ARIOVIS ACADEMY — IAM IT LAB

CorgiBOX has lost control of its access rights. Time to take back the leash.

Step into the role of an IAM consultant. Investigate an imperfect information system, interview its stakeholders, uncover access rights that should never have survived and design a model that can actually be operated. Then implement your decisions in an online technical laboratory.

No real corgi was granted Domain Admin privileges while designing this lab.

Assignment brief

Your client: the world leader in corgi file sharing

CorgiBOX designs and operates an international file-sharing platform devoted to the canine world. The company grew fast. Its information system, too. Following an audit, leadership realises they can no longer prove exactly who has access to what, why some employees still hold historical rights, or whether privileged accounts are being used properly. Exports only tell part of the story. Managers sometimes tell another. Your mission starts here.

Organisation

Fictional international group with several entities and teams

Sources of truth

HR system, Active Directory, LDAP, business application

Infrastructure

Linux servers, MariaDB database, file-sharing application

Populations

Business, IT, L1/L2/L3 support, administrators

Accounts

Office, named admin, technical, historical

History

Unprocessed leavers, unfinished transfers, inherited rights

CorgiBOX is a fictional company created for educational purposes. Any resemblance to an organisation that already granted root to half of its teams would be almost accidental.

The stated need is not always the real need

The lab plays out like a real consulting assignment. You gradually receive emails, an org chart, HR data, directory exports, account lists, groups, application rights, Linux permissions and database access — sometimes incomplete, outdated or inconsistent. You must consolidate identities, reconcile accounts, spot leavers, uncover historical rights, tell a genuine business need from operational convenience and challenge requests that do not hold up.

  1. 1Step

    Observe

    Understand the context, the actors and the available data without jumping to conclusions.

  2. 2Step

    Cross-check

    Compare HR, directory, technical accounts and permissions to rebuild identities.

  3. 3Step

    Interview

    Meet the scenario stakeholders to understand real usage.

  4. 4Step

    Challenge

    Distinguish need, convenience, historical exception and unjustified privilege.

  5. 5Step

    Model

    Design a defensible access model — RBAC, ABAC or hybrid.

  6. 6Step

    Implement

    Translate decisions into concrete configurations in the Lab.

  7. 7Step

    Explain

    Produce deliverables that IT, security and business teams can read.

In a real IAM engagement, no one hands you the target model in a sealed envelope.
“I have always had this right” is not an entitlement rule.
“Without root I cannot work” usually deserves a second question.
An export file can lie. So can a manager. Often unintentionally.
Mistakes are welcome. The point is to corgi-rect them.

Technique alone is not enough

The lab develops two inseparable dimensions: a consulting posture and IAM expertise. Participants learn to structure their reasoning, defend a recommendation and take responsibility for implementing it.

Consulting skills
  • Quickly understand an organisation
  • Conduct interviews with managers
  • Ask questions without steering the answer
  • Reformulate a need
  • Tell a request from its justification
  • Explain risk without blocking the business
  • Exercise a duty to advise
  • Document assumptions
  • Propose several scenarios
  • Defend a recommendation
  • Write a report readable by IT, security and business
  • Accept that the final decision belongs to the client
IAM skills
  • Joiner, Mover, Leaver lifecycle
  • Reconciling identities, accounts and entitlements
  • Structural, business and exceptional rights
  • Least-privilege principle
  • Separating office and admin accounts
  • Business and technical roles
  • Application-level privileges
  • RBAC model
  • ABAC logic
  • Direct and discretionary access
  • Data quality and naming conventions
  • Traceability and industrialisation-ready design

RBAC, ABAC and hybrid models

A good model does not systematically oppose RBAC and ABAC. Participants learn the strengths, limits and cases where a hybrid approach is more relevant.

RBAC — group access around understandable roles

Identity → job → business role → technical role → application right. The lab exercises the role catalogue, employee assignments, shared roles, exceptions and overall readability of the model.

  • Business and technical role catalogue
  • Employee assignment
  • Shared and sensitive roles
  • Documented exceptions
  • Avoid both pitfalls: too many roles, or too few
ABAC — decide with context

Use available attributes to make more contextual decisions: team, location, contract type, status, function, support level, environment, administration context.

  • Identity and resource attributes
  • Readable, testable rules
  • Environment policies (prod, non-prod)
  • Administration context and elevated sessions
  • Compatibility with an existing RBAC baseline

Four ways to grant an access

Direct access

Granted by name, to be defended case by case.

Role-based access

Grouped inside a business or technical role.

Rule-based access

Determined by attributes and context.

Time-boxed exception

Controlled in time and fully traced.

ABAC does not always replace RBAC. The lab shows where each approach is relevant, and where combining both becomes necessary.

IT Lab

Your recommendations must survive contact with the terminal

The Ariovis IT Lab is a remote, isolated virtual environment dedicated to experimentation. It reproduces a realistic information system, tied to the CorgiBOX scenario, where participants observe, analyse and implement their access model.

Components in play
  • Active Directory: domain, groups, accounts
  • Office accounts and named admin accounts
  • Linux servers and POSIX permissions
  • Apache and a demonstration application
  • MariaDB database and application privileges
  • LDAP directory and LDIF exports
  • HR, account and permission exports
What you will be asked to do
  • Review existing accounts and groups
  • Build a naming convention
  • Create or reorganise groups
  • Assign business and technical roles
  • Fix Linux permissions and access
  • Control privileged accounts
  • Produce an LDIF export
  • Extract users, groups and permissions
  • Document applied configurations
  • Compare the existing state with the target model
A lab lets you try, break things and start again. In production, the “I just wanted to see” button rarely qualifies as an acceptable change strategy.

In the end, you must be able to explain what you decided

Participants produce deliverables worthy of a consulting assignment. The slots below are ready to host our illustrations and report mockups.

Entitlement inventory

Description of privileges available across applications and systems.

Identity and account mapping

Reconciliation of HR, office, admin and technical accounts.

Target access matrix

Consolidated view of what each population should be able to do in each environment.

Role catalogue

Business roles, technical roles, associated rights and naming conventions.

RBAC or hybrid model

Relationships between users, jobs, groups, systems and permissions.

Gap analysis

Orphan accounts, unprocessed leavers, right accumulation, historical access and excessive privileges.

Consulting report

Approach, assumptions, trade-offs, residual risks and improvement recommendations.

Implementation documentation

Applied configurations, controls performed and technical evidence.

There is not necessarily one right answer. But an unargued answer is hard to defend in front of a client.

Two ways to live the assignment

The lab can be taken individually, as a team, or as part of an educational programme. Exchanges with Ariovis experts are scheduled in advance on Microsoft Teams.

Students and schools — learn together, even remotely

A shared platform for investigation, argumentation and debrief, embeddable in an IAM or cybersecurity module.

  • Access to the scenario and to the lab
  • Remote Microsoft Teams space
  • Exchanges between participants and shared questions
  • Educational facilitation depending on the chosen track
  • Interactions with scenario stakeholders depending on the session
  • Deliverables handover, debrief and correction
  • Possible integration into a broader module

Teams is not a 24/7 individual helpdesk: interactive slots are scheduled.

Companies and clients — level up a team on a shared case

A programme that challenges the functional and technical choices of an IAM, IT or cyber team on a shared case study.

  • Access to the scenario and to the lab
  • Individual or team work
  • Pre-scheduled Microsoft Teams sessions
  • Q&A slots with an Ariovis expert
  • Support to step back and challenge choices
  • End-of-programme debrief when relevant
  • Adaptation of level or angle depending on the chosen offer

The goal is not to hand over the answer, but to help the team build a better one.

Examples of deliverables produced by our students

Discover a selection of anonymized deliverables produced as part of this practical exercise.

Example of an IAM report produced during the CorgiBOX exercise
Example of an IAM deliverable produced during the CorgiBOX exercise
Example of a presentation produced during the CorgiBOX exercise

How to join the lab

Each session is scoped with the Ariovis Academy. Describe your context: we get back to you to shape the right access.

What to prepare
  • Student / individual, school, company or public administration
  • Estimated number of participants
  • Learning objectives
  • Estimated IAM level
  • Type of coaching expected
  • Preferred language
  • Contact details

Pricing and lab access duration depend on the selected package or session. They are confirmed before subscription.

This lab does not start with “what is a password?”

The lab is aimed at participants who already have a first understanding of information systems, identities, accounts, and access notions — or a technical, cyber, infrastructure, development, audit or risk background allowing them to engage with the topic.

I am discovering IAM consulting

To apply existing basics to a realistic case, under expert supervision.

I already practise IAM

To structure your reasoning, your models and your deliverables.

I train or lead a team

To rely on a shared basis for assessment, discussion and upskilling.

Knowing the definition of RBAC helps. Being able to explain why a RBAC model becomes unmanageable helps even more.

A programme designed to evolve

The CorgiBOX scenario and the IT Lab are built to grow over time, as projects, Ariovis consultants’ feedback and authorisation models evolve.

  • Scenario enrichment and new clues
  • New inconsistencies and pedagogical variants
  • New authorisation models
  • Lab improvements
  • Feedback from schools, clients and consultants
  • Possible integration into broader Academy tracks

The fictional IS keeps evolving; so do human mistakes. The lab is designed to keep chasing them.

Why Ariovis

The lab is built on situations encountered in Ariovis IAM projects, the methods used to scope, analyse, model and implement them, and the experience of the Ariovis Academy — whose training modalities are detailed on the Training & awareness page.

  • Situations drawn from real IAM engagements, anonymised and transposed
  • Scoping, analysis, modelling and implementation methods
  • Experience across consulting, integration, training and skills transfer
  • An approach where upskilling is part of the project itself
  • Environments reproducing interactions between directories, Linux systems, applications and data

Frequently asked questions

Is the lab fully remote?

Yes. The scenario and the lab are accessible online, and exchanges with the Ariovis team take place on Microsoft Teams.

Do I need to install anything on my computer?

No. The IT Lab is virtual and browser-accessible; depending on the exercise, an SSH client or plain browser access is enough.

What is the difference between the lab and a theoretical course?

A theoretical course explains concepts. The lab puts you in situation: you investigate, decide and implement.

Do I need to know RBAC already?

A first IAM culture helps. Fundamentals are recalled along the way, but the lab assumes that the notions of account, identity and entitlement are already familiar.

Does the lab also cover ABAC?

Yes. Part of the track explores attribute-based decisions, their use cases and how they combine with an RBAC baseline.

Can it be taken as a team?

Yes. The lab works individually or as a team, with shared debriefs and questions.

How do exchanges with Ariovis experts work?

Interactive slots are scheduled in advance on Teams: participants arrive with their observations, hypotheses and questions.

Can companies organise a private session?

Yes. We then design a track tailored to the team’s context, level and objectives.

Can schools embed it into their curriculum?

Yes. The lab can plug into an IAM or cybersecurity module, with modalities defined with the institution.

Is there a single correct answer to the CorgiBOX case?

No. Several defensible answers exist. What matters is the quality of reasoning, the clarity of the model and the feasibility of the implementation.

Do participants really interact with a technical environment?

Yes. Active Directory, Linux, LDAP, MariaDB and a demonstration application are set up in the virtual IT Lab.

How long does lab access remain open?

Access duration depends on the selected package or session. It is confirmed before subscription.

The investigation is waiting

CorgiBOX is still waiting for its access model.

The exports are ready. Every manager has their own version of the truth. A few former employees are probably still wandering through the directory, and someone most likely claims they need root access to read a file. The investigation is yours.

Bring your reasoning. We provide the Lab and the corgis.