IAM / IAM-07
Access certification and access governance
Organising campaigns in which accountable owners verify that user and third-party permissions remain justified.

WHEN IT HELPS
A focused response
to a defined need.
CISO, internal control or business owners; historical access, audit requirements or widely shared sensitive information.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Collect entitlements
- appoint reviewers
- record keep or remove decisions and track implementation
Deliverables
- Documented campaign
- signed or recorded decisions
- removal evidence and exception list
Acceptance evidence
Decisions are linked to implementation; non-responses and exceptions are not treated as approvals.
DELIVERY
How the work is structured.
Approach
Inventory identities and applications; define roles and policies; pilot with one group; test allow/deny/recovery paths; roll out and hand over.
Prerequisites & responsibilities
Customer: application owners, HR, administrators, pilot groups and emergency accounts. Provider: design, integration and testing within agreed permissions.
Scope factors
Users, directories, applications, protocols, privileged accounts, compatibility and migration. Licenses, physical keys and recurring operations are separate.
Questions to clarify
Who understands the entitlements under review? How often should reviews occur? Who implements approved removals?
IMPORTANT BOUNDARIES
Reviews are useful only when reviewers understand access and decisions are implemented.
Recovery and emergency access are tested before rollout. Authentication, authorisation and privileged-access management are complementary layers.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
A group never reviews access to finance folders. Project: owner-based access reviews. Target outcome: justified removals and retained evidence; bulk approval without review is identified and revisited.
Scenario 02
A SaaS environment retains partner accounts after contracts end. Project: reconcile access with contracts and approve removals. Target outcome: expired access removed and periodic reviews integrated with procurement.
Technology and reference context
Entitlement exports, IGA tools or controlled campaigns using existing systems.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
