Identity-first engineering

Blogging real IAM design, not vendor-level theory.

This blog is built for engineers, architects, and consultants working on modern identity stacks, with deep coverage of Okta org strategy, federation, lifecycle automation, governance-heavy integrations, and migration patterns for complex enterprise environments.

Coverage map

Topics that matter in enterprise identity

Federation Engineering

SAML, OIDC, inbound federation, IdP routing, and trust boundary design.

Access Governance

Entitlement models, approval paths, SoD concerns, and auditability.

Okta Operations

Org strategy, branding separation, policy design, and production runbooks.

Automation

Workflows, event-driven provisioning, SCIM reliability, and exception handling.

Latest writing

Start with the most useful pieces

Okta Workflows • 8 min read

Triggering Okta Workflows from MFA registration with Event Hooks

How to use the user.mfa.factor.activate event to trigger downstream workflow automation after MFA registration.

Read

Architecture • 8 min read

Zero Trust IAM as a platform

A practical framework for building identity as a control plane across workforce, partner, and customer applications.

Read

Okta • 10 min read

When a multi-org Okta strategy is the right call

Hub-and-spoke design, branding isolation, delegated admin, and tenant boundaries.

Read

Federation • 9 min read

B2B identity with inbound federation

How to structure trust, account linking, policy routing, and fallback flows.

Read
Read more articles

About this site

A focused blog for practical IAM problem solving

Use this site as a foundation for publishing implementation notes, migration lessons, design tradeoffs, and production architecture guidance around IAM and Okta. The content structure is now reusable, so new posts only need markdown frontmatter and article content.

Contact me for any new IAM or Okta solution requirements. Share your name, email, and the topic details, and the request will be emailed directly for follow-up.