By scale

For enterprise

Procurement, SSO and audit. Larger organisations do not buy differently because they are slower. They buy differently because more people have to be able to answer for the decision.


The constraint

Procurement, access review and audit are not obstacles to the work. They are the work, and a tool that ignores them never gets bought.


What goes wrong

Review runs on an export
Permissions are read out of a console by hand each quarter and pasted into a spreadsheet that is stale by the time it is signed. The reviewer approves a snapshot, not the state of the system.
Procurement arrives after the choice
A team picks the tool, then security review starts, and the questionnaire finds something that cannot be changed. Those eight weeks are not review, they are rework paid for twice.
The record is in three systems
Who changed what sits partly in the ticket, partly in the pipeline and partly in the console. Reconstructing an incident means correlating them by timestamp, which is a reconstruction presented as a record.

What changes

  • What stops

    A leaver is removed from four consoles, by four people, over two weeks.

    What replaces it

    Access follows the directory, so removal in one place is removal.

  • What stops

    A quarterly spreadsheet export stands in for the access review.

    What replaces it

    Roles are read live, per project, at the moment the review happens.

  • What stops

    Security review begins when the pilot ends and the answers are written from scratch.

    What replaces it

    The recurring questions are answered before the pilot, because they are the same questions each time.

  • What stops

    One invoice arrives and finance splits it between cost centres by estimate.

    What replaces it

    Cost is attributed per project, so a cost centre can sign for its own spend.

Questions we get asked

Can we use our own identity provider?
Yes, and it is the part to settle first rather than last. Access that is not tied to the directory has to be removed by hand when someone leaves, and removal by hand is the control that fails quietly, at the worst possible time, with a paper trail that says it succeeded.
How long does a migration take, honestly?
The deploy is the short part and is rarely the constraint. The schedule is set by network approvals, the access review and the change window, so plan against the calendars of the people who sign those rather than against an engineering estimate.
We are 200 people, not 20,000. Is this the wrong page?
Probably. If one person can still name everyone with production access from memory, the controls described here are cost without benefit, and the smaller shape is the honest one. Read the teams page instead, and come back when the access list stops fitting in one head.

What fits

Single sign-on, cost attributed per project, and an audit trail that answers who changed what and when.

Read more

Migration run as one engagement with a named accountable team, rather than a plan handed across a boundary.

Read more

Send us the questionnaire before the pilot rather than after it. If a control you need does not exist, you should find that out in week one, not in week nine.

Talk to us