Maturity Level Assessment
Evaluate your current IAM capabilities across governance, access requests, lifecycle events, role management, and privileged access to establish a practical maturity baseline.
Understand the five levels of IAM maturity and evaluate how prepared your organization is for stronger identity governance, access management, and privileged access programs. This guide explains the capabilities, risks, and requirements associated with each stage, helping identity leaders identify gaps, prioritize improvements, and build a practical roadmap toward more consistent, traceable, and implementation-ready identity operations.

Assess identity capabilities, uncover requirements gaps, and create a clearer foundation for IAM, IGA, and PAM improvement initiatives.
Evaluate your current IAM capabilities across governance, access requests, lifecycle events, role management, and privileged access to establish a practical maturity baseline.
Gather clear stakeholder input about access, approvals, provisioning, certification, and removal requirements through guided, asynchronous conversations instead of fragmented workshops.
Identify missing, conflicting, or incomplete identity requirements across stakeholders so unresolved issues can be prioritized before implementation, testing, or platform configuration.
Translate validated stakeholder responses into structured, traceable requirements documentation that can support design, implementation, acceptance, and ongoing governance.
Create reusable questionnaires and repeatable discovery practices that help consulting and identity teams deliver more consistent IAM, IGA, and PAM engagements.
Use conversational guidance and cross-stakeholder analytics to clarify terminology, surface contradictions, and build shared understanding of identity decisions.
IAM maturity is measured by more than the presence of an identity platform. It depends on whether your organization can define access consistently, assign accountability, manage lifecycle events, govern privileged access, and prove decisions through traceable requirements. Identity CoAnalyst helps teams gather the information needed to understand their current state, expose contradictions, and create implementation-ready documentation for the next stage of maturity.

Purpose-built capabilities help identity teams assess readiness with more structure, consistency, and traceability.
Built specifically for identity governance, access management, and privileged access requirements work.
Replace scattered interviews and spreadsheets with guided conversations that organize stakeholder input consistently.
Surface contradictions and gaps across stakeholder responses before they create downstream implementation problems.
Create documented requirements that connect stakeholder decisions to design, testing, acceptance, and governance.
Built from deep enterprise implementation experience and practical identity delivery challenges.

Senior IGA Consultant, Commercium Technology Inc (CTI)
Edward Thompson is a Senior IGA Consultant at Commercium Technology Inc (CTI) with 6+ years of highly focused experience on SailPoint's Identity Security Cloud (ISC) solution, holding formal SailPoint certification at the highest level (Engineer). His proficiency spans ISC solution architecture and best-practice methodologies for Identity Governance & Administration, and he excels at architecting, implementing and integrating solutions in expansive retail, healthcare and financial environments with robust RBAC and lifecycle management — working well within a team or as the primary consultant. Selected twice by SailPoint as a presenter at Developer Days 2024 and 2025 as an Expert Ambassador in the SailPoint technical community, Edward has been chosen by SailPoint for engagements including a hospital's IdentityIQ-to-ISC migration, Epic EMP/SER integration governing clinical and non-clinical access at Bryan Health, application onboarding and workflow-driven certification delegation at Boeing, and a custom Paycom HR connector for State Department Federal Credit Union. Earlier, as a principal SailPoint consultant, he led Sunbelt Rentals' migration from Microsoft Identity Manager to IdentityNow with a 1,400-role RBAC model for 30,000+ users and built a custom SaaS connector bridging MuleSoft and AS400 RentalMan. His integration experience covers Active Directory, Entra ID, Workday, PeopleSoft, Salesforce, Paycom, ServiceNow and Epic, and he holds a BS in Computer Science from Western Washington University.

Solution Architect, Commercium Technology Inc (CTI)
Jason Burt is a Solution Architect at Commercium Technology Inc (CTI) with more than 20 years of IT experience across the design, implementation, customization, integration, operation and administration of enterprise security solutions, and exceptionally deep SailPoint and IGA development skills. As a solution architect with SailPoint Professional Services, he has delivered implementations for major North American customers across insurance, finance, banking, government, higher education, healthcare, resource extraction and manufacturing, while also owning expert-services engagements that call for performance tuning and expert-level debugging of undocumented product behavior. Jay was lead architect on the replacement of a legacy Garancy access management platform with SailPoint at Highmark Blue Cross, delivered two years of bi-monthly milestone releases on the CNA Insurance projects team spanning password management, application onboarding, UI customization, certifications, workflows and provisioning, and architected a multi-campus identity lifecycle solution for 200,000+ users at the University of Nebraska. His hands-on work centers on Java-based custom and web-services connectors, IdentityIQ plugins, rules and workflows. Jay holds SailPoint Solution Architect, IdentityNow Engineer and Identity Security Cloud Expert certifications, and earned a BS in Interdisciplinary Science and a BA in Business Administration from Portland State University.

Senior SailPoint / IAM Architect, Commercium Technology Inc (CTI)
Mehul Chavda is a Senior Identity and Access Management architect at Commercium Technology Inc (CTI) with more than 18 years of IT experience, including 8+ years of deep, senior-level specialization in SailPoint-based identity management. He has a proven record of designing and implementing enterprise-scale IAM solutions with SailPoint IdentityIQ (IIQ), Identity Security Cloud (ISC), Okta and Oracle Identity Manager across the government, healthcare, banking and manufacturing sectors. Mehul's expertise spans user lifecycle management (joiner/mover/leaver), RBAC and birthright role frameworks, access certification, workflow automation and cross-platform integration — translating complex business requirements into secure, scalable identity solutions. As a Sr. SailPoint Architect with SailPoint Professional Services he architected a comprehensive ISC–ServiceNow integration across three workstreams (governance connector, service desk fulfillment for disconnected applications, and Service Catalog as a unified access request front end), upgraded IdentityIQ from 8.0 to 8.3 with the Accelerator Pack, integrated CyberArk via SCIM for privileged account management, and built Azure DevOps and Git pipelines for environment code migration. His earlier architect roles at CLS International Bank, SUPERVALU, John Wiley & Sons and New York City Health + Hospitals included Okta and AWS MFA rollouts, SAML SSO for 30+ applications, Epic EHR (EMP/SER) integration via custom web services, and a high-availability Oracle Identity Manager 11g R2 deployment. Mehul is a Certified SailPoint ISC Engineer and ISC Professional, and a Certified SailPoint IdentityIQ Solution Architect and Associate.

SailPoint Identity Security Cloud Tech Lead, Commercium Technology Inc (CTI)
Steven Hall is a SailPoint Identity Security Cloud (ISC) project tech lead at Commercium Technology Inc (CTI) with over 20 years of identity-security-focused experience and formal SailPoint ISC certification. Steve's strength is the full arc of a program: requirements discovery and definition, architecture, hands-on implementation, and integration within large and complex financial, pharmaceutical and healthcare environments. He has a particular interest in helping hospitals gain efficiency and cost savings by integrating SailPoint ISC with medical information systems such as Epic — work reflected in his role leading the SailPoint IdentityNow deployment at Temple University Hospital, where he implemented the Epic SER, Active Directory, ServiceNow and Azure connectors and replaced manual processes with role-driven automation. He currently leads the Montgomery County Government ISC program, integrating Oracle HRMS, Oracle EBS, Active Directory and SQL Server to support joiner/mover/leaver provisioning, access certification and access requests, and mentors less senior developers on ISC transforms, workflows and connector rules. Steve previously led the State Department Federal Credit Union's ISC migration from ADP to Paycom-HR with near-zero business disruption. Across his career he has worked with large-scale LDAP directory services, meta and virtual directories, data synchronization, password management, account provisioning and group management, and brings very strong Microsoft skills spanning Windows, Active Directory, Azure and PowerShell.
The five levels describe a progression from fragmented and reactive identity practices toward governed, measured, and continuously improved operations. Early levels typically rely on manual processes, inconsistent ownership, and limited visibility. More mature organizations establish repeatable lifecycle management, access governance, privileged access controls, traceable requirements, and ongoing measurement. The exact characteristics should be assessed against your organization’s people, processes, technology, and governance model.
Talk with the Identity CoAnalyst team about structuring your readiness assessment.
Identity CoAnalyst is generally available and running on live client engagements.
More than 500 practitioner-written questions across 11 identity domains.
Designed to support requirements work upstream of identity platform implementation.
Share your assessment goals and discuss how structured discovery can support your next identity initiative.
For immediate assistance, feel free to give us a direct call at 732 673 4260. You can also send us a quick email at bill.leonard@cticorp.com.
For immediate assistance, feel free to give us a direct call at 732 673 4260. You can also send us a quick email at bill.leonard@cticorp.com.