Miguel.

San Francisco Bay Area

Who gets in, and what they can touch.

That question is the whole job, and it is the one I want to work on. I am Miguel, and I am moving toward identity and access management.

The five seconds I care about

Every login, every time

  1. 01

    Request

    Someone asks for something. A file, a console, a payroll record.

  2. 02

    Identify

    The system works out which account is making the claim.

  3. 03

    Authenticate

    Prove it. A password is a start. A second factor is the point.

  4. 04

    Authorize

    Being you is not the same as being allowed. Policy decides.

  5. 05

    Record

    Write down what happened, so the next person can reconstruct it.

Most breaches are not exotic. Somebody had access they should not have had, or kept access they should have lost.

Right now

I am already doing the unglamorous half of this.

Identity work does not start in a console. It starts with a person who cannot get in and needs to be somewhere in ten minutes.

Independent IT support practice

I run a flat rate support business for people and small offices across the peninsula. Windows and Mac, remote and on site, price agreed before I touch anything.

  • Accounts, lockouts, password and MFA recovery for people under real time pressure
  • Endpoint setup and cleanup, so I see what actually happens on a machine
  • Explaining a security decision to somebody who did not ask for one
  • Quoting, scheduling and standing behind my own numbers

Moving toward identity and access management

The support work is the on ramp, not the destination. The part I keep finding interesting is the access decision itself, who holds what, how it was granted, and how it gets taken away cleanly when someone leaves.

Building in public, starting now

The projects index opens shortly. I would rather publish work as it happens than hold it back until it looks finished.

Projects

The index is empty, and I am not going to pretend otherwise.

No filler, no rebranded tutorials. When something real ships, it goes up here with what it does and what it does not.

Open the index

$ ls ~/projects

total 0

 

$ cat PLAN.md

# ship it before it is impressive

# label lab work as lab work

# write down what broke

If you work in identity, I would like to hear from you.

Email me