Skip to main content

IAM/IGA Project Portfolio

Evidence over slogans

Enterprise IDM/IGA engagements across banking, energy, telecom, public sector, manufacturing and agribusiness. Named references first, then anonymised profiles where contractual confidentiality applies.

Talk to an architect
Portfolio

The portfolio at a glance

Aggregated picture of our delivered work. Each direction has concrete engagements behind it — some openly described below, many under NDA.

  • 20

    years of IDM expertise

  • 39

    clients across multiple markets

  • 79

    projects delivered

  • 3

    IDM / IGA platforms in core focus today

Industries

Where we deploy IDM/IGA

Industry distribution across the portfolio. The numbers indicate orders of magnitude — exact figures are refined as more case profiles become public.

12

Financial Services

Banking, insurance and leasing — Evolveum MidPoint migrations, Oracle support and international-perimeter work

5

Energy & Utilities

Oil & gas, power and petrochemicals — large Oracle IdM operations, MidPoint migration and HR-driven provisioning

5

Public Sector

Government, critical infrastructure and national funds — legacy Oracle adaptations and EU-mandated environments

5

Manufacturing & Industrial

Manufacturing, automotive, mining and construction — Oracle IdM at multi-entity scale

2

Transportation & Logistics

Passenger and cargo aviation, rail — IDM licence supply and technical support

3

Telecommunications

Oracle Identity Manager → Evolveum MidPoint migration at large-enterprise scale

3

Retail & Consumer Goods

Retail and agribusiness — Evolveum MidPoint IGA deployments

3

Technology & Services

Consulting, IT services and a global ride-hailing platform — SailPoint ISC and MidPoint

1

Healthcare & Life Sciences

Global pharmaceutical group — IT-role simplification on SailPoint IdentityIQ (GxP, 21 CFR Part 11)

Platforms

What we actually run

Number of clients per IDM/IGA platform. See the dedicated service page for a deeper view.

  • 9

    clients

    Oracle Identity Manager (OIM / OIG)

    Long-term operations and managed migration to modern stacks (SailPoint, Evolveum midPoint). Identigy does not sell new Oracle implementations — only operations and migration off the stack.

  • 6

    clients

    Evolveum midPoint

    Partner of Evolveum, active upstream contributor. Greenfield deployments, migrations from legacy IDM, multi-entity governance.

  • 4

    clients

    SailPoint IdentityIQ

    On-prem IGA: implementation, evolution, version upgrades and IIQ → ISC migrations when the programme calls for it.

  • 1

    clients

    SailPoint Identity Security Cloud

    Cloud-native IGA: multi-year SaaS subscription delivered through Identigy for an international mobility platform (inDrive).

  • 1

    clients

    OneIdentity

    Operations and migration from OneIdentity stacks (including into midPoint or SailPoint) — full lifecycle from assessment to steady-state operations.

Full platform catalogue and our stance on each one is on the Identity Governance & Administration page.

References

Named case profiles

Clients who agreed to be named in our public materials. Headline is the organisation; sector and platform details follow in each card.

Filter the portfolio — multiple selections allowed

Showing 24 of 24

Filter by platform

Identigy (internal)

Evolveum MidPoint
Sector
In-house IGA contour (IT consulting · IDM/IGA)
Scale
Identigy staff, service access and corporate services
Period
Since 2025
Identigy role
Building and running Evolveum MidPoint as our own in-house IGA contour — the same open-source stack we deploy for clients

What stands out

«Cubes» is Identigy's own in-house identity governance (IGA) contour, built on Evolveum MidPoint (open-source). The principle is simple: we run the same IGA stack internally that we deploy for our clients, proving architectural decisions on our own infrastructure before they reach customer production. The contour covers a standardised joiner-mover-leaver lifecycle, access granted only through MidPoint with approval workflows, a self-service access-request portal, automatic revocation of unapproved entitlements and clean-up of leavers' access, role mining and an evolving role model, and centralised sign-in to all corporate services via Google SSO. The HR system is the source of truth; managed services include Google Workspace, Atlassian (Jira/Confluence), Google Drive, GitHub and Telegram. Policy changes are rolled out safely using MidPoint's simulation mechanism.

  • Platform

    Evolveum MidPoint (open-source)

  • Functions

    JML · self-service access requests · approvals · auto-revoke of unapproved access · role mining

  • Systems

    HR (source of truth) · Google SSO · Atlassian · GitHub · Telegram

Sector
Ride-hailing · mobility (international platform)
Scale
~3,000 identities · ~10 cloud (SaaS) target systems · 4 identity types (employees, contractors, recruiters, service accounts)
Period
03.2023 — 11.2024 (two-phase implementation)
Identigy role
Enterprise IGA implementation on SailPoint Identity Security Cloud, delivered in two phases

What stands out

inDrive is an international mobility and urban-services platform launched in 2013 around a distinctive direct-bargaining model — riders and drivers negotiate fares directly rather than accept an algorithmic rate. Legally headquartered in Mountain View, California, with its operational hub in Almaty, it operates in 1,000+ cities across 48 countries. Identigy implemented enterprise identity governance on SailPoint Identity Security Cloud (IDN) in two phases. Before the project, access was managed by hand across 42+ Google Sheets per country and department, with no unified identity lifecycle and no central HR. Phase 1 (03.2023 — 08.2023) brought up Zoho People as the trusted HR source and Google Workspace as the first target, with automated joiner/mover/leaver. Phase 2 (09.2023 — 11.2024) extended the perimeter to Jira and Jira Service Management, GitHub, Salesforce, Oracle NetSuite, the 1C platform, Figma and Tableau, adding a role model, access self-service, recertification and SoD controls. Governance spans not only employees but also contractors, recruiters and service accounts; custom connectors were built for GitHub and 1C. The partnership continues as an annual license subscription.

  • Integrated systems

    ~10 cloud (SaaS)

  • Access governance

    42+ Google Sheets → single pane

  • Automated

    JML · recertification · SoD

Confidentiality

For many programmes we cannot publish customer names or logos under contract. The cards below are anonymised — sector, platform, scale and outcomes only. Where it helps your procurement or architecture review, we can arrange a reference conversation with the customer's team, subject to their availability and a mutual NDA.

Under NDA

Anonymised case profiles

Industry and technical narrative without customer identification — the pattern we use when contractual confidentiality applies.

Banking

Oracle Identity Manager
Scale
bank · several target systems + HR source
Period
2010s
Identigy role
Full-cycle IGA implementation on Oracle Identity Manager

What stands out

A large bank engaged Identigy to deliver a production identity-governance (IGA) system on Oracle Identity Manager. Before the project, access was managed manually by each system's administrators, with no enterprise role model and no centralized password management. On OIM the team implemented an automated account lifecycle (joiner/mover/leaver), access requests with multi-step approval routing, audit and periodic certification, and detection of out-of-band changes with automatic rollback; the role model was built from the ground up through statistical role mining on a trusted HR source. Several target systems were brought under governance — the corporate directory and mail, the information-analytics system and the document-management system — several via custom connectors. The system passed acceptance testing and entered production (thousands of users across a branch network).

  • Scale

    banking contour

  • Platform

    Oracle Identity Manager

  • Coverage

    several systems + HR source · JML + role model + certification

  • Outcome

    role model & JML automation from scratch (was manual)

Global pharmaceutical group

SailPoint IdentityIQ
Scale
global pharmaceutical group
Period
2010s
Identigy role
IT Role Simplification on SailPoint IIQ

What stands out

A global research-driven pharmaceutical group engaged Identigy to simplify a sprawling IT-role model on its existing IGA platform and extend an end-to-end access process aligned to pharmaceutical industry regulation. The team designed a structured role model — business roles with characteristic sub-roles and rule-based birthright assignment — and built a request-to-grant flow across self-service, governance and learning systems, with multi-step approvals and e-signature. An access-after-training control grants regulated roles only once the mandatory curriculum is complete, with daily checks and roll-back on non-completion; joiner/mover/leaver events and periodic recertification with escalation were automated.

  • Scale

    global pharmaceutical group

  • Platform

    SailPoint IIQ · IT Role Simplification

  • Coverage

    access-after-training + JML + recertification

EU public-sector (national health insurance)

SailPoint IdentityIQ
Scale
Thousands of identities · national public health insurance
Period
Multi-year engagement
Identigy role
Multi-year identity governance programme via Identigy's international hub

What stands out

EU public-sector identity governance programme for a national health insurance authority. Delivered via Identigy's international hub into a compliance-driven public-sector perimeter; scope covers identity lifecycle, role model and the audit reporting expected from a national health insurance fund.

  • Platform

    SailPoint

  • Sector

    EU public-sector (national health insurance)

EU public-sector (national tax authority)

SailPoint IdentityIQ
Scale
National tax authority · EU
Period
Multi-year engagement
Identigy role
Multi-year identity governance programme via Identigy's international hub

What stands out

EU public-sector identity governance programme for a national tax authority under the Ministry of Finance. Identity-lifecycle automation and access governance with the compliance and audit posture appropriate for an EU government agency. Delivered via Identigy's international hub.

  • Platform

    SailPoint

  • Sector

    EU public-sector (national tax authority)

Marine & energy insurance (P&I club)

SailPoint IdentityIQ
Scale
1,000+ users · global office network
Period
Multi-year engagement (2016—2020)
Identigy role
Enterprise IGA implementation on SailPoint IdentityIQ

What stands out

A global Protection & Indemnity (P&I) insurer in the marine and energy sector engaged Identigy to implement an enterprise identity governance and administration (IGA) programme. The initiative centred on a scalable IGA platform to automate core identity lifecycle processes—onboarding, role changes, and offboarding—across a distributed international environment. A unified role model, aligned with both IT and business functions, was established using the corporate ERP as the authoritative source for organisational structure and role definitions. Governance was expanded to include not only employees but also external consultants and service accounts, strengthening compliance and control. Access certification campaigns and Segregation of Duties (SoD) policies were institutionalised to support regulatory requirements. The solution integrated with legacy systems and applications across the global perimeter, enabling consistent enforcement of parameterised access rights. The multi-year programme delivered sustained improvements in access transparency, operational efficiency, and regulatory alignment.

  • Platform

    SailPoint IdentityIQ

  • Automated

    JML · access certification · SoD

  • Governed

    employees · external consultants · service accounts

  • Engagement

    multi-year (4+ years)

Oil & gas

An OpenIDM/OpenICF (ForgeRock)-based IGA platform · migration from Oracle Identity Manager
Scale
corporate directory (1,000+ accounts) · ERP/accounting systems · corporate mail · roughly 800+ identities
Period
2019
Identigy role
Migration Oracle IDM → an OpenIDM/OpenICF-based IGA: role-management subsystem, custom 1C/directory/mail connectors, account lifecycle

What stands out

In the oil & gas sector, a critical infrastructure operator undertook the modernization of its identity governance and access management (IGA) environment, transitioning from an established enterprise IAM platform to a custom-built IGA solution based on the OpenIDM/OpenICF framework. The initiative spanned multiple operational entities within the group, including a major gas transmission and maintenance facility. The project involved decommissioning a legacy Oracle Identity Manager deployment and implementing a unified access-management contour compliant with stringent regulatory requirements for critical information infrastructure. Key deliverables included the design and rollout of a policy-driven role-management system (PUR/RBAC), development of custom connectors to core business systems—such as 1C (HR, payroll, project accounting), Active Directory, and corporate email—and the orchestration of end-to-end identity lifecycle processes: onboarding, transfers, leave management, offboarding, and role-based access requests with dynamic approval workflows. Integration and performance validation were conducted via automated testing tools, confirming system stability under load. The solution was formally accepted by stakeholders in early 2020, with full handover completed under a broader information security modernization program. The platform, while derived from open-source foundations, was tailored to meet specific compliance and operational resilience standards, marking its first deployment at scale within the organization’s portfolio.

  • Platform

    An IGA on the open OpenIDM/OpenICF (ForgeRock) stack

  • Migration

    Oracle Identity Manager → an OpenIDM-based IGA (critical-infrastructure objects)

  • Scale

    several critical objects · roughly 800+ identities

  • Coverage

    role-management subsystem (RBAC) · custom 1C / directory / mail connectors

  • Process

    automated account lifecycle (joiner, transfer, maternity, leaver, role requests)

Banking

Evolveum MidPoint
Scale
large bank · several target systems
Period
2020s
Identigy role
Full-cycle IGA implementation on Evolveum MidPoint: architecture, development, integrations, go-live, training

What stands out

A large retail bank engaged Identigy to deliver a production IGA platform on Evolveum MidPoint (open-source), replacing a legacy in-house, ERP-based access solution in which onboarding each new target system was slow and costly. On MidPoint the team implemented an automated account lifecycle (joiner/mover/leaver), access audit and periodic certification, and segregation-of-duties control, and rebuilt the role model from the ground up — roles assigned by conditions such as an employee's position level. Several target systems were brought under governance, including the core banking system, card processing, the corporate directory and mail, and the HR source. The complex role model surfaced performance challenges resolved through joint engineering with the platform vendor. The system runs in production (thousands of users) with ongoing development and third-line support.

  • Scale

    large banking contour

  • Platform

    Evolveum MidPoint (open source)

  • Coverage

    several target systems · JML + certification + SoD

  • Outcome

    fast onboarding of new systems

Gold mining

IGA audit & target-model design · vendor-neutral access-system selection
Scale
thousands of staff
Period
2022
Identigy role
Audit and design of access-management processes and a role model; vendor-neutral selection of an access-governance system

What stands out

A multi-business-unit mining group, then in an active phase of mergers and acquisitions, engaged Identigy for an access-governance audit and target-model design. Across a heterogeneous IT landscape with inconsistent practices and no centralized access governance, the team surveyed the group's core systems and designed the target access-management process from the ground up: a three-tier role model (RBAC) on a «location × organizational-structure» poly-hierarchy, anchored on the trusted HR source and spanning the directory, mail, ERP and HR systems. Deliverables included the access-governance concept, policy, regulations and statute, a role-formation and system-categorization methodology, and a vendor-neutral methodology for selecting an access-governance system — a ready, agreed foundation handed over ahead of any automation while the group restructured.

  • Coverage

    thousands of staff

  • Outcome

    role model + governance package + system-selection methodology

Major telecom group

Oracle Identity ManagerEvolveum MidPoint
Scale
tens of thousands of employees · hundreds of target systems · multi-domain directory
Period
2018 — present (Oracle IdM); 2023 — present (migration to MidPoint)
Identigy role
Long-term Oracle IdM operations and an in-progress migration to Evolveum MidPoint

What stands out

A multinational organization in the natural resources sector undertook the modernization of its identity governance framework, transitioning from a legacy commercial IGA system to a scalable, open-source platform. The environment encompasses a global directory, multiple subsidiary domains, and integrations with HR, ERP, email, and critical line-of-business applications. The initiative focused on streamlining a fragmented landscape of custom connectors by consolidating them into a standardized set of integration types. A new asynchronous message-broker-based integration layer was implemented to enhance reliability, scalability, and operational visibility. During the cutover phase, both platforms operated in parallel to ensure uninterrupted service delivery and mitigate migration risks. The updated architecture supports centralized policy enforcement, improves audit readiness, and aligns with evolving regulatory requirements for access governance, enabling greater agility and reduced long-term operational complexity across the enterprise identity landscape.

  • Access SLA

    Up to 10 working days → under 1 hour

  • Connectors

    many bespoke → a few unified types

  • Scale

    tens of thousands of employees · hundreds of target systems

  • Evolution

    Oracle Identity Manager → Evolveum MidPoint

Retail

Oracle Identity Manager
Scale
large retail network · distributed points of sale
Period
2010s
Identigy role
Development of an access-management system on Oracle Identity Manager: connector engineering, automated account and credential lifecycle management

What stands out

A telecommunications retail chain operating a nationwide footprint with a large, mobile workforce required enhancements to its in-production enterprise IAM platform, built on an Oracle-based identity management system. The platform governs access to critical resources including directory services, corporate communications, a 1C retail sales environment, and point-of-sale workstations, with SAP HR serving as the authoritative source for identity data. The existing architecture, originally designed by the same team engaged for the upgrade, was extended to improve reliability and automation across the identity lifecycle. Key improvements included a refactored 1C integration that isolated account provisioning logic, enforced identity consistency through personnel number and full name validation, introduced duplicate account detection with auto-remediation, and ensured synchronized name updates across all connected systems. Credential management for retail workstations was automated by capturing password changes in 1C and propagating them via a secure web service, with account recreation during inter-store transfers preserving existing credentials. Prior custom integrations with corporate email, a service bus, and a service management platform were also part of the evolved architecture. All deliverables were formally implemented and accepted.

  • Scale

    large retail network

  • Platform

    Oracle Identity Manager

  • Coverage

    directory · mail · communications · 1C sales system · cashier workstations

  • Processes

    automated JML + account dedup/consistency + credential management + custom connectors

Telecom

Oracle Identity Manager
Scale
mobile network operator · several target systems
Period
2010s
Identigy role
Identity governance implementation on Oracle Identity Manager: connectors to six target systems, a role model, and automated account lifecycle

What stands out

The operator in the telecommunications sector upgraded its corporate access‑management environment to improve compliance and operational efficiency. Using an enterprise identity‑and‑access‑management platform, the project automated onboarding, role changes and off‑boarding and introduced role‑based access control for six core systems, including directory services, corporate communications, billing and accounting applications. A custom integration component provided governed provisioning for the accounting suite while preserving the legal independence of the local entity. The solution supports a small user base, meets regional data‑residency and access‑oversight regulations, and was accepted after formal sign‑off, delivering centralized control without compromising jurisdictional requirements.

  • Scale

    mobile network operator

  • Platform

    Oracle Identity Manager

  • Coverage

    several target systems · directory/mail/comms/billing/1C

  • Processes

    automated JML + role model + custom 1C connector

Telecom

Oracle AACG (GRC)
Scale
large corporate ERP · multiple functional modules
Period
2010s
Identigy role
Oracle AACG implementer over the corporate ERP: connector rework on ODI, SoD-matrix middleware, conflict-analysis & compensating-control engine, go-live

What stands out

A large telecom operator engaged Identigy, as a technical subcontractor, to implement automated access-rights management and segregation-of-duties (SoD) control on Oracle Application Access Controls Governor (AACG) over a corporate Oracle e-Business Suite R12 ERP (multiple functional modules, from general ledger to payroll). The driver was regulatory SoD-compliance: SoD control had been manual, with no automated conflict analysis and no management of compensating controls. The team delivered what-if SoD analysis on every access request, automatic approval-chain build-up, a full lifecycle for the compensating-controls catalogue, user- and role-level control, and consolidated SoD-risk reporting for internal control and external auditors. The platform's stock functionality was extended with middleware on the customer's ITSM platform (two-way integration) and a deeply reworked ERP connector with custom filters eliminating false positives. The solution passed multiple test cycles plus load testing and entered production.

  • Scale

    large organization

  • Platform

    Oracle AACG (GRC)

  • Coverage

    corporate ERP · numerous modules · what-if SoD analysis + compensating controls

  • Outcome

    SoD control automated for regulatory compliance (was manual)

Public sector

Oracle Access Manager + Microsoft Active Directory (single sign-on + centralized account management)
Scale
public-sector organization · regional office network · heterogeneous estate (corporate directory, corporate mail, line-of-business systems)
Period
2010s
Identigy role
Regional rollout, subsystem integration and trial-operation enablement for a single-sign-on & account-management contour

What stands out

A public-sector organization in the social services sector, operating a large workforce across a nationwide network of regional offices and managing significant volumes of personal data, undertook the rollout of an enterprise single-sign-on and centralized account management system. Identigy supported the initiative—acting as a technical subcontractor to the prime contractor—by leading the regional deployment, integration of line-of-business subsystems, and transition to trial operations. The solution leveraged a unified authorization and end-to-end authentication platform based on an enterprise IAM system, supported by regional authentication centers, and a hierarchical identity provisioning layer synchronizing accounts from an HR system built on a 1C platform into a corporate directory service. Prior to the project, access provisioning was manual, relying on paper-based approvals and resulting in prolonged fulfillment cycles. The team deployed regional authentication components, integrated business applications with single sign-on, automated the full account lifecycle—including onboarding, transfers, name changes and offboarding—conducted readiness assessments for each regional office, trained local personnel, and facilitated operational handover. The rollout was completed successfully, fully accepted by the customer and delivered on schedule.

  • Scale

    public-sector organization — regional office network

  • Platform

    Oracle Access Manager + Microsoft Active Directory — single sign-on and account management

  • Coverage

    single sign-on (SSO) · centralized account management · line-of-business subsystems

  • Process

    automated account lifecycle (joiner/mover/leaver) — replacing a manual one (paper approvals)

  • Outcome

    regional segments rolled out, integrated and handed over into trial operation (accepted by the customer)

Professional services

Keycloak · Evolveum MidPoint · OpenLDAP (open source)
Scale
WebSSO federation of priority systems
Period
2020s
Identigy role
Architecture and rollout of an autonomous IAM contour on an open-source stack: WebSSO on Keycloak, IDM and access certification on MidPoint, trusted OpenLDAP directory

What stands out

A professional-services firm in a highly regulated sector required a segregated identity and access management environment to ensure control and compliance. The solution implemented an open-source technology stack comprising an enterprise SSO platform, a corporate identity governance system, and a centralized directory service. This independent IAM environment supports critical business applications, enabling seamless single sign-on, automated user lifecycle management, and recurring access reviews. Employee data is synchronized from a trusted HR source, while a self-service integration framework allows quick onboarding of new applications. Deployed using Agile CI/CD practices across multiple environments, the first application was secured within four weeks. The approach delivered a fully auditable, license-free access management layer, ensuring operational autonomy, regulatory alignment, and long-term vendor neutrality at scale.

  • Platform

    Keycloak · MidPoint · OpenLDAP (open source)

  • Coverage

    WebSSO federation of priority systems · access certification

  • Approach

    autonomous contour · pilot in a few weeks

Banking

Evolveum MidPoint
Scale
major commercial bank · several target systems
Period
2020s
Identigy role
Replacement of a legacy commercial IDM platform with open-source Evolveum MidPoint — full-cycle delivery plus multi-year support

What stands out

A financial institution in the banking sector faced growing operational and regulatory risks due to reliance on foreign identity management platforms, exacerbated by geopolitical shifts and withdrawal of international vendors from the local market. With a large workforce and complex HR processes—including concurrent employment and multi-record reconciliation—the organization required a resilient, locally sustainable IAM solution. The legacy environment, consisting of two enterprise IDM systems, necessitated strategic replacement of the primary platform to ensure continuity, compliance, and independence from external licensing constraints. Identigy implemented an open-source identity management platform across three CI/CD-aligned environments, delivering a fully automated account lifecycle covering joiner, mover, leaver, and special employment scenarios such as maternity leave and emergency access blocks. Key integrations included a high-performance email system connector meeting strict service levels and a re-architected HR feed capable of handling complex personnel data harmonization. A self-service portal and clear separation of duties across the remaining IDM systems enabled a smooth parallel run and transition. The new architecture significantly reduced account provisioning time in the corporate directory, with sustained performance over several years of post-go-live support and incremental enhancements.

  • Scale

    major commercial bank

  • Platform

    Evolveum MidPoint (open source)

  • Account provisioning

    account creation reduced substantially

  • Engagement

    implementation + multi-year support

Transport

Custom IGA on OpenIDM/OpenICF (ForgeRock)
Scale
multi-domain AD environment · enterprise-scale system estate
Period
2010s
Identigy role
Design, development and pilot rollout of a custom IGA on OpenIDM/OpenICF: connectors, role model, configurable approval routing, audit/self-service portals

What stands out

A transport sector organization sought to modernize its fragmented, manual access request procedures across a complex, multi-domain IT landscape. To address this, a custom identity governance and administration solution was developed using an open-source platform based on the OpenIDM/OpenICF framework, supported by a PostgreSQL database and integrated workflow engine. The system enabled automated user lifecycle management—including onboarding, role changes, transfers and offboarding—along with dynamic approval workflows, a unified cross-system role model, self-service access requests and periodic access recertification for compliance. Custom integration connectors were built to synchronize with directory services, email platforms, an enterprise service bus, IT service management tools and HR systems. The solution was successfully piloted in a defined operational zone, meeting all delivery milestones and achieving formal acceptance. Despite the pilot’s technical success, the organization did not proceed with a full-scale enterprise deployment. The project adhered to sector-specific regulatory requirements for access control and auditability throughout.

  • Scale

    multi-domain AD forest · enterprise-scale accounts

  • Platform

    OpenIDM / OpenICF (ForgeRock) — custom IGA

  • Coverage

    directory · mail platforms · ESB · ITSM · HR source

  • Process

    configurable approval routing (was manual)

  • Outcome

    pilot phase designed, built and delivered

Integrated petrochemical major

Oracle Identity Manager
Scale
tens of thousands of identities · multi-entity holding
Period
2020 — present
Identigy role
HR source migration → ongoing support and identity-governance development

What stands out

An industrial holding implemented a group-wide identity governance platform to enforce zero-trust and least-privilege access across multiple legal entities and IT systems. The initiative began with synchronizing identity data from a legacy HR system to a modern enterprise HR platform, aligning the identity cut-over with a critical payroll transition. This ensured accurate, automated provisioning based on verified workforce events. Subsequent phases expanded integration to core platforms including directory services, email, CRM, content management, and access governance systems. The program advanced the organization’s security posture through continuous development of role-based access controls, approval workflows, and governance of non-human identities, particularly service accounts. Operating under strict regulatory requirements, the solution strengthened compliance, reduced access risk, and improved operational scalability across the enterprise’s evolving digital landscape.

  • Identity scale

    tens of thousands of identities · multi-entity holding

  • HR migration

    Legacy in-house HR → modern enterprise HR platform

  • Target systems

    directory · mail · CRM · content management · access governance

Banking

SailPoint IdentityIQ
Scale
large bank · heterogeneous estate (mainframe · directory · core banking)
Period
2010s
Identigy role
SailPoint IdentityIQ engineering: HR-driven identity model, JML automation, account provisioning to mainframe, directory and core-banking targets, approval workflows

What stands out

A financial institution with a large identity population required improved compliance with sector-specific regulations and more efficient identity lifecycle management. To address this, an enterprise identity governance platform was implemented to centralize HR data sources, establish a unified identity model, and automate critical joiner-mover-leaver processes. The solution enabled systematic provisioning of access across core systems, including a mainframe environment, corporate directory, and key banking applications. Role-based access controls and embedded approval workflows were integrated with employment status logic to ensure appropriate access assignment. Where full automation was not viable, streamlined manual interventions were introduced to reduce operational overhead. Over a two-and-a-half-year implementation period, the initiative significantly reduced manual processes, improved accuracy in access provisioning, and strengthened audit readiness. The enhanced governance framework provided greater visibility into access rights and compliance posture across the organization’s IT landscape.

  • Scale

    large banking contour

  • Platform

    SailPoint IdentityIQ

  • Coverage

    heterogeneous estate · mainframe + directory + core banking · HR-driven JML

  • Engagement

    multi-year continuous development

Banking

Oracle Identity Manager
Scale
large banking identity contour · heterogeneous IT estate
Period
2020s
Identigy role
Multi-year technical support and development of an enterprise IDM platform on Oracle Identity Manager — running a large-scale identity-management contour under banking-secrecy constraints

What stands out

A financial institution in the banking sector operated a large-scale identity and access management environment serving a substantial workforce, managing high volumes of access requests through a centralized enterprise IAM platform. The solution supported a structured role-based access control model, automated directory provisioning, and integrated with a heterogeneous landscape including core banking, customer relationship, treasury, email, IT service management, and security systems. Over multiple years, under a direct support agreement, comprehensive technical oversight was delivered, encompassing defect resolution, deployment of fixes, administration of identity lifecycle processes under strict SLAs, routine audits for compliance, reconciliation of user entitlements, and evolution of integration components within the existing architecture. Services included on-site presence and ensured sustained operational stability, meeting regulatory requirements for data confidentiality and integrity. The environment remained resilient and fully functional throughout the engagement, with all deliverables accepted without dispute.

  • Scale

    large banking contour

  • Throughput

    high volume of access-change requests

  • Platform

    Oracle Identity Manager

  • Engagement

    multi-year support

Major energy company

SailPoint IdentityIQ
Scale
5,000+ identities · multiple sites · 10 IT systems
Period
2017 — present
Identigy role
SailPoint IdentityIQ modernization → functional extension → ongoing support → version migration

What stands out

A global energy enterprise managing access for over 5,000 identities across multiple regional facilities partnered to modernize its legacy identity governance environment. The initiative focused on upgrading a highly customized enterprise IAM platform to its latest release, extending core functionality beyond out-of-the-box capabilities, and implementing DevOps practices to streamline deployment cycles. The solution included continuous operational support and a concurrent migration to the updated platform version. A centralized role model, driven by HR data, enables dynamic access provisioning across a distributed infrastructure. Automated lifecycle management covers employees, contractors, and service accounts, with consistent recertification workflows triggered by role or location changes and continuous drift detection across ten integrated systems. The architecture ensures compliance with sector-specific regulatory requirements while improving access accuracy and operational resilience.

  • Tenure

    8 years of continuous development

  • Scale

    5,000+ identities · multiple sites · 10 IT systems

  • Architecture

    Dynamic matrix role model

Insurance

One Identity ManagerEvolveum MidPoint
Scale
tens of thousands of users (internal + external)
Period
2020 — present
Identigy role
Full IDM-stack lifecycle: replacing legacy One Identity Manager with open-source Evolveum MidPoint — from PoC and migration to multi-year direct support and development

What stands out

A multinational insurance organization with a broad network of agents and partners—spanning tens of thousands of identities—underwent a comprehensive identity management transformation supported by Identigy. The engagement began with the implementation of an enterprise IGA platform, enabling end-to-end account lifecycle management, business-driven role definitions for branch and partner channels, integration with managed systems, an ERP-based HR source, and cross-domain Active Directory environments, alongside a self-service access request portal. Subsequently, Identigy led a proof-of-concept and migration to an open-source identity governance solution, transitioning from a proprietary system to achieve greater vendor independence and internal development agility. Ongoing support now includes technical consulting, custom development, and enhancement of the platform’s object model, connectors, role architecture, access certification workflows, segregation-of-duties controls, user interface adaptations, reporting capabilities, and mitigation of product-level limitations through tailored engineering solutions. The initiative aligns with global regulatory requirements for access governance and auditability in the financial services sector.

  • Scale

    tens of thousands of users

  • Platform

    Evolveum MidPoint (open source)

  • Migration

    One Identity Manager → Evolveum MidPoint (open source)

  • Engagement

    full lifecycle — PoC → migration → direct support

Retail banking

Oracle Identity Manager + Oracle Access Manager
Scale
large retail bank · distributed branch & agent network · high-load fault-tolerant (HA) directory architecture across two data centres
Period
multi-year full lifecycle (build → develop → 12c upgrade → support)
Identigy role
Full lifecycle of an identity, access and biometric-authentication contour on Oracle — built for the bank's launch, developed for over a decade, upgraded to 12c and supported

What stands out

A financial sector retail banking institution managed a large-scale, multi-branch and agent-based operation requiring a resilient identity and access management (IAM) framework to support a diverse population of employees, agents and digital users. Facing stringent regulatory requirements and high-volume transaction demands, the organization implemented an enterprise IAM platform built on Oracle technology, later upgraded to Oracle 12c, ensuring long-term scalability and compliance. A core internal team led the architecture and evolution of the system over several years, while integration support rotated across multiple vendors due to shifting budget cycles. The solution featured a hierarchical role model for identity lifecycle management, automated provisioning to directories, audit-ready attestation processes, and a geo-distributed, highly available directory with active-passive data center replication. Access control was strengthened through SSO, directory services and a custom two-factor authentication layer with biometric verification, linked to real-time fraud monitoring. The platform seamlessly supported mission-critical operations such as customer onboarding, point-of-sale systems and CRM workflows, operating continuously under heavy load. Designed for resilience and regulatory alignment, the IAM system remained in production throughout its lifecycle, enabling secure, scalable access across the institution’s front-office functions.

  • Scale

    large retail bank · staff, agent network and digital-banking clients

  • Load · resilience

    high load · HA directory architecture (OID/OUD clusters, two DCs, 24×7)

  • Platform

    Oracle Identity Manager + Access Manager (upgraded to 12c)

  • Authentication

    custom multi-factor authentication

  • Lifecycle

    multi-year support, one team — build → develop → 12c → closure

Request references

Does your scenario look like one of these?

We can prepare an extended reference under a specific scenario — with figures, architecture and a customer contact for verification against your project.

Write to info@identigy.com or use the consultation form on the Contact page.

What to share in the request

  • Sector and size of your organisation
  • Current IDM / IGA, if any
  • Target platform or selection criteria
  • Engagement type: implementation, migration, audit or support
Request a reference