← Back to CV
Case Study — Identity & Access Governance

Building an Access-Governance Programme on Okta OIG

Interactive Investor · Infrastructure Architect · late 2025 – present

Context

As the infrastructure architecture remit at Interactive Investor matured, a gap opened up between the identity platform (Okta) and how access was actually governed for a regulated business unit: entitlements were assigned individually rather than through a role model, there was no repeatable way to certify who held what and why, and revoking access on a disconnected application meant a manual Service Desk ticket with no verification loop. That combination is a recurring audit finding waiting to happen — and it's exactly the kind of problem an infrastructure architect is well placed to fix, because it sits at the intersection of identity platform, ITSM process and the underlying application estate.

Technologies: Okta Identity Governance (OIG) · Okta Workflows · Okta Privileged Access · ServiceNow (ITSM integration) · SCIM 2.0

Approach

I took architectural ownership of the programme, working from a simple operating model: HR/ADP is the source of identity, ServiceNow carries access intent, and Okta Identity Governance (OIG) does the enforcement — provisioning connected applications directly, and raising a Service Desk fulfilment ticket for disconnected ones.

Related work in the same architecture remit

Two further pieces of work grew out of the same identity architecture ownership:

Outcome

Role-based
entitlement model, not raw permissions
Automated
revoke-to-ServiceNow with verification
3
architecture deliverables from one programme

The programme turned an ungoverned, individually-assigned access model into a certifiable, role-based one with a working enforcement loop back into ServiceNow — while producing two further architecture deliverables (the PAM assessment and the credential-recovery paper) that extended the same identity-governance thinking into adjacent risk areas.