How an engagement runs

A predictable path from first scoping call to remediation workshop — designed for identity and access management reviews, not open-ended consulting retainers.

Facilitator at a whiteboard mapping identity sources during a review kickoff
  1. Scoping call. We map directories, federation points, critical applications, and the compliance or insurance driver behind the review.
  2. Access and logistics. You nominate a technical contact, confirm read-only evidence paths, and schedule stakeholder interviews.
  3. Evidence collection. Exports, configuration screenshots, and ticket samples land in a controlled workspace. Interviews fill the gaps numbers cannot show.
  4. Analysis. Privilege chains, dormant accounts, joiner–mover–leaver breaks, and segregation-of-duties clashes are rated by business exposure.
  5. Draft review. Named owners see findings before the final pack so factual corrections happen early.
  6. Closing workshop. Severity, owners, and sequence are agreed in the room. The written report follows within the agreed window.

What you provide

A technical contact with rights to pull membership and role exports, a shortlist of critical applications, and calendar time for service desk, HR operations, and application owners. Classified environments may need extra clearance — tell us early.

What we provide

A fixed-scope proposal, a findings report with severity and suggested owners, an evidence appendix suitable for auditors, and a workshop agenda that forces prioritisation rather than endless discussion.