The diagnostic

Who and what holds access. Who owns it. How far you are from what is expected.

Two to three weeks. About six hours of your people’s time in total. A fixed price, agreed before we start — never time and materials, and never a day rate that drifts.

01 · What it assesses

Four questions, one estate.

PRIVILEGED

Who holds privileged access

An inventory of who and what holds it — people, service accounts, AI agents and integrations — and who owns each.

WORKFORCE

How identity moves

How a person’s identity is created, changed and removed; whether HR drives your identity provider; how much of the application estate sits behind single sign-on, and whether access into those applications is provisioned and removed or merely authenticated.

CONTROLS

Where you stand

Against what your regulator and your enterprise customers expect — least privilege, vaulting, rotation, traceability.

AI AGENTS

Agent governance

Whether agents are inventoried, how they are credentialed, whether each traces to a responsible person, and who is accountable when one acts.

02 · How it runs

Nothing is built for us. Gaps in the evidence are findings.

You hand over what already exists — configuration exports, your access policies and the procedures behind them, your last audit or customer-questionnaire findings, your application inventory. Usually the gaps are the useful findings.

1

Before we start

Scope, fixed

Two questions settle most of the price in two minutes: roughly how many applications your workforce uses, and roughly how many sit behind single sign-on.

2

Weeks 1–2

The evidence

We work from what you already have. About six hours of your people’s time across the whole engagement, most of it in two short working sessions.

3

Week 3

The decision meeting

Sixty minutes. Your leadership team decides the three things to fix first and who owns each.

4

What you keep

The record

The written roadmap that records the decision, and the one-page ownership finding.

03 · What you get

Two deliverables. Neither is a report.

1

The decision and the roadmap

It ends in a 60-minute meeting where your leadership team decides the three things to fix first and who owns each. The written roadmap is left with you as the record of that decision — there is no scored findings deck circulated in our absence.

2

The ownership finding

One page: who owns identity in your firm today, by name and by role; what decisions the roadmap will need over its life; who in the building is authorised to take them; and what happens to those decisions when that person is on leave, or leaves.

If you already have a competent owner with a mandate, the finding says so and the engagement closes cleanly. A finding that always concludes you need us is a sales instrument, and you would recognise one.

04 · Not in scope

What this is not

  • No penetration testing and no technical vulnerability assessment.
  • No hands-on configuration of any identity or privileged-access platform.
  • No legal advice and no opinion a third party can rely on. This is not an audit.
  • No customer identity. How your own customers sign up, authenticate and recover accounts is a separate discipline with a different owner inside your firm.
  • No general security awareness review. This is an identity and access diagnostic, not a general security assessment.

05 · What it costs

A fixed price, agreed before we start

The figure depends on the size of your estate. Two questions settle most of it in about two minutes: roughly how many applications does your workforce use, and roughly how many sit behind single sign-on?

Next step

A 20-minute conversation.

It costs nothing, and if a diagnostic is not the right thing for you, we will say so.