Skip to main content

Identity & Security

Identity is not login plumbing. It is who may see and do what — including agents.

Programmes start as a protocol upgrade and stall as an application-estate problem. Then GenAI reads from knowledge bases with the same coarse permissions as a search box.

Ecosystem map

Contemporary needs sit at the centre. Our offerings meet them at the edge.

Organisations already run CIAM, workforce access, PAM, pipelines, and — increasingly — agents. The binding question is who may see and do what. Kodez work maps onto that ecosystem as entry points.

If this user — or this agent — asked for an answer, could you prove what they were allowed to see?

[01 Constraint]

The binding constraint is rarely “pick Auth0 or Okta”. It is whether access is designed across apps, channels, and AI retrieval.

A useful filter: if this user — or this agent — asked the system for an answer, could you prove what they were allowed to see, and that the UX still converted? Tool-agnostic unless the engagement is a named platform.

  • Legacy apps cannot take modern protocols without real change

    An IdP or protocol upgrade is an application-estate problem. Treating it as configuration work is why programmes stall.

  • Adaptive MFA versus conversion

    Device signals and step-up done badly kill conversion. Security theatre that ignores UX is still a commercial failure.

  • Cloud and DevOps IdP integration without an owner

    AWS, Azure, hybrid, and CI/CD all grow identity surface. Cost, scale, and compliance need an owner — not another undocumented integration.

  • Commercial IdP cost when sizing is wrong

    TCO matters. Usage and tenancy design decide whether the platform is sustainable, not the logo on the contract.

  • AI retrieval without fine-grained authorisation

    GenAI over internal knowledge with search-box permissions becomes a leak and a compliance incident. Non-human and agent access is the same problem, not a side quest.

[02 Approach]

CIAM sits next to IGA, PAM, and everyday access — not in a silo.

Customer identity has to balance control with experience: conversion, audit, TCO, and — increasingly — what an agent may retrieve. We stay technology-agnostic unless you already run a named platform. When you do, certified depth on that platform is the next question.

Current state and outcomes first

Conversion, engagement, audit, and regulatory context (including APRA where it applies) before protocol or vendor selection.

Adaptive security without UX theatre

Step-up and device signals should protect the session without destroying the journey. Maturity reviews baseline usability alongside security and cost.

Permissions on the retrieval path

Auth for AI is fine-grained authorisation for generated answers — users and later agents — with an audit trail of what the model was allowed to see.

[03 Partnership]

Partnerships are optional enablers. Okta’s primary certified partner in APAC.

Enterprise buyers already know Okta and Auth0. The question is whether the delivery partner has been certified at that depth — and whether they still design identity across the rest of the estate. When Customer Identity Cloud is already in production, Kodez is the partner Okta certified in this region for conversion, tenancy, and authorisation, including agents. It is not a licence pitch, and it is not a claim that every identity programme starts here.

Okta Customer Identity Cloud

Primary certified partner

Asia Pacific

Auth0 is an example estate we operate and review because many of you already run it. It is not the identity catalogue.

Kodez
Okta
Auth0

Convert without killing the session

A clunky login is a growth problem. Adaptive MFA, passwordless, and threat signals have to protect the journey without becoming theatre. We implement that trade-off on the tenancy you already run.

Enterprise connections without a rebuild

SSO, federation, and organisations are how B2B and workforce identity actually land. Legacy apps still cannot take modern protocols without real change. Named-platform depth has to meet IGA, PAM, and the IdPs you already have.

Users, machines, and agents on one permission question

Fine-grained authorisation on the retrieval path so generated answers only include what the caller may see. Auth0 FGA is one mechanism we have used. The constraint is unchanged.

If the estate is not Okta or Auth0, we still start with current state and outcomes. CIAM sits next to IGA, PAM, and everyday access — not in a silo.

[04 Offerings]

Identity and security work labelled by type: consulting, delivery, managed, or training.

Each offering answers a specific failure mode — including named-platform work when the estate already chose Auth0. We do not offer a SOC. DevSecOps here is security-in-delivery; Digital & Cloud owns the platform product.

Security versus UX versus conversion versus cost across the application estate — not just enabling logins.

A shared baseline of security, usability, cost, and readiness for modern authentication before modernisation.

Fine-grained authorisation on the retrieval path so generated answers only include what the caller may see.

Operate and improve an IAM environment when identity is a function to run, not a one-off project.

Named-platform diagnostic when the estate already runs Auth0 — health, configuration, cost, and security.

Security as a paved road in the SDLC — analysis, scanning, policy, compliance — without making delivery impossible.

Hands-on secure coding, threat modelling, and identity practices — culture and skill, not a slide pack.

[05 How we start]

How engagements typically begin.

Current-state and outcomes before tools. Most work starts with conversion, TCO, audit, or “what may this agent see?”

  1. 01

    Name the commercial constraint

    Conversion friction, IdP cost, regulatory exposure, or AI retrieval risk — pick the scoreboard before the protocol.

  2. 02

    Baseline or Auth-for-AI diagnostic

    Maturity across security, usability, and cost — or a retrieval-path assessment when GenAI is already in front of users.

  3. 03

    Strategy, delivery, or operate

    Estate strategy, a named-platform review, implementation, or managed identity — whichever matches the constraint. Existing clients keep their methodology.

AIVD’s security pillar is how delivery is run. This page is the identity and security practice. Auth for AI is the permission layer Data & Analytics work depends on — we cross-link, we do not re-home it.

[10 Contact]

We'd love to hear from you.

Let's connect.

Level 3, 162 Collins Street
Melbourne VIC 3000
Australia

How can we help?

We'll get back to you within one business day.

By submitting, you agree to our Privacy Policy.

© 2026 Kodez Pty Ltd. All rights reserved.