Certified, and they have shipped it
SailPoint-certified engineers and CISSP holders who have run real implementations.
Phase one go-live usually lands around month four or five, or ten to twelve months on legacy estates. Application onboarding runs another six to twelve months after that, and a mature identity governance and administration program takes two to three years. Here is what each stage involves and what it asks of your team.


The most common misunderstanding about identity governance is that go-live is the end. It sits about a quarter of the way through.
Usually from an auditor, sometimes an insurer or a board member: who has access to what, and who approved it? In most organizations, finding out takes weeks of spreadsheets across several departments. That is where an IGA program starts.
The least glamorous stage, and the one most often cut short. Cutting it is the surest way to spend a year building the wrong role model, because everything later inherits these decisions.
Which identities, which applications, which populations. Drawing this line honestly is harder than it sounds.
What success is measured against, agreed before the build. This protects the program when it runs long.
SailPoint, Saviynt or Microsoft Entra ID, chosen against your estate. A wrong choice is expensive to unwind at month eight. Here is how SailPoint and Saviynt compare.
A slice built end to end and tested until it produces the right result every time. Nothing scales until this does.
The part that is not technical. Each department has its own idea of who should hold what, and people have to reconcile them. Role mining finds the patterns but does not make the decisions. The model you pick matters too: RBAC, ABAC or PBAC.
Three things, working across the applications in phase one scope, not across everything:
Joiner, mover and leaver changes run from HR data instead of tickets, so access appears on day one and disappears on the last day.
One place that answers who has access to what, and who approved it.
Produced by the process itself, not assembled each time someone asks.
Budgets get set against phase one because that is the number quoted. Then application onboarding needs another six to twelve months nobody planned for, and a program running to schedule gets called a failure.
One connector and one owner at a time. It is not technically hard. Its pace is set almost entirely by how fast application owners respond, and systems with no clear owner are where it stalls. Connectors to HR, ITSM and cloud systems are core IAM integration work.
The platform rarely breaks. The discipline around it does.
The lifecycle doing most of the work untouched.
Reviews that get read. Once managers approve everything unread, the program quietly stops working. See what makes access reviews hold up.
Exceptions granted with an expiry. The ones granted for a migration two years ago are the ones auditors find.
Syncs break quietly when source systems change. Nobody notices until an access review comes back empty.
Departments reorganize. Left alone for a year, the model stops describing the organization.
If you would rather not carry this, we run it as part of our managed IAM services.
Governance runs in the background instead of as a project with a steering committee. Reviews are routine, onboarding an application is a known process, and "who has access to what" takes minutes to answer.
This is where identity governance differs most from PAM implementation. IGA touches business rules, security policy and technical connections at once, so it needs a matrixed team, with one person whose job is bridging them.
| Role | Why it matters | Time |
|---|---|---|
| A single communicator | The bridge between departments, and the role that decides whether this succeeds | 50–100% |
| HR director | Lifecycle automation is only as good as the HR data behind it | 15–20% |
| Department decision-makers | Managers who decide who gets what, in short bursts throughout | 5–10% |
| Executive sponsor | Unblocks departments that will not engage | Weekly or biweekly update |
The ones that fail almost never fail on technology.
If an audit finding is driving this, start with a compliance readiness assessment.
SailPoint-certified engineers and CISSP holders who have run real implementations.
Governance designed around how your teams actually work, so adoption does not stall after launch.
No handoff between a consultancy and an operator.
Roles, reviews and reporting mapped to SOX, HIPAA, PCI-DSS and GDPR from the first design session.
Access removed and conflicts closed, not reports generated.
Governance sits at the center of it, not on the edge.
Certifications held by individual engineers.
Insurance, 20,000+ employees. Facing a SOX deadline, our engineers deployed a unified onboarding framework and integrated 470 databases across six complex types in six weeks, against a six-month baseline, with the certification pipeline streamlined and self-service onboarding in place afterwards.
Lifecycle churn and outside identities make governance harder in some sectors: whole student cohorts joining and leaving at once in identity security for education, independent agents and brokers in identity security for insurance, and clinician and contractor turnover in identity security for healthcare.
Phase one go-live is usually around month four or five, and ten to twelve months on legacy estates. Application onboarding then runs another six to twelve months, and program maturity takes two to three years. A single number for identity governance usually describes phase one only.
PAM is mostly about accounts and infrastructure. Identity governance touches business rules: every application has an owner who has to agree what a role means and who should hold it. That is a series of conversations across departments, and conversations do not compress the way technical work does.
A matrixed team, not one person:
Usually automated joiner-mover-leaver processes, one governance dashboard and audit-ready reporting, across the applications in phase one scope. What you will not have yet is every application onboarded. That is the next, longer stage.
Yes. We start with what is live: which lifecycles run, which connectors work, and where reviews have become a rubber stamp. Then we decide with you whether to repair the current platform or move, and plan it so access keeps working throughout.
Automated defaults doing most of the work, monthly access reviews, exception handling and healthy application and partner syncs. The usual failure is not the platform breaking. It is reviews becoming a rubber stamp and exceptions never being revoked.
A free consultation is 30 minutes with a certified engineer on your estate, your HR data and your application list. You get the findings in writing: a realistic phase one range, what it would need from your team, and where the hard parts are. No obligation to work with us.
Findings in writing afterwards, whether or not you work with us.
Needed for the site to work — page delivery, and the spam protection on our forms. These do not track you and cannot be switched off.
Google Analytics and Microsoft Clarity, so we can see which pages are useful and which are confusing. Clarity hides anything you type into a form. We use this to improve the site, not to identify you.
ZoomInfo WebSights, which tells us which organisation a visit is likely to have come from and which pages were read. With this on, ZoomInfo may also set third-party cookies that help it recognise a visit across other websites, and may share that with its own partners. Turning this off stops all of it.