Symptom
Leavers retain SaaS access for weeks
- Root cause
- No SCIM provisioning, manual offboarding tickets
- Business risk
- Insider threat, ISO 27001 A.5.16 finding
Identity Orchestration
Identity orchestration is a unified joiner-mover-leaver fabric across Entra ID, Okta, Active Directory, and SaaS, engineered for least privilege at enterprise scale. Evolvice designs and operates the fabric — from source-of-truth decisions to conditional access and quarterly recertification.
Overview
Identity is the new perimeter — and the most common audit finding in German enterprises. Sprawl across IdPs, manual access reviews and disconnected joiner-mover-leaver workflows leave standing privileges that no firewall can compensate for.
Diagnostic
Patterns we find when assessing existing identity estates.
Symptom
Symptom
Symptom
Symptom
Architecture
Single sign-on is table stakes. Orchestration is the discipline of routing every identity event — onboarding, role change, app entitlement, leaver — through a deterministic workflow with full audit trail.
We build that workflow with you, then operate it.
Definition
Identity orchestration is the practice of unifying identity providers, directories, HR systems and SaaS applications behind a single workflow engine that handles authentication, authorisation and lifecycle events with consistent policy and audit evidence.
Delivery model
A five-step engagement to lift identity into a real control plane.
Inventory of IdPs, directories, SaaS apps and existing access policies; entitlement-sprawl heatmap.
Choose the authoritative HR or directory source and design the SCIM/HRIS integration patterns.
Risk-based MFA, device compliance, and session controls implemented in Entra ID / Okta with phased roll-out.
Joiner-Mover-Leaver flows automated end-to-end, including SaaS provisioning and entitlement reviews.
Quarterly recertification owned by data owners, surfaced in their normal workflow tools — not a CSV email.
Compliance
How our delivery model maps to the four reference frameworks German enterprises are audited against.
| Control | ISO 27001 | NIS2 | BSI-Grundschutz | GDPR |
|---|---|---|---|---|
| Authentication | A.5.17 / A.8.5 | Art. 21(2)(i) | ORP.4.A.1 | Art. 32 |
| Authorisation | A.5.15 / A.5.18 | Art. 21(2)(i) | ORP.4.A.7 | Art. 32 |
| Joiner-Mover-Leaver | A.5.16 / A.6.5 | Art. 21(2)(i) | ORP.2 | Art. 5(1)(c) |
| Privileged Access | A.8.2 | Art. 21(2)(i) | ORP.4.A.18 | Art. 32(2) |
| Access Review | A.5.18 | Art. 21(2)(i) | ORP.4.A.20 | Art. 5(2) |
Questions & Answers
Definitions, delivery detail and commercial answers in one place — written to be quotable by search and AI answer engines, and readable by your team.
An identity provider authenticates users. Orchestration sits above one or more IdPs and routes lifecycle, authorisation and audit events deterministically — including across IdPs in M&A scenarios.
We start with a 30-minute diagnostic of your current delivery — at no cost and with no sales pitch. You leave with a written summary of findings either way.