Our point of view

Most IAM consulting stops where the real work starts.

We've watched too many engagements deliver a 90-page strategy and a Visio architecture — then leave the client to figure out how to actually run the program. Our work begins where most engagements end: at the boundary between policy and operating system.

Splunk-native, not Splunk-adjacent

We write the SPL. We build the data models. We design the dashboards your SOC and your auditor both use. No middleware shims, no "we sent the data and called it done." If it doesn't show up in CIM, it doesn't count.

APEX portals that ship to production

Our remediation engines aren't wireframes — they're PL/SQL packages, role-aware UIs, real workflows running against your CMDB. When auditors ask "where's the evidence?" we point at a URL.

Metrics tied to business goals

Tanium-vs-evidence reconciliation. Disposition velocity. Backlog burn-down. Coverage gaps by application. We measure the things both auditors and execs ask about — and put them on the same page.

Engagement model

Four phases. Real artifacts at every gate.

No "discovery deliverable" that's actually just notes. Every phase produces something operational that survives the engagement.

01

Diagnose — 2 to 4 weeks

Control mapping. Data inventory. Stakeholder interviews. We surface what's logged, what's missing, and what the auditor will fail you on. Output: gap analysis, risk register, and a roadmap with effort estimates — none of which gets thrown away in phase two.

02

Design — 2 to 4 weeks

Log standards by application. Eventtype/tag taxonomy. Lookup model. Workflow flows for remediation. Wireframes for portals and dashboards. Acceptance criteria written in language your engineers can build to and your auditors can read.

03

Build — 6 to 12 weeks

This is where most consultancies hand off. Not us. We build the Splunk dashboards, write the APEX portals, configure the Cribl pipelines, ship the lookups. Code, dashboards, and runbooks land in your repo and your environment.

04

Operate & transfer — 4 to 8 weeks

We run it with you, then run it less while you run it more. Knowledge transfer is structured: paired engineering, training sessions, runbooks, and on-call shadowing. We leave behind a team that owns it — not a dependency on us.

Proof, not promises

What you actually walk away with

Three representative artifacts from real engagements. Names changed; structures real.

A live HPA monitoring dashboard, normalized to CIM, with anomaly classification and drill-through to underlying events.

Sessions / 24h
3,418
Anomalies
12
Avg. session
7m 14s
CIM coverage
98.4%
ActorAssetActionAnomaly
m.alvarezWIN-FIN-DB-04Privilege UseNone
j.patelRHEL-PRD-12Sudo EscalateOff-hours
svc_etlWIN-DATA-01LoginNone
r.okaforAZURE-K8S-PRDRole BindNew asset

The Windows local non-admin remediation engine. Pulls from Tanium + AD + CMDB, recommends a disposition with confidence and a reason.

Hosts
8,402
Local accts
10,217
Auto-actionable
82%
In review
38
AccountLast logonRecommendationReason
tmpadmin312 daysRemoveStale, no owner
svc_backup_l12 hrsVaultService account
local_helpdesk14 daysDisableReplaced by AD group
vendor_smith5 daysInvestigateUnexpected priv group

Reconciliation between Tanium endpoint truth and the evidence/audit dataset. The deltas are the real story.

Tanium
10,217
Evidence
10,041
Δ
176
Reconciled
98.3%
CategoryTaniumEvidenceDelta
Service accounts4,1284,1280
Vendor accounts1,9021,884−18
Local admins3183180
Stale (>90d)1,4471,289−158
Disabled2,4222,4220
Working principles

How we behave on engagements

P · 01

Auditor-defensible by default

Every artifact we ship can answer "who, what, when, why, signature" without us standing next to it. If it can't, it isn't done.

P · 02

Show the work

Daily standups, weekly demos, source in your repo. No black-box deliverables and no mid-engagement surprises.

P · 03

Build for the operator

Help-desk-friendly portals. Auditor-readable dashboards. Engineer-extensible code. The first user you should optimize for is the person who'll run this in year two.

P · 04

AI as a copilot, not a pilot

LLMs accelerate review and triage. They don't make irreversible identity decisions. Human approval lives between recommendation and action.

P · 05

Compliance language matters

Code that's self-explanatory to engineers. Documentation that holds up to legal review. Evidence narrative that's audit-ready in the first cycle, not the third.

P · 06

Leave a team, not a dependency

We're not a managed service. We design every engagement to end with your engineers running what we built — confidently, without us.

Engagement

Want to see the actual artifacts?

We'll walk you through anonymized dashboards, portals, and metrics from past engagements — and how the same patterns would apply to yours.