Back to main siteBack Contact us
Identity and Access

Okta

Identity and Access

One identity, governed centrally, everywhere it is used

Okta sits between your people and every application they use, so access is granted, challenged and removed in one place rather than separately in forty. The value is not the login screen; it is that leaving the organization actually ends access.

STAFF CONTRACTOR DEVICE IDENTITY LAYER authenticate apply policy MICROSOFT 365 FINANCE APP CRM 40 OTHERS one place to revoke
The offboarding problem

Most organizations cannot prove a leaver lost access

Ask how many applications a departing employee had, and whether every one was closed. The answer is usually a list somebody maintains by hand, and it is usually incomplete.

Applications nobody registered

Departments buy tools directly. Those accounts are created outside any central process, so they appear on no offboarding checklist, and they remain live long after the person who used them has gone. The organization does not know they exist until an invoice or a breach reveals them.

Access that accumulates

People change roles and gain permissions, but permissions are rarely removed on a move because removing them risks interrupting work. After several years, long-serving employees hold access far beyond their current role, which is exactly the account an attacker wants.

The pipeline

How central identity changes each stage

Identity management is a lifecycle problem. Each stage below is where organizations without it lose control.

01

Joining: access from the role, not from a request

A new starter is assigned a role, and the applications and permission levels attached to that role are provisioned automatically. Nothing depends on a manager remembering what their predecessor had.

This also removes the common shortcut of copying an existing employee's access, which is how over-permissioned accounts propagate through an organization.

02

Working: one login, policy applied per attempt

Single sign-on means one credential to protect rather than forty to reuse. Each attempt is then evaluated against policy: who, from where, on what device, at what hour, and how sensitive the destination is.

That evaluation is what allows stronger verification to be demanded only when the circumstances warrant it, rather than making everyone perform the same challenge every time and training them to click through it.

03

Changing: permissions that follow the move

When somebody changes role, the access attached to the old role is withdrawn as the new role's access is granted. Accumulation stops being the default outcome of a career.

04

Leaving: one action, every application

Deactivating the identity ends access across every connected application at once, and sessions already open can be terminated rather than left to expire. The question of whether a leaver still has access becomes answerable, which is the point.

Specification

What sits where in your stack

FunctionHandled byReplaces
authenticationCentral identity layerPer-application logins
verificationAdaptive multi factorPasswords alone
provisioningRole based automationManual account creation
directoryUniversal directorySeveral partial lists
auditCentral access logReconstructing from apps
Honest qualification

What this suits, and what it demands

A strong fit

Organizations running many applications from different vendors, those with contractors and temporary staff, and anyone whose auditors have started asking for evidence of access reviews. Vendor neutrality matters here: an organization spread across Microsoft, Google and numerous other platforms benefits from an identity layer that favours none of them.

What it requires

An identity platform becomes the front door to everything, which makes its own availability and its own administrator accounts critical in a way they were not before. It also requires the application inventory to be honest. Integrations only cover applications you know about, and the ones nobody registered remain outside the perimeter you have just built.

In short

Start by listing what a leaver had access to

If that list cannot be produced quickly and completely, the gap is not a login problem, it is a governance problem, and it is the one worth closing first.

Book the access review

Get in touch with Your Company

Questions about this solution? Reach us directly.