Identity first
Centralise identity where practical, enforce MFA appropriate to risk and remove dormant identities quickly.
Open reference architecture
A practical identity-first control model for organisations whose business estate spans multiple SaaS platforms.
Centralise identity where practical, enforce MFA appropriate to risk and remove dormant identities quickly.
Use role-based access and time-bounded elevation; separate normal work from privileged administration.
Use device/session controls proportionate to sensitivity; reduce persistent sessions for privileged functions.
Maintain ownership, purpose, data classification, integrations, renewal and exit information for material services.
Review scopes and service accounts; revoke abandoned tokens and avoid broad delegated access.
Know what data enters each SaaS service, where exports exist and which subprocessors/regions materially affect risk.
Monitor meaningful authentication, privilege, sharing and integration events where the service exposes them.
Remove identity, sessions, tokens, shared access and data copies through a documented leaver/supplier-exit process.