Functional support
- Administrator assistance
- Recertification campaigns
- Business user guidance
An IAM platform does not stop at go-live. Identity sources evolve, applications change, connectors fail and business requirements continue to move.
Ariovis supports the functional and technical operation, incident resolution, maintenance, monitoring and continuous improvement of IAM, IGA, Access Management, CIAM and PAM environments. In French, this scope is often referred to as “RUN IAM”.
IAM operations are more than a ticketing channel. They combine business expertise, platform knowledge, technical monitoring and continuous improvement.
An IAM support offering that only acknowledges tickets resolves nothing. The client expects Ariovis to intervene, restore an acceptable state, and then durably eliminate the underlying cause.
We explicitly distinguish three commitments: acknowledgement / response time, service restoration time, and eradication (root cause resolution). Each answers a different question and is contracted separately.
The matrix below illustrates values previously proposed by Ariovis for critical and major incidents. It is a starting point for contractual negotiation.
Ariovis does not only commit to acknowledging a ticket. Depending on the contract, Ariovis can also commit to service restoration targets and a defined path to permanent resolution.
| Priority | GTI | GTR | Eradication | Post-mortem |
|---|---|---|---|---|
P1 Critical incident | 2 hours | 8 hours | 10 business days | 3 business days after restoration |
P2 Major incident | 4 hours | 24 hours | 20 business days | On request |
A service commitment cannot be read in isolation. It relies on an environment, service hours, access, and shared responsibilities. Here are the conditions to clarify before any figure is committed.
Ariovis operates its own support platform, with a single entry point and differentiated processes according to request type. It is the operational foundation of the service.
Not all requests follow the same SLA. Incident SLAs do not apply to service requests.
The Ariovis support platform lets you raise and follow requests at any time. This continuous availability is independent from staffed intervention hours.
Ariovis has already proposed a 9 a.m.–6 p.m. staffed support model with a dedicated team. This is one available coverage model, not the only formula.
Extended hours, on-call, smarthands or 24/7 monitoring can be part of a specific contractual scope. They are agreed case by case.
The client keeps a single point of contact. Behind that entry point, Ariovis mobilises multiple layers of expertise depending on complexity.
Ariovis does not solely commit to the fix timeline for a product defect that depends entirely on the vendor. Ariovis owns the escalation, the service restoration and the communication.
Good IAM monitoring does not just display green lights. It detects signals, qualifies them and triggers actions.
Non-incident requests follow a distinct cycle. The indicative timelines below illustrate values already used in contracts, and are clearly distinct from incident SLAs.
These timelines cover the qualification and kick-off of service and change requests. They must not be confused with the response and restoration SLAs applicable to incidents.
enIAM operations need clear roles. Depending on the contract, Ariovis mobilises a set of functions dedicated to service management and delivery.
The quarterly frequency is an example, not a requirement. Cadence is tuned to service criticality and contractual scope.
These KPIs are examples. The effective set depends on service maturity, platform and client priorities. Historical performance values are not fabricated.
A good service analyses what happens, captures lessons and reduces the incident surface. Ariovis embeds a structured proactive stream in the service.
An annual version upgrade cycle can be included in some contracts. It is not automatically included in every offering.
Operations are prepared during the build. The Ariovis support manager is engaged before go-live, not after. This timeline shows the typical build-to-run transition.
A selection of representative IAM operations engagements. Scopes are described in strict respect of contractual confidentiality.
Sensitive migration of an IGA platform, skills transfer and long-term managed operations.
Takeover of a platform with too many incidents, no roadmap and limited internal autonomy. Stabilisation, pipeline restructuring and continuous improvement.
Realignment of a multi-entity IAM programme, improved velocity, clearer priorities and stabilised operations.
IAM landscape rationalised around Entra ID, progressive decommissioning of components and simplified operations.
Takeover of PAM programmes, clarified usage, application onboarding and re-mobilisation of the setup.
Anonymized references. No client is named without written authorization.
Our operations and consulting teams are spread across four locations. A single contract can mobilise several sites depending on skills, escalation level and service organisation.
Steering, service governance and client relationship.
Consulting, technical expertise, integration and complex escalations.
Technical and consulting expertise, evolutions and platform support.
Team particularly focused on managed operations and managed services for Benelux, Switzerland and Germany.
Locations are not silos. The same client can be served by Paris for governance, Bordeaux for expertise and Brussels for managed operations.
IAM operations extend our integrator craft and prepare — where relevant — the transition to a fully managed identity service (IAM managed services). For a broader picture, explore our integrator approach, our managed services offering and our locations map.
IAM operations cover all the activities that keep an identity and access management platform running: functional and technical support, incidents, corrective and evolutive maintenance, flow monitoring, version management and continuous improvement.
TMA (third-party application maintenance) is a contractual model mostly focused on corrections and evolutions, often driven by work units. MCO (maintenance in operational conditions) covers the continuous availability of a system. Ariovis IAM operations is a broader service combining support, MCO, corrective and evolutive maintenance, monitoring and continuous improvement, with dedicated governance.
L2 brings functional and technical IAM expertise: workflows, connectors, configurations. L3 brings product and build-team expertise: advanced fixes, regressions, pre-production and production rollout. Ariovis can cover both levels and drives the vendor escalation when needed.
Response time is the maximum delay for an actual intervention on the incident. Service restoration time is the maximum delay to restore an acceptable state — through a fix, a workaround or a vendor escalation that enables restoration.
No. Depending on the contract, Ariovis can also commit to service restoration and to a defined path to permanent resolution. This is what distinguishes real IAM operations from a basic first-level support desk.
The clock starts when the incident is properly declared through the contractual channel with the correct priority. It is paused when the expected action depends on a third party (client, hosting provider, vendor) and resumes when that action is provided.
Eradication is the durable removal of the incident’s root cause, after service restoration. It may require a vendor patch, a configuration change, an evolution or a procedure change.
It is a structured analysis delivered after a major (P1) incident. It documents the origin, timeline, impact, workaround, corrective action and non-recurrence measures. Ariovis delivers it within a maximum of 3 business days after restoration.
Yes. The Ariovis portal lets you raise and follow requests at any time. Portal availability is independent from staffed intervention hours, which are defined contractually.
Not by default. Ariovis has proposed a 9 a.m.–6 p.m. staffed support model with a dedicated team. Extended hours, on-call and 24/7 monitoring are part of a specific contractual scope.
Ariovis opens and follows the vendor ticket, submits evidence, drives escalation until a fix is delivered and consolidates communication to the client. The client keeps a single point of contact.
Yes. We regularly take over IAM platforms built by other integrators. The takeover starts with a state audit, an access inventory, a review of existing documentation, then a hypercare phase before full handover.
Yes. Our approach is vendor-agnostic. We operate Netwrix Identity Manager, Ping Identity, Entra ID, Keycloak, Axiomatics, Netwrix Privilege Secure, Keeper and existing CyberArk environments, among others.
By combining execution metrics (success, failures, duration, volume), threshold alerts and automated ticket creation in the support portal. Depending on scope, alerts can create a qualified ticket directly.
By involving the support manager before go-live, documenting extensively, organising a hypercare period, formalising the handover, and starting continuous improvement from day one of operations.
It presents incidents for the period, SLA compliance, recurring causes, corrective actions, changes, versions, recommendations, improvements, risks and capacity consumption.
By opening a problem record, investigating the root cause, building an eradication action and validating non-recurrence. This is part of the proactive operations stream.
It can be included in some contracts as an annual cycle. It is not automatically included in every offering and is explicitly contracted.
Yes. Ariovis has teams in Paris, Châtillon (Hauts-de-Seine) and Bordeaux (Nouvelle-Aquitaine). These teams contribute to consulting, integration, L2/L3 support and platform improvement.
The Ariovis Brussels team is particularly focused on managed operations and managed services. It covers Benelux, Switzerland and Germany, in close coordination with the French teams.
Let’s talk. A first, no-commitment discussion helps qualify your context, the current maturity of the service, and the priorities of the next milestone.