Skip to main content

Case Studies

Real Results
From Real Engagements

How we have helped companies solve identity, device, SaaS, and managed IT challenges. Clients anonymised, outcomes genuine.

IAM & Access ManagementTechnology (Scaleup)

45 Apps. Zero Audit Trail. Three Weeks to Fix It.

A 450-person scaleup had 45 SaaS applications with no SSO, no audit trail, and manual provisioning. We deployed Okta via Terraform, connected HiBob as the HR source of truth, and automated the entire access lifecycle in 21 days.

21 daysDeployment Time
0Manual Provisioning Events Post-Cutover
45Applications Governed
~450Employees Covered
Case study: Securing Access Across a Global Workforce
Read the Full Case Study

At a Glance

Company Size
~450 employees
Industry
Technology (Scaleup)
Environment
Google Workspace, 45 SaaS applications
Timeline
21 days to full deployment
Services
Identity & Access Management, Lifecycle Automation
Stack Deployed
Okta (SSO/lifecycle), HiBob (HR source of truth), Terraform (IaC)

We went from having no visibility over who had access to what, to a position where everything flows from a single HR change. The difference was immediate.

Head of IT (name withheld by request)

The Problem

The entire identity layer ran through Google Workspace. There was no SSO, and 45 applications each managed their own access. When someone joined, a person built their account by hand. When someone left, their access stayed live until the right person remembered to remove it.

Nobody had a reliable picture of who held access to what, or from where.

What Was Actually at Risk

An ex-employee still active in a production app. A 45-application estate with nothing resembling an audit trail, right as a potential acquirer starts asking questions.

For a company at this stage, with acquisition conversations already in play, those things don't surface as technical debt. They surface as deal risk.

How We Did It

Okta was deployed via Terraform and mapped into the existing Google Workspace OU structure, keeping the directory intact and avoiding migration overhead. Nobody woke up to a broken login. Each of the 45 applications was onboarded individually, with permission layers documented and governed as they came in rather than retrofitted after the fact.

HiBob was then connected as the HR source of truth so that employment changes (new starters, role changes, departures) flow directly through to access and app entitlements. That removed the tickets, the manual handoffs, and the gaps between someone leaving and their access actually being revoked.

The Result

Three weeks of engineering and the entire access lifecycle is automated. HR makes a change in HiBob and the rest follows: right access on arrival, clean exit on departure. The ticket queue that used to fill with access requests cleared, and IT got their time back for project delivery. The estate went from invisible to governed.

We also brought their device estate under management as part of this engagement. See that engagement

Device Management & SecurityTechnology (Scaleup)

450 Devices Across Two Platforms. Most of Them Unmanaged. None of Them Wiped.

A 450-person scaleup had a mixed Apple and Windows fleet without MDM, policy enforcement, or visibility. We enrolled every device into IRU and Intune via phased rollout, deployed SentinelOne, and tied it all back to Okta, all without disrupting a single workday.

2Device Platforms Unified
0Workday Disruptions
100%Endpoint Security Coverage
21 daysRollout Window
Case study: Unifying Endpoint Management for Hybrid Teams
Read the Full Case Study

At a Glance

Company Size
~450 employees
Industry
Technology (Scaleup)
Environment
Mixed Apple & Windows
Timeline
Phased rollout across 21 days
Services
Device Management, Endpoint Security
Stack Deployed
IRU (Apple MDM), Intune & Autopilot (Windows), SentinelOne (endpoint), Okta (identity-based policy)
Also Delivered
HITRUST certification support (~50-person client)

The fact that we did this without disrupting a single person's workday was the part that surprised everyone. People expected pain and there wasn't any.

Head of IT (name withheld by request)

The Problem

The device estate was split across Apple and Windows, with most machines untouched by any management tooling. The estate had grown without MDM, without policy enforcement, and without visibility into what was out in the field. A device could leave the building with credentials intact and nobody would know until something went wrong.

For a company heading into acquisition due diligence, "we don't manage our devices" is not a conversation you want to be having.

How We Did It

Machines were already out with users, so enrollment had to work around people's days. It was phased by team and scheduled outside core hours.

On the Apple side, new hardware went through ABM directly into IRU. Existing machines were enrolled into MDM outside of ABM and will transition to the full lifecycle path as hardware turns over naturally. Nobody got a forced wipe or a disruption mid-project.

On Windows, self-service documentation walked people through the process: hardware hashes captured, devices registered into Autopilot. From that point they're Autopilot-ready, and the full wipe-and-reprovision happens either for compliance reasons or at the next hardware refresh. Users kept working throughout.

Both platforms were tied back to Okta for identity-based policy enforcement, which was deployed as part of a parallel identity and access management engagement.

SentinelOne was sourced below list price and pushed to every managed endpoint on completion.

The Result

The estate went from unmanaged to fully governed without disrupting anyone's workday. IT gained visibility over every device, the ability to enforce policy remotely, and a hardware lifecycle that actually works with the business rather than against it.

HITRUST for a Smaller Client

A separate ~50-person company came to us needing MDM for their device fleet. We enrolled their machines, deployed endpoint protection, and enforced baseline policies across the estate. The controls put in place then provided the evidence base their assessor needed when the company went through HITRUST certification. Enrolment records, endpoint compliance reports, and policy enforcement logs were already there because that is how the devices were managed day-to-day. We provide controls and evidence to support audits and questionnaires. Certification decisions sit with the auditor.

Identity-based policy enforcement was deployed as part of a parallel IAM engagement. See that engagement

SaaS, Licensing & Vendor ControlVC-backed Tech / Professional Services

Their SaaS Bill Was Fine. Their Discount Wasn't.

Multiple clients were paying list price on security and productivity software through large resellers who had gone unresponsive. We took over procurement through partner programmes, renegotiated stale contracts, and consolidated billing onto monthly net-30 terms.

15-30%Typical Saving vs List
Monthly, net-30Billing Terms
3Vendor Transitions Managed
Yes, mid-contractReseller Replaced
Case study: Cutting Software Costs Through Smarter Procurement
Read the Full Case Study

At a Glance

Company Sizes
50-500 employees
Industries
VC-backed tech, professional services
Timeline
Ongoing across multiple engagements
Stack Managed
SentinelOne, 1Password, Google Workspace, Microsoft 365, Cloudflare, and others
Services
SaaS Sourcing, Vendor Management, Licence Optimisation
Products Sourced
Security, identity, productivity, and infrastructure tooling

We were paying list price on almost everything and couldn't get anyone on the phone to fix it. Now we just send one email and it's handled.

Operations Lead (name withheld by request)

The Problem

Most growing companies buy software direct from the vendor at list price, or through a large reseller whose discounts barely move. One VC-backed client came to us after their existing reseller had gone effectively unresponsive. Invoices were still arriving but support had dried up, renewals were rolling through on autopilot, and nobody was reviewing whether the licensing matched what the company actually needed.

What Was Actually Happening

Contracts were renewing at or near list price because nobody was negotiating them. The reseller relationship had become transactional: invoices in, silence out. Volume discounts were not being applied. Partner programme tiers that would have unlocked better pricing were not being used. The client had no visibility into whether they were on the right SKUs or whether the same product was available at a lower cost through a different distribution channel.

How We Fixed It

We source through the same partner programmes and distributor relationships the big resellers use. The difference is we pass the margin through instead of sitting on it. For this client, we replaced the existing reseller mid-contract, migrated subscriptions onto our partner accounts, and renegotiated where pricing was stale. Billing was consolidated onto a single monthly invoice on net-30 terms instead of a stack of annual prepays scattered across vendors.

When a client buys SentinelOne, 1Password, or Cloudflare through us, we deploy it too. The software arrives configured, pushed to endpoints, and documented. That is included in the procurement relationship, not scoped as a separate project.

The Result

Clients pay 15-30% less than list price, get a single point of contact for procurement and support, and stop losing weeks to vendor sales cycles. The VC-backed client went from chasing an unresponsive reseller to having their entire software estate billed, managed, and supported through one relationship. Three vendor transitions were managed without service interruption.

SentinelOne was sourced below list and deployed as part of our device management engagement. See that engagement

No IT Estate. No Controls. We Built the Infrastructure. They Passed the Audit.

A stable 100-person SME needed ISO 27001 but had no structured IT estate to certify against. As part of an ongoing fractional CIO engagement, we designed and implemented the entire control set. The infrastructure was live and enforced from day one. Certification took around nine months, driven by the client working through HR policies and documentation at their own pace.

PassedISO 27001 Outcome
YesControls Mapped to Annex A
ScratchIT Estate Built From
~100Employees Covered
Case study: Passing ISO 27001 on Technical Controls
Read the Full Case Study

At a Glance

Company Size
~100 employees
Industry
Technology (SME)
Timeline
Ongoing advisory; infrastructure built as part of engagement, certification completed over ~9 months
Stack Deployed
Okta, Intune, SentinelOne, DNS filtering, access review tooling
Engagement Type
Fractional CIO and end-to-end implementation
Key Outcome
ISO 27001 certification passed on technical controls
Services
IT Strategy, Infrastructure Build, Compliance Controls, Documentation

Most companies pass ISO 27001 by writing documents. We passed it by showing what we had actually built. The auditor could see it was real.

CFO (name withheld by request)

The Problem

A stable 100-person SME was making technology decisions without a technical voice in the room. The company needed ISO 27001 certification but had no structured IT estate to certify against. There was no centralised identity provider, no device management, no endpoint protection, and no documented access controls. Every tool had been adopted ad hoc as the company grew.

What Was Actually at Risk

Growing without controls means the certification gap widens every month. Auditors do not accept policies on paper if nothing is technically enforced behind them. The longer the company waited, the larger the estate that would need to be retrofitted. Without a structured control set, there was nothing for an assessor to audit.

How We Did It

We designed the control set and implemented the tooling end-to-end. Identity went through Okta with lifecycle automation. Devices were enrolled into Intune with compliance policies enforced at login. SentinelOne was deployed to every endpoint. DNS filtering was configured to meet web access control requirements. Access reviews were built as a scheduled process rather than a one-off exercise.

Everything was built as infrastructure and handed over as code repositories coupled with documentation that mapped each control to the relevant ISO 27001 Annex A requirements. The client received working infrastructure and a clear record of what was implemented, why, and where it sat in the control framework.

The Result

The infrastructure was ready from the moment we built it as part of the ongoing engagement. When the auditor arrived, they walked through live controls rather than a policy binder. Enrolment records, endpoint compliance data, access review logs, and DNS filtering configuration were all available because they were how the estate was managed day-to-day. The nine-month certification timeline was driven by the client working through HR policies, documentation, and paperwork at their own pace. The IT controls side of ISO 27001 certification passed on the strength of what was technically enforced and evidenced.

The identity governance layer that helped pass ISO 27001 was built as part of a parallel IAM engagement. See that engagement

Managed IT ServicesSoftware / Technology

Their MSP Wanted to Migrate Everything to Microsoft. We Just Supported What They Already Had.

A mid-sized software company had the right tools but nobody dedicated to running them. Every MSP they spoke to wanted to migrate half the stack to Microsoft. We embedded a specialist who learned what was in place and supported the environment without changing a single platform.

6+Platforms Managed
0Platforms Migrated
£0Additional Licensing Required
Embedded, business hoursCoverage Model
Case study: Embedded IT Support Without the Stack Migration
Read the Full Case Study

At a Glance

Company Size
Mid-sized
Industry
Software / Technology
Timeline
Ongoing embedded engagement
Stack Managed
Okta, Jamf, Google Workspace, Slack, and others
Environment
Mixed stack, no single-vendor dependency
Engagement Type
Embedded IT support
Services
Ongoing Support, Stack Operations, Issue Resolution

Every MSP we spoke to wanted to change what we were running. These lot just learned it and made it better.

CTO (name withheld by request)

The Problem

Every MSP they spoke to opened with an audit, recommended migrating half the stack to Microsoft, and quoted a retainer that included migration work nobody asked for. The company did not have a platform problem. They had an operations gap. The tools were right; they just had nobody dedicated to running them.

What Was Actually at Risk

Without dedicated operations, issues queue up and workarounds become permanent. Shadow IT builds because people route around the bottleneck. A traditional MSP would have added licensing overhead and platform migration before solving any of it. The company needed someone who could learn the existing stack and keep it running.

How We Did It

An embedded specialist sits inside the environment, knows the stack, has access to admin consoles, and works alongside the internal team. This is not a ticket queue or an external helpdesk. The engagement runs on the company's own licensing. They own their stack and they own their data.

The specialist handles day-to-day operations across every platform in the estate. When something breaks, it gets fixed by someone who already understands the environment. When a new tool needs configuring, it gets done without a scoping call or a change request. The company gets IT operations without the overhead of hiring a full-time specialist or the compromise of handing their stack to an MSP that wants to change it.

The Result

The company got dedicated IT operations across their entire stack without migrating a single platform. Issues are resolved by someone who already knows the environment. The internal team got their time back for product work instead of fielding IT requests. No new licensing, no platform changes, no vendor lock-in.

The automation layer running alongside this engagement is documented separately. See that engagement

If the SKU Does Not Exist, We Build It.

Companies outgrow what their vendor SKUs can do. We build the automation they actually need: custom governance tooling, onboarding workflows, service desk automation, and Okta org remapping software that handles company restructures in hours rather than weeks.

45 min to < 5 minOnboarding Time
£0Additional Licensing Cost
~1 weekOrg Remapping Delivery
0Downtime During Restructures
Case study: Automation Engineering Across the Stack
Read the Full Case Study

At a Glance

Company Sizes
50-500 employees
Industries
Technology, professional services
Stack
Okta, Terraform, n8n, custom tooling
Delivery Model
Engineering-led, embedded
Engagement Type
Build and deploy, ongoing iteration
Services
Workflow Automation, Identity Engineering, Infrastructure as Code

We were being quoted five figures for an enterprise SKU to get a governance feature. They built it in a week and it works better than what the vendor was offering.

CFO, 100-person technology company (name withheld by request)

The Problem

Companies between 50 and 500 employees hit the same wall. The governance feature they need is locked behind an enterprise SKU they cannot justify. Onboarding a contractor takes 45 minutes of hand-built accounts across half a dozen platforms. App requests go through email chains because the service desk does not have approval workflows. When the company restructures, access policies are hardcoded and nobody wants to touch them.

The vendor answer is always the same: upgrade your licence. The internal answer is always the same: we do it by hand because we have no other option.

What We Actually Build

Four categories of work, delivered across multiple client environments.

Governance tooling when the SKU does not exist. One client needed a governance feature that sat behind an enterprise tier they were not on. We built it. The control works, the audit trail exists, and the client did not have to upgrade a single licence.

Onboarding automation triggered from a single event. HR marks someone as starting and the rest follows: accounts created, group memberships assigned, apps provisioned. What used to take 45 minutes of manual work runs in under five.

Service desk workflows for requests and approvals. App access requests, hardware requests, and permission changes routed through built workflows instead of email chains. Approvals tracked, access granted, audit trail logged.

Okta org remapping software. Custom tooling that reads an org chart change, maps it to access policy, generates the policy as Terraform, and deploys it. Zero downtime. This is used across our existing IAM clients to handle restructures that previously took weeks.

How the Org Remapping Works

When a company restructures, access policies need to change. Reporting lines shift, teams merge or split, and the permissions model that made sense last quarter no longer reflects who needs access to what. In most environments this is a manual exercise that takes weeks of planning, testing, and cautious rollout.

Our tooling takes the updated org chart and maps it against the existing access policy structure in Okta. It identifies what needs to change, generates the updated policy as Terraform code, and queues it for review. Once approved, it deploys through the standard infrastructure pipeline with zero downtime.

On a well-aligned Okta environment, standard delivery is roughly a week. That includes mapping, code generation, review, and deployment. We use this across existing IAM clients to handle restructures in hours of engineering time rather than weeks of project management.

The Result

Contractor onboarding dropped from 45 minutes to under five. Governance controls were delivered without SKU upgrades or additional licensing. Service desk requests that used to sit in inboxes now run through tracked workflows with approval chains. Org restructures that took weeks of planning and manual policy changes are handled through code generation and automated deployment.

Every piece of automation runs on the client's existing licensing. No additional platform costs.

The support layer that runs alongside this automation work is documented separately. See that engagement

Ready to Get Started?

Book a 20-minute call with an engineer. We will tell you what is broken, whether we can fix it, and what it costs. No obligation.

Book a Call