Skip to main content

The vaultIAM Way

You see every query before you grant us any access.

Every engagement starts with a read-only look at the tools you already pay for, using a query list we publish in advance, and ends with your team running it without us. Nothing we do requires you to buy anything or keep us on.

The Identity Risk Assessment

What the assessment actually looks at.

  • Read-only queries through each platform's own admin API — Microsoft Graph, the Okta API, AWS IAM and Access Analyzer, Azure and GCP IAM, CyberArk, Active Directory, GitHub, Kubernetes RBAC* — plus our own scripts, all of which we show you
  • The permission set we need is published before we ask for it, and the check list is the same one every time — no discretionary access, no surprises
  • Checks across permanent admin access, credential hygiene, the routes an attacker could take between accounts, machine identity ownership, and conditional-access policy gaps
  • Every finding mapped to FFIEC/NYDFS, HIPAA Section 164.312, SOC 2 CC6, OSFI B-13 and PIPEDA/Law 25 — with honest coverage disclosure per framework, because no automated check covers a whole framework
  • Runs inside your environment; nothing is uploaded to us or any third party

Identity Risk Assessment — sample layout

61

of 100

Critical

14 standing privileged accounts without JIT

Entra ID · Privileged roles

High

31 service accounts with no accountable owner

AWS IAM · NHI inventory

High

Conditional Access gap: legacy auth unblocked

Entra ID · CA policies

Medium

9 API keys older than 365 days

Cloud IAM · Credential hygiene

Framework coverage (automated controls)

FFIEC / NYDFS

HIPAA Section 164.312

SOC 2 CC6

PIPEDA / Law 25

How the work runs

Three phases. Take only the ones you need.

  1. 01 2 weeks

    Assess

    We run read-only queries against the systems you already have — Entra ID, Okta, AWS/Azure/GCP IAM, CyberArk, AD, GitHub, Kubernetes — using each platform's own admin APIs plus our scripts. Zero agents, zero config changes, nothing leaves your network.

    You get

    Scored, board-ready report

    Fixed scope, fixed fee

  2. 02 6–8 weeks

    Harden

    Sprints close the highest-risk gaps using tools you already license. Every change documented, every decision transferable, every step handed over.

    You get

    Hardened controls + runbooks

    Scope fixed per sprint

  3. 03 Quarterly

    Assure

    Optional quarterly re-checks catch drift before examiners do. Cancel anytime — never contractually required, never a condition of the work above.

    You get

    Drift & compliance delta report

    Optional · cancel anytime

Why no lock-in is structural, not marketing: consultancies that create dependency are solving for retention. Our deliverables are runbooks, documentation, and trained operators — because our next engagement should be won by results, not captivity.

* Platform and product names identify systems we work with. They do not imply partnership, certification, or endorsement by their owners.

See these queries run against your own systems

The assessment described above, on your systems, with the query list shown to you first. Thirty minutes to scope it, a fixed fee, and the findings are yours whatever you decide to do next.

Book an Identity Risk Review