Skip to main content
Style:
Size:

Part 5: The Consultant’s Playbook

Chapter 12: Designing the Target Operating Model (Large vs. Small Orgs)

We are now in the final stretch. You understand the theory, the risks, and the technical controls needed to secure Human, Non-Human, and AI Workloads.

But if you are a consultant—or an internal IAM leader—you cannot just walk into a company and say, "Turn on Zero Trust and Ephemeral Tokens for everyone." If you do that, you will break production, lock out the CEO, and be fired by Friday.

You have to design a Target Operating Model (TOM).

A Target Operating Model is your blueprint. It explains exactly how the 5 Pillars (People, Process, Technology, Control, and Impact) will be structured to achieve your security goals while minimizing negative friction on the business.

The biggest mistake you can make is taking a playbook designed for a Fortune 500 bank and trying to force it onto a 200-person tech startup. Let's break down how to design a TOM tailored to the size of the organization.


The SMB/Startup Model (The "Lean & Fast" Approach)

In a Small to Medium Business (SMB)—usually under 1,000 employees—IT budgets are lean, and agility is the absolute top priority. The company is trying to survive and grow; they cannot afford a 3-year IAM implementation project.

  • People: There is no dedicated "IAM Team." IT is usually handled by a handful of generalists. If you tell them to manually review access logs every Friday, they will laugh at you.
  • Process: Processes must be highly automated but lightweight. You rely heavily on HR-driven Joiner/Mover/Leaver (JML) automation. If someone is hired in the HR system, they automatically get a standard set of cloud apps.
  • Technology: Cloud-Native and SaaS. SMBs should almost never build on-premises identity infrastructure (like traditional Active Directory servers). They should use Identity-as-a-Service (IDaaS) like Okta or Microsoft Entra ID.
  • Control: The focus is on foundational hygiene. Enforce Phishing-Resistant MFA (FIDO2) everywhere, and implement basic Single Sign-On (SSO) so users aren't juggling 40 different passwords.
  • Impact (The Trade-off): You accept some risk to maintain speed. For example, you might not enforce strict network micro-segmentation for every single internal app, but you rigorously protect the main customer database.

The Enterprise Model (The "Fortress & Federation" Approach)

An Enterprise (1,000 to 100,000+ employees) operates in a fundamentally different reality. They have massive IT budgets, but they also have crippling technical debt, thousands of legacy on-premises servers, and strict regulatory compliance requirements (like SOX, GDPR, or HIPAA).

  • People: The IAM program is its own department. You have dedicated Role Engineers, Privileged Access (PAM) administrators, and Identity Governance analysts.
  • Process: Everything is driven by Governance and Compliance. Access Reviews are not optional; they are legally required by auditors. Separation of Duties (SoD) is strictly enforced.
  • Technology: Hybrid Identity Fabrics. Enterprises cannot just use the cloud; they have legacy mainframe applications that don't speak modern cloud protocols. Their technology stack includes complex Identity Governance and Administration (IGA) tools (like SailPoint or Saviynt) tied to on-premise Active Directory and Cloud IDaaS.
  • Control: Advanced Zero Trust Network Access (ZTNA), Just-In-Time (JIT) provisioning for administrators, and strict Secrets Management for their massive Non-Human Identity (NHI) sprawl.
  • Impact: Changes move slowly. Implementing a new security control requires a Change Advisory Board (CAB) approval. The goal is absolute stability and risk reduction across a massive, distributed environment.

Interactive Tool: Target Operating Model Comparison Matrix

Compare how the 5 Pillars and technology stack adapt as organizations scale from Startup to Enterprise:

Target Operating Model (TOM) Comparison Matrix

See how IAM architecture and the 5 Pillars adapt as organizations scale from Startup to Global Enterprise.

Chapter 12 Tool
Selected Profile
Global Enterprise (Fortress & Federation)
Typical IAM Budget
$2M – $15M+ / year
Pillar 1: People & Roles
Dedicated IAM Department: Role Engineers, IGA Analysts, PAM Architects, AI Governance Officers.
Pillar 2: Process & Governance
Strict continuous access governance, Separation of Duties (SoD) enforcement, Change Advisory Board (CAB).
Pillar 3: Technology & Fabric
Hybrid Identity Fabric connecting on-prem Active Directory, multi-cloud IDaaS, and full IGA suite.
Pillar 4: Core Controls
Hardware security keys (YubiKeys mandatory), dynamic ephemeral tokens for all NHIs, HITL AI circuit breakers.
Pillar 5: Impact & Risk Profile
SOX, HIPAA, GDPR, EU AI Act compliance. Zero tolerance for unmanaged sprawl or lateral movement.
Representative Technology Stack
SailPoint / Saviynt IGACyberArk PAMHashiCorp Vault EnterpriseZscaler / Palo Alto ZTNA

Designing the Model: Step-by-Step

When you sit down to design the TOM for a client, you follow a strict 3-step process.

Step 1: The Maturity Assessment (Where are we today?)

You cannot build a roadmap if you don't know where you are starting. You assess their current state across the 5 Pillars:

  • Do they know how many bots they have? (Usually no).
  • Are they still using passwords, or have they moved to passwordless MFA?
  • Is HR talking to IT automatically, or are they sending emails?

Step 2: The Future State Definition (Where do we want to be?)

You map out the perfect end-state based on their size and industry.

  • If it's an SMB, the future state is a 100% cloud-based SSO environment with automated onboarding.
  • If it's a massive bank, the future state is a fully micro-segmented Zero Trust network with Ephemeral Tokens for AI agents and strict PAM controls for human admins.

Step 3: The Transitional Architecture (How do we get there?)

This is where consultants earn their money. You do not jump from Step 1 to Step 2 overnight. You build a transitional state.

By breaking the TOM into phases, you deliver quick security wins (ROI) early on, while slowly building the foundation for the complex, long-term architecture.