Skip to content

Identity Governance & Privileged Access

Identity & Access Management

Who has access? To what? On what grounds? Until when? Four simple questions most companies cannot answer without opening a spreadsheet.

Learn more
+200MCustomer identities under management
+60Certified engineers in Brazil
6th yearSailPoint Delivery Admiral running
+20 yearsWorking in identity

How SEK works

Four business problems, one integrated coverage.

Each discipline solves a concrete problem, with results measured in the programme.

“I don't know who has access to what in the company.”

Identity governance (IGA + IAM)

Automated lifecycle, access reviews, provisioning and revocation — SailPoint, Ping Identity. SOX and data-protection compliance built in.

“Our admin account was compromised and nobody saw it.”

Privileged access control (PAM)

Credential vault, just-in-time access, recorded and audited sessions. Removes shared passwords and standing access. CyberArk.

“Digital onboarding loses 30% of customers halfway through.”

Customer identity (CIAM)

Frictionless login, adaptive MFA, consent management and fraud prevention in the digital channel. Ping Identity, Entrust, OneSpan.

“Our AI agents have more access than any human.”

Machine and AI identity

Registration, authentication and auditing of APIs, services and AI agents. Decentralised identity (DID), SPIFFE and AuthZEN for dynamic authorisation.

What's included

Six identity fronts

IGA01Identity governanceRoles, certification and lifecycle
PAM02Privileged accessVault, sessions and high-risk credentials
IAM03Workforce access managementAuthentication and federation for employees
CIAM04Customer identityRegistration, consent and external login
NHI05Non-human and machine identityServices, scripts, bots and AI agents
ITDR06Identity threat detectionCredential-abuse signals and response

What changes in practice

Well-managed identity reduces risk, speeds up the operation and delivers audit evidence without stopping the company.

<1h

Access revocation on offboarding

Today it takes days or weeks. With automated provisioning, access disappears the moment HR records the exit — no manual tickets.

↓70%

Orphaned accounts in 12 months

Ownerless accounts are a way in. IGA with an automated lifecycle removes the build-up of access no manager ever reviewed.

↓80%

Time spent on access reviews

An access-review campaign that took weeks of manual email now runs in days, with evidence ready for audit.

+15%

Digital channel conversion

CIAM with frictionless login and adaptive authentication cuts drop-off at onboarding and checkout without giving up security.

↓Fraud

Account takeover in the customer channel

Adaptive MFA and behavioural analysis cut fraud attempts at login without affecting the legitimate customer's experience.

Hours

Privileged access auditing

Evidence of who accessed what, when and why, ready for SOX, data-protection rules and external auditors. No chasing logs.

Results observed in projects delivered by SEK. They vary by environment and scope.

Why SEK

From choosing the platform to running it day to day

01 Selection02 Implementation03 Support04 Maintenance05 Continuous improvement
Typical vendorCovers the stageCovers the stageDoes not coverStops hereDoes not coverDoes not cover
SEKCovers the stageCovers the stageCovers the stageCovers the stageCovers the stage
Covers the stageDoes not cover

Most vendors stop at the project. SEK covers the whole cycle with the same team, with reserved capacity to act immediately when something goes off plan.

Whoever implements is who operates afterwards, so knowledge of the environment isn't lost in the handover from project to day-to-day.

Strategic partners

Best of breed — the right technology for each use case.

Governance · IGA

The leading platform for enterprise identity governance. SEK has been a Delivery Admiral for six consecutive years, SailPoint's highest partnership tier.

Authentication · CIAM

Authentication and CIAM for workforce and customers. SEK is the only Delivery Approved Partner for IAM in all of Latin America.

Privileged access

Global leader in PAM. Password vaulting, just-in-time access and protection of administrative and service accounts against compromise.

MFA · Anti-fraud

Entrust · OneSpan

Advanced authentication, biometrics and fraud prevention for the digital channel and workforce. Open Banking, CIAM and banking environments.

How it works

From diagnosis to operation

01Diagnosis

Fast Resilience Assessment (FRA): 50 minutes to measure identity maturity and prioritise by risk, not by product.

02Design

Access model, roles and recertification rules, defined before the tool is chosen.

03Implementation

Integration with the chosen vendor, phased migration and knowledge transfer to the internal team.

04Operation

Periodic recertification, privileged access review and tracking of the identity indicator in Nautilus.

Next step

Start with the diagnosis

Fifty minutes with a specialist to assess where your identity programme stands and where to start.

Book an FRA session