The checkpoint principle
REF ACC-IDN-400OWNER Identity DeskSOURCE Single directory
Air traffic control does not clear an aircraft because it is friendly; it clears it because the flight plan,
the conditions and the timing all check out. Access control should work the same way. In our engagements the
identity provider is the checkpoint, and every path into the estate is required to present itself there before
anything else happens.
We start by consolidating identity. Where an organization has grown through acquisitions, we often find three
or four directory sources with overlapping accounts and no single owner. We agree one directory of record,
document the exceptions, and schedule the rest for retirement. That step alone removes a large share of the
orphaned accounts that audits complain about.
What the policy covers
REF ACC-IDN-420RULES Written and enforcedREVIEW Quarterly
- Authentication strength. Which classes of access demand which factors, and why ordinary reach and
administrative reach are deliberately different.
- Joiner, mover, leaver. The lifecycle that grants access on day one, adjusts it when roles change,
and removes it the moment someone leaves — with evidence that it happened.
- Conditional rules. Location, device posture, time of day and network source feeding a decision
rather than a flat allow or block.
- Privileged reach. Administrative access treated as an exception that is requested, approved,
time-boxed and observed, not a permanent attribute.
- Third parties. Contractors, vendors and support engineers held to the same rules as staff, with
sponsorship, expiry dates and sponsor accountability.
- Emergency access. Break-glass paths that exist for genuine outages, are physically protected, and
trigger an automatic review of every use.
From rule to evidence
REF ACC-IDN-440EVIDENCE Reports and logsAUDIENCE Owner + auditor
A rule that cannot be evidenced is a wish. For every control we design, we also design the report that proves
it is working: who holds privileged reach today, which exceptions are older than their review date, which
accounts were disabled within the required window after a departure, and which sign-in attempts were blocked by
policy. These reports go to named owners on a fixed cadence, and we review them with you each quarter.
We also keep the policy readable. Rules are written in plain language with a stated purpose, an owner and a
review date, so a new administrator can understand the intent without reverse-engineering a change ticket from
four years ago.
Deliverables · identity policy document, enforcement configuration inside your directory
and access broker, evidence reports, and a quarterly review pack.
One practical rule saves more trouble than any other: a person should be able to see, on request, everything
they can reach, and a manager should be able to see it too. We build that view early, because visibility is what
turns an identity policy from a document into something the organization can actually govern.
Migration without disruption
REF ACC-IDN-460APPROACH WavedROLLBACK At every step
Identity changes touch everyone, so we move in waves with a rollback position at each stage and a rehearsal in
a non-production replica first. Communication is part of the work: staff receive plain instructions on what will
change, what they will notice, and where to get help. Our target is that no user is surprised on cutover day.