Comprehensive IAM Review
A structured review of identity lifecycle controls, entitlement sprawl, and access decision points across your directories and applications.
Who it is for
Security, IT, and compliance leads who need an independent view of who can access what — and why those permissions still exist.
What you leave with
A prioritised findings report, evidence pack for auditors, and a practical remediation roadmap tied to your identity stack.
- Format
- On-site and remote engagement
- Duration
- Typically 3–6 weeks, depending on directory and application scope
- Location
- Cape Town and remote across South Africa
- Provider
- Senior IAM reviewers based in Cape Town
- Pricing basis
- Fixed-scope proposal after a scoping call
- Indicative fee
- From R48 000
Included
- Inventory of identity sources, federation points, and privileged roles
- Sampling of high-risk entitlements and orphaned accounts
- Review of joiner–mover–leaver handoffs against written policy
- Segregation-of-duties spot checks on finance and admin roles
- Written findings with severity ratings and owner suggestions
- Closing workshop with your security and identity owners
Outside this engagement
- Hands-on remediation or directory reconfiguration
- Penetration testing or vulnerability scanning
- Ongoing access certification facilitation (available as a separate engagement)
How the review unfolds
- Scoping call to map directories, apps, and compliance drivers
- Read-only evidence collection and stakeholder interviews
- Analysis of privilege patterns, dormant access, and control gaps
- Draft report review with your nominated owners
- Final report and remediation workshop
Preparation
Nominate a technical contact with read access to identity admin consoles and a list of critical applications. Share current access policies if they exist.
Constraints
We work with read-only or export-based evidence unless you explicitly grant broader access. Classified environments may require additional clearance steps.