Identity & Access
Regulated environments where trust, compliance, and operational resilience are non-negotiable.
This interactive experience is the shipped product itself — the same application code customers run in production, mounted read-only in your browser over a real sample journey. Not a video, not a mockup: because the demo and the product are one codebase, it can never drift from the real thing.
Inside this journey
-
Risk & Compliance Discovery
Map current privileged access posture, audit findings, stakeholder roles, timelines, and examiner success criteria.
Discovery Questions
The Board Called, Tell Us the Story
- How did the audit finding about thirty five percent of terminated employees with active credentials come to the board's attention?
- When did the ninety day remediation mandate officially begin for your organization?
- Who is the formal owner accountable for meeting the remediation mandate and who signs committee-level approval for progress milestones?
- Describe the specific systems and account types the audit called out, for example mainframe RACF profiles, SWIFT operator IDs, trading service accounts, or domain admin accounts.
- Estimate how many unique privileged accounts tied to departed employees remain active in your environment today
Where Privilege Actually Lives
- If a single compromised privileged account could reach your payment processing systems, how confident are you that your current account map would reveal that path?
- Walk me through your current inventory process for privileged accounts across mainframe, SWIFT, cloud, and SaaS systems.
- Which discovery capabilities do you already have in place for automated account enumeration versus manual spreadsheets?
- List the teams and tools that currently own periodic entitlement reviews and their review cadence
- Does your inventory tie each privileged account to a business owner and an explicit access purpose?
What's Breaking First When an Account Goes Wrong
- Who notices first when a privileged credential is misused in your environment, and how fast can that person or team stop activity?
- Where would lateral movement from a breached privileged account most quickly reach your payment processing or trading systems?
- Describe a recent incident of orphaned accounts or delayed deprovisioning and the measurable business impact it caused
- How many days on average passed between employee termination and credential deactivation across the last twelve months?
- If you could change one operational control immediately to reduce this risk, which control would that be and why?
What Success Looks Like to Your Examiners
- Tell me which exact evidence your internal audit and external examiners require to close this finding, and which items are currently missing from that list.
- Which report formats, retention windows, and audit trails will satisfy your examiners for recertification?
- Name the stakeholders who will validate evidence for close and the acceptance criteria each requires
- In a successful recertification, within what timeframe must you be able to produce examiner-ready access evidence after an access change?
- Would failing to produce that evidence within your target window trigger regulatory escalation or a consent order risk?
The Other Options You're Weighing
- Why might the committee prefer to stay with the incumbent solution or address this problem internally rather than bringing in an external platform?
- List the internal remediation options and the main reasons those were proposed
- Name any incumbent systems or outsourced models that currently deliver parts of privileged access control in your environment
- Does the current approach have the capacity to meet the board's ninety day timeline if you assign additional resources?
- What single change would need to be in place for the committee to decide to stay with the current approach instead of procuring a new platform?
Who and When Must Be Ready
- Identify your critical integration owners and whether they can commit to the remediation schedule required by your committee
- Provide your list of environments that must remain available for a non disruptive rollout, including production, pre production, and trading simulators
- Estimate how many full time equivalents from security and operations can be dedicated to configuration and cutover during the pilot
- State any regulatory approvals, legal reviews, or compliance sign offs that could gate your timeline
- Is there a documented schedule of maintenance windows your deployment must avoid for trading and wire transfers?
Configuration Details That Will Make or Break Cutover
- Assess whether your directory mappings, API credentials, and mainframe settings are documented, current, and owned by named contacts
- Provide the authoritative directories, credential stores, and session policy owners the deployment team should contact
- Outline your rollback criteria that would force an immediate cutback to the previous state during a phase one cutover
- Approximate how many service accounts require secret rotation during phase one and the expected time per account
- Select which configuration items are already automated in your environment
Deployment Sequencing and Rollback Tests
- Quantify the business loss if a trading window is missed during cutover and who in your organization bears that exposure
- Share the Gantt milestones and verification test points you require for a phased rollout, including rollback exercises
- Identify the owners who will run verification tests and whether you have test accounts that mirror production
- Approximate how long your acceptance tests must run to generate examiner ready evidence
- Select the rollback triggers you require to halt cutover and return to the previous state
Final Acceptance and Next Steps
- Assuming the pilot proves the platform meets your acceptance criteria, what internal obstacles remain before procurement can issue a purchase order?
- Enumerate the signatures and approvals required for PO release and the typical time each approval takes
- State the remediation timeboxes you require after go live and the SLA consequences for missed targets
- Is there an internal budget holder who can commit funds immediately upon committee sign off?
- Choose the next milestone that would accelerate your decision
-
Solution Evaluation
Prove the platform against the buyer's acceptance criteria, validating mainframe and SWIFT connectors, reporting for examiners, and non-disruptive session controls.
- success_criteria
- current_state
- gaps
- decision_readiness
- desired_state
- stakeholders
- desired_state
- success_criteria
- gaps
- decision_readiness
- current_state
- stakeholders
- stakeholders
- current_state
- desired_state
- success_criteria
- gaps
- decision_readiness
- decision_readiness
- decision_readiness
- decision_readiness
- decision_readiness
-
Solution Scope
Define modules, connectors, certification cadence, responsibilities, rollback criteria, and measurable deliverables for phased rollout.
Scope Configuration
- Vault and Rotate Privileged Secrets
- Deploy Just-in-Time Privilege Elevation
- Configure Session Recording and Replay
- Integrate Mainframe Credential Management
- Integrate Payment and SWIFT Operator IDs
- Implement Real‑Time Session Termination Rules
- Migrate and Consolidate Directories
- Execute Role Mining and Role Catalog Creation
- Configure Access Certification and Recertification
- Provision Multi‑Factor Authentication for Privileged Users
- Deploy Application Connectors and Account Onboarding
- Perform Phased Cutover for Time‑Sensitive Systems
- Enable Examiner‑Ready Access and Compliance Reporting
Scope Questions
Vault and Rotate Privileged Secrets
- Which credential stores currently hold privileged secrets that must be vaulted (for example Active Directory service accounts, on-prem HSMs, file-based key stores)?
- How frequently must secrets be rotated to meet your internal audit or regulator expectation (for example 30 days, 90 days)?
- Who is the owner for secrets rotation in each system (for example the mainframe ops lead for RACF, the Windows domain admin team)?
- Are there any credentials that cannot be automatically rotated because of legacy integration constraints (for example hard-coded SWIFT passwords, trading system service accounts)?
- Specify the acceptable failure rate for automated rotation (for example maximum percentage of secrets that may require manual intervention per week).
- List any compliance artifacts required after rotation (for example audit log entries showing old/new key hashes, PKI certificate chain snapshots).
Deploy Just-in-Time Privilege Elevation
- Which privilege elevation workflows must be supported (for example temporary domain admin elevation during batch window, just-in-time RACF profile grants on z/OS)?
- How long may an elevation session remain active before re-approval is required (for example 30 minutes, 8 hours)?
- Who will approve elevation requests for emergency access to payment systems and which contact method must be used (for example pager/phone escalation for wire ops)?
- Do you require elevation tied to a change ticket or trade identifier (for example the trade blotter ticket or a Jira/ITSM change ID)?
- Specify any allowed elevation preconditions for high-risk roles (for example MFA, manager approval, risk scoring threshold).
- Identify systems where elevation must be non-disruptive during trading hours (for example order management systems, wire transfer queues).
Configure Session Recording and Replay
- Which session types must be recorded for examiner evidence (for example RDP/SSH sessions to trade servers, 3270 mainframe operator sessions)?
- How long must session recordings be retained to satisfy internal audit and regulator expectations (for example 90 days, 1 year)?
- Who should have access to replay sessions for investigations (for example internal audit, examiner representative, SOC analyst)?
- Do you require tamper-evident controls and chain-of-custody metadata for session evidence used in recertification or regulatory responses?
- Specify replay performance constraints (for example playback start within 5 seconds, indexing by operator ID or ticket number).
- Are transcripts required in addition to video/packet capture for SWIFT or payment investigations?
Integrate Mainframe Credential Management
- Which mainframe environments and LPARs must be integrated (for example z/OS LPAR IDs, RACF namespaces)?
- How are RACF profiles currently provisioned and who owns the RACF policy (for example security team, mainframe operations)?
- Do you require automated onboarding of RACF user IDs and mapping to directory identities (for example map Windows AD accounts to RACF operator IDs)?
- Which integration method is preferred for the mainframe (for example SAF connector, batch sync of profiles, LDAP bridge)?
- Specify any mainframe change freeze windows or batch cycles that constrain connector installation and testing.
- List any legacy tools or middleware that depend on direct RACF credentials and must be accounted for during migration.
Integrate Payment and SWIFT Operator IDs
- Which SWIFT operator IDs and payment system accounts must be onboarded first to meet the 90-day remediation mandate?
- Do SWIFT operator IDs require multi-signature or dual-approval workflows before elevation or use?
- Who is the business owner for each payment queue or SWIFT BIC stream that will be impacted during connector testing?
- Are there SWIFT CSP evidence items your examiner expects (for example access logs correlated to FIN messages, operator session recordings)?
- Specify any blackout periods for payment processing when connector changes are prohibited (for example end-of-day settlement, high-value payment windows).
- Identify any downstream reconciliations or message-delivery dependencies that must be validated after onboarding an operator ID.
Implement Real‑Time Session Termination Rules
- Which anomalous conditions must trigger immediate session termination (for example a privileged session initiating outbound SWIFT messages, simultaneous logins from different geolocations)?
- How should termination actions be performed for time-sensitive sessions to avoid transactional corruption (for example soft disconnect, freeze commands, alert-only)?
- Who must be notified in real time when a session is terminated (for example trading desk lead, security operations center)?
- Do you require correlation between anomalous trading patterns and session scoring to automate termination (for example volume spike > X trades in Y minutes)?
- Specify allowable false-positive thresholds for automated terminations to minimize disruption to wire/trading windows (for example <0.5% of terminations require rollback).
- List any consoles or monitoring feeds that must ingest termination events (for example SIEM correlation rules, trade surveillance system).
Migrate and Consolidate Directories
- Which directory forests and LDAP domains must be consolidated (for example AD forest names, LDAP DNs)?
- How many privileged accounts exist per directory that must be reconciled during consolidation (provide counts or ranges)?
- Do you have any cross-forest trusts that will remain during cutover and need special handling?
- What is the acceptable account-mapping error rate during directory consolidation (for example percentage of accounts requiring manual resolution)?
- Who will sign off on directory cutover readiness (for example AD ops lead, network/security operations)?
- Identify any dependent systems that consume directory attributes and must be updated as part of consolidation (for example CAS, trading apps, middleware).
Execute Role Mining and Role Catalog Creation
- Which business units and application domains are highest priority for role mining (for example front-office trading, SWIFT operations, payments ops)?
- How many unique entitlement combinations exist today that you expect to rationalize into roles (approximate ranges)?
- Do you require segregation of duties (SoD) rules encoded into the role catalog based on your risk matrix (for example prevention of trade-entry + trade-approval)?
- Who will validate and approve the canonical role definitions (for example business process owner, internal audit)?
- Specify the target coverage for role-based assignments versus entitlement-level assignments at go-live (for example 80% of privileged accounts assigned via role).
- List any systems where role mining is not possible and manual role design is required (for example legacy bespoke trading applications).
Configure Access Certification and Recertification
- Which certification campaigns must be configured first to satisfy the 90-day remediation (for example terminated user recertification, privileged account recertification for SWIFT)?
- How frequently must recertification run for privileged roles to meet examiner expectations (for example 30 days, 90 days, quarterly)?
- Who are the approvers for each certification campaign and what alternate approver paths exist if the primary approver is unavailable?
- What defines done for a certification campaign for internal audit and the regulator (for example percentage of accounts recertified, remediation tickets closed)?
- Do you require automated creation of remediation tickets in your ITSM when a certification revokes access (for example attach ticket with user ID and action)?
- Specify reporting fields required in certification evidence for examiners (for example timestamped decision, approver identity, linked ticket number).
Provision Multi‑Factor Authentication for Privileged Users
- Which MFA methods are acceptable for privileged access in your environment (for example hardware token, mobile OTP, FIDO2)?
- How will MFA be enforced for cross-domain elevation (for example require MFA for any elevation to domain admin or RACF operator)?
- Who will manage lost-device or emergency access to privileged accounts when MFA device is unavailable?
- Are there hardware-constrained systems that cannot support modern MFA and need compensating controls (for example legacy batch job accounts)?
- Provide your target onboarding timeline for privileged users to be enrolled in MFA (for example 30 days, 60 days).
- Do you require MFA logs forwarded to your SIEM with a specific schema for correlation with privileged session activity?
-
Mutual Commit
Finalize commercial, legal, and operational terms; lock acceptance criteria, procurement prerequisites, and remediation timeboxes.
Agreement Modules
- Master Services Agreement (MSA)
- Statement of Work (SOW)
- Subscription Agreement & Order Form
- Acceptance Criteria & Remediation Timebox Agreement
- Procurement Prerequisites & Purchase Order Conditions
- Financial Services Compliance Addendum
- Operational Cutover & Maintenance Window Agreement
- Service Level Agreement (SLA)
- Change Order Agreement
-
Deployment
Lock readiness facts and configuration values before execution begins.
-
Pre-Deployment Readiness
Confirm owners, maintenance windows (trading/wire constraints), environments, and access permissions required for a non-disruptive rollout.
Pre-Deployment Questions
Environment and access
- List each in‑scope environment/site and its role (production, DR, pre‑prod, test), the datacenter or cloud region, and the technical owner (name + email). (Used to build per‑site runbooks.)
- Are network access paths (VPN/firewall/NAT) from the deployment team's source IPs to each in‑scope environment already provisioned?
Data and configuration
- Has the authoritative identity/entitlement source(s) been finalized for the rollout (single directory/store or multiple systems)? If multiple, list each owner. (This defines mapping and reconciliation owners.)
- Will any bulk synchronizations, credential migrations, or entitlement imports occur during the cutover? If yes, state the owner and the target completion date. (Needed to sequence migration tasks.)
People and ownership
- Provide the named owner (full name + email) for each deployment workstream: environment/network, application connectors, mainframe/RACF, and trading operations/line‑of‑business. (These owners will approve access and changes.)
- Are there assigned change approvers and a single escalation owner who will be available during the cutover window? (If yes, provide name and reachable phone in the next field.)
Timing and constraints
- List confirmed blackout or restricted periods that must not be impacted (recurring trading windows, settlement cutoffs, wire batch times) including time ranges and timezone. (Required to schedule non‑disruptive cutover.)
- What is the current procurement/contract status that affects the deployment start? Select the state and, if pending, provide the expected completion date. (Deployment cannot begin until prerequisites are met.)
-
Configuration Details
Capture exact configuration values the deployment team will use — directory mappings, API credentials, mainframe settings, and session-policy thresholds.
Configuration Details
Environments & Endpoints
- Enter the production environment name (exact string used in the platform; e.g., "prod-nyc-01")
- Enter the production API endpoint URL (format: https://api.yourdomain.example/path — exact URL the platform will call)
- Select the primary deployment region (this value drives region-specific endpoints and support routing)
Options & Features
- Choose modules/connectors to enable for this deployment (select all that apply)
- Select session policy enforcement mode (Default: Non-disruptive — monitor-only)
- Select your identity provider type for SSO/integration (your identity provider (IdP))
- Enter certification/recertification campaign cadence in days (Default is 90 days — confirm or specify another value)
Limits, Policies & Mappings
- Enter the primary directory base DN / search root used by the directory connector (format example: DC=corp,DC=example,DC=com) — exact string for connector settings
- Enter session recording retention in days (Default is 365 days — keep or specify another value)
- Enter maximum concurrent privileged sessions per account (numeric — Default is 3)
-
Deployment
Execute the phased rollout with Gantt sequencing, cutover plans tied to trading windows, verification tests, and rollback procedures.
-
-
Success
Validate remediation targets, deliver examiner-ready access evidence, and maintain a shared channel for issues and enhancements.
Success Reviews
- Go-live Health Check
- First Measurement Review
- Acceptance Gate and Incumbent Retirement
- Monthly Remediation Burn-down
- Quarterly Operational Review
Issues & Enhancements
- Remediate any evidence export deficiencies and provide a verified export demonstrating required fields and retention metadata.
- Produce a documented acceptance decision with a named signatory for enterprise ratification.
- Confirm the incumbent system is decommissioned or retained-read-only, with data archive or migration completed and fallback habits closed.
- Capture any outstanding remediation items with firm resolution dates and verification steps.
- Publish the formal acceptance record signed by the named signatory and store it in the shared evidence channel.
- Execute the incumbent wind-down plan including data archive or migration and confirm completion of contract or renewal handling.
- Deliver any conditional remediation items and evidence for verification by the agreed resolution dates.
- Open remediation inventory and burn-down status
- Increase remediation closure rate to meet the committed timeline.
- Reduce mean time to revoke privileged access after termination to the target recorded in Mutual Commit.
- Ensure examiner evidence deliveries continue to meet completeness requirements and no trading-window incidents recur.
- Update the remediation tracker with closure dates and verification evidence for each item resolved this month.
- Reconfirm acceptance criteria and owners
- Schedule a targeted maintenance window if required to resolve high-risk remediations that cannot be completed during business hours.
- Quarterly KPI trend presentation
- Verify that privileged session recording and evidence completeness remain within target thresholds.
- Resolve or set timelines for persistent operational blockers that threaten KPI stability.
- Agree the next quarter's operational adjustments and evidence schedules for upcoming exams.
- Publish the quarterly KPI dashboard and archive the certified evidence snapshots for auditor access.
- Deliver a remediation or enhancement plan for any persistent blockers with target completion dates for the next quarter.
- Prepare sample examiner evidence exports and a runbook for evidence requests during the next audit cycle.
- Confirm the phased rollout completed without disrupting trading or wire windows.
- Identify and assign owners and target dates for all open critical issues discovered during go-live validation.
- Verify that early user onboarding and authentication patterns meet operational expectations.
- Publish a go-live validation checklist with issue owners and target resolution dates.
- Remediate any connector gaps or orphaned accounts identified during validation and confirm closure before the first measurement meeting.
- Provide a short usage summary with onboarding counts and authentication success rates ahead of the next session.
- Present KPI data vs targets recorded in Mutual Commit
- Establish whether termination-related exposure and revocation mean time are improving toward targets recorded in Mutual Commit.
- Document root causes for any KPI shortfalls and agree timebound corrective actions to reach the day 90 acceptance gate.
- Confirm that examiner-ready evidence meets the minimum completeness rate required for audit submission.
- Deliver a remediation plan with discrete tasks, deadlines, and acceptance criteria to close KPI gaps before the acceptance gate.
- Provide a verified sample set of examiner evidence exports demonstrating required fields and retention metadata.
- Address identified connector or HR feed failures and report closure status at the next meeting.
- Restate acceptance criteria and numeric targets recorded in Mutual Commit
- KPI trend review focused on revocation time
- Present outcome data against each criterion
- Diagnose root causes for any gaps
- Deployment and cutover validation
- Compliance posture summary
- Evidence delivery verification
- Early adoption signals and usage patterns
- Document pass or fail per criterion and formal acceptance decision
- Evidence readiness for examiners
- Open operational issues and persistent blockers
- Production incident and trading-window review
- Enhancement backlog triage
- Agree remediation actions and timelines
- Incumbent system wind-down
- Open issues and blockers
- Agree remediation items and final resolution timeline
- Confirm path to the acceptance gate
- Agree next-month remediation commitments
- Plan for upcoming examiner cycles
- Agree immediate remediation actions