The engineering behind our products

Alongside our own products, we design and build enterprise systems where identity, controls and audit evidence have to hold up in production. Everything here is work we have shipped.

Enterprise platforms

Multi-tenant software and control layers for organisations that need strong governance, identity fidelity and long-term reliability. Permissions, auditability and integration boundaries are architecture decisions from day one, not post-launch fixes.

Cinturon360, our flagship platform, is this model in production. cinturon360.com ↗

  • Multi-tenant architecture with strict tenant isolation
  • Entra ID integration and delegated administration
  • Role and permission models for complex organisations
  • Audit and event evidence for compliance-heavy operations
  • Subscription and entitlement logic for SaaS products
  • API boundaries for ERP, HR and ITSM systems

Cloud tooling and governance

Practical tooling for teams that need operational visibility and control across cloud accounts, teams and providers, connected to the identity, service desk and finance processes they already run.

  • Cloud cost governance and FinOps visibility
  • Infrastructure automation that retires manual runbooks
  • Certificate and expiry-risk tracking
  • Cross-cloud operational dashboards for Azure and AWS
  • Remediation workflows with clear ownership
  • Integration with Microsoft and ITSM platforms

Microsoft 365 identity

Manual identity administration turned into governed automation, so access, licensing and lifecycle changes stay accurate at scale and leave a clean audit trail.

  • Onboarding and offboarding orchestration
  • Entra ID policy and role governance
  • Licence assignment and reclamation
  • Mailbox and group access with approvals
  • Integration with HR and ITSM data sources
  • Audit-grade reporting and exception handling

PowerShell delivery

Production PowerShell that removes repetitive work without giving up supportability. Modules are idempotent, logged, tested where practical, and documented so they never depend on one person.

  • Identity and access automation modules
  • Approval-aware workflow orchestration
  • Operational reporting and evidence pipelines
  • Service management and remediation scripts
  • Glue between legacy and modern systems
  • Tested, maintainable modules for enterprise teams

Selected work

Client names are withheld. Figures come from the systems as delivered.

Identity automation, retail

2,100 staff on rule-driven Microsoft 365 lifecycle automation

Problem
Identity operations across multiple brands took significant manual IT effort for account lifecycle, group access and mailbox governance.
Approach
Rule-driven automation tied HR events to identity actions, approvals and policy-safe controls across Microsoft 365 and adjacent systems.
  • Microsoft 365
  • Entra ID
  • PowerShell

Finance operations, 200+ brands

An estimated four full-time roles of manual processing removed

Problem
Manual approval and reconciliation workflows created cost, delay and control risk across a large retail footprint.
Approach
End-to-end workflow orchestration brought identity, approvals and reporting into one governed flow.
  • Oracle HCM
  • Workflow automation
  • Identity

FinOps, multi-cloud

About US$7M of annual cloud spend in one governed view

Problem
Cloud spend ownership and savings tracking were fragmented across AWS, Azure and GCP, with no single decision view.
Approach
A governance tool classified spend, tracked remediation actions and connected cost findings to accountable teams.
  • AWS
  • Azure
  • GCP
  • FinOps

Questions about this kind of work? Send us a message.