Cybersecurity · Identity and privileged access
Access granted deliberately and removed automatically
Lifecycle automation, phishing-resistant authentication, entitlements derived from real usage, and privileged access that is brokered and recorded rather than permanently held. Identity and privileged access management, engineered rather than administered.
Where this starts
Credentials remain the most reliable way in
Stolen and misused credentials are involved in a large share of breaches every year, and the reason is structural rather than technical. Access is granted quickly because somebody is blocked, removed slowly because nobody is blocked, and reviewed annually by managers approving lists they cannot interpret. The result is an estate where accumulated permission is far larger than anyone intends and nobody can see the shape of it.
What we usually find
- Leavers retaining access to applications that sit outside the main directory
- Contractors and service accounts with no owner and no expiry date
- Access reviews approved wholesale because the entitlement names are unreadable
- Administrators holding standing privilege because elevation is inconvenient
- Shared break-glass credentials in a password manager, never rotated after use
- Machine identities and API keys outnumbering people, and managed by nobody
Our position
Permission granted for one urgent afternoon is usually still there three years later. Access needs an expiry date more than it needs an approval.
What the work covers
People, privilege and machines
Identity programmes go wrong when they cover employees thoroughly and ignore the two populations carrying more risk: administrators and machines.
Lifecycle automation
Joiner, mover and leaver driven from the human resources system through automated provisioning, so access follows the role and a departure removes it the same day rather than at the next review cycle.
Authentication
Single sign-on across the estate, including the applications bought outside procurement, with phishing-resistant factors such as passkeys and hardware keys for administrators, and conditional access driven by device posture and risk.
Entitlements and least privilege
Roles derived from what people actually use rather than from what they once asked for, separation of duties enforced where it genuinely matters, and certification that presents a manager with a decision they can reasonably make.
Privileged access
Credentials vaulted and brokered, elevation granted just in time and expiring on its own, session recording for the systems that warrant it, and break-glass that is monitored and rotated after every use.
Machine and workload identity
Service accounts with owners, short-lived credentials in place of static keys, workload identity federation between cloud and pipeline, and certificate lifecycles automated so an expiry is never again an outage.
Directory consolidation
Reducing the number of places identity is held. Every additional directory is another place a leaver survives and another set of reviews that nobody completes properly.

How it stays fixed
Access that expires on its own
The single most effective change in most estates is not a new tool. It is making grants temporary by default, so the system tends towards less access rather than more.
Joiner
Provisioning driven from the source of truth, so a starter has the right access on their first morning without anyone raising a ticket.
Mover
A role change revokes the previous entitlements rather than adding to them. This single behaviour is where most accumulated permission comes from.
Leaver
Same-day revocation across federated applications, with an evidenced trail the auditor can read without an interview.
Elevation
Privilege requested, approved and granted for a bounded window, then removed automatically. No standing administrator, including ours.
Review
Certification campaigns generated with usage data attached, so a manager can see what an entitlement has actually been used for before approving it again.
What you are left holding
- Provisioning and deprovisioning driven from your source of truth
- Phishing-resistant authentication for administrators, enforced rather than encouraged
- Just in time elevation, with standing privilege removed
- An owned inventory of service accounts and machine credentials
- Access reviews that produce decisions rather than approvals
One question to begin with
If somebody left on Friday, which systems would still let them in on Monday? We usually start by answering that properly.
