A focused course, tailored for you
Access Recertification Without the Quarterly Fire Drill
Build the role-lifecycle and entitlement-review process that passes an auditor's access control review on the first pass.
Every quarter the access recertification closes and looks clean in the IGA tool. Then the auditor pulls a sample and finds provisioning drift nobody caught. The problem is not the tool. It is the missing artefacts between the tool's view and what the application actually enforces.
Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.
Why this course
IAM engineers running access recertification programmes at SaaS-scale organisations face a specific structural problem: the IGA platform reports entitlements, but the ground truth lives in three other places simultaneously. The role definition in the directory may not match the permission set in the application. The SCIM provisioning log shows the push succeeded, but the app did its own override. The quarterly review campaign captures current state but not the drift that accumulated between campaigns. Auditors for SOC 2 Type II and ISO 27001 access controls know to pull out-of-band samples precisely because they have seen this pattern. The engineer who can present a role-lifecycle runbook, a provisioning-verification procedure, and a recertification scope document that accounts for all three sources passes the walkthrough. The engineer who cannot has another finding.
What you walk away with
- Design a role-lifecycle runbook that documents the full provisioning-to-deprovisioning chain and satisfies access control evidence requests from SOC 2 and ISO 27001 auditors.
- Build an out-of-band entitlement verification procedure that compares IGA-reported entitlements against application-enforced permissions and surfaces drift before the quarterly campaign closes.
- Write a recertification scope document that defines what is in scope, what sampling methodology was used, and what the review outcome means, in language an auditor can accept without further clarification.
- Implement a role explosion remediation process that reduces active role count without breaking existing access, using a role rationalisation framework tied to business function rather than historical provisioning.
- Produce a SCIM provisioning hygiene checklist that catches common provisioning overrides and sync failures before they become audit findings.
- Assemble the complete access control audit-evidence package that a SOC 2 Type II auditor expects for the logical access management and access review control families.
The 12 modules
How this addresses your situation
Specific modules that map to what you said you are dealing with.
What you get with this course
- Twelve written modules with downloadable templates for every artefact: role-count diagnostic worksheet, SCIM hygiene checklist, out-of-band entitlement verification procedure, recertification scope document, role-lifecycle runbook, campaign-to-control mapping table, reviewer enablement pack, drift-response procedure, SOC 2 evidence package index, and pre-campaign readiness checklist.
- The hand-built implementation playbook, delivered alongside course access, covering your specific IGA tool category and application mix.
- Self-paced access through the Art of Service learning environment, no scheduled sessions.
What you will have in hand by Day 1, Week 1, Month 1
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.
Before and after
Quarterly recertification closes in the IGA tool, shows clean, and then the auditor finds provisioning drift in out-of-band samples. Another finding. Another remediation. Same conversation next quarter.
The role-lifecycle runbook, out-of-band verification procedure, and recertification scope document are in place. The next auditor walkthrough uses those documents as the primary evidence set and the campaign produces no surprises.
What happens if you do not address this
Access recertification findings are among the most repeatable IT audit observations because the underlying structural problem, the gap between IGA-reported state and application-enforced state, does not self-correct. Each quarter without the artefacts in place is another cycle where drift accumulates and the auditor has standing to issue a repeat finding.
Who it is for
IAM engineers and identity platform engineers at organisations running IGA tools who are responsible for the quarterly access recertification campaign and the audit evidence package that follows. You understand SCIM, OAuth, RBAC, and directory synchronisation. What you need is the operational framework that connects those technical components to the audit artefacts the compliance team needs.
How it arrives
Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.
Time investment. Approximately 8-10 hours across the twelve modules, plus the time to apply each template to your environment. Most engineers complete the course and produce their first artefact set within two weeks.
Why $199 is the right number
IGA vendor training covers the tool mechanics, not the governance layer. Compliance frameworks describe the control objective, not the operational procedure. This course builds the artefacts that sit between the tool and the framework and that auditors actually check.
FAQ
30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.