Cláudio Gonçalves
← Back to Expertise

Identity & Access Management

From Active Directory hygiene to federated, attribute-based identity as the new security perimeter.

Identity work started as a foundational IT responsibility: keeping Active Directory clean, resetting locked-out accounts, retiring stale devices. It grew into one of the most strategic domains in the whole practice. By 2021 I was authoring the organization's identity-management Service Level Agreement; by 2025 identity had become the backbone for every digital service the organization wanted to build.

What this looks like in practice

  • Directory services architecture: AD structure, OU hygiene, replication health
  • Logical grouping treated as governance rather than tidiness
  • Certificate lifecycle management and authentication hardening (ADFS, TLS, SSO)
  • Privileged-account controls and least-privilege enforcement
  • Identity governance frameworks: SLAs, RACI matrices, support-model definitions
  • Federated and attribute-based access across hybrid cloud and on-premise platforms
  • Identity risk scoring and identity-lifecycle automation

Why it matters

Every system depends on knowing, reliably, who someone is and what they are allowed to do. As the platform landscape expanded to take in SAP, Documentum, IoT, and cloud collaboration tools, identity stopped being a background system and became the thing that decides whether any of the other integrations can be trusted.


Where this shows up in the journey