Skip to content

How we work

Method over methodology.

Four steps, applied the same way whether the subject is an identity programme, a cryptographic migration or a fleet of AI agents. Nothing here is proprietary — which is rather the point.

01 — Discover

We establish what exists, not what is documented. That means configuration exports, scans, log samples and short interviews with the people who actually operate the system — not a workshop where everyone describes the target state.

This phase is deliberately unglamorous and consistently the most valuable. The gap between the architecture diagram and production is where risk lives, and it is almost never where anyone expected.

02 — Prioritise

Findings are ranked by business exposure against effort, and we are explicit about the trade-off rather than hiding it behind a heat map. A finding that is critical but takes eighteen months does not belong ahead of three high findings that can be closed this quarter — unless the critical one is genuinely existential, in which case we will say so plainly.

You get a sequenced backlog with dependencies, so the first quarter of work removes the most risk rather than the easiest tickets.

03 — Design

Target-state architecture, policies and runbooks — written for the tools you own and the people you have. A design your team cannot operate after we leave is a failed design, however elegant it looked in the report.

We write decision records, not just outcomes: what we chose, what we rejected, and why. When someone asks in two years why the model looks like this, the answer exists.

04 — Prove

A control you cannot evidence is a control you do not have. Every workstream ends with tests, metrics and an evidence pack mapped to whatever framework you are assessed against — and with an honest read on whether the control is actually working, which is not the same as whether it exists.


Principles we do not negotiate

  • We will tell you when you do not need us. A short honest answer costs us a project and earns the next three.
  • No vendor commission, ever. Product recommendations are only worth something if nobody is paying for them.
  • Your team keeps the knowledge. Deliverables are written to be maintained by you, and we run a handover session, not a document drop.
  • Findings are specific. “Improve your access governance” is not a finding. A named entitlement, a named owner and a named fix is.
  • Bad news travels fast. If scope, cost or feasibility changes, you hear it that week — not in the closing report.

What a first engagement looks like

  • Day 0 — Discovery call. Thirty minutes, no charge, no slides. We establish the question and whether we are the right people to answer it.
  • Day 2–3 — Scope and fixed price. A one-page proposal: the question, the method, what you receive, the price and the dates.
  • Week 1–3 — Fieldwork. Interviews, data collection and analysis, with a short written update every week so nothing lands as a surprise.
  • Week 4 — Readout. Findings, roadmap and a working session with the people who will do the work.
  • After. Retainer, delivery support, or nothing at all — whichever is actually right.

Bring us a question, not a brief.