domains
03 — coverage
Each domain has its own vocabulary, its own implementer market, and its own failure modes. The governance seat is identical: write the brief, qualify the implementer, frame the decisions, produce the record.
d.01 — identity
The programme that quietly underwrites everything else. IAM failures rarely show up as IAM failures; they show up as audit findings against systems downstream. Our role is to scope the target state honestly, validate the joiner-mover-leaver model the implementer is actually building, and ensure the access certifications survive contact with the business.
d.02 — privileged access
The domain where the implementer's deck and the operating reality diverge the most. We govern the onboarding sequence, the break-glass posture, and the session-recording policy — and we resist the temptation, which is considerable, to let coverage stand in for control.
d.03 — security operations
A SOC is judged twice: once by the dashboard at go-live, and once by the incident review eighteen months later. The two judgements are seldom the same. We govern the detection backlog, the runbook discipline, and the handover from build team to the people who will actually answer the pager.
d.04 — zero trust
A term that has been used to sell almost anything. We do not adjudicate the vocabulary; we govern the architecture decisions the programme will be asked to defend — policy decision points, identity-aware proxies, segmentation boundaries — and we make sure each decision is recorded with an honest cost.
d.05 — cloud posture
The posture is easy to measure and hard to govern. Findings multiply faster than they can be triaged, and the temptation is to optimise the dashboard rather than the underlying control. We govern the ownership model, the exception lifecycle, and the relationship between posture findings and the risk register the board actually reads.
d.06 — grc
The function most often asked to do governance work without governance authority. We help separate the three — the control framework, the risk position, and the compliance evidence — and we produce the artefact set that lets each of them stand on its own when examined.