Financial services — India
Self-Hosted PAM to Privilege Cloud migration
Privilege CloudMigrationSecure TunnelSession history preserved
Engaged to move a mature Self-Hosted estate to Privilege Cloud without any lapse in vaulting, rotation or session control. Ran a full inventory of accounts, safes, platforms and integrations and mapped each to its target equivalent.
Built connector servers and Secure Tunnel in the tenant, rebuilt platforms and policies, and validated every integration on the target before a single account moved.
Cut over in waves grouped by account owner, each with a rollback point, so a wave could be reversed without touching the others. Session recording history was preserved rather than left behind.
Closed with hypercare and a runbook set, then handed the platform to the customer's own team.
✓ OutcomeA cloud-hosted platform with the same controls as before, lower infrastructure overhead, continuous audit history, and a team able to operate it without us.
Enterprise — multi-region
Identity platform integration across SailPoint, Entra ID and AWS
SailPoint ISCEntra IDAWS IAM Identity CenterSecrets Manager
The customer ran governance in SailPoint, authentication in Entra ID and cloud access through AWS IAM Identity Center, and none of them agreed on who a person was. Provisioning was manual and every connector held a standing credential.
Designed a single identity source with attribute hygiene, employeeID mapping and a UPN strategy every platform could rely on.
Connected SailPoint provisioning to Active Directory using service credentials retrieved from Secrets Manager rather than stored in the connector, removing a standing credential from the governance platform.
Wired Entra ID as the identity source for AWS IAM Identity Center with SAML and SCIM, and Idira as the privilege broker for cloud consoles.
✓ OutcomeProvisioning, authentication and privileged access driven from one identity, with vaulted credentials replacing static ones in every connector.
Enterprise — India
Custom CPM plugins and PSM connectors for unsupported applications
CPM pluginsPSM connectorsCCPRotation policy
Several business-critical applications had no vendor-supported platform, so their service accounts sat outside rotation policy — visible in every audit as an exception.
Built CPM plugins with change, verify and reconcile flows for each target, and PSM connection components so administrators reached them through isolated, recorded sessions.
Onboarded the accounts under the same rotation policy as the rest of the estate and moved application retrieval onto the Central Credential Provider.
✓ OutcomeEvery service account rotating under one policy, no audit exceptions, and a pattern the customer's team now reuses for new applications.
Technology — cloud-native
AWS and Azure IAM automation for Secure Cloud Access
Secure Cloud AccessAWSAzureDockerLambda
Just-in-time cloud elevation through Secure Cloud Access depended on roles and policies that were being created by hand across dozens of accounts and subscriptions, and drifting the moment they were.
Automated the creation and lifecycle of AWS and Azure IAM roles and policies for SCA, packaged as Docker containers and AWS Lambda functions.
Moved entitlement provisioning into the pipeline, so a new account or subscription arrives with its SCA roles already in place and drift is corrected automatically.
✓ OutcomeZero standing privilege in the cloud consoles, entitlements provisioned by pipeline rather than by hand, and a control plane the platform team can extend.