Identity & Security
Identity is not login plumbing. It is who may see and do what — including agents.
Programmes start as a protocol upgrade and stall as an application-estate problem. Then GenAI reads from knowledge bases with the same coarse permissions as a search box.
[01 Constraint]
The binding constraint is rarely “pick Auth0 or Okta”. It is whether access is designed across apps, channels, and AI retrieval.
A useful filter: if this user — or this agent — asked the system for an answer, could you prove what they were allowed to see, and that the UX still converted? Tool-agnostic unless the engagement is a named platform.
Legacy apps cannot take modern protocols without real change
An IdP or protocol upgrade is an application-estate problem. Treating it as configuration work is why programmes stall.
Adaptive MFA versus conversion
Device signals and step-up done badly kill conversion. Security theatre that ignores UX is still a commercial failure.
Cloud and DevOps IdP integration without an owner
AWS, Azure, hybrid, and CI/CD all grow identity surface. Cost, scale, and compliance need an owner — not another undocumented integration.
Commercial IdP cost when sizing is wrong
TCO matters. Usage and tenancy design decide whether the platform is sustainable, not the logo on the contract.
AI retrieval without fine-grained authorisation
GenAI over internal knowledge with search-box permissions becomes a leak and a compliance incident. Non-human and agent access is the same problem, not a side quest.
[02 Approach]
CIAM sits next to IGA, PAM, and everyday access — not in a silo.
Customer identity has to balance control with experience: conversion, audit, TCO, and — increasingly — what an agent may retrieve. We stay technology-agnostic unless you already run a named platform. Partnerships are optional enablers.
Current state and outcomes first
Conversion, engagement, audit, and regulatory context (including APRA where it applies) before protocol or vendor selection.
Adaptive security without UX theatre
Step-up and device signals should protect the session without destroying the journey. Maturity reviews baseline usability alongside security and cost.
Permissions on the retrieval path
Auth for AI is fine-grained authorisation for generated answers — users and later agents — with an audit trail of what the model was allowed to see.
[03 Offerings]
Identity and security work labelled by type: consulting, delivery, managed, or training.
Each offering answers a specific failure mode. We do not offer a SOC. DevSecOps here is security-in-delivery; Digital & Cloud owns the platform product.
Security versus UX versus conversion versus cost across the application estate — not just enabling logins.
A shared baseline of security, usability, cost, and readiness for modern authentication before modernisation.
Fine-grained authorisation on the retrieval path so generated answers only include what the caller may see.
Operate and improve an IAM environment when identity is a function to run, not a one-off project.
Named-platform diagnostic when the estate already runs Auth0 — health, configuration, cost, and security.
Security as a paved road in the SDLC — analysis, scanning, policy, compliance — without making delivery impossible.
Hands-on secure coding, threat modelling, and identity practices — culture and skill, not a slide pack.
[04 How we start]
How engagements typically begin.
Current-state and outcomes before tools. Most work starts with conversion, TCO, audit, or “what may this agent see?”
01
Name the commercial constraint
Conversion friction, IdP cost, regulatory exposure, or AI retrieval risk — pick the scoreboard before the protocol.
02
Baseline or Auth-for-AI diagnostic
Maturity across security, usability, and cost — or a retrieval-path assessment when GenAI is already in front of users.
03
Strategy, delivery, or operate
Estate strategy, a named-platform review, implementation, or managed identity — whichever matches the constraint. Existing clients keep their methodology.
AIVD’s security pillar is how delivery is run. This page is the identity and security practice. Auth for AI is the permission layer Data & AI work depends on — we cross-link, we do not re-home it.
[05 Contact]
Got an identity or access constraint?
Let's talk.
Level 3, 162 Collins StreetMelbourne VIC 3000
Australia
Tell us about your challenge
We'll get back to you within one business day.
© 2026 Kodez Pty Ltd. All rights reserved.
© 2026 Kodez Pty Ltd. All rights reserved.