12
Financial Services
Banking, insurance and leasing — Evolveum MidPoint and 1IDM migrations, Oracle support and international-perimeter work
Projects
Enterprise IDM/IGA engagements across banking, energy, telecom, public sector, manufacturing and agribusiness. Named references first, then anonymised profiles where contractual confidentiality applies.
Talk to an architectAggregated picture of our delivered work. Each direction has concrete engagements behind it — some openly described below, many under NDA.
20
years of IDM expertise
39
clients across multiple markets
79
projects delivered
3
IDM / IGA platforms in core focus today
Industry distribution across the portfolio. The numbers indicate orders of magnitude — exact figures are refined as more case profiles become public.
12
Financial Services
Banking, insurance and leasing — Evolveum MidPoint and 1IDM migrations, Oracle support and international-perimeter work
5
Energy & Utilities
Oil & gas, power and petrochemicals — large Oracle IdM operations, MidPoint migration and HR-driven provisioning
5
Public Sector
Government, critical infrastructure and national funds — 1IDM, legacy Oracle adaptations and EU-mandated environments
5
Manufacturing & Industrial
Manufacturing, automotive, mining and construction — 1IDM and Oracle IdM at multi-entity scale
2
Transportation & Logistics
Passenger and cargo aviation, rail — IDM licence supply and technical support
3
Telecommunications
Oracle Identity Manager → Evolveum MidPoint migration at large-enterprise scale
3
Retail & Consumer Goods
Retail and agribusiness — Evolveum MidPoint and a sovereign IDM contour under import substitution
3
Technology & Services
Consulting, IT services and a global ride-hailing platform — SailPoint ISC and MidPoint
1
Healthcare & Life Sciences
Global pharmaceutical group — IT-role simplification on SailPoint IdentityIQ (GxP, 21 CFR Part 11)
Number of clients per IDM/IGA platform. See the dedicated service page for a deeper view.
9
clients
Oracle Identity Manager (OIM / OIG)
Long-term operations and managed migration to modern stacks (SailPoint, Evolveum MidPoint). Identigy does not sell new Oracle implementations — only operations and migration off the stack.
6
clients
Partner of Evolveum, active upstream contributor. Greenfield deployments, migrations from legacy IDM, multi-entity governance.
4
clients
On-prem IGA: implementation, evolution, version upgrades and IIQ → ISC migrations when the programme calls for it.
2
clients
SailPoint Identity Security Cloud
Cloud-native IGA: multi-year SaaS subscription delivered through Identigy for international clients — including a global mobility platform (inDrive) and an international agribusiness group.
1
clients
OneIdentity
Operations and migration from OneIdentity stacks (including into MidPoint or SailPoint) — full lifecycle from assessment to steady-state operations.
Full platform catalogue and our stance on each one is on the Identity Governance & Administration page.
Clients who agreed to be named in our public materials. Headline is the organisation; sector and platform details follow in each card.
Filter by platform — multiple selections allowed
Showing 24 of 24
What stands out
Gard is the world's leading marine and energy insurer and the top-tier Protection & Indemnity (P&I) club, headquartered in Arendal, Norway. The group runs 15 offices worldwide — across Europe, the Americas, the Middle East and Asia — with employees from 30+ nationalities, and insures roughly half the world's merchant fleet. Identigy delivered an enterprise identity governance (IGA) programme on SailPoint IdentityIQ: automated identity lifecycle (joiner / mover / leaver), an IT- and business-role model, access-certification campaigns and Segregation-of-Duties (SoD) controls. Governance was extended beyond employees to external consultants and service accounts. The corporate ERP served as the source of roles and org structure, and the solution reached legacy systems and applications with parameterised privileges across a distributed international perimeter. The engagement ran over several years.
Platform
SailPoint IdentityIQ
Automated
JML · access certification · SoD
Governed
employees · external consultants · service accounts
Engagement
multi-year (4+ years)
What stands out
«Cubes» is Identigy's own in-house identity governance (IGA) contour, built on Evolveum MidPoint (open-source). The principle is simple: we run the same IGA stack internally that we deploy for our clients, proving architectural decisions on our own infrastructure before they reach customer production. The contour covers a standardised joiner-mover-leaver lifecycle, access granted only through MidPoint with approval workflows, a self-service access-request portal, automatic revocation of unapproved entitlements and clean-up of leavers' access, role mining and an evolving role model, and centralised sign-in to all corporate services via Google SSO. The HR system is the source of truth; managed services include Google Workspace, Atlassian (Jira/Confluence), Google Drive, GitHub and Telegram. Policy changes are rolled out safely using MidPoint's simulation mechanism.
Platform
Evolveum MidPoint (open-source)
Functions
JML · self-service access requests · approvals · auto-revoke of unapproved access · role mining
Systems
HR (source of truth) · Google SSO · Atlassian · GitHub · Telegram
What stands out
inDrive is an international mobility and urban-services platform launched in 2013 around a distinctive direct-bargaining model — riders and drivers negotiate fares directly rather than accept an algorithmic rate. Legally headquartered in Mountain View, California, with its operational hub in Almaty, it operates in 1,000+ cities across 48 countries. Identigy implemented enterprise identity governance on SailPoint Identity Security Cloud (IDN) in two phases. Before the project, access was managed by hand across 42+ Google Sheets per country and department, with no unified identity lifecycle and no central HR. Phase 1 (03.2023 — 08.2023) brought up Zoho People as the trusted HR source and Google Workspace as the first target, with automated joiner/mover/leaver. Phase 2 (09.2023 — 11.2024) extended the perimeter to Jira and Jira Service Management, GitHub, Salesforce, Oracle NetSuite, the 1C platform, Figma and Tableau, adding a role model, access self-service, recertification and SoD controls. Governance spans not only employees but also contractors, recruiters and service accounts; custom connectors were built for GitHub and 1C. The partnership continues as an annual license subscription.
Integrated systems
~10 cloud (SaaS)
Access governance
42+ Google Sheets → single pane
Automated
JML · recertification · SoD
Confidentiality
For many programmes we cannot publish customer names or logos under contract. The cards below are anonymised — sector, platform, scale and outcomes only. Where it helps your procurement or architecture review, we can arrange a reference conversation with the customer's team, subject to their availability and a mutual NDA.
Industry and technical narrative without customer identification — the pattern we use when contractual confidentiality applies.
What stands out
A large state-owned bank engaged Identigy to deliver a production identity-governance (IGA) system on Oracle Identity Manager. Before the project, access was managed manually by each system's administrators, with no enterprise role model and no centralized password management. On OIM the team implemented an automated account lifecycle (joiner/mover/leaver), access requests with multi-step approval routing, audit and periodic certification, and detection of out-of-band changes with automatic rollback; the role model was built from the ground up through statistical role mining on a trusted HR source. Four target systems were brought under governance — the corporate directory and mail, the information-analytics system and the document-management system — several via custom connectors. The system passed acceptance testing and entered production (~9,000 users across a branch network).
Users
~9,000
Platform
Oracle Identity Manager
Coverage
4 systems + HR source · JML + role model + certification
Outcome
role model & JML automation from scratch (was manual)
What stands out
A global research-driven pharmaceutical group (~45,000 identities) engaged Identigy to simplify a sprawling IT-role model on its existing IGA platform and extend an end-to-end access process aligned to pharma regulation (GxP, 21 CFR Part 11). The team designed a structured role model — business roles with characteristic sub-roles and rule-based birthright assignment — and built a request-to-grant flow across self-service, governance and learning systems, with multi-step approvals and e-signature. An access-after-training control grants regulated roles only once the mandatory curriculum is complete, with daily checks and roll-back on non-completion; joiner/mover/leaver events and periodic recertification with escalation were automated.
Identities
~45,000
Platform
SailPoint IIQ · IT Role Simplification
Coverage
access-after-GxP-training + JML + recertification
What stands out
EU public-sector identity governance programme for a national health insurance authority. Delivered via Identigy's international hub into a compliance-driven public-sector perimeter; scope covers identity lifecycle, role model and the audit reporting expected from a national health insurance fund.
Platform
SailPoint
Sector
EU public-sector (national health insurance)
What stands out
EU public-sector identity governance programme for a national tax authority under the Ministry of Finance. Identity-lifecycle automation and access governance with the compliance and audit posture appropriate for an EU government agency. Delivered via Identigy's international hub.
Platform
SailPoint
Sector
EU public-sector (national tax authority)
What stands out
A national-scale retail bank engaged Identigy to deliver a production IGA platform on Evolveum MidPoint (open-source), replacing a legacy in-house, ERP-based access solution in which onboarding each new target system was slow and costly. On MidPoint the team implemented an automated account lifecycle (joiner/mover/leaver), access audit and periodic certification, and segregation-of-duties control, and rebuilt the role model from the ground up — roles assigned by conditions such as an employee's position level. Eight target systems were brought under governance, including the core banking system, card processing, the corporate directory and mail, and the HR source. The complex role model surfaced performance challenges resolved through joint engineering with the platform vendor. The system runs in production (~15,000 users) with ongoing development and third-line support.
Users
~15,000
Platform
Evolveum MidPoint (open source)
Coverage
8 systems · JML + certification + SoD
Outcome
fast onboarding of new systems
What stands out
A multi-business-unit mining group, then in an active phase of mergers and acquisitions, engaged Identigy for an access-governance audit and target-model design. Across a heterogeneous IT landscape with inconsistent practices and no centralized access governance, the team surveyed the group's core systems and designed the target access-management process from the ground up: a three-tier role model (RBAC) on a «location × organizational-structure» poly-hierarchy, anchored on the trusted HR source and spanning the directory, mail, ERP and HR systems. Deliverables included the access-governance concept, policy, regulations and statute, a role-formation and system-categorization methodology, and a vendor-neutral methodology for selecting an access-governance system — a ready, agreed foundation handed over ahead of any automation while the group restructured.
Coverage
thousands of staff
Outcome
role model + governance package + system-selection methodology
What stands out
The client, a large multinational organization operating in the manufacturing sector, needed to modernize its identity‑governance estate, which spanned a global directory, multiple subsidiary domains and critical HR/ERP, email and line‑of‑business applications. The project replaced a legacy commercial IGA suite with an open‑source identity‑governance platform, consolidating dozens of bespoke connectors into a handful of unified types and rebuilding the integration layer on an asynchronous message‑broker architecture. Both solutions ran in parallel during the cut‑over to guarantee service continuity, delivering a streamlined, regulator‑compliant architecture that reduced integration complexity and maintenance effort while supporting thousands of user identities.
Access SLA
Up to 10 working days → under 1 hour
Connectors
many bespoke → a few unified types
Scale
tens of thousands of employees · hundreds of target systems
Evolution
Oracle Identity Manager → Evolveum MidPoint
What stands out
The project involved a telecom operator’s nationwide retail subsidiary that needed to modernize its enterprise identity‑and‑access management platform built on a commercial IAM solution. The environment integrated Microsoft Active Directory, Exchange, Lync, a retail ERP system and point‑of‑sale workstations, with the parent company’s SAP HR database as the authoritative source. Enhancements refactored the ERP connector to enforce full‑name and personnel‑number consistency, added duplicate‑account detection and automatic removal, and introduced automated credential propagation for POS devices during password changes and store transfers. The resulting solution delivered consistent identity data across all connected systems and streamlined account‑lifecycle operations while supporting relevant data‑protection regulations.
Employees
~20,000
Platform
Oracle Identity Manager
Coverage
directory · mail · communications · 1С sales system · cashier workstations
Processes
automated JML + account dedup/consistency + credential management + custom connectors
What stands out
A telecommunications operator in the Central Asian region, part of a multinational telecom group, modernized its corporate access management infrastructure to align with group-level security standards while maintaining local regulatory compliance. The project focused on automating identity lifecycle management and role-based access control across six core systems: directory services, enterprise communications, billing platforms, and financial accounting. A custom integration component was developed for the 1C ERP module, enabling seamless provisioning within the unified framework. The solution was built on an enterprise IAM platform, establishing automated joiner-mover-leaver processes for approximately 600 employees. A key aspect involved securely extending the parent organization’s identity governance model across borders, enabling centralized oversight and connectivity between geographically dispersed IT segments, while preserving the subsidiary’s independent legal and operational status. The implementation included full integration of target systems, ensuring consistent policy enforcement and audit readiness under regional regulatory requirements. Project deliverables were formally accepted upon completion in 2019.
Users
~600
Platform
Oracle Identity Manager
Coverage
6 target systems · directory/mail/comms/billing/1С
Processes
automated JML + role model + custom 1С connector
What stands out
A large telecom operator (group headcount ~120,000) engaged Identigy, as a technical subcontractor, to implement automated access-rights management and segregation-of-duties (SoD) control on Oracle Application Access Controls Governor (AACG) over a corporate Oracle e-Business Suite R12 ERP (16 functional modules, from general ledger to payroll). The driver was Sarbanes–Oxley §404 compliance: SoD control had been manual, with no automated conflict analysis and no management of compensating controls. The team delivered what-if SoD analysis on every access request, automatic approval-chain build-up, a full lifecycle for the compensating-controls catalogue, user- and role-level control, and consolidated SoD-risk reporting for internal control and external auditors. The platform's stock functionality was extended with middleware on the customer's ITSM platform (two-way integration) and a deeply reworked ERP connector with 24 filters eliminating false positives. The solution passed three test cycles plus load testing and entered production.
Users
~120,000
Platform
Oracle AACG (GRC)
Coverage
corporate ERP · 16 modules · what-if SoD analysis + compensating controls
Outcome
SoD control automated for SOX-404 (was manual)
What stands out
The client is a nationwide public‑sector organization with a large employee base and a network of regional offices that processes personal data. Identigy acted as a technical subcontractor to deliver the regional rollout, line‑of‑business integration and trial‑operation hand‑over of an enterprise single‑sign‑on and centralized account‑management contour. The core used an Oracle Access Manager‑based unified authentication system with regional points and a hierarchical provisioning layer feeding Microsoft Active Directory from an HR source. The project replaced manual, paper‑based access requests with automated lifecycle provisioning (joiner, transfer, leave, re‑hire) and provided readiness assessments and training for each office. The rollout was completed on schedule and accepted in full.
Scale
federal public-sector organization — dozens of regional offices, 100,000+ accounts
Platform
Oracle Access Manager + Microsoft Active Directory — single sign-on and account management
Coverage
single sign-on (SSO) · centralized account management · line-of-business subsystems
Process
automated account lifecycle (joiner/mover/leaver) — replacing a manual one (paper approvals, weeks to fulfil)
Outcome
regional segments rolled out, integrated and handed over into trial operation (accepted by the customer)
What stands out
Sector: professional services. The firm required a sovereign identity and access‑management contour after losing its external authentication infrastructure. Identigy delivered an autonomous IAM stack based on open‑source components: a WebSSO solution (SAML/OAuth/OpenID), an identity‑governance engine for store, reconciliation and certification, and a directory service for federation. The solution covered 4 000 users and ~70 critical corporate applications, providing full lifecycle automation, access‑certification campaigns and a self‑service onboarding method. Delivered via Agile CI/CD with separate dev, QA and production environments, the contour was operational within weeks and gave the organization an auditable, vendor‑independent access‑management platform without licensing lock‑in.
Users
~4,000
Platform
Keycloak · MidPoint · OpenLDAP (open source)
Coverage
WebSSO federation of ~70 priority systems · access certification
Approach
autonomous contour · pilot in ~4 weeks
What stands out
A financial institution in the banking sector with approximately 11,000 employees faced growing operational and regulatory risks due to reliance on foreign identity management platforms, as geopolitical shifts and market exits disrupted long-term vendor support. The organization operated multiple legacy IAM systems, including a primary enterprise IAM platform and a corporate IGA solution, which required replacement to ensure compliance, reduce sanctions-related exposure, and enable in-house development capabilities. To address this, a strategic migration was executed toward an open-source identity governance platform, implemented over six months under a direct engagement. The solution encompassed end-to-end account lifecycle management across complex employment scenarios—joiners, movers, leavers, concurrent roles, maternity leaves, and emergency access blocks—supported by a re-engineered HR connector to handle multi-record employee data integrity and a high-performance email system integration meeting strict service levels. Three CI/CD-aligned environments were established, enabling robust testing and deployment cycles, while a self-service portal improved user autonomy. During transition, architectural controls ensured clear separation of duties across the coexisting IDM systems. Post-implementation, provisioning latency for core directory services dropped significantly, reducing processing time from hours to minutes. Ongoing support and incremental enhancements continued over the following two years, including remediation of integration edge cases.
Scale
~11,000 employees
Platform
Evolveum MidPoint (open source)
Account provisioning
account creation 2 hours → 15 minutes
Engagement
6-month implementation + 2-year support
What stands out
An organization in the transportation sector with a federal‑scale workforce of roughly 670 000 employees, more than 500 corporate information systems and over 800 000 annual access requests needed to replace a manual, multi‑step request process. A custom identity‑governance and administration solution was built on an open‑source stack (OpenIDM/OpenICF with a workflow engine and PostgreSQL) to provide automated account lifecycle, configurable approval routes, self‑service and periodic recertification. Integrated connectors linked the solution to the enterprise directory, mail platforms, service bus, IT service management tool and HR source. The pilot zone was delivered, accepted and entered operation in late 2015, though a full enterprise rollout was not pursued.
Scale
enterprise AD forest — dozens of domains, hundreds of thousands of accounts
Platform
OpenIDM / OpenICF (ForgeRock) — custom IGA
Coverage
directory · 2 mail platforms · ESB · ITSM · HR source
Process
~800,000 access requests/year — configurable approval routing (was manual)
Outcome
pilot phase designed, built and delivered
What stands out
An industrial holding with multiple subsidiaries implemented a group‑wide identity‑governance platform to enforce zero‑trust and least‑privilege principles across its digital estate. The project began by migrating the authoritative human‑resources data from a legacy in‑house system to a modern enterprise HR platform, synchronising the cut‑over with a payroll go‑live. Subsequent phases expanded the governance perimeter to include directory services, email, CRM, content‑management and access‑control systems, while continuously refining role models, workflow automation and service‑account lifecycle management. The solution now provides consistent access policies, reduces manual provisioning effort and supports compliance with relevant data‑protection and industry regulations.
Identity scale
tens of thousands of identities · multi-entity holding
HR migration
Legacy in-house HR → modern enterprise HR platform
Target systems
directory · mail · CRM · content management · access governance
What stands out
A financial institution in the Nordic-Baltic region, operating across multiple countries, required modernization of its identity and access management framework to support approximately 50,000 identities. The environment featured a highly heterogeneous IT landscape, including a legacy mainframe platform, enterprise directory services, and core banking applications. As part of the transformation, a comprehensive access management automation solution was implemented using an enterprise IAM platform, integrating with HR systems to enable end-to-end joiner-mover-leaver processes. The solution established a centralized identity model, automated provisioning and deprovisioning across critical systems, and introduced role-based access controls with approval workflows and employment-state validation logic. A key technical challenge involved bridging disparate target systems—particularly the mainframe environment—with differing account management paradigms, requiring hybrid automation and manual intervention workflows where full integration was unfeasible. The initiative was delivered incrementally over a 30-month period, aligning with strict financial regulatory requirements and enhancing audit readiness, operational efficiency, and access governance maturity.
Identities
~50,000
Platform
SailPoint IdentityIQ
Coverage
heterogeneous estate · mainframe (z/OS) + directory + core banking · HR-driven JML
Engagement
multi-year continuous development (2018–2020)
What stands out
The client, a systemically important commercial bank in the financial services sector, operates a large identity‑management contour built on an enterprise IAM platform serving over 36 000 identities and processing more than 1 000 access‑change requests each day. Under a multi‑year contract, the provider delivered continuous technical support and development: diagnosing and fixing defects, handling daily lifecycle and role‑assignment requests within defined SLAs, performing preventive maintenance and regular entitlement audits, and evolving the integration layer across heterogeneous banking systems. The solution maintained reliable operation under strict financial‑regulatory confidentiality requirements and was completed without any claims.
Scale
36,000+ identities
Throughput
1,000+ access-change requests per day
Platform
Oracle Identity Manager
Engagement
multi-year support (~3.5 years)
What stands out
A multinational energy organization with over 5,000 identities across multiple regional facilities partnered to modernize its enterprise identity governance environment. The initiative focused on upgrading a deeply customized legacy deployment of an enterprise IAM platform to its latest version, including migration to version 7.3, while extending core functionality beyond out-of-the-box capabilities. The solution introduced a dynamic role model driven by HR data, enabling automated provisioning and deprovisioning across a distributed infrastructure for employees, contractors, and service accounts. Key enhancements included lifecycle management, access recertification workflows for inter-site role changes, and drift detection across ten integrated systems. DevOps practices and CI/CD tooling were implemented to support continuous integration and long-term maintainability. The engagement ensured compliance with sector-specific regulatory requirements, strengthened audit readiness, and improved operational resilience through a scalable, automated identity framework.
Tenure
8 years of continuous development
Scale
5,000+ identities · multiple sites · 10 IT systems
Architecture
Dynamic matrix role model
What stands out
A national health-insurance payer — a central fund with regional branches — runs a single enterprise identity and access management (IAM) platform on SailPoint IdentityIQ, implemented and developed by Identigy as a subcontractor. The platform governs the full lifecycle of four identity types — employees, contractor staff, interns/auditors and system accounts — with automated joiner/mover/leaver, multi-step approval including a dedicated stage for privileged roles, segregation of duties (SoD), periodic recertification of entitlements by data owners, and detection of native (out-of-band) changes. Unified provisioning spans six connected systems, including ERP and the directory service, at a scale of 2,000+ accounts and ~1,100 users — with controlled privileged access to sensitive (medical) data under ISO/IEC 27001 and a first-category state-information-system regime. Implemented 2017–2018, upgraded to a newer platform release in 2021.
Accounts
2,000+
Integrated systems
6
National coverage
HQ + 5 territorial funds
What stands out
A national tax administration runs a single identity-governance platform (IGA) on SailPoint IdentityIQ, implemented and developed over several years by Identigy as a subcontractor. The platform governs the full lifecycle of four identity types — employees, interns, external contractors and system accounts — with automated joiner/mover/leaver, access self-service, dual certification of both entitlements and roles with escalation to unit managers, detection of native (out-of-band) access changes, and dormant-access suspension. Unified provisioning spans 30+ systems, including the directory service and the authoritative HR source, at a scale of 3,000+ identities and 50,000+ entitlements — under GDPR, ISO/IEC 27001 and applicable national cybersecurity requirements.
Identities under management
3,000+
Integrated systems
30+
Entitlements governed
50,000+
What stands out
An insurance organization with roughly 9 000 employees and over 19 000 internal and external users required a comprehensive identity‑governance solution. Identigy first deployed a commercial IGA platform to manage full account lifecycles, business roles for branches and agent channels, integrate with HR and directory services, and provide a self‑service portal. A subsequent proof‑of‑concept migrated the workload to the open‑source Evolveum MidPoint, delivering vendor‑independent governance. Ongoing support now covers connector development, role modeling, access‑approval workflows, segregation‑of‑duties policies, UI customization and reporting, ensuring regulatory compliance and streamlined access management across the enterprise.
Scale
17,000+ internal + 2,200+ external users
Platform
Evolveum MidPoint (open source)
Migration
One Identity Manager → Evolveum MidPoint (open source)
Engagement
full lifecycle — PoC → migration → direct support
Request references
We can prepare an extended reference under a specific scenario — with figures, architecture and a customer contact for verification against your project.
Write to info@identigy.com or use the consultation form on the Contact page.