Identity and access management services

Know who has access to what — through every acquisition, restructure and leaver.

Access sprawl accumulates constantly. Orphaned accounts, toxic permission combinations, third-party access nobody owns. We map your identity estate, remediate what we find, and put the governance in place to keep it that way, so you can get back to business.

Why it happens

Every change to the business is a change to who needs access.

Every acquisition brings another directory. Every restructure leaves roles mapped to an organisation that no longer exists. Every leaver leaves a residue — an account, a group membership, a shared credential. Access drifts as a by-product of the business changing, and the business changes constantly.

The result is rarely one large hole. It is an accumulation of small ones that no single person can see.

What it looks like in practice

  • Orphaned accounts

    Accounts that no longer map to anyone on the payroll. They keep their access until somebody happens to notice.

  • Manual joiner, mover and leaver processes

    Lifecycle changes handled by ticket and memory. Movers accumulate access from every role they have held; leavers linger.

  • Over-provisioned third-party access

    Vendors and contractors granted broad access at onboarding, rarely reviewed afterwards and seldom revoked at the end.

  • Group sprawl and toxic combinations

    Nested groups nobody can unpick, and permission pairs that are harmless alone but break segregation of duties together.

  • Gaps in reviews and ownership

    No regular access reviews, incomplete audit trails, and systems with no named owner able to sign anything off.

  • Shadow IT and silent automation failures

    Tools bought outside IT, and integrations that stop working quietly. Both leave access that nobody is tracking.

These are the patterns we find most often. They tend to return unless the underlying process changes, which is why we treat them as design problems rather than clean-up work.

48%

of breaches now involve a third party — up 60% in a single year.

Verizon Data Breach Investigations Report, 2026 edition.

Why it is worth doing properly

The access you cannot see is the access nobody is reviewing.

Third-party access is the clearest example. Vendors, contractors and integration accounts are granted access during onboarding, and the relationship changes long before the access does. It is now the fastest-growing route into organisations, and it is created by exactly the business changes that make identity difficult to keep on top of.

Identity specialists are scarce and expensive, so this work usually falls to people already carrying a full remit. That is not a resourcing failure. It is why most organisations reach for help at the point where the estate has grown past what one person can hold in their head.

How we work

From first look to business as usual.

Four stages. Each one ends with something you can act on, and the fourth is what stops the first three needing to happen again.

  1. 1 Discover

    Find out what you actually have.

    • Maturity assessment across the full set of identity domains
    • Identity, entitlement and privileged-account discovery
    • Gap analysis against ISO 27001 and NIST
    • Prioritised risk and quick-wins register
  2. 2 Design

    Decide who owns what, before you buy anything.

    • Target operating model and governance charter
    • Role and entitlement model, with segregation of duties
    • Reference architecture and integration patterns
    • Platform evaluation, independent of vendor
  3. 3 Implement

    Build it in waves, not in one go.

    • Joiner, mover and leaver automation driven from HR
    • Access request and approval workflows
    • Access certification campaigns
    • Privileged access vaulting and session control
  4. 4 OperateOngoing

    Keep it true after go-live.

    • Recertification campaigns run to schedule
    • New applications onboarded as they arrive
    • Platform upgrades and continuous enhancement
    • Audit evidence produced on demand

The full identity lifecycle

Five questions an identity programme has to answer.

Identity covers people, services and machines, across every directory and every system they reach. These are the questions that decide whether it is under control.

IdentitiesPeople, services and machinesDirectories and identity storesWhere identities liveSystems and applicationsWhat people actually reach
  • Who has access?

    Visibility across every identity, human and machine, wherever it lives.

  • Should they have it?

    Governance, access reviews and entitlements that someone owns and signs off.

  • How do they get in?

    Authentication, zero trust and adaptive access appropriate to the risk.

  • What happens when things change?

    Joiners, movers, leavers and deprovisioning, driven from an authoritative source.

  • What about high-risk accounts?

    Privileged access treated as its own discipline, not a tier of ordinary access.

Seeing the estate

A spreadsheet cannot show you this.

We map every identity to its source of truth and render the whole estate as a graph. Access that looks reasonable row by row shows its shape once you can see the connections — who sits at the centre of everything, which groups nest inside which, and which accounts are attached to nothing at all.

Accounts with far more access than their peersToxic combinations across groupsOrphaned accounts, connected to nothingIllustrative identity graph

What it surfaces

  • Orphaned and dormant accounts with no owner
  • Group sprawl and nesting nobody can unpick
  • Toxic permission combinations across systems
  • Third-party access that outlived the contract
  • Accounts holding far more access than their peers
  • Identities that map to no source of truth

The graph is a working tool rather than a deliverable. It is how we decide what to prioritise, and how we show you why.

Identity Governance Maturity Assessment

Solution brief

Identity Governance Maturity Assessment

An eight-page brief covering the pressures making identity harder to govern, the six findings we encounter most often, how the assessment runs, and what you receive at the end.

  • Six categories of exposure
  • The four assessment stages
  • What you receive
  • Outcomes it supports
Download the briefPDF, 8 pages. No form to fill in.

What we cover

Four capabilities, governed as one.

Identity is usually bought in pieces and ends up managed in pieces. These four areas share the same roles, the same owners and the same evidence, so they are designed together.

  • Identity governance and administration

    Roles, entitlements, access reviews and certification campaigns, with the evidence trail an auditor will ask for.

  • Access management

    Single sign-on, multi-factor and adaptive access policies applied consistently across cloud and on-premises systems.

  • Privileged access management

    Credential vaulting, just-in-time elevation, session recording and break-glass governance for the accounts that matter most.

    More on privileged access →
  • Customer identity

    Secure, scalable registration and authentication for customers and partners, without pushing complexity onto them.

Evidence

Where we have done this before.

Named engagements in regulated and operationally complex environments. Reference contacts are available on request.

  • Wealth managementSeven years, ongoing

    Quilter / Utmost International

    Identity migration and Transition Services Agreement exit, moving identity services onto cloud platforms. Talanos continues to run governance and recertification campaigns.

    Separation completed without a break in access governance

  • TelecommunicationsFour years, ongoing

    Mascom

    Identity governance built on Saviynt, automating joiner, mover and leaver processes from Oracle EBS HR and Active Directory, with birthright access by role.

    Lifecycle driven from HR rather than tickets

  • Higher educationFive-year programme

    University of Pretoria

    Directory consolidation, workflow-based provisioning, password self-service and web access management, alongside substantial change management.

    Hundreds of thousands of identities across students, staff and external users

Trusted with identity by

  • WesBank
  • Utmost
  • Quilter
  • Mascom
  • Old Mutual

Independently assessed

  • ISO 27001
  • ISO 9001
  • Cyber Essentials Plus
  • CREST Security Operations
  • FSQS registered

Common questions

What people ask before they start.

Do we need to choose a platform before we start?

No. Choosing a platform first is the most common way these programmes go wrong, because the tool ends up defining the operating model instead of supporting it. We assess what you have and design the target model first, then evaluate platforms against those requirements.

Can you work with the identity tooling we already have?

Usually, yes. We hold accreditations across several identity platforms and have built production services on them, so a recommendation to keep what you have is as likely as a recommendation to replace it.

What do we need to provide?

Access to the people who understand your processes, and to the systems that hold identity data. The heaviest demand is on your HR, IT and application owners during discovery, and it lightens considerably after that.

Do you hand it over at the end, or keep running it?

Either. Some clients take the programme in-house after implementation and some ask us to keep operating it, which is why several of our identity engagements have run for years. The decision is yours and it does not have to be made at the outset.

How does this relate to our audit and compliance obligations?

Access governance is where most identity findings originate: reviews that are not evidenced, entitlements with no owner, and accounts that outlived their purpose. The governance framework and access certification work is designed to produce the evidence an auditor asks for as a by-product of running the process, rather than as a separate exercise.

Find out what has accumulated.

An identity assessment maps every identity to its source, surfaces the access nobody is tracking, and gives you a prioritised plan you can act on.

Book an identity assessment