- Zen IT Technologies
- Project Engagements
Some problems have an end.
Not every requirement needs an ongoing relationship. A migration finishes. An audit produces a document. A network gets deployed and then it works.
We take on defined projects in the areas we already work in. Scoped up front, with a written deliverable and a date it is done by.
How project work runs
-
Scoped before it starts.
You get a written scope that says what is included, what is not, and what you receive at the end. Discovery is part of the scoping, so the commitment reflects your environment rather than an assumption about it.
-
It finishes, and you own it.
Every project ends with something you keep: a working system, a written baseline, a design, or all three. You get the documentation, administrative access, runbooks and training to operate it, and if a question comes up later about something we built, ask.
-
No ongoing commitment by default.
If the work can be designed, implemented, documented and handed over, it can be a project. Work that needs continuous monitoring, maintenance, or judgment belongs in an ongoing engagement. We will tell you which it is.
Identity and access
-
Identity platform migration
Moving between identity platforms: JumpCloud to Okta, directory to Entra ID, or consolidating parallel platforms behind one authoritative source. Sequenced application by application with rollback at each stage.
You get: the migration completed, group model designed, applications federated, and a document covering what changed and why.
-
SSO and provisioning rollout
Federating your SaaS estate and automating the joiner, mover, and leaver lifecycle through SCIM. Prioritized by risk rather than by ease, so the systems holding code, customer data, and money are done first.
You get: applications federated, lifecycle flows running from your HR system, and the reporting that proves the process is running.
-
Access review
A point-in-time review of who holds what across your platforms, including the grants that never went through a process. Standing privilege identified, a group model designed to replace individual assignment, and a review cadence handed to whoever will own it.
You get: an entitlement inventory, a remediation log, and a documented process. The artifacts an auditor asks for.
-
Zero Trust network access migration
Moving remote access from VPN or a legacy platform to an identity-aware access model, including migration between Zero Trust providers and re-federating access policies against a new identity source.
You get: access policies migrated, applications reachable through the new model, and the policy set documented.
-
API authorization design
Custom authorization servers for your own customer-facing APIs: scope and namespace design, token model, and consent behavior, documented for the engineering team that will own it.
You get: the authorization server built and a document your engineers can work from.
Email infrastructure
-
Deliverability audit
An assessment of every sending source, authentication record, tracking domain, and reputation signal you have. Diagnostic rather than remedial. It tells you what is wrong and what it will take to fix.
You get: a written baseline with prioritized findings, whether or not remediation work follows.
-
Sending architecture design and rebuild
Separating transactional, product, marketing, and outreach mail across dedicated subdomains with independent reputation. Authentication rebuilt, high-risk sending isolated, new subdomains warmed, and monitoring configured.
You get: the architecture implemented, and a monitoring regime your marketing team can run independently.
-
DMARC enforcement
Moving from p=none to enforcement without dropping legitimate mail. Every sending source identified from aggregate report data before the policy tightens.
You get: enforcement reached, sources documented, and reporting in place.
Network and infrastructure
-
Wi-Fi survey and deployment
Predictive RF survey, access point placement, channel and transmit-power planning, and controller configuration. For new offices, floor expansions, or environments where the existing deployment generates constant complaints.
You get: the survey, the design, the deployment, and a documented channel plan that survives someone else touching it.
-
Firewall assessment, hardening and upgrade planning
Configuration, exposure and policy review; firmware and management-plane assessment; remediation of unsafe configuration; and a sequenced upgrade plan where required.
You get: a hardened configuration, prioritized findings, documented policy and an upgrade plan where needed.
-
Core network services
Internal time and name resolution built properly: dedicated appliances, DHCP option rollout across sites, and upstream configuration. Unglamorous, and the cause of a surprising share of authentication and certificate failures.
You get: the services deployed across sites, with a runbook.
Endpoint management
-
Endpoint management rollout
MDM deployment and configuration: enrollment, baseline policy, patch and update posture, and integration with your identity platform. This includes migrations between management platforms and building around security tooling that does not natively support your chosen platform.
You get: the fleet enrolled and under policy, with the baseline documented.
-
EDR configuration review and remediation
Endpoint detection platforms generating alert volume nobody can triage, or blocking legitimate software after an OS update. Fleet-wide analysis, exclusion policy designed properly rather than per-alert, and vendor escalation where the platform is at fault.
You get: alert volume reduced to something a human can act on, with the exclusion policy documented and defensible.
Platforms, integration and compliance
-
Google Workspace and Microsoft 365 configuration and migration
Tenant configuration, security baselines, license segmentation, delegation and admin role design, and migrations between platforms.
You get: the configuration implemented against a documented baseline.
-
Workplace automation
Scripted automation across your workplace platforms: signature deployment, provisioning glue, HR system data extraction, and the reporting nobody has time to assemble manually.
You get: the automation running, with the code and documentation handed over.
-
Compliance readiness review
A structured review of the technical controls and evidence required for SOC 2 or ISO/IEC 27001, identifying gaps between the environment you have today and the applicable technical controls and evidence relevant to your scope.
You get: a prioritized remediation plan your team can execute internally or with us.
Not listed?
The examples above are the projects we are asked for most often, not a complete list. If you have a defined technical problem with a clear outcome that can be implemented, documented and handed back to your team, talk to us.
When ongoing work makes more sense
A project suits a defined problem with an end. It is less suitable when the requirement is continuous judgment or when the real need is someone who holds the whole estate and notices what is drifting. When the need is continuous architecture and senior technical judgment rather than a defined deliverable, fractional IT architecture is usually the better model.
If you find yourself scoping a third project in a year, the underlying need is probably continuous rather than episodic. We will say so.
Tell us what you are trying to fix.
A 30-minute call with Jonny to scope it. If it is a project, you get a written scope. If it is not, we will tell you what it actually is.