Tracks
Pick the role you want to practise.
Each track is graded on the outcome and the process, with the control behind every decision.
Paths
Choose your path
Pick a path when you open the app and switch any time. Each path keeps its own progress, and all three are free.
IAM
Work the Pacific Crest service desk: joiners, movers and leavers, caller verification, access requests and compromised accounts. Tickets stay in the queue until they're actually fixed.
- IAM only
- Work the queue until it's clear, then a shift summary.
- IAM + GRC
- The same shift, then an optional audit of your own work.
GRC
Take the auditor's side: walkthrough, sampling, control testing, evidence, findings, risk ratings and management's response, with the NIST, HIPAA, ISO 27001, SOC 2 and PCI DSS requirements behind each decision.
- GRC only
- Audit Jordan Reyes, a simulated IAM analyst whose shift includes realistic mistakes.
- IAM + GRC
- Audit the shift you just worked on the desk.
PAMEarly access
Just-in-time elevation, break-glass accounts, credential rotation and privileged session review.
- In development
- PAM joins the paths as it's released.
IAM Ops
A full shift on the identity service desk at Pacific Crest Logistics, worked like a real ServiceNow queue.
Start the shiftWhat it covers
- Joiner, mover, leaver, rehire and leave-of-absence requests provisioned from the access matrix
- Caller verification before password, MFA and unlock actions
- Requestable access with documented approvals, and SoD enforcement
- Inactive-account sweeps, contractor expiry and service-account ownership
- Compromised-account containment and escalation
- Tickets stay open until resolved: requesters reply when a fix didn't work, and 13 possible follow-up incidents land in the same queue
GRC Audit
The same company from the auditor's side, for a Q3 SOX IT general controls cycle.
Open the audit deskWhat it covers
- Test new-user provisioning (APD-01) and timely terminations (APD-02) against sampled evidence
- Classify deficiencies: control deficiency, significant deficiency or material weakness
- Audit the change log of the IAM Ops shift just worked (APD-03)
- Assess access-review completeness (UAR-01) and rate an IT risk register
- Review a vendor SOC 2 Type II report and decide a policy exception
- Map controls to NIST 800-53, ISO 27001, SOC 2 and CMMC, and write the finding
PAMEarly access
Privileged access operations: elevation, emergency access and oversight.
In development
- Just-in-time role activation with approval and time limits
- Break-glass account use, monitoring and post-use review
- Credential rotation for shared and service credentials
- Privileged session review and escalation
Early access
Be first to try new companies and labs.
Get one email each time a new company, the PAM track or a platform lab is released. No payment details needed.

