Comprehensive IAM Review
A structured review of identity lifecycle controls, entitlement sprawl, and access decision points across your directories and applications.
Details
Workspace Lakepath
Independent assessments of directories, privileged roles, and joiner–mover–leaver paths for security and compliance teams in South Africa.
We examine identity sources, entitlement chains, and the human handoffs that create privilege creep. The work is advisory and evidence-led, not a product rollout.
Whether you are preparing for an external audit or cleaning up years of nested admin groups, the engagement produces a prioritised findings pack your owners can act on.
How an engagement runs
Each engagement is scoped to your directories and applications. Start with a full IAM review or a narrower privileged-access or certification focus.
A structured review of identity lifecycle controls, entitlement sprawl, and access decision points across your directories and applications.
DetailsFocused examination of admin accounts, break-glass paths, and standing privileges that bypass day-to-day controls.
DetailsDesign and dry-run of manager and owner certification campaigns so reviews produce decisions, not rubber stamps.
DetailsWalkthrough of hire, transfer, and exit access paths — from ticket queues to automated provisioning — with gap notes for HR and IT.
Details
Read-only evidence collection and stakeholder interviews — on-site when it helps, remote when distance does not. Fees stay proposal-based so scope matches your identity estate.
View fee guidanceStories from security, infrastructure, and people teams who commissioned identity and access management reviews with us.
They spent two full days with our service desk before touching the directory exports. That patience showed up in the findings — several of our ‘temporary’ admin groups had been temporary since 2019. The report was dense, and we needed a second read to prioritise, but the workshop sorted that.
We brought Workspace Lakepath in ahead of an external audit focused on privileged access. They flagged break-glass accounts that still shared a password vault entry among six people. Remediation took longer than we hoped, yet the evidence pack made the auditor conversation straightforward.