It looks like you're in the US. Switch to the US site
    IAM & Access Management

    IAM & AccessManagement

    Identity and access management consulting. SSO, MFA, and Zero Trust implementation with Okta and Microsoft Entra ID.

    Okta · Entra ID · Google Workspace · IRU

    Day 1

    New Hire Access

    Hours

    Leaver Revocation

    4-8 Weeks

    Full Rollout

    Always

    Audit-Ready

    Platforms We Deploy • Authorised Partners

    Okta
    Entra ID
    Google Workspace
    IRU
    1Password

    This might sound familiar

    These patterns cost you time, money, and peace of mind.

    How We Work

    A typical 6-8 week implementation that eliminates manual provisioning forever

    The Architecture

    HR-driven identity lifecycle with automated provisioning to apps and devices

    We use Infrastructure as Code: Rebuild destroyed environments in minutes · Full version control with audit trail

    Custom Okta tooling for rapid spin-up · Alt config management for Entra ID

    What You Get

    Pricing

    50 users or 1,000+. Most projects are fixed-fee.

    Scoping included. Complexity drives pricing, not headcount alone. Apps, integrations, and governance features all factor in.

    Get a Quote

    20-minute call. No commitment. We'll scope it properly.

    Single IdP

    From £4,999

    (typical: 50-1000+ users)

    One platform. SSO and lifecycle. Done in 4-6 weeks.

    Already on Okta, Entra, or Google? We configure it properly. SSO for your apps, MFA policies, HR sync, and offboarding automation. Discovery included. Licences through us at partner pricing. Most projects are fixed-fee, scoped upfront. Extended features like Access Governance (OIG) or PAM/PIM are priced as add-ons or scoped separately.

    • Discovery and scoping included
    • Platform configuration (Okta/Entra/Google)
    • SSO integration for all apps & devices
    • MFA rollout and policies
    • HR sync (SCIM provisioning)
    • Offboarding automation
    • Handover documentation

    Extends with: Requests & Approvals, Workflow Automation, Access Governance (OIG), PAM/PIM, Hub & Spoke, AD Hybrid. These features add complexity and are scoped accordingly.

    Pairs well withSaaS, Licensing & Vendor Control

    SSO reveals every app. We help you rationalise them.

    Multi-IdP / Migration

    From £7,999

    (typical: 50-1000+ users)

    Consolidating platforms. Moving from legacy. We've done it before.

    Migrating from Okta to Entra? Merging two IdPs post-acquisition? Running Google and Entra side by side? We handle the complexity. Discovery included. Fixed-fee for most projects. Hub & Spoke architectures, AD migrations, or multi-HR integrations increase scope and are priced accordingly. Very complex environments (e.g., 3+ IdPs, 50+ app integrations) may be scoped as day rate for a dedicated engineer.

    *Everything in Single IdP, plus:

    • Platform migration planning
    • Legacy IdP decommissioning
    • Cross-platform federation
    • User migration with zero downtime
    • M&A identity consolidation
    • Conditional access policy design

    Extends with: Requests & Approvals, Workflow Automation, Access Governance (OIG), PAM/PIM, Hub & Spoke, AD Hybrid. These features add complexity and are scoped accordingly.

    Pairs well withDevice Management & Security

    Device trust validates identity trust.

    Managed

    Monthly

    Ongoing identity operations. Licences through us.

    Available to everyone. Skip project fees and go straight to monthly. We embed in your workspace as your identity team. Handle access requests, joiner/mover/leaver workflows, access reviews, and continuous policy refinement. All licence purchases flow through us. Project work can be spread into the managed fee structure. Complex estates with extensive governance requirements may require custom scoping.

    *Everything in Multi-IdP / Migration, plus:

    • Embedded in Slack/Teams
    • Joiner/mover/leaver operations
    • Quarterly access reviews
    • Continuous policy updates
    • Compliance reporting (SOC 2, ISO 27001)
    • Vendor liaison

    Extends with: Requests & Approvals, Workflow Automation, Access Governance (OIG), PAM/PIM, Hub & Spoke, AD Hybrid. These features add complexity and are scoped accordingly.

    Pairs well withWorkflow Automation & IT Support

    Extend your team's identity expertise.

    Most projects are fixed-fee, scoped before we start. Complexity drives pricing.

    Integration count, governance features, and timeline all factor in. Day rate available for dedicated engineering on complex, evolving work.

    Our Promise

    "VC-backed software company. 500 users. Okta deployment. Entra ID connected. AWS connected. Atlassian with permissions. Hybrid Windows and Mac fleet. No disruptions."
    Real Scale
    "No death-by-PowerPoint. No meetings to schedule more meetings. No 47-page discovery documents. Slack us, hop on a quick call, we'll just crack on. You'll talk to the people doing the work."
    Skip the Decks
    "23 global admins where you need 4. Service accounts with God-mode since 2019. Shared passwords, no MFA. Orphaned accounts from staff who left two years ago. We flag it all. Even when it's not in scope."
    We Find the Holes

    Boutique means something.

    We don't rotate account managers. We don't hide behind ticket queues. We don't disappear after go-live.

    We know your stack because we built it. When something breaks, you don't file a ticket. You send us a message.

    IAM & Access Management FAQs

    What do we need to provide before starting?

    Three things: admin access to your identity provider and key apps, a decision owner (IT lead or similar) for approvals, and a list of your core applications with any compliance deadlines. We handle the rest.

    How long does a typical IAM rollout take?

    Most implementations take 4 to 8 weeks depending on the number of applications and complexity. We start with your most critical apps and expand from there.

    Do we need to replace our existing identity provider?

    Usually not. We work with what you have: Okta, Entra ID (Azure AD), Google Workspace, or others. If a migration makes sense, we will tell you why.

    What happens when someone leaves the company?

    With proper lifecycle automation, access is revoked automatically when HR updates their system. No manual chasing, no orphaned accounts.

    Will this help us pass security audits?

    Yes. We deliver the controls and evidence documentation that auditors look for: access policies, admin registers, JML runbooks, and architecture diagrams.

    Can you integrate with our HR system?

    In most cases, yes. We connect identity provisioning to your HR system so joiners, movers, and leavers are handled automatically. If your current HR system does not support integrations, we can deploy HiBob for you. It is built for modern identity workflows and we have done multiple rollouts.

    How do I know which pricing model is right for me?

    We work it out with you. Discovery is always included, so we scope your needs before quoting. If you have clear requirements, fixed project pricing works best. For complex or fast-changing environments, we recommend project plus managed. We'll tell you which fits after a scoping call.

    Will this disrupt our employees during rollout?

    No. We deploy incrementally, app by app, with clear comms before each change. Most users notice nothing except fewer password prompts.

    We have legacy apps that do not support SSO. What then?

    We audit everything first. Apps that support SAML or OIDC get proper SSO. Apps that do not get password vaulting through 1Password, our recommended partner, or controlled workarounds. Nothing gets left behind or swept under the rug.

    Does MFA slow people down?

    Absolutely not. Okta FastPass is biometric and on-device. You do not even pull your phone out. Passkeys and device trust mean users authenticate once and stay signed in across apps. We design for minimal friction, not security theatre.

    What does an IAM consulting engagement involve?

    Our IAM consulting starts with discovery: mapping your applications, current authentication flows, and compliance requirements. We then design the target architecture, implement SSO and MFA across your apps, build automation for joiners/movers/leavers, and document everything for audit readiness. Most projects are 4-8 weeks.

    Do you provide Okta consulting and implementation services?

    Yes. We are Okta specialists and have deployed Okta Workforce Identity across dozens of organisations. This includes SSO integration, MFA rollout, lifecycle automation, and advanced features like Okta FastPass and device trust. We also work with Microsoft Entra ID and Google Workspace for organisations on those platforms.

    How much does Okta implementation cost?

    Okta implementation costs vary based on scope. A typical SMB deployment with SSO, MFA, and lifecycle automation runs £12,000-30,000 for the project, plus Okta licensing (roughly £6-12/user/month for Workforce Identity). Enterprise deployments with complex integrations and advanced features cost more. We provide fixed pricing after discovery.

    Next Step

    Book a 20-minute call

    • Quick gap assessment of your current setup
    • Scope and timeline estimate
    Book a Call

    Request an access audit

    • Access posture snapshot
    • Risk summary with priority recommendations
    Get an Audit

    Talk to an engineer. Get a straight answer and next steps.

    Cookie Preferences

    This site uses cookies for bookings and core features. Optional cookies help us improve your experience.

    Privacy Policy