Technology Cybersecurity Identity & Access Security

Identity Governance

High scrutiny and high blast radius; proof and governance matter.

Example organizations in this space: SailPoint Saviynt IBM Oracle

This interactive experience is the shipped product itself — the same application code customers run in production, mounted read-only in your browser over a real sample journey. Not a video, not a mockup: because the demo and the product are one codebase, it can never drift from the real thing.

Inside this journey
  1. Pre-Sales

    Qualify and diagnose before investing in a full evaluation cycle.

    1. Qualification

      Confirm budget, decision authority, timeline, and urgency created by the compliance finding before committing to full discovery.

      Qualification Questions

      Compliance finding and urgency

      • Can you briefly summarize the compliance finding that prompted this engagement and the date it was issued?
      • What is the required remediation or evidence date tied to the finding, if any? Options: Within 2 weeks, 2–6 weeks, 6–12 weeks, More than 12 weeks, No formal deadline / unknown
      • Does the finding involve regulated data or controls that imply conditional contract requirements (for example PHI, PCI, or classified/government data)? Options: Yes — PHI, Yes — PCI/cardholder data, Yes — classified/government data, No, Not sure

      Initial technical scope for evaluation

      • Which 2–3 high-risk applications would you want us to validate first so we can assess connector completeness and risk scoring? Options: SAP, Active Directory, Oracle E-Business Suite, Mainframe / RACF, Cloud platform (AWS, Azure, GCP), Other (please name)

      Budget and decision authority

      • Is there an allocated budget range for remediation or for running an initial evaluation? Options: $0 – $50k, $50k – $150k, $150k – $500k, $500k+, No budget allocated / unknown
      • Who is the primary decision-maker for a solution like this and which roles must sign off (title or role)?

      Timeline and next-step readiness

      • What is your target timeframe to complete the initial evaluation and decide whether to proceed? Options: Within 2 weeks, 2–6 weeks, 6–12 weeks, More than 12 weeks, No set timeframe
      • To make the most of a discovery meeting, are you available for a 60-minute discussion within the selected timeframe? Options: Yes — within 1 week, Yes — within 2–4 weeks, Yes — within the timeframe but scheduling later, No — prefer asynchronous next steps
    2. Enterprise Discovery

      Map stakeholders, in-scope applications, HR data quality, success metrics, and constraints across the buying group.

      Discovery Questions

      Quick tour of your current access posture

      • Give a concise summary of the failed audit finding that initiated this project, including systems implicated and the auditor's core concern.
      • How many applications are in your current inventory, and which application categories hold the majority of access risk? Options: On-prem ERP, Active Directory / Windows domains, Mainframe / RACF, Cloud IaaS/PaaS, SaaS business apps, Custom legacy apps, Other
      • When did you last run a certification campaign covering both on-prem and cloud systems, and what was the elapsed time to completion? Options: Within 30 days, Within 90 days, Within 6 months, Longer than 6 months, Never run a combined campaign
      • Describe the typical process from an auditor finding to the first remediation action, including owners and handoffs.
      • Estimate the number of people (reviewers, approvers, integration engineers) who participate during a single certification campaign. Options: 1-5, 6-15, 16-30, 30+
      • Is there an executive sponsor who will commit to the pilot within the next 30 days? Options: Yes, sponsor identified and available, Maybe, sponsorship pending approval, No sponsor identified

      If this fails again, what actually breaks

      • If the next audit names your team again, which immediate operational change would you expect, budget reallocation, mandated project, or leadership review? Options: Budget reallocation, New mandated remediation project, Leadership review or personnel change, No immediate change expected
      • Provide an estimate of combined costs for remediation hours, external audit work, and potential regulatory penalties from a repeat finding. Options: <$50k, $50k-$250k, $250k-$1M, >$1M, Unknown
      • Name the business units or revenue streams that would be most affected by recurring access review failures. Options: Retail banking / customer accounts, Wealth management / trading, Clinical systems / patient care, Contracting / defense programs, Shared services / HR, Other
      • Who in the executive chain typically reallocates funds after a compliance event? Options: CISO / VP IT Security, CIO, CFO, General Counsel / Compliance, CEO / Board
      • Which metric would be decisive for you after a pilot: certification cycle time, risk signal precision, or entitlement completeness? Options: Certification cycle time, Risk signal precision (true positives), Entitlement completeness, Reduction in orphan accounts, Audit evidence completeness

      Where your access visibility actually breaks

      • List up to three systems that are most likely to produce incomplete entitlement exports and would expose you in an audit.
      • On those systems, indicate the current method of entitlement extraction: API, direct database, scheduled report, or manual spreadsheet. Options: API or connector available, Direct database export, Scheduled report extract, Manual spreadsheet export, No reliable extract
      • Walk me through the last time a connector failed to deliver full entitlement data, what detection lag you saw, and who noticed it.
      • Do any of your critical applications require elevated network paths, jump hosts, or privileged service accounts that would block automated extraction? Options: Yes, multiple systems, A few systems, No, Unsure
      • Identify any systems without a clear owner who can approve connector access within your pilot timeline.

      Who signs and who slows things down

      • Who is the single operational owner we should work with for pilot approvals and emergency escalations?
      • List the cross-functional roles that must be engaged for a pilot and note their typical availability, for example security, HR, app owners, audit, and legal.
      • Explain how priority disputes between security, HR, and application owners are resolved today. Options: Security arbitrates, Joint decision with business sponsor, Application owner decides, Escalation to executive committee
      • Name the team responsible for HR data quality and the person we can hold accountable for corrections during the pilot.
      • How often do application owners complete certification assignments on schedule under the current process? Options: Almost always, Often, Sometimes, Rarely, Never

      Connector reality check

      • If one of your top-three risk systems needs a custom connector, how will that affect your timeline and approval process?
      • Identify which target systems already expose APIs suitable for entitlement retrieval and which require alternative access methods such as report parsing or DB queries. Options: APIs available, DB access, Report parsing required, Manual export only, Unsure
      • Estimate the number of distinct connector types required for a three-application pilot. Options: 1, 2, 3, 4+
      • Do you currently have service accounts and network rules that allow automated entitlement queries, or will new approvals be necessary? Options: All accounts and rules in place, Some approvals required, Major approvals required, Unsure
      • What's an acceptable minimum percentage of entitlement coverage on day one for the pilot to be considered valid? Options: >=95%, 90-94%, 80-89%, <80%
      • Is there any application in the proposed pilot set that has no feasible connector path within four weeks, and would that single app block the pilot? Options: Yes, one or more apps block the pilot, No, pilot feasible, Unsure

      Can HR be trusted as the identity source?

      • Provide typical rates at which HR onboarding, transfers, and terminations fail to reflect in downstream directories. Options: <5%, 5-10%, 11-25%, >25%, Unknown
      • Specify the HR systems that feed identity processes and identify who controls API or export access for each.
      • Walk me through a recent joiner or leaver error that resulted in stale or orphaned access, and the steps taken to remediate it.
      • What percent of your identities have a consistent employee ID mapped across HR and directory systems today? Options: >95%, 90-95%, 75-89%, <75%, Unsure
      • Would you be willing to dedicate an HR data owner for the pilot to sign off on corrections within two weeks? Options: Yes, Maybe with conditions, No

      Technical and compliance gates that stop progress

      • Which compliance, legal, or contractual approvals must clear before any connector can query production data? Options: Privacy review, Vendor contract amendment, Security approval / architecture review, Pen test, Audit notification
      • Are there vendor agreements or contracts that restrict automated entitlement extraction from any critical system? Options: Yes, multiple restrictions, One or two restricted systems, No contractual restrictions, Unsure
      • Confirm whether network segmentation, jump hosts, or auditing proxies will require special routing for connectors. Options: Yes, special routing required, Minor routing adjustments, No special routing needed, Unsure
      • Report the typical calendar time required to obtain security approvals for integrations, including pen tests and privacy review. Options: <2 weeks, 2-4 weeks, 1-3 months, >3 months, Unsure
      • Point to who would sign risk acceptance if a connector requires elevated privileges for the pilot. Options: CISO, IT Operations, Application owner, Legal / Compliance, Other

      The alternatives you're actually weighing

      • Reveal what would have to be true about an internal tool or process for you to avoid procuring an external platform.
      • Specify the alternatives you are evaluating or have already considered: incumbent IGA, spreadsheet/process remediation, new cloud governance, custom integrations, or other. Options: Incumbent IGA, Spreadsheet/process fix, New cloud governance vendor, Custom internal integration, Other
      • Has any team proposed solving this entirely in-house, and if so, what resource and timeline estimates were provided? Options: Yes, with resource estimate, Yes, no estimate provided, No in-house proposal, Unsure
      • Offer a concise assessment of whether any evaluated vendor or internal approach can deliver audit-ready certification evidence within your target window. Options: Yes, Only with heavy manual work, No, Unsure
      • What single capability missing from the alternatives would make you switch to an external platform immediately?

      Readiness checklist that must be true before we start

      • Select the three prerequisites that must be satisfied before we begin work: HR feed access, directory read, application admin account, network routes. Options: HR feed access, Directory read / LDAP, Application admin account, Network routes and firewall rules, Test environments
      • Confirm whether APIs, service account credentials, and test environments exist for each pilot system, or whether we will need production access. Options: All test artifacts available, Some test artifacts available, Production access required, Unsure
      • State the available internal headcount for the pilot: technical owner, application owners, and HR data owner. Options: All roles available, Limited availability with reassignments, No available headcount, Unsure
      • Are test environments available for all pilot systems, or will some work need to proceed directly in production? Options: Test available for all, Some test, some production, Production only, Unsure
      • Describe any regulatory approvals or audit notifications that must be logged before we begin, and typical lead times.

      How you will measure success and make the call

      • Assume the pilot reduces certification cycle time by 3x for the three target systems, what would prevent you from approving a purchase that week?
      • Report the KPIs you will track during the pilot and the target improvement that would represent a clear win. Options: Certification cycle time, Number of risky entitlements surfaced, Entitlement completeness percentage, Time to revoke improper access, Audit evidence readiness
      • State whether you have a baseline of manual analyst flags to compare against risk scoring and how that baseline will be provided. Options: Full baseline available, Partial baseline available, No baseline, Unsure
      • Point to who has final budget authority to move from pilot to production if targets are met. Options: CISO / VP Security, CIO, CFO, Procurement committee, Other
      • What's your target timeline from pilot completion to procurement decision? Options: Within 2 weeks, 2-4 weeks, 1-2 months, >2 months, Unsure

      Next steps to keep momentum

      • Highlight the immediate blocker that, if not resolved within 72 hours, will pause the project.
      • Share the primary technical and business contacts you will assign for the pilot, including emails and availability windows.
      • Select which artifacts from us would accelerate your internal approvals: architecture diagram, data flow map, privacy impact assessment, sample connector plan. Options: Architecture diagram, Data flow map, Privacy impact assessment, Sample connector plan, Security and compliance checklist
      • Choose your preferred cadence for pilot updates: weekly written summary, twice-weekly sync, or dashboard access only. Options: Weekly written summary, Twice-weekly sync, Dashboard access only
      • Are there blackout windows or system freeze periods in the next quarter that would prevent connector work? Options: Yes, major freeze windows exist, Minor windows but manageable, No freezes scheduled, Unsure
  2. Solution Evaluation

    Validate connectors, entitlement completeness, and risk-scoring by loading sample systems and running an automated certification campaign against acceptance criteria.

    • desired_state
    • current_state
    • stakeholders
    • gaps
    • success_criteria
    • decision_readiness
    • desired_state
    • decision_readiness
    • current_state
    • success_criteria
    • gaps
    • stakeholders
    • desired_state
    • success_criteria
    • stakeholders
    • gaps
    • current_state
    • decision_readiness
    • decision_readiness
    • decision_readiness
    • decision_readiness
    • decision_readiness
  3. Solution Scope

    Define connector inventory, modules, responsibilities, timelines, and measurable acceptance criteria for the rollout.

    Scope Configuration

    • Connect to core ERP system
    • Connect to on-prem directory services
    • Connect to cloud platform entitlements
    • Aggregate and normalize entitlement data
    • Map entitlement attributes per connector
    • Activate default risk-scoring engine
    • Execute initial risk-scored certification campaign
    • Deploy reviewer UI and certification templates
    • Integrate HRIS for joiner-mover-leaver automation
    • Implement separation-of-duty enforcement
    • Deploy automated remediation and revocation workflows
    • Generate audit evidence package and logs
    • Provide ongoing connector maintenance and upgrades

    Scope Questions

    Connect to core ERP system

    • Which core ERP application and modules (for example SAP FI, SAP MM, Oracle GL) must be connected for entitlement collection? Options: SAP (specify modules), Other ERP (specify vendor and modules)
    • How many distinct ERP modules or tenancy domains (for example production GL, test AP) are in scope for the initial connector run? Options: 1, 2-3, 4+
    • Do you require read-only connector access or service account credentials with delegated rights for the ERP integration? Options: Read-only credentials, Service account with delegated rights, Not sure - need guidance
    • Which artifacts can you provide to validate ERP entitlement completeness (for example export of ERP role-to-user assignments, authorization objects for SAP modules)?
    • What acceptance criteria will confirm the ERP connector is complete for audit purposes (for example: all users in SAP FI/AP/MM present; entitlement counts match the ERP export within 5%)?

    Connect to on-prem directory services

    • Identify the on-prem directory service in use and supply domain names (for example corp.example.com) for group and permission enumeration.
    • How many domain forests or cross-forest trusts must we inventory to capture group nesting that maps to production access? Options: 1, 2-3, 4+
    • Do you have privileged directory service accounts reserved for integrations and can you provide the service account owner contact for each domain? Options: Yes - will provide contacts, No - need to create service accounts, Need guidance
    • List Active Directory object classes, groups, or naming patterns that directly gate access to production financial systems (for example Finance-Prod-Admins, Finance-Approvers).
    • Are there existing scripts or exports (for example LDAP dumps, PowerShell exports) you prefer we reuse for entitlement collection? Options: Yes, No
    • What evidence will validate directory connector completeness for auditors (for example: LDAP export showing all groups mapped to production servers and a reconciliation report with >=98% match)?

    Connect to cloud platform entitlements

    • List the cloud platforms and account identifiers that hold high-risk workloads to connect (for example the AWS account ID for payments systems).
    • Estimate the number of cloud service principals, roles, and identities expected to be inventoried across the accounts (for example 1,200). Options: Less than 500, 500-2,000, More than 2,000
    • Select whether we should fetch role-level IAM policies, inline policies, and resource-level permissions as part of entitlement collection. Options: Fetch role assignments only, Include inline policies and resource-level permissions, Full policy artifacts (recommended for audit)
    • Identify high-risk cloud resources to prioritize in the initial connector run (for example S3 buckets storing PII, production Kubernetes clusters).
    • Provide the principle of least privilege baseline or benchmark you follow (for example CIS profile or internal policy document name) to align mapping.
    • How will you supply API credentials or cross-account access to each cloud account (for example cross-account role ARN, temporary assume-role, API key)? Options: Cross-account role ARN, Temporary assume-role via STS, API key/service principal, Need guidance

    Aggregate and normalize entitlement data

    • Confirm whether canonical identifiers exist across systems such as a global employee ID present in HR exports to drive identity matching. Options: Yes - global employee ID available, Partially - email only, No - need mapping work
    • Provide the HRIS fields available for matching such as employee ID, corporate email, manager id, and cost center.
    • Give example title and department normalization rules you expect us to apply (for example map 'Sr. Accountant' and 'Sr Accountant' to 'Senior Accountant').
    • Select a data quality threshold for identity merging across ERP, directory, and cloud (for example minimum 90% match on employee ID and email). Options: >=95% match, >=90% match, >=80% match, No threshold - manual review
    • How will you verify that aggregated entitlement data meets audit readiness (for example reconciliation report showing >=95% coverage of accounts in SAP FI/AP and matched HRIS records)?

    Map entitlement attributes per connector

    • Specify entitlement attributes from the ERP (for example authorization object, role name, TCODE) that must be captured and mapped to platform fields.
    • For Active Directory, state which group attributes or nested group behavior must be preserved (for example primary group, tokenGroups, nested membership).
    • Specify cloud IAM attributes to map (for example policy ARNs, resource ARNs, role session tags) and how they should translate to risk categories.
    • Choose whether custom attribute transformations are required (for example concatenating role+resource into a single entitlement string). Options: None - use defaults, Simple transforms (concatenate/trim), Complex rule-based mappings
    • Who will own decisions on attribute mapping conflicts and who is the technical contact for connector field mapping (name and email)?
    • Are there regulatory attributes that must be retained for audit trails (for example job code, supervisor approval flag)? Options: Yes - list fields, No

    Activate default risk-scoring engine

    • Choose which risk models to prioritize for the pilot (for example segregation-of-duty, privileged access to production financial systems, lateral movement risk). Options: Segregation-of-duty, Privileged access to production financial systems, Lateral movement risk, Custom pattern - provide example
    • Confirm whether you want default risk thresholds applied (for example high risk >=80) or if thresholds must align to your audit policy. Options: Use defaults (high >=80), Define custom thresholds
    • Describe one prior audit finding we should tune the scoring to detect (for example a single user with approve+execute on wire transfers).
    • Who in your compliance team should be included in risk model tuning sessions (name, role, and availability)?
    • Should automated risk overrides be allowed during certification campaigns and if enabled, what escalation path do you require? Options: No automated overrides - escalate all, Allow automated overrides with manager approval, Allow automated overrides with SOC review

    Execute initial risk-scored certification campaign

    • When should we schedule the initial certification campaign against the three pilot applications (ERP module, Active Directory domain, cloud account)?
    • Estimate the number of reviewers and reviewer groups participating in the pilot (for example 10 finance managers, 5 application owners). Options: Less than 10, 10-30, More than 30
    • State measurable pilot targets you want us to aim for during the initial campaign (for example complete campaign in 7 days, reviewer response rate >80%).
    • Pick whether reviewers should see risk-score explanations and entitlement context inline (for example linked transaction IDs, last activity date). Options: Show explanations and context, Minimal view - only entitlement and risk score, Toggleable detailed view
    • Enter the contact (name and email) for the reviewer training owner who will approve sample responses for test cases.

    Deploy reviewer UI and certification templates

    • Will reviewers access the UI via your SAML single sign-on and multi-factor authentication (for example your SAML identity provider)? Options: Yes - SSO/MFA configured, No - need to configure SSO, SSO planned later
    • Describe the certification templates you need for Finance and IT applications (for example default reviewer instructions, due dates, escalation rules).
    • Enter the desired default reviewer SLA for certification tasks (for example 3 business days per reviewer). Options: 1 business day, 3 business days, 5 business days, Custom
    • State whether reviewer roles require read-only, comment-only, or approve-and-revoke permissions within the UI. Options: Read-only, Comment-only, Approve-and-revoke
    • Give sample reviewer groups and their expected membership counts to pre-populate templates (for example Finance Managers: 12).
    • Indicate whether certification templates need localization beyond English (for example Spanish for regional teams). Options: English only, English + Spanish, Multiple languages - list required

    Integrate HRIS for joiner-mover-leaver automation

    • Name the authoritative HRIS system and the export artifact that provides hire, termination, and transfer events (for example core HR export file name).
    • Enumerate the HR fields available for automation such as employee status, termination date, employee ID and cost center.
    • Indicate whether existing HR-to-ID mapping tables exist (for example mapping contractor IDs to corporate IDs) and if they can be shared. Options: Yes - can share, Partial - need mapping work, No - mapping required
    • How often are HR feeds updated and what is the expected latency for new hire and termination events? Options: Near real-time, Daily, Weekly, Monthly
    • Supply the contact (name and email) for HR data quality ownership and the approver for exceptions across business units.
    • Outline the process for handling unmatched HR records during automation runs (for example create ticket and 48-hour SLA for HR review).

    Implement separation-of-duty enforcement

    • Enumerate the segregation-of-duty policies from prior audits that must be encoded (for example approve vs execute on wire transfers).
    • Where can we access your existing control matrix or policy document to import rules and baseline controls?
    • Outline the conflict resolution workflow required when a separation-of-duty violation is detected (for example automatic revocation, manager approval within 24 hours).
    • Name the approver role for exceptions to separation-of-duty controls and specify the auditor sign-off artifact required.
    • Declare the regulatory standards and control identifiers to which these policies must map (for example OCC guidance, HIPAA control identifiers, CMMC control IDs).

    Deploy automated remediation and revocation workflows

    • Declare the systems that must support automated revocation actions (for example AD account disable, ERP role removal, cloud role detach).
    • Pick remediation mode: staged (notify manager then revoke after set days) or immediate automated revocation on high-risk findings. Options: Staged remediation, Immediate automated revocation, Hybrid - configurable per policy
    • Detail the approvals and audit trail metadata that must be recorded when automated revocations occur (for example approver id, ticket ID, timestamp).
    • Supply contact details for the playbook owner and the emergency contact for remediation failures (name and phone/email).
    • Declare business hours or change windows during which revocations must not occur (for example end-of-day payroll windows).
  4. Mutual Commit

    Agree commercial and contractual terms, data-access authorizations, and implementation dependencies required to start work.

    Agreement Modules

    • Master Services Agreement (MSA)
    • Statement of Work (SOW)
    • Subscription Order Form
    • Data Processing Agreement (DPA)
    • Data Access Authorization
    • Implementation Dependencies & Schedule
    • Service Level Agreement (SLA)
    • Change Order Agreement
    • Payment Schedule Agreement
    • Regulatory Compliance Addendum
  5. Deployment

    Lock readiness facts and configuration values before execution begins.

    1. Pre-Deployment Readiness

      Confirm environments, owner contacts, HR source alignment, and scheduling windows the deployment depends on before connector work begins.

      Pre-Deployment Questions

      Environment and access

      • List the production and non-production environments we must connect to for the initial deployment, naming each by system category (e.g., "ERP (SAP)", "Active Directory", "Cloud IAM").
      • For the environments you listed, is programmatic read-only access available now (so we can validate connector compatibility)? Options: All ready now, Some ready — will identify which, None available yet
      • Have integration/service accounts with the required read-only entitlements been created for connector work? Options: Yes, for all target environments, Partially — some systems covered, No — accounts not created yet
      • If integration/service accounts are partial or missing, who is responsible for creating them? Provide name and role (so the seller can coordinate provisioning).

      Data and configuration

      • Which HR system is the authoritative source of joiner/mover/leaver data for the deployment scope? Name by category (e.g., "single global HRIS instance", "multiple HRIS by region", "payroll system as source"). Options: Single global HRIS instance, Multiple HRIS instances (by region/business unit), Payroll system as canonical source, Other — will specify
      • Has the HR population for the scoped business units been reconciled to a single canonical employee identifier (so joiner/mover/leaver automation can run reliably)? Options: Yes — reconciled and stable, Partially reconciled — some mismatches, No — multiple inconsistent identifiers
      • Who owns HR data reconciliation and mapping? Provide the contact name, role, and whether they have agreed to validate field mappings (this owner is required for mapping sign-off).

      People and ownership

      • Please assign a named owner for each workstream: connector integrations, HR data, application owner certification, and security/change approvals (list name and role for each—these map directly into the deployment RACI).
      • For the applications in scope, have application owners agreed to participate in certification campaigns and supplied expected reviewer lists? Options: Yes — all owners confirmed and committed, Partially — some owners pending confirmation, No — application owners not yet identified

      Timing and constraints

      • Are there scheduled blackout windows, compliance freeze periods, or maintenance windows that will block connector activity or certification campaigns in the next 90 days? If yes, indicate whether calendar access will be provided or coordination is pending. Options: No scheduled constraints, Yes — windows exist and calendar access will be provided, Yes — windows exist and coordination is pending
      • What is the preferred maintenance window (typical nightly or weekend hours) for connector syncs and automated certification runs so we can align scheduling? Select the closest match. Options: Weeknights (local 18:00–06:00), Weekends only, Business hours by exception (requires advance notice), No preference — coordinate per application
      • Are any organizational approvals required before connector access is granted (change advisory board, data-access authorization, security exceptions)? If yes, indicate whether the approval owner is assigned and whether an expected approval date is known. Options: No approvals required, Yes — approvals required and owner assigned, Yes — approvals required but owner not assigned
      • What is the target start date for connector access and the initial certification run? (Provide a date so we can create a draft timeline and resource plan.)
    2. Configuration Details

      Capture connector credentials, API endpoints, field mappings, risk-threshold settings, and any custom integration parameters.

      Configuration Details

      Connector & Target Environment

      • Select the connector's target system category (choose the single best match) Options: Active Directory (on‑prem directory), SAP application / ERP, Mainframe RACF (z/OS), Cloud platform (SaaS or cloud IAM), Custom / Other
      • Enter the environment name the connector will target (format: short label; Default: production)
      • Enter the connector API or endpoint URL the platform should call (format: https://hostname[:port]/path — provide exact base URL used for API calls)

      Authentication & Credential Handoffs (identifiers only — secrets exchanged via your vault)

      • Select the authentication method the target system supports for this connector Options: OAuth2 client credentials (provide client_id; client_secret exchanged via your secrets manager), Service account username (provide service account name; password via your secrets manager), API key (provide key name; key value via your secrets manager), Kerberos/NTLM (provide service principal name), Other (describe in next field)
      • Provide the non-secret credential identifier for the chosen auth method (e.g., client_id, integration user name, key name) — do NOT paste secrets

      Field & Entitlement Mappings (exact source field names)

      • Enter the exact source field name that identifies the account/user in the source system (format: exact field/attribute name from source)
      • Enter the exact source field name that contains entitlement/role attributes (format: exact attribute name; e.g., memberOf, roleName)

      Risk & Operational Parameters (values consumed by certification engine)

      • Risk score threshold to flag an entitlement as HIGH RISK (integer 0-100; Default: 70)
      • Enter the full name and email of the connector credential owner who will approve secret handoff (format: Full Name <user@domain>)
    3. Deployment

      Execute integrations, run certification campaigns, remediate data issues, and operationalize reviewer workflows with clear owners and milestones.

  6. Success

    Review certifications completed, reductions in cycle time and risk exposure, and maintain a shared channel for issues and enhancement requests.

    Success Reviews

    • Go-live Health Check (weeks 1-4)
    • First Measurement Review (weeks 4-10)
    • Acceptance Gate and Ratification (around day 90)
    • Monthly Operational Review (months 4-6 post-acceptance, recurring)
    • Quarterly Business Review (recurring quarterly)

    Issues & Enhancements

    • Run root-cause investigation for any connector above the error-rate threshold and publish findings within 7 days.
    • Record the acceptance decision and named signatory in the project record and notify governance stakeholders.
    • Execute the archival and read-only retention of legacy spreadsheets and publish the archive location and retention policy.
    • Publish remediation tasks for any conditional or failed criteria with owners, verification steps, and firm resolution dates.
    • Current metrics and trend analysis
    • Reduce the average time to remediate flagged entitlements month over month until the target is met.
    • Ensure connector error rate is within acceptable bounds or has a mitigation plan with dates.
    • Prioritize enhancement requests that materially affect reviewer throughput and acceptance criteria realization.
    • Re-confirm success criteria and owners
    • Update the remediation tracker with new target dates and verification checkpoints.
    • Add prioritized enhancement requests to the shared backlog with proposed delivery windows.
    • Outcome summary vs baseline
    • Demonstrate a sustained reduction in risky entitlements versus the pre-deployment baseline.
    • Confirm audit evidence is complete and that outstanding evidence gaps have assigned owners and timelines.
    • Agree the top operational priorities for the next quarter to protect and extend realized outcomes.
    • Publish a quarter-to-date report comparing reduction in risky entitlements and campaign cycle time to the pre-deployment baseline.
    • Assign owners and dates for any remaining audit evidence gaps and track to closure.
    • Update the quarterly operational plan with the agreed priorities and circulate for acknowledgment.
    • Core connectors are returning entitlement sets consistent with expected schemas and no critical errors remain.
    • All open high-priority blockers have an assigned owner and target resolution date.
    • Your reviewers have access and have begun initial interactions with the certification campaigns.
    • Publish the deployment validation checklist including exceptions and remediation target dates.
    • Log all open issues to the shared channel and tag each with severity and a proposed owner.
    • Schedule a connector re-test window after fixes are applied.
    • Present first-campaign results
    • Establish whether average certification campaign cycle time and review completion rate are trending toward the targets recorded in the Solution Scope.
    • Agree a prioritized remediation plan for the top 3 root causes with target dates to reach acceptance readiness.
    • Confirm data quality actions required on HR sources if they are contributing to gaps.
    • Publish the remediation plan with task-level dates and link it to the Solution Scope acceptance checklist.
    • Run a connector completeness re-check and report the percentage of entitlements successfully reconciled.
    • Produce a short diagnostics packet showing root-cause evidence for each metric gap.
    • Restate acceptance criteria and numeric targets
    • Capture a formal acceptance decision with a named signatory for the enterprise engagement.
    • For any failed or conditional criteria, agree a remediation plan with clear dates and verification steps.
    • Confirm the incumbent spreadsheet process is archived or locked to read-only and that no active reviews continue outside the platform.
    • Open remediation and blocker burn-down
    • Audit readiness and evidence
    • Present measured outcomes against each criterion
    • Gap diagnosis
    • Deployment and connector validation
    • Enhancement requests and prioritization
    • Document pass, conditional pass, or fail per criterion
    • Persistent risks and policy adjustments
    • Agree corrective actions and timelines
    • Early adoption signals and usage patterns
    • Quarter roadmap and operational commitments
    • Blockers and open issues
    • Confirm readiness path to acceptance gate
    • Operational adjustments and next steps
    • Remediation plan for any failed or conditional criteria
    • Agree immediate remediation actions
    • Incumbent process wind-down confirmation
First-Party AI

1-2 minutes please — Your AI agent is working

First-Party AI™ can make mistakes. Always check important information.