Skip to content
Insights
Request Services
Approach
Approach

Our five-phase delivery.

Every engagement follows the same five-phase shape: diagnostic, design, build, harden, hand-off. The phases are sized to the program scope, but the shape is consistent. Below is the canonical engagement at a mid-tier-enterprise scope — typically 36 weeks from kickoff to audit-cycle hand-off.

Start with the diagnosticSee the services
Manifesto · 02

Evidence over decks.

Audit evidence is a release artifact — not a quarterly project. Every phase below ends with control-mapped artifacts in your repository under your license, runnable on day one. Decks are an output, not the deliverable.

Brutalist manifesto poster — evidence over decks
The five phases

Diagnostic to hand-off, sequenced.

  1. 01

    Weeks 1-4

    Diagnostic

    A fitness assessment against the audit framework that matters most for your program. The output is a written diagnostic with the dominant maturity level, the top three gaps, and a sequenced backlog with named owners.

    Deliverables

    • Maturity diagnostic against the IAM model
    • Control mapping artifact set (FFIEC / NIST / HIPAA / FedRAMP / etc.)
    • Sequenced 12-week backlog with named owners
    • Risk-adjusted scope decision for the build phase
  2. 02

    Weeks 5-8

    Design

    Reference architecture for the build phase. The design is opinionated — we recommend the platform, the integration shape, and the operating-model decisions. We do not produce option-comparison documents in lieu of recommendations.

    Deliverables

    • Reference architecture diagrams + written narrative
    • Platform selection recommendation (with the trade-off modeled)
    • Integration registry — every downstream system mapped
    • Operating-model runbook (draft)
  3. 03

    Weeks 9-20

    Build

    The first audit-scope workflow shipped end-to-end. Pair-programmed in your tenant with named owners on every workflow. Configuration-as-code in your Git repository; deployment via CI; tests for every policy.

    Deliverables

    • Production deployment of the first audit-scope workflow
    • Configuration-as-code in customer Git repository
    • CI pipeline for policy + workflow deployment
    • Initial control-test suite running continuously
  4. 04

    Weeks 21-32

    Harden

    The 90-day hardening period after the first workflow ships. The long tail of integrations, the exception backlog, and the operating-model muscle memory all get built during this phase. Audit-evidence pipeline runs end-to-end.

    Deliverables

    • Full integration coverage across the in-scope program
    • Exception policy documented and signed off
    • Evidence-as-code pipeline operational
    • Internal audit dry-run completed
  5. 05

    Weeks 33-36

    Hand-off

    Clean handoff to your platform team. Written runbook, exception policy, on-call shadow during the first audit cycle, and a written escalation policy. We do not create dependency — we stay available, but we do not stay needed.

    Deliverables

    • Written operating runbook — signed off by the customer
    • On-call shadow during the first audit cycle
    • Quarterly review cadence agreement (optional)
    • Escalation policy with named contacts
The principles

The four rules every phase follows.

  • Opinionated, not exhaustive

    We make recommendations. We do not produce option matrices in lieu of decisions. If you want a deck with three platforms compared on 47 attributes, we are the wrong firm.

  • Configuration is code

    Production policy lives in your Git repository, not in console screenshots. The audit trail is the commit history. The dashboards are for diagnosis, not for change.

  • Evidence is a byproduct

    Every control test produces an audit artifact as a byproduct of operations. The auditor question is answered in minutes, not weeks.

  • Hand-off is the deliverable

    The engagement is not done when the platform works. It is done when your platform team can run it without us. The runbook is the artifact that signals completion.

Identity, cybersecurity, and custom software for regulated enterprises. Audit-ready operations from advisory through audit.

Americas HQ

Wilmington, DE

America/New York

India HQ

Hyderabad, TG

Asia/Kolkata

Services
  • IAM Consulting
  • IAM Technologies
  • Custom Software & AI
  • IAM Staffing
  • Request Services
  • Case Studies
Resources
  • All Resources
  • Complete Guide to IAM
  • IAM Frameworks Compared
  • IAM Certification Roadmap
  • IAM API Hub
  • IAM Explainers
  • IAM Vendor Status
  • Release Notes
  • State of Identity
  • State of PAM
  • State of IGA
  • State of CIAM
  • State of AI Agent Identity
  • IAM Salary Benchmark
  • Vendor Pricing Index
  • Year in Review 2026
  • Acquisition Tracker
  • Outage Tracker
  • Identity Incidents
  • Vulnerability Tracker
  • Cheat Sheets
  • Standards Explainers
  • Migration Playbooks
  • Audit Checklists
  • Reference Architectures
  • RFP Templates
  • IAM Anti-Patterns
  • Compliance Crosswalk
  • Market Landscape
  • Awesome IAM
  • IAM Glossary
  • Compliance Frameworks
  • Integration Guides
  • Vendor Alternatives
  • IAM by Industry
  • Salary Lookup
  • Directory
Research & media
  • IAM Compensation 2026
  • Vendor Moves Q3 2026
  • Identity Incidents Q3 2026
  • Vendor Security Posture 2026
  • Vendor Pricing 2026
  • AI Citation Tracker
  • Top 50 IAM Tools 2026
  • Podcast
  • Videos
  • Newsletter
  • Newsletter Archive
  • Embed Widgets
Free tools
  • JWT Decoder
  • JWT Signer
  • SAML Decoder
  • SAML Metadata Diff
  • OAuth Flow Visualizer
  • OIDC Debugger
  • OIDC Discovery Validator
  • PKCE Generator
  • WebAuthn Tester
  • Bearer Token Inspector
  • SCIM Validator
  • Password Entropy
  • IAM RFP Template
  • PAM Vendor Selector
  • Maturity Assessment
  • ROI Calculator
  • TCO Calculator
  • MFA Bypass Risk
  • Audit-Prep Burden
  • Quizzes
Company
  • About
  • Leadership
  • Approach
  • Why Choose Us
  • Partners
  • Press Kit
  • Press Topics
  • Global Presence
  • Locations
  • Insights
  • Now
  • Community
  • Open Roles
  • Submit Resume
  • Training
  • Contact

© 2026 askmeidentity, Inc.. Safeguard your digital frontier.

  • Privacy Policy
  • Terms of Service
  • Accessibility