With more than 25 years of experience and over 1,000 completed projects, we guide you through every step of your IAM implementation. Our proven methodologies - whether traditional or agile - ensure high-quality, sustainable results.
Implementing IAM Projects with Precision - From Strategy to Go-Live
1000+
25+
60+
Recommended Starting Point
Start With a Thorough Assessment
A solid implementation starts with a clear understanding of the current situation. Our assessments provide the foundation for technical decisions, migration planning, and solution design.
Project Approach
Classic | Waterfall
A Structured Approach to Your Goal
The classic process model is suitable for clearly defined requirements and regulated environments. Phases, milestones, and deliverables are clearly defined - the process is managed through disciplined project management with mandatory review gates.
- Initialization
- Architecture & Design
- High-Level Concept
- Detailed Concept
- Implementation
- Testing & Acceptance
- Deployment
- Transition
Agil | Iterativ
Adaptive and Iterative
For complex or changing requirements, we rely on agile methods. Short sprints deliver results that can be used early on and allow for ongoing adjustments. Note: Even in agile projects, not everything is always clear - the phases overlap and evolve dynamically.
- Sprint-based implementation
- Continuous stakeholder feedback
- Incremental delivery
- Retrospectives & adjustments
- Product backlog & prioritization
- Definition of Done & acceptance per sprint
Project Phases in Detail
The initialization phase lays the foundation for every successful IAM project. Project goals, scope, budget, and timeline are firmly established. All relevant stakeholders are involved early on, and roles and responsibilities are clearly defined.
A strong start to the project prevents costly corrections in later phases and creates the necessary transparency for everyone involved.
Key Activities
- Kick-off: Initial project meeting with all stakeholders; introduction of the team and the approach
- Goal Definition: Binding definition of project goals, scope, and success criteria
- Stakeholder Analysis: Identification of all stakeholders, expectation management, and communication plan
- Project Organization: RASCI matrix, escalation paths, and decision-making structures
- Planning: Project plan, milestones, resources, and budget baseline
- Risk Management: Initial risk analysis, mitigation measures, and early warning indicators
During this phase, we develop the technical and functional architecture of the IAM solution. We define the system structure, select appropriate technologies, and establish the security architecture.
The architecture and design decisions set the course for the entire project: scalability, security, integrability, and operational reliability are fundamentally determined at this stage.
Key Activities
- Current State Analysis: Assessment of existing systems, processes, interfaces, and vulnerabilities
- Technology Selection: Selection of identity provider, access control, directory services, and deployment model
- Architecture Design: Component diagrams, data flows, authentication architecture
- Security Framework: Encryption, MFA, privileged access controls, zero-trust principles
- Integration Architecture: Interfaces to HR, ERP, cloud services, and identity providers
- Scalability & Availability: High-availability concept, load balancing, cloud options
The high-level concept describes the solution at a general level: the overall architecture, key integration points, and overarching security requirements are documented and coordinated with the stakeholders.
It serves as a communication tool between the business unit, IT, and project management, and forms the basis for the subsequent detailed design.
Key Activities
- Overall Architecture: Overview of all system components and their interactions at the conceptual level
- Integration Points: Identification and prioritization of interfaces to source and target systems
- Security Requirements: Derived from regulatory requirements (DSG, GDPR, NIS2) and internal guidelines
- Process Overview: Joiner/Mover/Leaver processes, access request workflows, recertifications
- Stakeholder Review: Coordination and formal approval of the high-level concept
The detailed design transforms the high-level architecture into a complete specification ready for implementation. Role models, authorization structures, workflows, and all technical parameters are worked out in detail.
This document serves as the binding basis for implementation and also functions as a reference for acceptance testing and subsequent operational documentation.
Key Activities
- Role Model: Definition of all roles, permissions, exceptions, and segregation-of-duties rules
- Process Specification: Detailed description of all IAM processes, including exception and escalation scenarios
- Interface Specification: Technical description of all integration points, data formats, and protocols
- Data Model: Identity data, attributes, mappings, and transformation rules
- UI Specification: Screens, workflows, and user guidance for self-service portals and administrative interfaces
- Acceptance Criteria: Measurable criteria for the subsequent acceptance of the implementation
The implementation phase includes the development, configuration, and integration of the IAM system in accordance with the detailed design. Our team implements all specified requirements - from workflow configuration to the integration of source and target systems.
The goal is a fully configured, integrated, and internally tested system that is ready for formal acceptance.
Key Activities
- System Configuration: Setting up roles, permissions, workflows, and authentication mechanisms
- Development: Customizations, connectors, and interface implementations
- System Integration: Integration with HR, ERP, AD/LDAP, cloud services, and other target systems
- Federation & SSO: Configuration of SAML, OAuth 2.0, and OpenID Connect for cross-platform access
- Development Testing: Unit tests, integration tests, and technical quality assurance
- Monitoring Setup: Configuration of logging, alerting, and performance monitoring
The testing phase validates the implementation based on the acceptance criteria defined in the detailed design. In addition to functional tests, security, performance, and user acceptance tests are conducted.
During the pilot phase, the solution is tested with a controlled group of users in the production environment before the full rollout takes place.
Key Activities
- Functional Testing: Systematic testing of all use cases based on the test cases from the detailed design
- Security Testing: Penetration testing, authorization analysis, and vulnerability assessment
- Performance Testing: Load testing, stress testing, and availability testing
- User Acceptance Testing (UAT): Acceptance testing by the business unit and key users based on real-world scenarios
- Pilot Operation: Controlled operation with a selected user group, feedback evaluation
- Formal Acceptance: Documented approval by the client as the basis for the rollout
The implementation phase brings the IAM solution into production. A well-thought-out rollout plan, accompanying training sessions, and targeted change management ensure acceptance and a smooth go-live.
IPG actively supports the rollout - from the communication strategy and end-user training to providing support during the first days of production.
Key Activities
- Rollout Planning: Phased rollout by user groups, regions, or systems
- Training: User, administrator, and key user training on the new solution
- Change Management: Communication strategy, stakeholder updates, resistance management
- Go-Live Support: Intensive support during the first days of production
- Help Desk Enablement: Briefing of the support team, FAQs, and operations manual
- Hypercare: Increased level of support during the ramp-up phase following go-live
Transition refers to the structured shift from the project phase to stable operation. Knowledge, processes, and responsibilities are handed over seamlessly - whether to the customer’s operations or to IPG’s operations.
The handover is carried out in accordance with a binding transition protocol. In addition, an early-life-support phase is defined to ensure enhanced support during the initial operational phase.
Key Activities
- Operational Documentation: Complete technical and procedural documentation of the solution
- Knowledge Transfer: Handover meetings, training of the operations team, knowledge base
- Onboarding Checklist: Structured completion of all operational handover items
- Monitoring Setup: Configuration of monitoring, alerting, and dashboards for routine operations
- Early-Life Support: Defined support phase with reduced response times following go-live
- Transition Protocol: Formal documentation of the handover, signed by both parties
Integration Skills
Provisioning & Deprovisioning
Single Sign-On (SSO)
Multi-Factor Authentication
Identity Federation
ERP & HR Integration
Monitoring & Compliance Logging
Subsequent Operating Performance
Transition
A structured transition from the project phase to stable operations - with an onboarding checklist, early-life support, and a transition protocol.
Operational Support
Ongoing operation of your IAM application by the IPG Operation Center - with defined SLAs, a service manager, and proactive monitoring.
Managed Services
Complete outsourcing of IAM operations - monthly, measurable, and customized. Includes Premium SLA, disaster recovery, and a dedicated service manager.
Ready for Your Next IAM Project?
Over 1,000 completed projects speak for themselves. Contact us for a no-obligation assessment of your project - we’ll find the right approach for your situation.