RECORD 01
Global enterprise software environment / 1,100 users
Identity architecture, lifecycle automation and passwordless migration.
STARTING POINT
The environment depended on UKG, SailPoint, Okta and Duo across a large SaaS estate. Identity data and provisioning logic were distributed across systems, profiles and mappings were inconsistent, and the migration had to preserve user access while the target architecture was built.
WHAT I DESIGNED AND DELIVERED
- Mapped the target source-of-truth → Okta → service-provider architecture across four authoritative identity sources, integrating three custom source processes through Okta Workflows and Access Requests and connecting UKG through its supported integration.
- Rebuilt the Okta data model with custom attributes, profile mappings, validation and Okta Expression Language logic.
- Designed and delivered a migration programme covering 110 SSO applications and 31 provisioning integrations, using native SCIM where viable.
- Built lifecycle management for pre-hire staging at T-7 (seven days before start), activation at T-1 (the day before) and controlled end-date deactivation, alongside delegated Slack and Access Request workflows with validation, logging and defined approvals.
- Designed adaptive MFA and passwordless policies for managed internal devices, external access and mobile/BYOD use cases; rolled out FastPass to 1,100 Windows and macOS users with checks that the device meets defined management and security requirements through Intune and Kandji.
- Planned and led the Okta organisation and subdomain cutover, including runbooks, communications, support preparation and rollback thinking.
- Used Python and platform exports to correct identity data and make attributes dependable enough for dynamic access rules.
- Produced architecture diagrams and technical proposals, led stakeholder reviews and delivery meetings, and supported junior engineers through implementation.