance structure agreed early is what keeps a phased roadmap from quietly reverting to whoever shouts loudest, three phases in — see what that operating model actually needs to cover.

Key takeaways

  • Start with principles, not a platform shortlist — the shortlist should be a consequence of the strategy, not the starting point.
  • Four pillars — Access Management, Identity Lifecycle Management, Identity Governance, Privileged Access Management — do the actual work, whatever the vendor.
  • Maturity is rarely uniform across pillars. Know where the real gap is before writing a roadmap around it.
  • A phased roadmap with an agreed governance model survives contact with reality. A big-bang programme with no operating model rarely does.
See Strategy & Identity Acceleration →

← All insights

Not sure where your own IAM strategy actually stands?

A current-state maturity assessment usually answers that faster than another round of internal debate.

Talk to us