PAFTAK
[IAM]

Identity & Access Management — Consultancy & Architecture

Design and audit of identity programs — from access model to provisioning lifecycle — so the right people hold the right entitlements, and nothing else. We work top-down from the access model and bottom-up from what’s actually provisioned today, and reconcile the two.

  • RBAC / ABAC model design
  • SSO & federation (SAML, OIDC)
  • Joiner–mover–leaver lifecycle
  • Entitlement & access reviews
  1. 01
    Discover

    Inventory identities, entitlements, and where access decisions actually get made today.

  2. 02
    Design

    Model roles and policies against real job functions, not org-chart titles.

  3. 03
    Migrate

    Cut over provisioning and federation without a Monday-morning lockout.

  4. 04
    Operate

    Recurring access reviews and drift detection, not a one-time audit binder.

← Home · Read our insights · SSO federation cutover without a Monday-morning lockout · Why RBAC breaks down without a real job-function model · The joiner–mover–leaver problem nobody automates

[FAQ]

Frequently asked

What does PAFTAK's IAM engagement include?
RBAC/ABAC model design, SSO & federation (SAML, OIDC), the joiner-mover-leaver lifecycle, and entitlement & access reviews — delivered across four phases: Discover, Design, Migrate, and Operate.
Does PAFTAK support SAML and OIDC federation?
Yes — SSO & federation covering both SAML and OIDC is a core part of the IAM practice.
How does PAFTAK approach access model design?
We work top-down from the intended access model and bottom-up from what's actually provisioned today, then reconcile the two — modeling roles and policies against real job functions rather than org-chart titles.
Is PAFTAK based in Alberta?
Yes — PAFTAK Software Inc. is an Alberta, Canada consultancy taking enterprise engagements worldwide.