Our company becomes your IAM department.
Not a contractor you manage. Not a project you scope. Not headcount you hire and hope to keep. You hand over your identity platforms, and we run them as your team.
What is an Identity Practice Subscription?
An Identity Practice Subscription is a recurring agreement under which GCA takes ownership of your identity platforms and operates as your identity team. You are not buying named people or a defined scope. You are delegating the function, and we staff it from the whole practice.
Every other way of buying identity work asks you to predict the future.
Fixed price asks you to describe the work accurately before you have done any of it. A T&E project asks you to assume the team you brought in for your governance platform can also federate with your directory and integrate with your privileged access tooling. Hiring asks you to be right about a person, and leaves you one resignation away from stagnation and one bad hire away from months of lost progress.
None of that is a planning failure. The only way to scope identity work perfectly in advance is to own a crystal ball. Everything else is a change order waiting to happen.
And the ground is moving faster than it used to. Every AI agent your organization adopts is another identity that has to be created, entitled, monitored and eventually removed. In our experience most organizations cannot yet answer who owns those identities, what they are able to reach, or whether an agent's access should outlive the task that prompted it. That is a category of work that simply was not in the roadmap anyone wrote last year. If you are trying to write a fixed scope today, you are no longer only predicting your own priorities. You are predicting a category that is still forming. We built an AI Identity Governance Assessment because clients kept arriving at that question without a way to answer it.
So stop scoping it and delegate it. IGA work, done. SSO work, done. PAM work, done. Want your identity risk discovered, scored and tallied? Done. Want to start reducing that risk once you have the report? Also done.
That is a lot of trust to hand over. It should be.
Rated by the people who bought it
That matters more for this model than for any other. When you subscribe to a practice, you are not evaluating a scope document or a rate card. You are making a judgment about whether the practice is any good. Those reviews are written by the people who found out.
Gartner Peer Insights attribution
GARTNER is a registered trademark and service mark, and PEER INSIGHTS is a trademark and service mark of Gartner, Inc. and/or its affiliates and are used herein with permission. Gartner Peer Insights content consists of the opinions of individual end-users based on their own experiences with the vendors listed on the platform, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.
4.6 / 5.0
One of the most reviewed IAM Professional Services Providers, Worldwide based on 32 verified reviews on Gartner Peer Insights as of 5/1/2026.
Read the reviews on Gartner Peer Insights →The five ways to buy identity services
Most buyers open this conversation framing it as staff augmentation vs managed services. That is the wrong question, because it assumes there are two answers. There are five, and any firm that tells you otherwise is describing its own preference rather than your situation. Four of them sell you units of something. The fifth sells you the practice.
| Model | Who manages | Overrun risk | Spend | Best when |
|---|---|---|---|---|
| Staff Augmentation | You | You | Rate fixed, total varies | You have the leadership, not the hands |
| T&E Project | We do | You | Rate fixed, total varies | You want a team you do not manage |
| Milestone Fixed Price | We do | We do | Fixed | Your scope is genuinely settled |
| Managed Service | We do | We do, in scope | Fixed | You need it kept running |
| Identity Practice Subscription | We do | We do | Fixed | Priorities change faster than a scope document can |
Staff Augmentation
You hire named people from us and manage them yourself. They sit in your standups, follow your process, and report to your leads. People often frame the choice as staff augmentation vs consulting, but the real difference is not seniority or rate. It is who carries the outcome.
This works when you have strong internal identity leadership and a specific, known gap. It stops working when the gap is broader than one skill set, or when your leadership bandwidth is the actual constraint. You are still doing the managing, and management is the thing most teams have least of.
T&E Project
You get a team rather than a person, and we manage it. Work is billed for time and materials, which is where the name comes from.
This is the right model when you know roughly what you want but not exactly, and you would rather not build a delivery structure to oversee it. The tradeoff is honest: because you are paying for time, an estimate that moves means a total that moves.
The failure mode is narrower than most buyers expect, and it is rarely about effort. A team engaged for your governance platform is a governance team. When that work needs to federate with your directory, or integrate with privileged access tooling, the people in the room may not be the people who can do it. That is the moment a project stalls: not because anyone is unwilling, but because the engagement was scoped around one platform and the work turned out to span three.
Milestone Fixed Price
Same team structure, different risk allocation. We commit to milestones at a fixed price, which means overruns are ours to absorb.
Clients like this model for budgeting, and rightly so. What surprises people is the behavior it creates. When the price is fixed against a defined scope, both sides have a strong incentive to get the definition perfect before anything starts. That works beautifully when your requirements are genuinely settled. When they are not, it turns discovery into negotiation, and change requests start doing work that a conversation should have done.
In our experience, this is the model most often chosen for the wrong reason: not because scope was settled, but because a fixed number was easier to get approved.
Managed Service
In the managed services model we take operational ownership of a defined scope and keep it running to agreed service levels. Provisioning, certifications, reporting, incident response.
The boundary is the point. A managed service keeps things running. It does not add new functionality, because new functionality is outside the scope you fixed. That is a feature when you want operational stability and a predictable number. It becomes a constraint the moment the business asks for something new, and the answer has to be "that is a separate engagement."
Identity Practice Subscription
This is where the pattern breaks. The other four models sell you a quantity: hours, a team, a scope, a service level. This one sells you access to the practice itself.
Governance work this month. A federation project next month. Privileged access onboarding after that. You are not re-scoping, re-contracting or re-onboarding a new set of people each time, because you did not buy people or a project. You bought the practice, and we point it at whatever matters most to you right now.
Why subscribe to a practice instead of building one
Building an internal identity practice is not one hire. It is an architect who can design across platforms, engineers who know the specific products you run, someone who understands governance as a discipline rather than a tool, and enough coverage that a resignation is not an outage.
Then it is keeping them. Identity skills are portable and in demand, and the engineer you spent four months hiring is a target from the day they update their profile.
You are not alone in this, and it is not a failure of planning. It is arithmetic. Very few organizations have enough sustained identity work to justify carrying every skill they periodically need, which is exactly why they end up carrying some of them and outsourcing the rest anyway.
A subscription inverts that. You carry the priorities. We carry the bench.
You already have a team
Most organizations we work with are not starting from zero. They have identity people, often good ones, who know the business, the internal politics, and the history behind every decision that made the environment what it is. None of that is replaceable, and we are not proposing to replace it.
What a small internal team cannot be is two deep on every platform at once. That is not a criticism of anyone, it is arithmetic. Three or four people cover the work in front of them and carry the on-call, and there is nothing left over when a certification redesign, a federation migration and a privileged access rollout all land in the same quarter.
So the subscription is built around your team rather than instead of it. They keep ownership of direction and priorities. We supply the depth behind them: the governance specialist for the certification work, the federation engineer for the migration, the privileged access hands for the onboarding push. Your people decide what matters and in what order. Ours do the work that needs a specialist your headcount could never justify hiring on its own.
In practice your identity lead runs the backlog and we work it. The people who understand your environment stay in charge of it, and they stop being the limit on how much can happen at once.
If you do not have a team yet, the model works the same way. The only difference is who sets the priorities.
Identity operations, or identity engineering?
"Operations" in identity usually means a queue. Access requests arrive, somebody works through them, tickets close, and the number everyone watches is how fast. That work is real and plenty of providers sell it.
It is not what this is.
We are an engineering team. When a joiner, mover and leaver flow needs building, we build it. When an automation that ran cleanly for eight months quietly stops firing for one source system, we go and find out why instead of working around it by hand. When an auditor asks for evidence, we produce it from the system rather than assembling it in a spreadsheet the week before the deadline.
The difference shows up in what gets measured. An operations engagement is judged on how quickly the queue is serviced. This one is judged on the queue getting shorter, because the work that kept generating it got automated.
That is also why a subscription is priced on capacity rather than ticket volume. Paying per ticket rewards a provider for the queue staying long.
What you get
The whole bench, not a seat filler
When you work with GCA you do not get a body to fill a seat. You get a team of experts working together, with the architects, engineers and platform specialists your objective actually calls for.
Any platform in our practice
We hold skills across most of the major identity platforms in the market. One agreement covers whichever of them you run, so a change in direction is a conversation rather than a procurement cycle. Our partner pages go into specifics.
Assessment, implementation and operations under one agreement
Most models make you choose which phase you are buying. This one does not. Assess a program in the spring, implement in the summer, operate it from the autumn, without a new contract at each boundary.
Continuity of context
The people who learn your environment stay with your environment. Nobody re-reads your architecture from scratch at the start of every engagement, which is where a surprising amount of project cost quietly goes.
Protocol-level rigor
OIDC, SAML and SCIM 2.0 are handled to spec, and audit evidence is produced from the system rather than assembled by hand. When an auditor asks, the answer comes from the platform, not a spreadsheet built the week before the deadline.
How pricing works
Managed services pricing models are usually built around a fixed scope. This one is built around capacity instead. A subscription is a recurring fee for defined capacity across our practice, and capacity is what is fixed. What that capacity works on is yours to direct, and can change as often as your priorities do.
Concretely, that runs as a backlog and a sprint cadence. Your priorities go into a shared backlog. We pull from it into sprints, so at any point you can see what is in flight now and what is queued behind it. Changing your mind means moving an item up the backlog, not renegotiating an agreement.
That structure trades one thing for another, and it is worth being plain about it. Because capacity is fixed rather than scope, we do not decline work for being outside a statement of work. What we do instead is sequence it. If you bring us three priorities in the same week, all three get done, and we will tell you honestly in what order and by when.
If demand consistently exceeds capacity, we review tier together before anything changes. You never pay overage without agreeing to it.
How the subscription works day to day
You prioritize. We deliver. You see what is next. No change orders, just sequencing.
Backlog
Your priorities go into one shared backlog: governance, federation, PAM, risk remediation. Your lead owns the order.
Sprint
We pull from the backlog into sprints. You see what is in flight now and what is queued behind it. No timesheets, just outcomes shipped.
Shipped
Work ships, then the next item moves up. If demand exceeds capacity, we sequence honestly and review tier when it is consistently full.
Changing your mind means moving an item up the backlog, not renegotiating an agreement. If you bring us three priorities in the same week, all three get done, and we tell you in what order and by when.
When a subscription is not the right model
We would rather tell you this now than three months into an agreement.
A subscription is the wrong choice when you have one well-defined project with a firm scope and no expectation of follow-on work. Buy that as a milestone fixed-price engagement through IAM Implementation Services and let us carry the overrun risk.
It is also wrong when what you need is operational stability at a fixed number, with no appetite for new functionality. That is IAM Managed Services, and it will cost you less.
And if you are not yet sure what you need, start with an IAM assessment. Subscribing to a practice before you know what you want it to do is a good way to pay for capacity you have not decided how to use.
The platforms you already run
We hold skills across most of the major identity platforms in the market. You are not asked to move to something we prefer.
See the platforms we partner on →
Which of your platforms we take ownership of is settled when you subscribe. That is a conversation we have before you sign, not a boundary you discover afterward. From that point they are ours to operate.
The work that spans several of them is ours to coordinate too, and that is the part worth paying attention to. Federating a governance rollout with your directory, or wiring it into privileged access tooling, is exactly where a single-platform team stalls. Here it is one team that has seen how these systems behave together rather than in isolation.
For specifics on the vendors and platforms we work with, see our partner pages.
Frequently Asked Questions
What is the difference between staff augmentation and professional services?
Staff augmentation supplies named individuals who work under your direction and your management. Professional services engagements are managed by the provider, who is accountable for the delivery rather than just the hours. The practical difference is who is responsible when something goes wrong.
What is considered staff augmentation?
Staff augmentation is any arrangement where you contract for named people, billed for their time, working under your management and following your processes. The provider supplies the person. You supply the direction and carry the outcome.
What are examples of managed services?
In identity, managed services typically cover ongoing operations: user provisioning and deprovisioning, access certification campaigns, compliance reporting, identity incident response, and platform administration, all delivered against agreed service levels.
How is a practice subscription different from managed services?
A managed service keeps a defined scope running and does not add new functionality within that scope. With a practice subscription we take ownership of your identity platforms and operate as your identity team, so new build is included rather than excluded. Capacity is the fixed quantity, not scope.
Is this a help desk or a ticket-queue service?
No. Ticket-queue provisioning is operations work, and it is not what this model is for. GCA works as your engineering team: building and fixing the automation that generates the queue, investigating why a flow has stopped firing, and producing audit evidence from the system rather than by hand. The measure of success is the queue getting shorter, not being serviced faster.
Can this work alongside our existing identity team?
Yes, and that is the more common case. Your team keeps ownership of direction and priorities and runs the backlog; we supply the platform depth behind them. Nobody is replaced. The point is that a small internal team stops being the limit on how much identity work can happen at once.
How quickly can we change priorities under a subscription?
Immediately, because the agreement covers capability rather than a scope document. Moving from a certification campaign to an urgent federation project is a prioritization conversation, not a change order and not a new contracting cycle. What changes is the order of the queue, not the paperwork.
What happens if we need a platform you do not currently support?
We will tell you before you sign, not after. We hold skills across most of the major identity platforms, and which of them we take ownership of for you is agreed when you subscribe. If your estate includes something we do not run, we would rather say so during that conversation and point you to someone who does it well than take the work and learn on your environment.
What service levels come with the subscription?
Service levels are agreed when you subscribe and reviewed with the tier. Response commitments are set by priority, reporting follows a monthly cadence, and the backlog makes what is in flight and what is queued visible at any time. Targets are agreed between us before they are published anywhere, so what you see reflects your environment rather than a generic number.
Why GCA
We do one thing. Identity is not a division here, it is the whole company, and it has been for more than twenty years.
In our experience, a meaningful share of the work that reaches us begins as someone else's implementation. We are usually the second firm in. That is not a boast, it is context for why this model exists: the pattern we see most often is not a technology failure, it is an organization that bought people or a project when what it actually needed was a practice.
Ready to subscribe to a practice?
Tell us what is on your identity roadmap for the next twelve months. We will tell you honestly whether a subscription is the right way to buy it, or whether one of the other four models fits better.