Fictional international group with several entities and teams
CorgiBOX has lost control of its access rights. Time to take back the leash.
Step into the role of an IAM consultant. Investigate an imperfect information system, interview its stakeholders, uncover access rights that should never have survived and design a model that can actually be operated. Then implement your decisions in an online technical laboratory.
No real corgi was granted Domain Admin privileges while designing this lab.
Your client: the world leader in corgi file sharing
CorgiBOX designs and operates an international file-sharing platform devoted to the canine world. The company grew fast. Its information system, too. Following an audit, leadership realises they can no longer prove exactly who has access to what, why some employees still hold historical rights, or whether privileged accounts are being used properly. Exports only tell part of the story. Managers sometimes tell another. Your mission starts here.
HR system, Active Directory, LDAP, business application
Linux servers, MariaDB database, file-sharing application
Business, IT, L1/L2/L3 support, administrators
Office, named admin, technical, historical
Unprocessed leavers, unfinished transfers, inherited rights
The stated need is not always the real need
The lab plays out like a real consulting assignment. You gradually receive emails, an org chart, HR data, directory exports, account lists, groups, application rights, Linux permissions and database access — sometimes incomplete, outdated or inconsistent. You must consolidate identities, reconcile accounts, spot leavers, uncover historical rights, tell a genuine business need from operational convenience and challenge requests that do not hold up.
- Step
Observe
Understand the context, the actors and the available data without jumping to conclusions.
- Step
Cross-check
Compare HR, directory, technical accounts and permissions to rebuild identities.
- Step
Interview
Meet the scenario stakeholders to understand real usage.
- Step
Challenge
Distinguish need, convenience, historical exception and unjustified privilege.
- Step
Model
Design a defensible access model — RBAC, ABAC or hybrid.
- Step
Implement
Translate decisions into concrete configurations in the Lab.
- Step
Explain
Produce deliverables that IT, security and business teams can read.
In a real IAM engagement, no one hands you the target model in a sealed envelope.
“I have always had this right” is not an entitlement rule.
“Without root I cannot work” usually deserves a second question.
An export file can lie. So can a manager. Often unintentionally.
Mistakes are welcome. The point is to corgi-rect them.
Technique alone is not enough
The lab develops two inseparable dimensions: a consulting posture and IAM expertise. Participants learn to structure their reasoning, defend a recommendation and take responsibility for implementing it.
- Quickly understand an organisation
- Conduct interviews with managers
- Ask questions without steering the answer
- Reformulate a need
- Tell a request from its justification
- Explain risk without blocking the business
- Exercise a duty to advise
- Document assumptions
- Propose several scenarios
- Defend a recommendation
- Write a report readable by IT, security and business
- Accept that the final decision belongs to the client
- Joiner, Mover, Leaver lifecycle
- Reconciling identities, accounts and entitlements
- Structural, business and exceptional rights
- Least-privilege principle
- Separating office and admin accounts
- Business and technical roles
- Application-level privileges
- RBAC model
- ABAC logic
- Direct and discretionary access
- Data quality and naming conventions
- Traceability and industrialisation-ready design
RBAC, ABAC and hybrid models
A good model does not systematically oppose RBAC and ABAC. Participants learn the strengths, limits and cases where a hybrid approach is more relevant.
Identity → job → business role → technical role → application right. The lab exercises the role catalogue, employee assignments, shared roles, exceptions and overall readability of the model.
- Business and technical role catalogue
- Employee assignment
- Shared and sensitive roles
- Documented exceptions
- Avoid both pitfalls: too many roles, or too few
Use available attributes to make more contextual decisions: team, location, contract type, status, function, support level, environment, administration context.
- Identity and resource attributes
- Readable, testable rules
- Environment policies (prod, non-prod)
- Administration context and elevated sessions
- Compatibility with an existing RBAC baseline
Four ways to grant an access
Granted by name, to be defended case by case.
Grouped inside a business or technical role.
Determined by attributes and context.
Controlled in time and fully traced.
ABAC does not always replace RBAC. The lab shows where each approach is relevant, and where combining both becomes necessary.
Your recommendations must survive contact with the terminal
The Ariovis IT Lab is a remote, isolated virtual environment dedicated to experimentation. It reproduces a realistic information system, tied to the CorgiBOX scenario, where participants observe, analyse and implement their access model.
- Active Directory: domain, groups, accounts
- Office accounts and named admin accounts
- Linux servers and POSIX permissions
- Apache and a demonstration application
- MariaDB database and application privileges
- LDAP directory and LDIF exports
- HR, account and permission exports
- Review existing accounts and groups
- Build a naming convention
- Create or reorganise groups
- Assign business and technical roles
- Fix Linux permissions and access
- Control privileged accounts
- Produce an LDIF export
- Extract users, groups and permissions
- Document applied configurations
- Compare the existing state with the target model
In the end, you must be able to explain what you decided
Participants produce deliverables worthy of a consulting assignment. The slots below are ready to host our illustrations and report mockups.
Entitlement inventory
Description of privileges available across applications and systems.
Identity and account mapping
Reconciliation of HR, office, admin and technical accounts.
Target access matrix
Consolidated view of what each population should be able to do in each environment.
Role catalogue
Business roles, technical roles, associated rights and naming conventions.
RBAC or hybrid model
Relationships between users, jobs, groups, systems and permissions.
Gap analysis
Orphan accounts, unprocessed leavers, right accumulation, historical access and excessive privileges.
Consulting report
Approach, assumptions, trade-offs, residual risks and improvement recommendations.
Implementation documentation
Applied configurations, controls performed and technical evidence.
There is not necessarily one right answer. But an unargued answer is hard to defend in front of a client.
Two ways to live the assignment
The lab can be taken individually, as a team, or as part of an educational programme. Exchanges with Ariovis experts are scheduled in advance on Microsoft Teams.
A shared platform for investigation, argumentation and debrief, embeddable in an IAM or cybersecurity module.
- Access to the scenario and to the lab
- Remote Microsoft Teams space
- Exchanges between participants and shared questions
- Educational facilitation depending on the chosen track
- Interactions with scenario stakeholders depending on the session
- Deliverables handover, debrief and correction
- Possible integration into a broader module
Teams is not a 24/7 individual helpdesk: interactive slots are scheduled.
A programme that challenges the functional and technical choices of an IAM, IT or cyber team on a shared case study.
- Access to the scenario and to the lab
- Individual or team work
- Pre-scheduled Microsoft Teams sessions
- Q&A slots with an Ariovis expert
- Support to step back and challenge choices
- End-of-programme debrief when relevant
- Adaptation of level or angle depending on the chosen offer
The goal is not to hand over the answer, but to help the team build a better one.
Examples of deliverables produced by our students
Discover a selection of anonymized deliverables produced as part of this practical exercise.



How to join the lab
Each session is scoped with the Ariovis Academy. Describe your context: we get back to you to shape the right access.
- Student / individual, school, company or public administration
- Estimated number of participants
- Learning objectives
- Estimated IAM level
- Type of coaching expected
- Preferred language
- Contact details
Pricing and lab access duration depend on the selected package or session. They are confirmed before subscription.
This lab does not start with “what is a password?”
The lab is aimed at participants who already have a first understanding of information systems, identities, accounts, and access notions — or a technical, cyber, infrastructure, development, audit or risk background allowing them to engage with the topic.
To apply existing basics to a realistic case, under expert supervision.
To structure your reasoning, your models and your deliverables.
To rely on a shared basis for assessment, discussion and upskilling.
Knowing the definition of RBAC helps. Being able to explain why a RBAC model becomes unmanageable helps even more.
A programme designed to evolve
The CorgiBOX scenario and the IT Lab are built to grow over time, as projects, Ariovis consultants’ feedback and authorisation models evolve.
- Scenario enrichment and new clues
- New inconsistencies and pedagogical variants
- New authorisation models
- Lab improvements
- Feedback from schools, clients and consultants
- Possible integration into broader Academy tracks
The fictional IS keeps evolving; so do human mistakes. The lab is designed to keep chasing them.
Why Ariovis
The lab is built on situations encountered in Ariovis IAM projects, the methods used to scope, analyse, model and implement them, and the experience of the Ariovis Academy — whose training modalities are detailed on the Training & awareness page.
- Situations drawn from real IAM engagements, anonymised and transposed
- Scoping, analysis, modelling and implementation methods
- Experience across consulting, integration, training and skills transfer
- An approach where upskilling is part of the project itself
- Environments reproducing interactions between directories, Linux systems, applications and data
Frequently asked questions
Is the lab fully remote?
Yes. The scenario and the lab are accessible online, and exchanges with the Ariovis team take place on Microsoft Teams.
Do I need to install anything on my computer?
No. The IT Lab is virtual and browser-accessible; depending on the exercise, an SSH client or plain browser access is enough.
What is the difference between the lab and a theoretical course?
A theoretical course explains concepts. The lab puts you in situation: you investigate, decide and implement.
Do I need to know RBAC already?
A first IAM culture helps. Fundamentals are recalled along the way, but the lab assumes that the notions of account, identity and entitlement are already familiar.
Does the lab also cover ABAC?
Yes. Part of the track explores attribute-based decisions, their use cases and how they combine with an RBAC baseline.
Can it be taken as a team?
Yes. The lab works individually or as a team, with shared debriefs and questions.
How do exchanges with Ariovis experts work?
Interactive slots are scheduled in advance on Teams: participants arrive with their observations, hypotheses and questions.
Can companies organise a private session?
Yes. We then design a track tailored to the team’s context, level and objectives.
Can schools embed it into their curriculum?
Yes. The lab can plug into an IAM or cybersecurity module, with modalities defined with the institution.
Is there a single correct answer to the CorgiBOX case?
No. Several defensible answers exist. What matters is the quality of reasoning, the clarity of the model and the feasibility of the implementation.
Do participants really interact with a technical environment?
Yes. Active Directory, Linux, LDAP, MariaDB and a demonstration application are set up in the virtual IT Lab.
How long does lab access remain open?
Access duration depends on the selected package or session. It is confirmed before subscription.
CorgiBOX is still waiting for its access model.
The exports are ready. Every manager has their own version of the truth. A few former employees are probably still wandering through the directory, and someone most likely claims they need root access to read a file. The investigation is yours.
Bring your reasoning. We provide the Lab and the corgis.