SECURITY ARCHITECTURE & IMPLEMENTATION
SECURITY ARCHITECTURE & IMPLEMENTATION
Avalon connects your existing applications and directories to a modern identity platform so your agency can prove, not just claim, that the right people have the right access, and no one else does.
Avalon wires your agency's directories, PIV/CAC credentials, and applications into one governed identity system, so every login is phishing-resistant, every account lifecycle is automated, and every access decision is logged and auditable.
THE PROBLEM & THE APPROACH
The Challenge
Our Approach
Fragmented identity is a mission, compliance, and cost risk at once: compromised credentials remain the leading initial-access vector, orphaned accounts and missing MFA are perennial FISMA and IG findings, and manual account administration eats ISSO labor that automation could eliminate.
Avalon inventories every identity store and application, then wires them into one governed identity platform with phishing-resistant authentication, automated account lifecycle, and logged access decisions, a single system an auditor can actually examine.
Federal identity is unusually complex: decades-old applications built on local accounts and Kerberos can't natively consume a modern federated login, and any new platform has to interoperate with the world's largest smart-card credential program rather than starting greenfield.
Avalon designs a per-application integration strategy, SAML/OIDC federation where apps support it, a gateway or delegation pattern for legacy systems that can't, so PIV/CAC and FIDO2 authentication extend to applications, not just the desktop login.
OMB M-22-09 set enterprise identity and phishing-resistant MFA as government-wide requirements, and DoD's Zero Trust Strategy makes the identity pillar foundational to 91 target-level activities due by the end of FY2027, deadlines that arrive faster than agency staffing can absorb.
Avalon delivers through a wave-based application-onboarding model with per-app runbooks, so progress toward the mandate is countable, reportable, and doesn't wait on a hiring cycle.
Deprovisioning is still a manual ticket at most agencies, a separated employee's account found still active is the single most common trigger that unlocks automation budgets, and DoD is retiring the paper DD Form 2875 process on a dated timeline.
Avalon connects the authoritative HR source to the identity system so joiner-mover-leaver events happen automatically, replacing manual request forms with the automated ICAM workflow the deadline requires.
CORE CAPABILITIES
Inventorying every identity store and account, then standing up or hardening the enterprise identity provider that everything else depends on.
Onboarding applications to the identity provider in waves and automating the account lifecycle auditors actually check.
Producing the control evidence an authorization package needs and the bounded privileged-access controls agencies can act on now.
OUR PROCESS
Access provisioning for Avalon staff, stakeholder interviews, identity-store and application inventory, account-hygiene analysis, and review of existing SSP/POA&M and prior audit findings. (2–4 weeks)
FICAM-aligned target design, assurance-level selection per SP 800-63-4, platform validation against what the agency licenses, and wave sequencing agreed with the ISSM or ZT PMO. (2–4 weeks)
Identity provider deployment or hardening, PIV/CAC and FIDO2 authentication policy, conditional access baseline, directory cleanup, and pilot integration of 2–3 representative applications. (4–8 weeks)
Wave-based integration of typically 5–15 applications per wave, JML and provisioning automation, legacy-app strategies executed, and per-app runbooks and evidence capture. (6–20+ weeks, scales with app count)
Knowledge transfer, admin training, O&M runbook, final evidence package, and a closeout brief mapping delivered work to POA&M items and zero trust reporting metrics. (2–4 weeks)
WHY AVALON
6
Federal Frameworks Addressed
Founder-Level ICAM Architecture
On a $400K component-level integration, a large systems integrator staffs mid-level engineers under program-office overhead. At Avalon, the buyer's questions about conditional access policy or a legacy app's auth pattern are answered by the person configuring it.
The ICAM architect is in the engagement from discovery through the final onboarding wave, not handed off to junior staff after the sale.
HUBZone status lets a contracting officer award directly at sizes large integrators can't chase economically, and Avalon can start in weeks, not the quarter-plus a large SI needs to mobilize.
Every integration ships with an 800-53-mapped evidence package built for direct SSP and POA&M ingestion, because Avalon's catalog spans both the engineering and the authorization side.
Avalon does not resell identity platform licenses, so architecture recommendations carry no margin conflict, the agency's own tenancy, integrated cleanly.
FREQUENTLY ASKED
Straight answers about scope, timelines, and what identity integration will, and won't, get you.
Talk to Our Team →6
Federal Frameworks Addressed
No. That line gets drawn clearly, not just when asked. This service implements phishing-resistant MFA and automated account lifecycle management aligned to NIST SP 800-53 IA-2/AC-2, producing an evidence package suitable for inclusion in your authorization documentation and for closing related POA&M items, subject to your agency's independent assessment. The assessment and the authorization decision remain separate steps owned by your Authorizing Official.
Licensing is not integration. The gap between "we have Entra ID" and "our 40 applications enforce phishing-resistant MFA with automated deprovisioning" is exactly this service, and it's the gap your Zero Trust Maturity Model identity-pillar score reflects.
Some applications can't federate natively, that's why the methodology includes a per-app legacy strategy (gateway, delegation, or documented risk acceptance) and a pilot wave before anything mission-critical moves. Nothing cuts over without the application owner's tested sign-off.
We'd point you to the methodology and the people: FICAM-aligned architecture, NIST SP 800-63-4 assurance-level selection, and the specific platform certifications our architects hold. The engagement model is also built for exactly this concern, a fixed-price assessment sized so your exposure is one small task order before committing to integration waves.
Not a department-wide enterprise program today, and we say so upfront. Avalon is sized for component and bureau-level engagements, roughly 15–40 applications, one identity platform, that enterprise integrators routinely under-serve because the deal size doesn't clear their overhead.
A single-bureau engagement with one identity provider and 15–40 applications typically runs 4–7 months end to end. The entry-point readiness assessment alone runs 4–8 weeks.
PIV at the desktop login does not mean phishing-resistant authentication at each application, per-application enforcement is the actual requirement, and the actual gap this service closes.
Talk to Avalon about scoping an ICAM readiness assessment or an identity integration engagement for your agency.