Build & Respond

Identity and access management

Bring every account, SSO connection and access review into one identity program that answers the auditor, the enterprise buyer and the incident responder.

Ali Aleali

Ali Aleali, CISSP, CCSP

Co-Founder & Principal Consultant

Former security architect for Bank of Canada and Payments Canada. CISSP, CCSP, more than twenty years in enterprise security. Leads every engagement.

Connect on LinkedIn

What the engagement covers

Inventory, design, and the evidence that the design is followed.

icon-9

Identity and application inventory

Every system with accounts, every account with an owner, every integration with a credential. The blind spots are the old ones.

icon-8

Joiner, mover, leaver

Provisioning and deprovisioning designed end to end, including the SaaS tools outside the identity provider, and the compensating steps for the ones that cannot be automated.

icon-6

SSO and MFA coverage plan

Which applications connect, in what order, and what happens to the local accounts left behind. Exceptions recorded with compensating controls.

icon-5

Role design and least privilege

Roles mapped to job functions and directory groups, proportionate to the size of the team.

icon-4

Access reviews that produce evidence

A cadence and a record: who reviewed what, when, and what changed as a result.

icon-7

Customer-facing identity in your product

SSO, role-based access mapped to the buyer's directory, session management and audit logs: what enterprise security teams evaluate before they approve.

Assess, Build, Operate, applied to identity and access

We design around the identity provider you already have. A documented methodology, led by a senior architect with more than ten years of enterprise security experience and a CISSP.

01

Assess

Systems, accounts, owners, integrations. Compared against HR records to find the accounts that should not exist.

02

Build

Lifecycle process, SSO and MFA coverage plan, role model, review cadence, and the exceptions with compensating controls.

03

Operate

In waves by risk, with the identity vendor's engineers on the product and Truvo on the design. Review cadence and evidence handed to your team.

What you hold at the end

An identity program that answers the auditor, the enterprise buyer and the incident responder from the same records.

  • Identity and application inventory

  • Joiner, mover, leaver procedure

  • SSO and MFA coverage plan with exceptions

  • Role model mapped to job functions

  • Access review cadence and records

  • Customer-facing identity requirements for the product

What changes

Coverage you can state, offboarding that completes, reviews that leave a record.

When an IAM engagement is the right call, and when it is not

We are independent of every identity vendor. Where you already have an identity provider, we design around it.

Frequently asked questions

The identity provider covers the applications that were connected to it. What is usually left is the inventory of everything that was not, the lifecycle process around it, the exceptions, and the review cadence that turns the design into evidence. In our experience the gap is rarely the tool.

The frameworks are written for organizations of every size, but the examples assume large ones. A company with a two-person IT team does not need an enterprise ticketing workflow for provisioning. It does need to show that access is granted on a process, removed on departure and reviewed on a cadence. The minimum viable formalization is usually what you already do, written down and made demonstrable.

Two things: that you are secure, and that your product lets them stay secure. The second is where deals stall. SSO so they do not manage local accounts, role-based access that maps to their directory groups, security logs they can send to their SIEM, stale-account detection and session controls. In SOC 2 terms these map to the complementary user entity controls sophisticated reviewers read first.

We are independent of every vendor. Where you have an identity provider, we design around it and the vendor's engineers execute the product work. Our role is the inventory, the design, the exceptions and the evidence.

SOC 2 CC6.1, CC6.2 and CC6.3 cover logical access restriction, provisioning and removal, and review. ISO 27001 Annex A covers identity management, access rights and authentication. The engagement produces the inventory, lifecycle records and review evidence those controls are tested against.

Talk to the architect who would do the work

A 30-minute call. We look at your environment and say plainly whether we can help and what it would take.

From the blog: access control

vCISO Services for Mid-Market SaaS: How to Evaluate Fractional Security Leadership in 2026

vCISO services give a mid-market SaaS company senior security leadership on a fractional basis: someone who owns the security program, drives SOC 2 ...

Top 8 vCISO Services for Mid-Market SaaS in 2026

The right vCISO service for a mid-market SaaS company is the one that owns and runs the security program end to end, on a fractional basis, the way a ...

What a Security Architect Actually Does: Three Roles and Where Requirements Come From

A security architect does three jobs: sets security requirements for systems other people design, assesses and reviews those designs, and solutions ...