They spent two full days with our service desk before touching the directory exports. That patience showed up in the findings — several of our ‘temporary’ admin groups had been temporary since 2019. The report was dense, and we needed a second read to prioritise, but the workshop sorted that.
Client stories
Accounts from security, infrastructure, compliance, and people teams who commissioned identity and access management reviews with Workspace Lakepath.
We brought Workspace Lakepath in ahead of an external audit focused on privileged access. They flagged break-glass accounts that still shared a password vault entry among six people. Remediation took longer than we hoped, yet the evidence pack made the auditor conversation straightforward.
Our first certification campaign was a mess of role codes nobody understood. Their support redesigned the reviewer packets and ran a dry-run with finance only. Completion rates improved, and managers stopped approving everything on Friday afternoons.
The joiner–mover–leaver review caught that transfers between branches never triggered a rights review. We had assumed HR tickets covered it. They don’t — not yet — but at least we know where the handoff fails.
Extended note: regional logistics IAM review
A Western Cape logistics firm asked for a comprehensive identity and access management review ahead of renewing cyber insurance. Directory nesting from two acquisitions had left warehouse supervisors with lingering ERP admin rights.
Over four weeks we sampled high-risk groups, interviewed the service desk, and traced three dormant shared accounts still used for month-end posting. The mild reservation from their security lead — that the draft report felt dense — led us to add a one-page executive sequence before the closing workshop. That sequence became the board pack attachment.
Discuss a similar review