Services

The services we offer, and where organisations bring us in

We offer ten services, from a single focused health check to a full end-to-end programme: Strategy & Identity Acceleration, Integration Services, Architecture & Design, IAM Platform Health Check, Full RFP & Platform Selection, Managed Access Governance, Specialist IAM Testing & Business Analysis, Compliance & Audit Readiness, Legacy Modernisation & Cloud Migration, and Agentic AI-Driven Delivery. Every engagement is vendor-neutral and scoped to your actual risk.

What sets us apart

Not just what we do: how we do it differently

  • Architecture-led, not configuration-led: most IAM problems are architecture problems disguised as technology problems, so we design the solution architecture first
  • Negative-case-led testing: proving access that shouldn't exist doesn't, not just that access which should work does
  • The shortlist comes out of the requirements workshop, not off a preferred-vendor list
  • We publish the reference model we evaluate against, not just the verdict: a vendor's own architecture diagram isn't independent advice

Strategy & Identity Acceleration

We assess your current identity landscape and build a pragmatic, risk-prioritised roadmap, then accelerate delivery by streamlining the processes behind it, so security doesn't come at the cost of speed or user experience.

  • Current-state identity & access assessment
  • Target operating model & architecture
  • Risk-prioritised, phased roadmap
  • Direct advisory to CISOs, CTOs & CIOs on identity strategy and risk
  • Identity and access guardrails for enterprise AI adoption: Copilot, agents, and LLM tools

Integration Services

Engage us as your integration partner across the full delivery lifecycle, not just for advice on paper. We design, build, test, and roll out your IAM platform, then stay on afterwards so the programme doesn't stall the moment it ships.

  • Solution design carried through into a working build, not handed off as a document
  • Configuration and development across governance, privileged access, and cloud IAM platforms
  • Structured testing before go-live, so defects surface in test rather than in production
  • Phased roll-out planning, sequenced to avoid business disruption
  • Post-go-live hypercare and stabilisation support
  • One accountable team across design, build, and support, not a different vendor at every stage

Architecture & Design

Most IAM problems are architecture problems disguised as technology problems. A roadmap is only as good as the architecture behind it, so we design the solution architecture itself, or evaluate one you already have or one a vendor or systems integrator has proposed: identity data flows, integration patterns, role and policy models, and how it sits alongside your existing directory, HR, and IT Service Management (ITSM) systems.

  • Identity data flow and integration pattern design
  • Role and policy model design, mapped to how your organisation actually operates
  • Target-state architecture documented for steering committee or architecture board sign-off
  • Integration design across the whole estate: directory, HR and ITSM, every in-scope application that can be connected by connector or API, and the long tail that cannot, which still needs governed manual fulfilment and evidence rather than being left outside the model
  • Architecture Evaluation & Report
    An independent review of an existing or proposed target-state design against a vendor-neutral reference model, not a vendor's own reference architecture, with findings you can take to a steering committee or architecture board.
  • The same team that designs the architecture is available to build it, with no hand-off to another firm

The reference model we evaluate against →

IAM Platform Health Check

Already have a platform in place? We run a structured, expert-led evaluation of what you have today (configuration, process, and coverage) and hand you a written report your board or audit committee can act on. It's a deeper, evidence-based step up from our free online health check, not a replacement for it.

  • Platform configuration review: roles, policies, entitlements, and workflow design against best practice
  • Access governance process review: Joiners/Movers/Leavers (JML), certification campaigns, and Segregation of Duties (SoD) controls
  • Privileged access and non-human/AI identity coverage assessment
  • Application coverage assessment: which in-scope applications the platform actually governs, which are handled manually, and which are governed by nobody
  • Gap analysis against the compliance frameworks that apply to you: ISO 27001, SOC 2, NIST CSF, GDPR, DORA
  • Risk-prioritised written report and remediation roadmap, presented back to your stakeholders

Full RFP & Platform Selection

Engagements, not licences. We take no resale margin from any vendor, so a structured, evidence-based procurement replaces the vendor beauty contest. We run the Request for Proposal (RFP) and proof-of-concept evaluation end to end, scored against your requirements, not against our familiarity with any one platform.

  • Structured RFP and proof-of-concept evaluations across the identity governance, privileged access and cloud IAM platforms that fit your requirements: the shortlist comes out of the requirements workshop, not off a preferred-vendor list
  • Full, capability-wide RFP for greenfield organisations with no existing IAM strategy: governance, privileged access, and cloud IAM evaluated together, not vendor by vendor
  • Requirements workshops translated into a weighted evaluation matrix
  • Vendor responses and proof-of-concept results scored consistently against that matrix, not gut feel
  • Final recommendation report, plus support through commercial and contract negotiation
  • A recommendation you can defend to a board or audit committee, with the scoring behind it

Managed Access Governance

The ongoing operation of your access governance programme: certification campaigns run on schedule, JML kept current, and segregation-of-duties conflicts caught before an auditor finds them.

  • Scheduled access reviews and certification campaigns, run and chased through to completion
  • JML process operation and exception handling
  • Segregation-of-duties conflict monitoring and remediation
  • Policy and control tuning as the business and platform evolve
  • Quarterly identity risk reporting for security leadership and audit committees

See how a Directory Hygiene Review works →

Specialist IAM Testing & Business Analysis

Generic QA testers and business analysts can slow an IAM programme down as much as help it: the domain has its own failure modes and its own way of gathering requirements. The testers and business analysts we put on your programme specialise in IAM specifically, not software delivery in general, brought in for identity work rather than redeployed from a general QA pool. They bring a wealth of experience from some of the most complex IAM programmes delivered.

  • IAM testing is negative-case-led: proving access that shouldn't exist doesn't, not just that the access that should work does
  • Segregation-of-duties conflict testing, entitlement correctness testing, and JML scenario testing across every connected system
  • Automated regression after every policy or role change, so a fix in one area doesn't silently break certification elsewhere: proving a joiner lands the exact entitlement set, replaying segregation-of-duties rule sets against the matrix, and confirming a revocation reached the target system rather than just closing the ticket
  • IAM business analysis means mapping organisational structure and process to a technical access and role model, not writing user stories for a single application
  • Requirements gathered directly from application and data owners across your estate, then reconciled into a single entitlement catalogue, not one product team's user stories
  • Audit and regulatory evidence requirements translated into testable control requirements upfront, not retrofitted after go-live

Compliance & Audit Readiness

We map your identity controls to the frameworks that matter to your business, and prepare the evidence trail before the auditor asks for it.

See which framework applies to your sector →

Legacy Modernisation & Cloud Migration

Legacy identity platforms and on-premises infrastructure accumulate risk quietly: unsupported software, manual processes, and technical debt that make every audit slower than it should be. Whatever you're moving from (an ageing platform, a homegrown identity system, or infrastructure that's simply run out of road), we plan and deliver the move to modern technology without disrupting the business along the way.

  • Legacy IAM platform migration to modern Software as a Service (SaaS) governance platforms
  • Migration from bespoke, in-house built identity solutions to supported commercial-off-the-shelf (COTS) platforms
  • On-premises to cloud IAM migration, phased for zero business disruption
  • Data and entitlement migration strategy for large, complex estates
  • Legacy infrastructure decommissioning once the new platform is live

Agentic AI-Driven Delivery

We build our own products, including Directory Hygiene, with agentic AI under a real, independently-audited review discipline, not a one-shot generated build. Where your engagement means building something rather than just configuring a platform, we bring that same approach to it.

  • Faster iteration on the actual working thing, not a faster route to something unreviewed
  • Every change independently verified, then that review itself independently audited, before it ships
  • Speeds up the unglamorous parts of advisory work too: documentation, evidence packs, consistency checks across a large estate
  • A real product to point to, not a claim: see the actual demo, not staged screenshots

How we build this way →

Questions about how we work?

Platforms we cover, who delivers the work, insurance and NDAs, references, and how we charge, answered directly.

Read the FAQ

Not sure where to start?

Tell us about your environment and we'll recommend the right first engagement.

Talk to us
Talk to us