01
Scoping call
Thirty minutes. Hierarchy, scale, constraints, and whether an audit is even the right first move. If it is not, we will say so. No credentials change hands on this call.
02
Read-only evidence collection
Scripted and non-intrusive. Run by your team, or by us with your team watching. Nothing is written, nothing is restarted, nothing is enrolled — and the script is yours to read first.
03
Analysis
Templates and permissions tested against the known escalation paths. Revocation, key protection, algorithm and validity hygiene tested against operational failure modes.
04
Risk-ranked report
Every finding with impact, exploitability and a specific remediation — ordered so that the first week of work removes the most risk.
05
Remediation walkthrough
A working session with your engineers. You can fix it yourselves, or we can. Either way you keep the documentation and the verification scripts.