Services
Seven modules. One governed identity fabric.
Each module below can run on its own or as part of a combined program. Together, they cover every identity in your organization — staff, customers, vendors and machines — across on-prem, hybrid and cloud.
How It Fits Together
Every module feeds one unified identity fabric
MODULE / IGA
Identity Governance & Administration
Automate access reviews, role and entitlement management, joiner-mover-leaver workflows, and audit reporting.
Purpose
- Centralize identity lifecycle (HR-to-IT provisioning/deprovisioning) so access is granted and revoked consistently from a single authoritative source.
- Implement RBAC/ABAC for least-privilege at scale to reduce excessive entitlements and enforce separation of duties.
- Automate periodic access recertification and exception handling to provide continuous compliance evidence.
Tools we work with
- SailPoint IdentityNow/IdentityIQ
- Oracle Identity Governance (OIG)
- Microsoft Entra (Identity Governance capabilities)
Compliance mapping
- CBN IT Governance: enforce access recertification & separation of duties.
- NDPA: minimize PII exposure via least-privilege & governance.
- PCI DSS, ISO 27001: evidence of access control reviews.
How long does an IGA rollout take?
Pilots often complete in 6–8 weeks.
MODULE / PAM
Privileged Access Management
Vault, rotate, broker and record privileged sessions for admins, DBAs, and service accounts.
Purpose
- Eliminate hardcoded/admin passwords and shared credentials by vaulting and automating credential rotation.
- Enforce just-in-time elevation and session monitoring to ensure privileged actions are approved and recorded.
- Protect critical banking infrastructure with session isolation and detailed forensic logs.
Tools we work with
- CyberArk
- BeyondTrust
- Microsoft Entra PIM (for Azure/Entra privileged accounts)
Compliance mapping
- CBN Cybersecurity Framework: insider threat controls & logging.
- SWIFT CSP: strong controls for operator workstations & sessions.
- ISO 27001 A.8/A.9: privileged access restriction & monitoring.
Agent or agentless?
We can start agentless with session brokering and add lightweight agents where deeper control is required.
MODULE / NHI
Machine & Third-Party Identity
Extend governance to vendors, contractors, service accounts, API keys and workloads — not just employees.
Purpose
- Onboard and offboard vendor and contractor access on a defined schedule instead of indefinite standing access.
- Inventory and rotate service account and API key credentials that traditionally sit outside IGA/PAM scope.
- Apply least-privilege and expiry policies to workload and application identities across cloud and on-prem systems.
Tools we work with
- CyberArk Secrets Hub
- HashiCorp Vault
- Microsoft Entra Workload ID
Compliance mapping
- CBN Cybersecurity Framework: third-party and vendor access controls.
- ISO 27001 A.5.19–A.5.23: supplier relationship security.
Does this cover cloud workload identities too?
Yes — we extend the same governance model to workload and application identities in cloud environments.
MODULE / SSO ZERO TRUST
Access Management — SSO & MFA
Federated SSO, adaptive MFA, and centralized access policies for employees, partners, and customers.
Purpose
- Unify login across internet banking, admin consoles, and APIs to improve user experience and reduce password-related risk.
- Apply step-up MFA based on risk (device, geo, behavior) to protect sensitive transactions and administrative access.
- Accelerate fintech/onboarding with standards-based federation (SAML/OAuth/OIDC) to securely onboard partners.
Tools we work with
- Microsoft Entra ID (Azure AD)
- Okta / Auth0
- Ping Identity
Do you support passwordless?
Yes.
MODULE / CIAM
Customer Identity & Access Management
Secure onboarding, login and fraud-aware authentication for the customers who use your digital banking channels.
Purpose
- Link digital onboarding to KYC/BVN verification so new customers are identity-proofed before their first login.
- Apply adaptive, risk-based authentication to internet and mobile banking without adding friction to low-risk transactions.
- Detect account-takeover patterns and step up verification only when device or behavior signals warrant it.
Tools we work with
- Microsoft Entra External ID
- Okta Customer Identity Cloud
- Ping / ForgeRock CIAM
Compliance mapping
- CBN consumer protection & KYC circulars: identity-proofed onboarding.
- NDPA: lawful basis and data minimization for customer data collected at onboarding.
Does CIAM replace our core banking KYC checks?
No — we integrate with your existing KYC/BVN provider rather than replace it.
MODULE / GRC
Compliance Reporting & Audit Dashboards
Unified evidence packs and dashboards mapped to CBN, NDPA, PCI DSS, ISO 27001 and internal policies.
Purpose
- Automate collection of access logs, approvals, and exceptions to shorten audit response time.
- Map controls to regulations and internal policy owners so each control has a clear owner and SLA.
- Deliver regulator-ready reports with drill-down evidence to support CBN and third-party audits.
Tools we work with
- Splunk Enterprise Security
- Microsoft Sentinel
Can dashboards map to our policy IDs?
Yes.
MODULE / MSP-SOC
24/7 Managed Services & SOC for IDAM
Operate, monitor, and continuously improve the IDAM stack with SLAs tailored to Nigerian banks, government institutions and enterprises.
Purpose
- Provide run, incident, and change management for IGA/PAM/SSO tools to keep services available and secure.
- Detect identity threats with UEBA and correlate in SIEM for rapid triage and containment.
- Deliver quarterly tuning, cost & posture reviews and roadmaps aligned with business needs.
Tools we work with
- Runbooks & SRE tooling
- SIEM + UEBA
- Ticketing/ITSM (ServiceNow/Jira)
- Microsoft Entra (for identity telemetry)
Where is the SOC based?
Local Nigerian coverage with follow-the-sun support for 24/7 availability.
MODULE / TRAINING
IAM Awareness & Training
Executive briefings, administrator training and governance workshops that build identity and access management literacy across every level of your organization.
Purpose
- Build baseline IAM awareness across the organization so security and compliance become everyone's responsibility, not just IT's.
- Brief executives and board members on identity risk in language tied to business outcomes, not just technical detail.
- Train administrators on the day-to-day operation of IGA, PAM and SSO tools so your team can run the program confidently, not just watch us run it.
- Run governance workshops that align stakeholders on policy, ownership and escalation paths before an audit forces the conversation.
Training formats
- IAM awareness sessions (all staff)
- Executive briefings (board / C-suite)
- Administrator training (hands-on, tool-specific)
- Governance workshops (policy & ownership alignment)
Is training bundled with other modules, or offered on its own?
Either — training can run alongside any module rollout, or as a standalone engagement for teams that already have tooling in place but want stronger internal literacy.
MODULE / AI-GOV EMERGING RISK
AI Agent Identity Governance
Treat every AI agent as a first-class identity — owned, scoped, monitored and retired with the same rigor as human and machine accounts, as autonomous agents become one of the fastest-growing attack surfaces in the enterprise.
Purpose
- Assign clear ownership and a defined lifecycle to every AI agent deployed, from provisioning through retirement — no agent should exist without an accountable owner.
- Apply least-privilege, action-level scoping so agents can only take the specific actions they're authorized for, rather than inheriting broad standing access built for humans or static service accounts.
- Replace persistent standing credentials with just-in-time, time-bound access that automatically revokes once a task completes, reducing the blast radius if an agent is compromised.
- Monitor agent behavior continuously and separate identity governance (what an agent may reach) from runtime inspection (what it actually does) — autonomous decision-making produces anomalies that don't always match typical human or service-account misuse patterns.
Approach
- Extends your existing IGA/PAM platforms to govern agent identities alongside human and machine ones
- Agent-aware protocols including OAuth 2.1 and signed delegation tokens
- Just-in-time, time-bound access for agent tasks in place of standing credentials
- Continuous behavioral monitoring layered on top of static access boundaries
Compliance mapping
- CBN Cybersecurity Framework, NDPA and ISO 27001 hold organizations accountable for actions taken on their behalf — whether by a human, a service account, or an AI agent.
- Existing access-control clauses (including ISO 27001 A.5.19–A.5.23) extend naturally to agent identities, but only once agents are actually inventoried and governed.
How is this different from your Machine & Third-Party Identity module?
NHI covers static, relatively predictable non-human identities — service accounts, API keys, vendor integrations. AI agents behave differently: their scope can vary per task, their credentials are often ephemeral, and they can chain actions autonomously. This module extends the same ownership-and-lifecycle discipline to that faster-moving category.
Not sure which modules you need?
See how these map to your role and your industry, or talk to us directly.