An independent architect’s view of your identity platform, and a target-state design you can put through governance. For organisations running ForgeRock or Ping, Okta, or Microsoft Entra ID who are planning a migration, a major upgrade, or who simply want to know whether the platform is doing what it should.
Two ways to engage
Platform Review (two weeks). A structured health check of your current IAM or CIAM platform: architecture, integration patterns, authentication journeys, federation, privileged access, resilience, operational readiness and technical debt. You get a prioritised findings report and a roadmap, written for both the CISO and the engineers who run the platform.
Migration Design (four to eight weeks, scoped to your estate). The target-state architecture and transition plan for moving from a legacy platform to a modern one, for example on-premise ForgeRock AM to Ping Advanced Identity Cloud, a legacy directory to Okta, or a fragmented estate onto Entra ID. Includes discovery of what maps and what doesn’t, identity and credential migration strategy, coexistence and cutover approach, non-functional requirements, and the design authority pack.
Who it’s for
Heads of identity, security architects and platform owners at organisations with member- or customer-scale identity estates, where a failed migration is a front-page problem and the vendor’s proposal needs a second opinion from someone who has done it.
What you get
1. Discovery and inventory. Journeys, custom modules and scripts, policies, OAuth and SAML integrations, session and token behaviour, and the integrations nobody documented.
2. Target-state architecture. Patterns for authentication, federation, self-service, MFA and passwordless, privileged access and non-human identity, aligned to Zero Trust and your regulatory context (FCA, GDPR, Open Banking, PSD2 where relevant).
3. Migration strategy. Bulk versus just-in-time credential migration, coexistence period, routing by application or cohort, rollback criteria, and how sessions behave across the boundary.
4. Non-functional and resilience review. Performance at peak, availability targets, DR, logging and monitoring, with particular attention to what changes when you move to a SaaS platform.
5. Governance pack. Design authority material, decision records, risks with owners, and a phased plan your delivery team or the vendor’s can execute.
Platforms
Ping Identity and ForgeRock (AM, IDM, DS, IG, Advanced Identity Cloud), Okta (Workforce and Customer Identity, Auth0), Microsoft Entra ID (including B2B, B2C and External ID), and cloud IAM on AWS, Azure and GCP.
Why United Kloud
Shailesh Kejadiwal has led the target-state design and migration architecture for a 10-million-member building society moving from a legacy platform to ForgeRock Identity Cloud on AWS, designed Okta-to-Auth0 migration patterns for a global share registrar, delivered Ping and ForgeRock platforms for HSBC and NatWest, and consolidated customer identity across the Virgin Media O2 digital channels. He has worked as a delivery partner to both Ping Identity and Okta, so he knows what the vendors’ proposals leave out.
Planning a migration, or unsure whether you need one?Book a 30-minute scoping call. Bring the vendor’s proposal if you have one; a second pair of eyes costs nothing at this stage.