Procurement capability sheet · v0.1

Privileged Identity & Secure Cloud Assurance

A bounded specialist work package for organisations and delivery partners that need measurable Microsoft identity and secure-cloud outcomes, objective acceptance criteria and reusable technical evidence.

Discuss a work package

From expertise to contractable outcome

Define what is delivered before discussing how many engineering hours it takes

The capability is designed to be purchased directly by a regulated organisation or inserted into a larger integrator or prime-led programme. Scope remains deliberately narrow: identity, secure-cloud access and continuous technical assurance.

Capability field
Definition
Buyer value
Acceptance relevance
Reuse
Problem
Privileged access and cloud security controls may be correctly configured once but drift over time, while evidence is recreated manually when assurance stakeholders ask for it.
Reduces ambiguity between security intent, technical delivery and evidence.
Can be linked to measurable deliverables and buyer-approved thresholds.
Designed to reuse Enki architecture, controls, evidence and automation across engagements.
Capability
Privileged Identity & Secure Cloud Assurance for Microsoft Entra ID and Azure, combining evidence-backed assessment, controlled remediation and repeatable validation.
Reduces ambiguity between security intent, technical delivery and evidence.
Can be linked to measurable deliverables and buyer-approved thresholds.
Designed to reuse Enki architecture, controls, evidence and automation across engagements.
Core scope
Privileged roles, PIM/JIT, Conditional Access, authentication strength, emergency access, selected workload identities, control evidence and drift.
Reduces ambiguity between security intent, technical delivery and evidence.
Can be linked to measurable deliverables and buyer-approved thresholds.
Designed to reuse Enki architecture, controls, evidence and automation across engagements.
Primary deliverables
Baseline inventory, control-to-evidence matrix, findings, exception register, remediation backlog, verification results and reusable evidence pack.
Reduces ambiguity between security intent, technical delivery and evidence.
Can be linked to measurable deliverables and buyer-approved thresholds.
Designed to reuse Enki architecture, controls, evidence and automation across engagements.
Acceptance model
Outcome → measurement → evidence → threshold. Acceptance criteria are agreed before delivery and verified against the final evidence package.
Reduces ambiguity between security intent, technical delivery and evidence.
Can be linked to measurable deliverables and buyer-approved thresholds.
Designed to reuse Enki architecture, controls, evidence and automation across engagements.
Dependencies
Read-only or approved administrative access, named technical owner, agreed scope, access to relevant policy context and client change/approval processes.
Reduces ambiguity between security intent, technical delivery and evidence.
Can be linked to measurable deliverables and buyer-approved thresholds.
Designed to reuse Enki architecture, controls, evidence and automation across engagements.
Delivery team
Senior Microsoft Cloud / identity lead with additional specialist engineering capacity added where scope, duration or procurement requirements justify it.
Reduces ambiguity between security intent, technical delivery and evidence.
Can be linked to measurable deliverables and buyer-approved thresholds.
Designed to reuse Enki architecture, controls, evidence and automation across engagements.
Typical duration
Bounded assessments can begin in days or weeks; remediation and recurring assurance are scoped from the accepted baseline and client change windows.
Reduces ambiguity between security intent, technical delivery and evidence.
Can be linked to measurable deliverables and buyer-approved thresholds.
Designed to reuse Enki architecture, controls, evidence and automation across engagements.
Commercial model
Fixed-scope assessment, defined remediation work package, recurring assurance, or partner-led subcontracting. Pricing is agreed against scope and acceptance criteria rather than hourly effort alone.
Reduces ambiguity between security intent, technical delivery and evidence.
Can be linked to measurable deliverables and buyer-approved thresholds.
Designed to reuse Enki architecture, controls, evidence and automation across engagements.
Reusable IP
Reference architecture, control specification standard, identity-control library, evidence model, exception workflow, remediation patterns and collector automation.
Reduces ambiguity between security intent, technical delivery and evidence.
Can be linked to measurable deliverables and buyer-approved thresholds.
Designed to reuse Enki architecture, controls, evidence and automation across engagements.
Partner fit
MSPs, systems integrators, cyber/GRC advisers and primes that need a narrow Microsoft identity/security capability without building every specialist function internally.
Reduces ambiguity between security intent, technical delivery and evidence.
Can be linked to measurable deliverables and buyer-approved thresholds.
Designed to reuse Enki architecture, controls, evidence and automation across engagements.
Boundary
Enki Tech does not claim NATO affiliation, defence accreditation, security clearance or compliance for a specific environment unless independently established for that engagement.
Reduces ambiguity between security intent, technical delivery and evidence.
Can be linked to measurable deliverables and buyer-approved thresholds.
Designed to reuse Enki architecture, controls, evidence and automation across engagements.

Opportunity filter

What Enki should pursue

Identity, secure cloud or continuous assurance is at least 70% of the requirement
The work package has objective deliverables and can be accepted through evidence
Delivery can be bounded without creating an unmanaged 24/7 operations obligation
Security, procurement and eligibility barriers are known before bid investment
Existing Enki IP materially reduces delivery effort or risk

What Enki should reject

Do not chase procurement volume for its own sake

Generic hardware or infrastructure supply with little identity/security content
Opportunities requiring unsupported accreditation, clearance or legal eligibility
Work that depends primarily on staffing volume rather than a specialist capability
Procurements that require speculative hiring or tooling before qualification

Next buyer step

Turn the sheet into a specific Statement of Work

For an active requirement, the next step is to agree the in-scope tenant/resources, acceptance criteria, dependencies, delivery interfaces, change authority and evidence package.