Skip to main content

Identity & Security

Identity is not login plumbing. It is who may see and do what — including agents.

Programmes start as a protocol upgrade and stall as an application-estate problem. Then GenAI reads from knowledge bases with the same coarse permissions as a search box.

[01 Constraint]

The binding constraint is rarely “pick Auth0 or Okta”. It is whether access is designed across apps, channels, and AI retrieval.

A useful filter: if this user — or this agent — asked the system for an answer, could you prove what they were allowed to see, and that the UX still converted? Tool-agnostic unless the engagement is a named platform.

  • Legacy apps cannot take modern protocols without real change

    An IdP or protocol upgrade is an application-estate problem. Treating it as configuration work is why programmes stall.

  • Adaptive MFA versus conversion

    Device signals and step-up done badly kill conversion. Security theatre that ignores UX is still a commercial failure.

  • Cloud and DevOps IdP integration without an owner

    AWS, Azure, hybrid, and CI/CD all grow identity surface. Cost, scale, and compliance need an owner — not another undocumented integration.

  • Commercial IdP cost when sizing is wrong

    TCO matters. Usage and tenancy design decide whether the platform is sustainable, not the logo on the contract.

  • AI retrieval without fine-grained authorisation

    GenAI over internal knowledge with search-box permissions becomes a leak and a compliance incident. Non-human and agent access is the same problem, not a side quest.

[02 Approach]

CIAM sits next to IGA, PAM, and everyday access — not in a silo.

Customer identity has to balance control with experience: conversion, audit, TCO, and — increasingly — what an agent may retrieve. We stay technology-agnostic unless you already run a named platform. Partnerships are optional enablers.

Current state and outcomes first

Conversion, engagement, audit, and regulatory context (including APRA where it applies) before protocol or vendor selection.

Adaptive security without UX theatre

Step-up and device signals should protect the session without destroying the journey. Maturity reviews baseline usability alongside security and cost.

Permissions on the retrieval path

Auth for AI is fine-grained authorisation for generated answers — users and later agents — with an audit trail of what the model was allowed to see.

[03 Offerings]

Identity and security work labelled by type: consulting, delivery, managed, or training.

Each offering answers a specific failure mode. We do not offer a SOC. DevSecOps here is security-in-delivery; Digital & Cloud owns the platform product.

Security versus UX versus conversion versus cost across the application estate — not just enabling logins.

A shared baseline of security, usability, cost, and readiness for modern authentication before modernisation.

Fine-grained authorisation on the retrieval path so generated answers only include what the caller may see.

Operate and improve an IAM environment when identity is a function to run, not a one-off project.

Named-platform diagnostic when the estate already runs Auth0 — health, configuration, cost, and security.

Security as a paved road in the SDLC — analysis, scanning, policy, compliance — without making delivery impossible.

Hands-on secure coding, threat modelling, and identity practices — culture and skill, not a slide pack.

[04 How we start]

How engagements typically begin.

Current-state and outcomes before tools. Most work starts with conversion, TCO, audit, or “what may this agent see?”

  1. 01

    Name the commercial constraint

    Conversion friction, IdP cost, regulatory exposure, or AI retrieval risk — pick the scoreboard before the protocol.

  2. 02

    Baseline or Auth-for-AI diagnostic

    Maturity across security, usability, and cost — or a retrieval-path assessment when GenAI is already in front of users.

  3. 03

    Strategy, delivery, or operate

    Estate strategy, a named-platform review, implementation, or managed identity — whichever matches the constraint. Existing clients keep their methodology.

AIVD’s security pillar is how delivery is run. This page is the identity and security practice. Auth for AI is the permission layer Data & AI work depends on — we cross-link, we do not re-home it.

[05 Contact]

Got an identity or access constraint?
Let's talk.

Level 3, 162 Collins Street
Melbourne VIC 3000
Australia

Tell us about your challenge

We'll get back to you within one business day.

By submitting, you agree to our Privacy Policy.

© 2026 Kodez Pty Ltd. All rights reserved.