Home / Continuous / Identity & Access

Identity & Access

Who can reach what, and whether the controls that decide it actually hold. This module tests your authenticated applications and APIs across every role, and the identity layer sitting behind them.

What it covers

Applications and APIs

  • Access control between roles, including horizontal and vertical privilege escalation
  • Business logic and workflow abuse, which is where automated tooling is weakest
  • Session handling, authentication flows and password reset paths
  • Injection and input handling across authenticated surfaces
  • API authorisation: object-level and function-level access control, and excessive data exposure

The identity layer

  • Single sign-on configuration and the trust relationships behind it
  • OAuth and OIDC flow handling, including redirect and token handling
  • SAML assertion handling and signature validation
  • MFA coverage: which accounts and which paths are not actually covered
  • Conditional access policy, and the gaps between what the policy says and what it enforces

How the work is carried out

A consultant directs this module and does the work that needs judgement, with automation carrying the continuous load between their passes. Your intervals are set during onboarding and recorded in the service agreement, because a schedule that suits one application would be wrong for a large, sprawling estate. What is fixed is the shape: a scheduled layer that runs the same checks on fixed intervals so change is visible, and an exploratory layer that a consultant directs based on what turns up. Reporting is monthly.

What the tooling handles

  • Keeps authenticated crawling and endpoint enumeration current as the application changes
  • Keeps coverage checks running across accounts, applications and policies
  • Flags candidate issues across every role, and new accounts or changed policy, for a consultant to pick up
  • Repeats constrained, non-destructive checks only

What our consultants do

  • Test the application by hand across every role, using the credentials you provide
  • Build the role model and work out what each role should and should not be able to do
  • Attempt bypass against the identity flows by hand, which needs judgement rather than pattern matching
  • Perform business-logic testing and chain findings into a real attack path
  • Assess which coverage gaps matter given who holds the account
  • Confirm every finding before it is reported

Every finding in this module is reproduced or confirmed by a consultant before it reaches you.

What you receive

  • Validated findings, each reproduced or confirmed by a consultant
  • A monthly written report, including what changed since the last one
  • Critical and high findings notified within one business day of validation
  • A current view of MFA and policy coverage across your identities
  • Re-testing after you ship significant changes
  • Verification of fixes once you have applied them

What is out of scope

  • Source code review. This module tests the running application, not the repository
  • Mobile application binaries, which are scoped as separate point-in-time work
  • Physical access control and building security
  • Social engineering of your users or your help desk, which is the People module
  • Large-scale password cracking or credential stuffing, which is blocked by default
  • Denial-of-service and load testing, including against your identity provider

Prerequisites

Nothing runs until these are in place. We pause rather than proceed against an unconfirmed register.

  • Credentials for each role we are asked to test, with a test account per role
  • Accounts we can safely manipulate, ideally in a non-production environment
  • Read access to the identity provider tenant, or a configuration export
  • API documentation or a request collection, where one exists
  • Signed authorisation from someone entitled to grant that access, and a confirmed asset register

Next module: Cloud