The platform
One migration path from discovery to validated cutover
PhaseArc is the technology layer that makes an identity migration visible and repeatable. It holds the inventory, the mapping decisions, the wave plan, the execution record, and the validation evidence in one place, so nobody has to reconstruct the project from spreadsheets and scripts.
What is the PhaseArc platform?
PhaseArc is an identity migration platform for organizations moving from Okta or Ping Identity to Microsoft Entra ID. It structures and automates repeatable migration work, from source inventory and object mapping through wave execution, validation, and the record of every change, while leaving target design, exception handling, and cutover decisions with the identity team.
Seven capabilities
What the platform does
Each capability produces something the next one depends on, which is what keeps a migration from drifting.
01
Discover and inventory
02
Normalize and map
03
Plan controlled waves
04
Execute repeatable work
05
Validate access and configuration
06
Prepare cutover and fallback
07
Record migration evidence
Delivery model
What PhaseArc does, what identity teams decide
Being explicit about this boundary is what makes the plan credible to a security review.
| Area | PhaseArc | Your identity team |
|---|---|---|
| Inventory | Collects and structures the source record. | Confirms what is in scope. |
| Mapping | Proposes treatment per object and flags gaps. | Approves the target design. |
| Naming and structure | Applies the agreed convention consistently. | Defines the convention. |
| Exceptions | Surfaces objects that cannot follow the standard treatment. | Decides how each is handled. |
| Waves | Builds the wave plan and tracks entry and exit criteria. | Approves each wave before it runs. |
| Execution | Runs prepared changes and records the outcome. | Authorizes the change window. |
| Validation | Generates validation tasks and captures results. | Accepts results and signs off. |
| Cutover | Prepares cutover and fallback steps. | Makes the cutover or fallback call. |
| Decommission | Reports on remaining dependencies. | Approves retirement of the source. |
Principles
How the platform behaves
- Nothing moves without a treatment recorded against it first.
- The source platform stays active until cutover is approved for that wave.
- Every wave has a fallback position defined before it runs.
- Validation results are captured as evidence, not as a verbal confirmation.
- Objects with no clean target equivalent are escalated as decisions, not silently skipped.
For the access model behind this, see migration security and controls.
Platform questions
What is an identity migration platform?
Does PhaseArc replace the identity team?
How is the scope of automation confirmed?
See the platform against your own estate
An assessment turns your source inventory into a mapped, sequenced migration plan with the exceptions named up front.