Identity and access management services
Know who has access to what — through every acquisition, restructure and leaver.
Access sprawl accumulates constantly. Orphaned accounts, toxic permission combinations, third-party access nobody owns. We map your identity estate, remediate what we find, and put the governance in place to keep it that way, so you can get back to business.
Why it happens
Every change to the business is a change to who needs access.
Every acquisition brings another directory. Every restructure leaves roles mapped to an organisation that no longer exists. Every leaver leaves a residue — an account, a group membership, a shared credential. Access drifts as a by-product of the business changing, and the business changes constantly.
The result is rarely one large hole. It is an accumulation of small ones that no single person can see.
What it looks like in practice
-
Orphaned accounts
Accounts that no longer map to anyone on the payroll. They keep their access until somebody happens to notice.
-
Manual joiner, mover and leaver processes
Lifecycle changes handled by ticket and memory. Movers accumulate access from every role they have held; leavers linger.
-
Over-provisioned third-party access
Vendors and contractors granted broad access at onboarding, rarely reviewed afterwards and seldom revoked at the end.
-
Group sprawl and toxic combinations
Nested groups nobody can unpick, and permission pairs that are harmless alone but break segregation of duties together.
-
Gaps in reviews and ownership
No regular access reviews, incomplete audit trails, and systems with no named owner able to sign anything off.
-
Shadow IT and silent automation failures
Tools bought outside IT, and integrations that stop working quietly. Both leave access that nobody is tracking.
These are the patterns we find most often. They tend to return unless the underlying process changes, which is why we treat them as design problems rather than clean-up work.
48%
of breaches now involve a third party — up 60% in a single year.
Verizon Data Breach Investigations Report, 2026 edition.
Why it is worth doing properly
The access you cannot see is the access nobody is reviewing.
Third-party access is the clearest example. Vendors, contractors and integration accounts are granted access during onboarding, and the relationship changes long before the access does. It is now the fastest-growing route into organisations, and it is created by exactly the business changes that make identity difficult to keep on top of.
Identity specialists are scarce and expensive, so this work usually falls to people already carrying a full remit. That is not a resourcing failure. It is why most organisations reach for help at the point where the estate has grown past what one person can hold in their head.
How we work
From first look to business as usual.
Four stages. Each one ends with something you can act on, and the fourth is what stops the first three needing to happen again.
-
Find out what you actually have.
- Maturity assessment across the full set of identity domains
- Identity, entitlement and privileged-account discovery
- Gap analysis against ISO 27001 and NIST
- Prioritised risk and quick-wins register
-
Decide who owns what, before you buy anything.
- Target operating model and governance charter
- Role and entitlement model, with segregation of duties
- Reference architecture and integration patterns
- Platform evaluation, independent of vendor
-
Build it in waves, not in one go.
- Joiner, mover and leaver automation driven from HR
- Access request and approval workflows
- Access certification campaigns
- Privileged access vaulting and session control
-
Keep it true after go-live.
- Recertification campaigns run to schedule
- New applications onboarded as they arrive
- Platform upgrades and continuous enhancement
- Audit evidence produced on demand
The full identity lifecycle
Five questions an identity programme has to answer.
Identity covers people, services and machines, across every directory and every system they reach. These are the questions that decide whether it is under control.
Who has access?
Visibility across every identity, human and machine, wherever it lives.
Should they have it?
Governance, access reviews and entitlements that someone owns and signs off.
How do they get in?
Authentication, zero trust and adaptive access appropriate to the risk.
What happens when things change?
Joiners, movers, leavers and deprovisioning, driven from an authoritative source.
What about high-risk accounts?
Privileged access treated as its own discipline, not a tier of ordinary access.
Seeing the estate
A spreadsheet cannot show you this.
We map every identity to its source of truth and render the whole estate as a graph. Access that looks reasonable row by row shows its shape once you can see the connections — who sits at the centre of everything, which groups nest inside which, and which accounts are attached to nothing at all.
What it surfaces
- Orphaned and dormant accounts with no owner
- Group sprawl and nesting nobody can unpick
- Toxic permission combinations across systems
- Third-party access that outlived the contract
- Accounts holding far more access than their peers
- Identities that map to no source of truth
The graph is a working tool rather than a deliverable. It is how we decide what to prioritise, and how we show you why.
Solution brief
Identity Governance Maturity Assessment
An eight-page brief covering the pressures making identity harder to govern, the six findings we encounter most often, how the assessment runs, and what you receive at the end.
- Six categories of exposure
- The four assessment stages
- What you receive
- Outcomes it supports
What we cover
Four capabilities, governed as one.
Identity is usually bought in pieces and ends up managed in pieces. These four areas share the same roles, the same owners and the same evidence, so they are designed together.
-
Identity governance and administration
Roles, entitlements, access reviews and certification campaigns, with the evidence trail an auditor will ask for.
-
Access management
Single sign-on, multi-factor and adaptive access policies applied consistently across cloud and on-premises systems.
-
Privileged access management
Credential vaulting, just-in-time elevation, session recording and break-glass governance for the accounts that matter most.
More on privileged access → -
Customer identity
Secure, scalable registration and authentication for customers and partners, without pushing complexity onto them.
Evidence
Where we have done this before.
Named engagements in regulated and operationally complex environments. Reference contacts are available on request.
- Longest running
WesBank
Enterprise identity governance across the bank: lifecycle management from source, rule-based provisioning, segregation of duties across financial systems, quarterly attestations and privileged access controls.
99.99% availability across a geographically distributed platform
Quilter / Utmost International
Identity migration and Transition Services Agreement exit, moving identity services onto cloud platforms. Talanos continues to run governance and recertification campaigns.
Separation completed without a break in access governance
Mascom
Identity governance built on Saviynt, automating joiner, mover and leaver processes from Oracle EBS HR and Active Directory, with birthright access by role.
Lifecycle driven from HR rather than tickets
University of Pretoria
Directory consolidation, workflow-based provisioning, password self-service and web access management, alongside substantial change management.
Hundreds of thousands of identities across students, staff and external users
Trusted with identity by
Independently assessed
Common questions
What people ask before they start.
Do we need to choose a platform before we start?
No. Choosing a platform first is the most common way these programmes go wrong, because the tool ends up defining the operating model instead of supporting it. We assess what you have and design the target model first, then evaluate platforms against those requirements.
Can you work with the identity tooling we already have?
Usually, yes. We hold accreditations across several identity platforms and have built production services on them, so a recommendation to keep what you have is as likely as a recommendation to replace it.
What do we need to provide?
Access to the people who understand your processes, and to the systems that hold identity data. The heaviest demand is on your HR, IT and application owners during discovery, and it lightens considerably after that.
Do you hand it over at the end, or keep running it?
Either. Some clients take the programme in-house after implementation and some ask us to keep operating it, which is why several of our identity engagements have run for years. The decision is yours and it does not have to be made at the outset.
How does this relate to our audit and compliance obligations?
Access governance is where most identity findings originate: reviews that are not evidenced, entitlements with no owner, and accounts that outlived their purpose. The governance framework and access certification work is designed to produce the evidence an auditor asks for as a by-product of running the process, rather than as a separate exercise.
Find out what has accumulated.
An identity assessment maps every identity to its source, surfaces the access nobody is tracking, and gives you a prioritised plan you can act on.
Book an identity assessment









