An independent reading of your identity and access architecture, in writing, by someone with no Okta or Entra ID licence to sell you.
Identity has quietly become the actual security perimeter for most businesses, and most IAM implementations grow organically — a group added here, an SSO integration bolted on there, SCIM provisioning that works for some applications and not others. What you don’t have is an independent reading of whether the current architecture is genuinely coherent, or a collection of individually reasonable decisions that don’t add up to real zero-trust posture.
That is what this engagement is.
€15,000. Three to four weeks. Delivered in writing, with a presentation to whoever needs to hear it.
Fixed fee. No implementation work. No commissions. No product recommendations influenced by suppliers.
Why clients commission this review
- An IAM platform migration or consolidation — moving to Okta, Entra ID, or between them — is being considered, and the board wants an independent strategy before committing.
- Access reviews keep surfacing stale permissions and orphaned accounts, and the board wants to know why the underlying process keeps failing.
- A genuine zero-trust posture has been discussed as a goal, but no one has assessed how far the current architecture actually is from it.
- An acquisition or growth event has brought a second identity domain into the business that needs to be reconciled with the first.
Who this is for
Boards and technology leaders planning an IAM strategy, migration, or consolidation who want an independent architectural read first.
Compliance and risk functions needing evidence the identity architecture genuinely supports the access control claims made in other compliance documentation.
Who this is not for
Organisations wanting the IAM platform configured or migrated. We identify and recommend; we do not implement.
What you receive
The Review tells you three things in writing: where your identity architecture genuinely stands, where the priorities are, and what to fix first. Five artefacts, delivered together, in plain language.
A scored architecture reading. SSO coverage, SCIM provisioning consistency, and genuine zero-trust posture assessed with evidence, not assumed from the platform’s marketing claims.
An access review process assessment. Whether the current access review cadence and process actually catches stale permissions, or just produces a report no one acts on.
A risk register sorted by business impact. Every material gap identified, ranked by consequence.
A prioritised roadmap. What to address first, second, third, sequenced across the next year.
A board presentation. A one-hour session with your board or security committee, findings presented, challenged, and discussed in the room.
How the Review runs
Three to four weeks, in four phases: scoping and inventory, interviews and evidence gathering across IT, security, and HR, synthesis and writing, then presentation and revisions around your board cycle.
Everything is written before it is said. Nothing is presented to your board that you have not read first.
What this is not
An implementation engagement. We identify and recommend; we do not implement. Ongoing IAM governance advisory can be discussed separately as a retainer where the Review surfaces a need for it.
Proof
References available on request.
What happens next
Start a ConversationThirty minutes. We confirm fit, scope, and timing. No proposal is sent unless you ask for one.