Rebuilding an Enterprise Identity Foundation
An identity platform became an operating model.
- Capacity
- Senior security engineer doing architecture work
- Changed
- Source of truth, directory integrations, policies, account management, onboarding, and entitlements
- Proof
- The platform became easier to use, operate, and audit
- Context
- I was brought in to make the organization’s identity platform work. That was the visible problem. The deeper problem was that the organization did not have a reliable picture of its own application environment, much less a mature identity architecture for governing it.
- Problem
- Teams were siloed, application ownership was often unclear, and the architecture had grown brittle through accumulated exceptions. Without a trustworthy source of truth or a consistent model for directory integration, policy, and lifecycle management, each new application risked adding a local solution to a systemic problem.
- Approach
-
I began with application onboarding because it gave me a practical way into the system. Each integration exposed another part of the architecture that needed to be understood or rebuilt.
Over time, I reworked the source of truth, directory integrations, policy framework, account management experience, and application onboarding process. I also automated access entitlements and strengthened lifecycle management.
The work moved from solving individual integrations to building a repeatable identity model the organization could operate.
- Outcome
-
The platform is now used, not merely deployed. Applications enter through a consistent process, entitlements are automated, lifecycle events are handled more reliably, and audit evidence is supported by coherent controls.
The organization also has a clearer understanding of its application environment and the relationships that govern access within it. Those outcomes did not come from the platform alone. They came from resolving assumptions the platform had previously been expected to absorb.
- What I learned
-
Identity architecture is often as much about organizational clarity as it is about access. It forces decisions about authority, ownership, lifecycle, and exception.
When those decisions remain implicit, technology makes inconsistency faster. When they are explicit, automation reinforces the architecture instead of hiding its weaknesses.