02 · Identity & access

Identity and access across your organisation.

We design and migrate identity platforms, automate access changes and implement access review campaigns across your HR and business systems. Specialist expertise in Okta.

Identity architecture. The HR system is the authoritative people record and the source for Okta: Universal Directory holds profiles and attributes, group rules map role to membership, and access policies use MFA and device signals. Connected applications use SSO through SAML or OIDC for each app and provisioning through SCIM or native APIs: Google Workspace by native API, Slack by SCIM, the finance system by SCIM, and other connected SaaS apps per app. Device management through Jamf and Intune covers enrolment; device context from Okta Verify and device assurance informs the access decision; an audit log records logins and changes.

Identity architectureIllustrative example
SourceHR systemAuthoritative people record
Okta
Universal Directoryprofiles · attributes
Group rulesrole → membership
Access policiesMFA · device signals
Connected applicationsSSO · SAML / OIDC for each app
Provisioning · SCIM or native APIs
  • Google Workspace Native API
  • Slack SCIM
  • Finance system SCIM
  • Other SaaS apps per app

Device signals inform the access decision

Device managementJamf · Intune · enrolment
Device contextOkta Verify · device assurance
Audit loglogins · changes

Specialist identity services

Start with the one that matches your situation.

We adapt the architecture, lifecycle rules and governance to the platforms you use. Tell us what you run and what needs to change.

  • Okta consulting & implementation

    Design a new Okta environment or improve the one you have: SSO, MFA, FastPass, provisioning and lifecycle rules, with rebuilds and migrations delivered in tested stages.

  • Okta Workflows

    Onboarding, contractor access with end dates, approvals and SaaS administration as flows with error handling and a completion record.

  • Hire to Exit Systems Review

    A fixed scope review of the employee lifecycle across HR, identity, SaaS and devices. You receive findings on accounts, access and licences and a roadmap for the next 90 days.

What we do

Identity, from design to working access.

  1. Architecture, integrations and migrations

    Connect HR records, identity attributes and group rules so each person receives the access their role needs. Integrate identity with device management, SaaS and internal systems. Plan tenant rebuilds and moves between identity providers, piloted before a staged migration.

  2. Authentication

    Configure SSO, MFA and passwordless sign in, including Okta FastPass, with authentication policies that can take device checks into account.

  3. Provisioning and lifecycle

    Create, update and deactivate accounts through SCIM and APIs. Handle future start dates, role changes, contractor end dates and leavers with approvals and reconciliation.

  4. Governance and access reviews

    Run access review and recertification campaigns with a named reviewer for each item, decisions recorded, and removals verified rather than assumed.

Experience behind the work

Enterprise identity at scale

Distributed identity sources were rebuilt into one authoritative model in Okta. Migrated 110 SSO applications and 31 provisioning integrations from SailPoint and Duo into Okta over SAML, OIDC, SCIM and REST with no loss of service. FastPass passwordless access was delivered to 1,200 users on Windows and macOS with device assurance checks.

Before you enquire

Questions we are usually asked first.

Can you build Okta from scratch or improve our existing tenant?
Both. A new tenant, an improvement plan for an existing one, or a migration. Changes are tested with a pilot group before wider rollout.
We use a different identity platform. Can you still help?
Yes. The HR integration, lifecycle rules, access reviews and application integrations are designed around your HR records and the identity platform you run.
Do you work with US and international companies?
Yes, remotely, with agreed meeting overlap and change windows.

Tell us about your identity setup.

Which HR and identity systems you run, where access is slow or uncertain, and what needs to change. Joe replies with a suggested review, integration or build.