Skip to content

Identity and user lifecycle

Joiner, mover, leaver — automated and provable.

Identity governance, birthright access, downstream provisioning, segregation of duties, and access certification campaigns your auditor can read. Warden, Gatepost, Tenure and Keyring in Techtons are the reference implementations.

The premise

Joiner, mover, leaver — automated, and provable to somebody who does not trust you. Identity is where SaaS replacement gets serious, because every other system depends on it and because it is the one area where the auditor has an opinion. It is also the area with the largest gap between what the licence costs and what the organisation actually uses.

Reference implementations

Four applications in Techtons are the reference implementations for this service. Read their parity matrices before the first meeting — they will tell you more about our position than a proposal will.

What you get

  • An authoritative source model: which system owns which fact about a person, and what happens when two of them disagree.
  • Birthright access defined as policy — role, department, location and employment type in, entitlements out — with the rules readable by someone who is not an engineer.
  • Automated downstream provisioning and, more importantly, deprovisioning, with a leaver path that completes in minutes and leaves an evidence trail.
  • Segregation of duties rules encoded and enforced at request time, not discovered during a certification campaign six months later.
  • Access certification campaigns your reviewers will actually complete: scoped, pre-filtered, with revocation that executes rather than producing a spreadsheet.
  • Privileged access with brokered sessions, checkout, rotation and recording for the accounts that matter.
  • An evidence pack per control, generated from the running system rather than assembled by hand the week before the audit.

How it runs

5 phases, each with a date attached.

Durations below are what this shape of work typically takes with a team of two to four. They move with scope, and the assessment is where they stop being typical and start being yours.

  1. 01

    Discovery and current state

    2 to 3 weeks

    Every identity source, every connected system, and the honest map of what is provisioned by hand today. Almost always includes finding accounts belonging to people who left, which is a useful thing to be able to show a sponsor early.

  2. 02

    Policy and role design

    3 to 4 weeks

    Birthright policy, role model and segregation of duties rules, designed with HR, the business owners and the auditor in the room. This is the phase people try to skip and it is the phase that determines whether the rest works.

  3. 03

    Build and connector work

    4 to 8 weeks depending on connector count

    The governance engine, the lifecycle automation and the connectors to downstream systems. Connector count is the honest driver of duration here — twelve targets is roughly twice the work of five, and no amount of platform cleverness changes that.

  4. 04

    Parallel run and certification

    3 to 4 weeks

    Run the new lifecycle alongside the existing process, compare every decision, and use a live certification campaign as the acceptance test. If the reviewers can finish it, it works.

  5. 05

    Cutover and evidence handover

    2 weeks plus 30 days hypercare

    The new system becomes authoritative, the old licence stops at renewal, and your compliance team gets a walkthrough of where each control’s evidence now comes from.

What it costs

No rate card on this page, on purpose.

Priced per phase. The discovery and policy phases are worth buying on their own — several clients have run them, fixed their role model, and then decided to keep their existing identity governance licence for another cycle. That is a legitimate outcome and we price the phases so it is possible.

The one number that predicts cost here is the number of downstream systems that need real provisioning connectors, and the second is how many of them have an API worth the name. A system with SCIM support is a few days; a system whose provisioning interface is a CSV dropped on an SFTP server at midnight is a fortnight and a support contract. We count the targets in discovery and quote the build after, never before.

Where you are replacing a licensed identity governance product, the incumbent list price is public for some vendors and quoted privately for others. We work from your actual contract, not from a published figure, and the payback arithmetic is done against what you really pay.

A published day rate would be a number we could not stand behind for your specific situation, and every firm that publishes one quotes something different in the room. What we will commit to before you sign is the phase scope, the phase price and the team shape. Use the calculator for the replacement arithmetic against your own seat count.

Normally bought inside

02

Join

Hire a Forward Deployed Engineer. They sit in your team.

Monthly per engineer. 3-month minimum, 30-day exit.

03

Deliver

We take it end to end and hand over the keys.

Fixed price per phase. Run priced separately.

All three commercial models in full →

When not to buy this

3 reasons to walk away.

Every library entry has rows where the honest answer is no. Every service page has this section for the same reason: the cases below are ones we have seen go badly, and we would rather lose the work than deliver into them.

You have not decided who owns identity

If it is unclear whether HR, IT or security owns the joiner process, automation will encode the confusion and make it faster. Settle the ownership question first; it is cheaper than a rebuild.

Your certifications are a regulatory requirement you cannot risk

If a failed access certification in the next cycle is an existential problem for the business, do not change the machinery that produces it this quarter. Do the design work now, cut over after the cycle closes.

The estate is fewer than about a dozen systems

Below that, a well-configured directory and a good starter-leaver checklist genuinely works, and a governance platform of any kind is overhead you will resent.

Pick one contract. We will show you the replacement.

A two-week assessment: we take your single most expensive SaaS line item, establish what you actually use, and come back with a parity matrix, an architecture for AWS and Azure, a cost model and a delivery plan. Fixed price. If the answer is keep buying it, we will tell you that.