← Back to the call brief
External24 Apr 2026· Crestline Wealth28% captured

Aegis / Crestline Wealth - Identity Module Deployment

43 turns · 11 min captured of 36 min stated?Only the captured portion exists in the database. The remaining 25 min of this call was never transcribed, so nothing said in it appears anywhere in this application.

Show facts?Markers in the left gutter show which facts the model built from each turn. Click a marker to open that fact's evidence — this is the citation trail running backwards.

Showing 43 of 43 turns · 30 turns were used as evidence for at least one fact.

  1. Rachel TorresAegisCloud0:04turn 0ASR 95%

    Alright, I think we've got everyone on — Derek, can you hear us okay?

  2. Derek OwensCustomer0:09turn 1ASR 97%

    Yeah, loud and clear. Good to go.

  3. Rachel TorresAegisCloud0:13turn 2ASR 91%

    Perfect. Okay so, welcome everyone — I'm Rachel Torres, Senior Account Manager here at Aegis, and I have Sofia Petrov with me today, she's one of our Senior Engineers on the Identity side of things. Sofia, you wanna say a quick hi?

  4. Sofia PetrovAegisCloud0:28turn 3ASR 94%

    Hey Derek, great to meet you. Really excited to be working with Crestline on this — Identity deployments in financial services are kind of my favorite thing to dig into, so, yeah, looking forward to the conversation.

  5. Derek OwensCustomer0:42turn 4ASR 96%

    Likewise, honestly. I've been looking forward to this one. We've had Protect and Detect running for a while now and the team's been happy, so adding Identity feels like a natural next step.

    +1Derek reports his team has been happy with Protect and Detect and sees Identity as a natural next step. · product capability

  6. Rachel TorresAegisCloud0:55turn 5ASR 89%

    That's great to hear, and yeah, that's — that's kind of the pattern we see with a lot of our financial services customers. They start with backup and threat monitoring and then once Identity is on the roadmap it sort of becomes a priority real fast, especially given the regulatory environment you're dealing with.

  7. Derek OwensCustomer1:15turn 6ASR 88%

    Exactly, yeah. We had our annual audit in February and the auditors flagged some gaps around privileged access management and MFA coverage across our admin accounts specifically. So that sort of lit a fire under us to get this moving.

  8. Rachel TorresAegisCloud1:31turn 7ASR 94%

    Okay, that's — that's actually super helpful context, Derek, thank you. So Sofia, that kind of shapes where we should probably start today, right?

  9. Sofia PetrovAegisCloud1:41turn 8ASR 90%

    Yeah, absolutely. So Derek, before I get into the actual deployment steps, can you give me a quick picture of your current identity landscape? Like, what are you using today for SSO or directory services, if anything?

  10. Derek OwensCustomer1:55turn 9ASR 91%

    Sure, so we're running Azure AD — or I guess it's Entra ID now, still getting used to that name — for our primary directory. We've got about 340 users total, around 40 of those are in elevated or admin roles. MFA right now is a mix of, uh, Nextera Authenticator and some legacy SMS-based auth that we've been meaning to deprecate for a while but just haven't gotten around to it.

  11. Sofia PetrovAegisCloud2:21turn 10ASR 97%

    Okay, great. And the SMS-based stuff — is that mostly for a specific group of users or is it kind of scattered across different departments?

  12. Derek OwensCustomer2:31turn 11ASR 96%

    Honestly it's a bit scattered. I think it's probably 20, maybe 25 users, a lot of them are in our wealth advisory group. Some of the senior advisors have been resistant to changing their auth flow, if I'm being honest.

  13. Sofia PetrovAegisCloud2:47turn 12ASR 92%

    Ha, yeah, that's — that's a very common story. We hear that a lot. The good news is Aegis Identity has some tooling around phased MFA policy rollout that makes that transition a lot smoother. You can essentially grandfather users into a migration window rather than doing a hard cutover, which tends to reduce the, uh, the pushback significantly.

  14. Derek OwensCustomer3:09turn 13ASR 90%

    Oh that's actually really good to know. My manager was asking about that specifically — like whether we'd have to do a big bang cutover. I was not looking forward to that conversation with the advisory team.

    +1Derek is relieved that a phased rollout avoids the big-bang cutover he feared. · onboarding and implementation

  15. Sofia PetrovAegisCloud3:23turn 14ASR 92%

    You can tell your manager that's a hard no on the big bang approach. We've got you.

  16. Rachel TorresAegisCloud3:31turn 15ASR 91%

    I love it. Okay so Sofia, do you want to walk Derek through sort of the high level deployment phases? I think that'll help frame the rest of the conversation.

  17. Sofia PetrovAegisCloud3:43turn 16ASR 91%

    Yeah, definitely. So, at a high level we're looking at three phases for a deployment like yours. Phase one is directory sync and SSO configuration — basically getting Aegis Identity talking to your Entra ID environment, setting up the SAML or OIDC connectors, depending on what your apps support. Phase two is MFA policy configuration and enrollment, which is where we'd handle that phased migration you mentioned. And then phase three is privileged access management, which sounds like it's actually going to be really important for you given what the auditors flagged.

  18. Derek OwensCustomer4:16turn 17ASR 92%

    Yeah, the PAM piece is huge for us. Can you tell me a bit more about what that looks like in practice? Like, are we talking just session recording, or is there more to it?

  19. Sofia PetrovAegisCloud4:29turn 18ASR 91%

    So it's quite a bit more than just session recording, which I think you'll find pretty compelling. Aegis Identity gives you just-in-time access provisioning for admin roles, so instead of users having standing admin privileges 24/7, they request elevated access for a specific window, it gets approved through a workflow, and then it auto-expires. You still get full session recording and audit logs, but the just-in-time piece is really what closes that standing privilege gap that auditors love to flag.

  20. Derek OwensCustomer4:59turn 19ASR 94%

    Okay, that's — yeah, that's exactly what we need. That's honestly the thing that's going to make my auditors happiest. We've had a few instances where terminated employees still had admin access longer than they should have because the offboarding process wasn't fully automated, and that's a conversation I don't want to have again.

    +1Derek says JIT PAM and automated offboarding are exactly what his team needs and will please auditors. · compliance reporting

  21. Sofia PetrovAegisCloud5:19turn 20ASR 97%

    The automated deprovisioning is actually one of the things our financial services customers consistently call out as like a — a real pain point solved. We can tie it directly into your HR system or your ticketing system so the moment an offboarding ticket is triggered, access is revoked automatically. No manual steps, full audit trail.

  22. Derek OwensCustomer5:39turn 21ASR 91%

    We're using ServiceNow for ITSM, would that work?

  23. Sofia PetrovAegisCloud5:43turn 22ASR 88%

    ServiceNow is one of our, uh, supported integrations out of the box, yeah. We've got a native connector.

  24. Derek OwensCustomer5:51turn 23ASR 93%

    Perfect. Okay I'm taking notes furiously over here.

    +1Derek responds enthusiastically, saying he is taking notes furiously. · other

  25. Rachel TorresAegisCloud5:54turn 24ASR 92%

    Ha, I love to hear it. So Derek, just while we're talking timelines — you mentioned the audit flagged some gaps. Do you have a target date in mind for when you want to have the Identity module fully deployed? Like, is there a next audit or a compliance checkpoint you're working toward?

  26. Derek OwensCustomer6:13turn 25ASR 90%

    Yeah, so our next internal compliance review is in August, and I'd really love to have everything buttoned up by end of July at the latest so we have time to generate some reports and actually show progress. Is that — is that a realistic window?

  27. Sofia PetrovAegisCloud6:30turn 26ASR 96%

    End of July is very doable. If we can get the kickoff scheduled within the next week or two, we're looking at roughly ten to twelve weeks of deployment work depending on how complex the app integrations get, and that puts us comfortably in the early July range for full deployment.

  28. Derek OwensCustomer6:48turn 27ASR 89%

    That's — yeah, that's better than I was expecting honestly. I had budgeted for like a four month process in my head.

    +1Derek is pleasantly surprised that the timeline is better than the four months he budgeted. · onboarding and implementation

  29. Rachel TorresAegisCloud6:57turn 28ASR 97%

    I mean, it can get longer if there are a lot of custom app integrations or if there's a lot of back and forth on MFA policy decisions, but for your environment as you've described it — 340 users, existing Entra ID foundation — we've got a really solid baseline to work from. Sofia's done probably a dozen of these in the financial services space at this point.

  30. Sofia PetrovAegisCloud7:21turn 29ASR 89%

    Closer to fifteen actually, but who's counting.

  31. Derek OwensCustomer7:25turn 30ASR 91%

    Ha, even better. Oh, one thing I did want to mention while I have you both — I saw the announcement about Aegis Comply v2 that went out earlier this month. We're not currently on the Comply module but the on-demand SOC 2 and the multi-framework reporting — that caught my eye. Is that something we could potentially layer in down the road?

  32. Rachel TorresAegisCloud7:47turn 31ASR 92%

    Oh, absolutely. And honestly the timing is great because the Identity deployment is going to generate a ton of the underlying audit data that Comply v2 pulls into those reports. Like, all of the access logs, the privileged session records, the MFA enrollment status — that all feeds directly into the compliance reporting engine. So by the time you're ready to look at Comply, you'll already have months of clean data to work with.

  33. Derek OwensCustomer8:15turn 32ASR 90%

    Oh that's a really good point, I hadn't thought about it that way. So it's not like starting from scratch with Comply, we'd already have a head start.

    +1Derek appreciates that Comply will have a head start because Identity generates the underlying audit data. · compliance reporting

  34. Rachel TorresAegisCloud8:25turn 33ASR 93%

    Exactly. And just so you know, Comply v2 has SOC 2, PCI DSS, HIPAA, and ISO 27001 all supported now as of the April launch. I know financial services customers often need to juggle multiple frameworks, so having all of that in one place on demand — no more waiting for quarterly report runs — it's pretty compelling.

  35. Derek OwensCustomer8:46turn 34ASR 93%

    Yeah, I'm going to bring that up with our Chief Compliance Officer. She's been asking about the SOC 2 reporting specifically. But let's — let's get Identity locked in first and then circle back on Comply. One thing at a time.

  36. Rachel TorresAegisCloud9:02turn 35ASR 89%

    Totally, that's the right approach. Okay so in terms of next steps — I'm going to send over a deployment plan document after this call that Sofia will put together, it'll have the three phases laid out with rough timelines, the integration checklist for the Entra ID connector and ServiceNow, and what we'll need from your side to get started. Does that work?

  37. Derek OwensCustomer9:25turn 36ASR 89%

    Yeah, that's perfect. If you can also include the MFA migration framework stuff Sofia mentioned — the phased rollout approach — that would be great because I'm going to want to share that with my manager before the kickoff.

  38. Sofia PetrovAegisCloud9:39turn 37ASR 93%

    I'll include a section on that specifically, and I'll flag the just-in-time PAM stuff too since that sounds like it'll be an important talking point for your audit preparation.

  39. Derek OwensCustomer9:50turn 38ASR 92%

    Awesome. This has been — yeah, this has been really helpful. I feel a lot more confident about the timeline than I did going into this call. I'll loop my manager in on the doc once I get it and then let's get that kickoff on the calendar.

    +1Derek says the call was really helpful and he feels more confident about the timeline. · onboarding and implementation

  40. Sofia PetrovAegisCloud10:08turn 39ASR 91%

    Sounds great. We'll aim to get the document to you by end of day Monday, and then we can do a quick kickoff call early next week if that works. Rachel, does that align with what you're thinking?

  41. Rachel TorresAegisCloud10:22turn 40ASR 92%

    Yep, that works perfectly on our end. Derek, I'll send a calendar invite with a few options for early next week. And as always, if anything comes up before then, don't hesitate to reach out — you've got my direct line. We're really excited to get this moving with the Crestline team.

  42. Derek OwensCustomer10:42turn 41ASR 92%

    Likewise, thanks so much Rachel, thanks Sofia. Talk soon.

  43. Sofia PetrovAegisCloud10:46turn 42ASR 97%

    Take care, Derek!