Real engagement outcomes: scope, findings, and results.
A client deployed a full security-role redesign straight to production without a UAT pass of the shipped build, and the first business day was quiet. Why an additive, evidence-built cutover makes that safe, and what it does and does not prove.
How two Dynamics 365 clients went live on a new security design without a UAT pass of the shipped build, and why the weeks of data collection beforehand are the test that makes a fast, low-risk go-live possible.
A client chose to deliver their security redesign in batches, a completely reasonable call for a business that can't pause. Here's what that decision actually costs on our side, batch after batch, and why it isn't anyone's fault.
Cost came first, then it came third, out of a legitimate concern about revoking access without proof of use. Remediation exists to cut a real bill, so we adapted our strategy to keep finding savings compatible with the new order.
Our evidence model leans on telemetry and audit-log evidence together. This environment had almost no usable telemetry at all. Here's what the redesign looked like on one evidence source instead of two.
Our cheapest role-mining design still produced 760 roles. The client asked for as few roles as possible, and told us upfront they'd pay more for it.
A client rejected a 100-role fix and asked us to mine roles from real usage instead. Our first attempt would have cost more per month than doing nothing.
The security model wasn't the biggest driver of this estate's license bill. The way one integration authenticated was.
Four published engagements with real before-and-after numbers, including the one where our own recommendation got turned down, and why we publish that one too.
A mentoring engagement on a greenfield D365 F&SC implementation found over a thousand segregation-of-duties conflicts in thirty roles, a day before user acceptance testing. What doing security right the first time actually looks like.
Our first fully automated D365 F&SC security migration: an XML import replaced weeks of manual role-building. What that automation actually required, and the framework we had to build around it.
The mathematically optimal security model saved $32,000 a month. The client rejected it as unmaintainable, and was right to. Why, and how we rebuilt our methodology because of it.
A European estate with genuinely well-built security still carried $40,000 a month in avoidable license cost. What a clean configuration hides, and how we found it anyway.