Gebäude der Thüringer Aufbaubank
Thrünger Aufbaubank

Role-Based Identity Management with Garancy

Success Story6 min read
65
Systems Integrated
5.500+
Technical Roles
12.700
Individual Permissions

Thüringer Aufbaubank (TAB) – development finance institution of the Free State of Thuringia in Germany – faced the challenge of adapting its Identity & Access Management to increasingly demanding regulatory requirements. Its existing IAM solution could no longer provide the required depth of role-based access rights management.

With Garancy, the development bank redesigned its IAM approach around a clear principle: “No permission without a role.” Access rights are derived from responsibilities, positions, and functions, centrally managed, and regularly reviewed – strengthening Governance, reducing administrative effort, and making access assignment more transparent and traceable.

The Case at a Glance

  • Challenge: The existing IAM solution could no longer adequately support the bank’s growing regulatory and business requirements for access rights management.

  • Approach: With Garancy, TAB established role-based IAM following the principle “No permission without a role,” consistently aligning permissions with responsibilities, positions, and functions.

  • Success: Around 65 systems, 5,540 technical roles, and 12,700 individual permissions are represented within a centralized IAM structure managing approx. 1,100 accounts.

Growing Requirements Call for a New IAM Approach

Thüringer Aufbaubank is the development bank of the German state of Thuringia. It supports businesses, municipalities, and technology initiatives and works closely with the state government, banks, and other financing partners.

For a bank operating in this environment, transparent and controlled access rights management is essential. TAB already had a centralized tool for managing digital identities and access rights. As regulatory requirements increased, however, it became clear that the existing solution would no longer be sufficient in the long term.

An audit under Section 44 of the German Banking Act (KWG) confirmed the need for action. TAB therefore decided to rethink its existing IAM concept and introduce a new identity management solution. In addition to supporting regulatory requirements, good usability was a key consideration. Positive experiences with Garancy reported by other banks also contributed to the decision.

“No Permission Without a Role” as the Guiding Principle

The central principle behind the new access rights management approach is clear: No permission without a role. As a rule, permissions are requested and assigned through roles. Individual permissions are reserved for exceptions, such as temporary read or write access to project directories.

TAB had already used roles and profiles in its access rights management. With Garancy, however, the bank was able to apply this approach much more consistently and at a greater level of detail. Roles are aligned with business responsibilities, positions, and functions, providing a more systematic implementation of the need-to-know principle.

With Garancy, we can design access rights based on roles and manage role adjustments and role concepts at a level and depth that our previous IAM system did not allow.

Thüringer Aufbaubank Logo
Cindy Schöneweck
Compliance Officer in IT Governance

Basic, Organizational, Business, and Functional Roles Create Structure

Access rights concepts are defined for applications with user administration. Individual permissions – such as read, write, or administrative access – are then bundled into different types of roles. TAB distinguishes in particular between:

  • Basic roles for fundamental access such as time tracking, email, Active Directory, and network drives

  • Organizational roles for specific organizational units

  • Business roles derived from job descriptions and business responsibilities

  • Functional roles for cross-departmental functions

Employees with the same job description and responsibilities therefore generally receive the same business role and the corresponding access rights.

This creates a transparent role model that connects the bank’s organizational structure with technical access provisioning.

Reducing Administrative Effort for Access Provisioning

The role-based approach particularly simplifies access provisioning for new hires and employees whose responsibilities change. Instead of assembling individual permissions for each person, the appropriate profile can be selected from an existing set of roles and access rights.

Basic, business, organizational, and, where required, functional roles combine to form the employee’s permission profile. This significantly reduces the administrative effort involved in assigning access rights.

The objective is to derive roles as directly as possible from organizational information. If the HR system reports a new employee together with their organizational unit and job description, the appropriate organizational and business roles can be derived from this information.

Criticality Determines the Level of Control

Another important element of TAB’s IAM concept is the assessment of critical access rights. Not every permission carries the same level of risk. Administrative rights, for example, can be particularly critical. The same applies to technical users or business permissions that allow sensitive transactions to be performed.

TAB uses information containers to group similar information and data. Permissions in the relevant systems are mapped to these containers. This makes it possible to transfer the criticality of the information being processed to the corresponding access rights and, ultimately, to the roles themselves.

The criticality level also determines how frequently a role must be recertified. The intervals described in the reference range from every six months to annually or every three years. This allows TAB to directly connect business-level protection requirements with access rights management.

Three Organizations Within One IAM Structure

Another challenge was the need to incorporate not only Thüringer Aufbaubank itself but also two subsidiaries into the IAM environment.

Garancy therefore supports three organizationally separate tenants within the shared IAM structure. This multi-tenant approach allows common IAM principles to be applied across multiple entities while still accommodating their organizational differences.

Integrating Core Systems and Additional Applications

The central IAM landscape includes SAP with relevant master and HR data, Microsoft Active Directory, and custom-developed applications for processing grants and loans. It also incorporates TAB’s information systems, which provide data for analysis and reporting, as well as a portal solution used for communication with applicants.

Additional applications can be integrated into access rights management through Garancy. Each system first requires a defined access concept specifying which permissions exist and how they are represented through roles. This creates a centralized IAM structure spanning around 65 systems.

Results at a Glance

  • Around 65 connected systems

  • 5,540 technical roles

  • 12,700 individual permissions

  • Around 1,100 managed accounts, including technical users and external staff

  • Role-based access assignment following the principle “No permission without a role”

  • Basic, organizational, business, and functional roles for structured access assignment

  • Risk-based recertification intervals according to access criticality

  • Three tenants within a shared IAM structure

  • Reduced administrative effort for access provisioning

Access Governance with Clear Responsibilities

For TAB, introducing Garancy was more than a technology project. One of the key objectives was to place greater responsibility for access rights with the business functions where those permissions originate.

Business departments understand the applications, data, and responsibilities of their employees and are therefore expected to take ownership of how the corresponding access rights are designed. IT Governance, organizational management, technical teams, and business departments work together within a shared IAM framework.

In this way, Thüringer Aufbaubank combines regulatory requirements with a practical Governance model: Access rights are derived from business responsibilities, structured through roles, and reviewed according to their criticality.

Role-Based IAM as the Foundation for Secure and Efficient Processes

The Thüringer Aufbaubank success story demonstrates how access rights management can evolve from a technical, system-by-system approach into a business-driven Governance process.

With Garancy, TAB consistently applies the principle “No permission without a role.” Access rights are structured according to responsibilities, positions, and functions, critical permissions are subject to targeted controls, and different entities and systems are brought together within a shared IAM structure.

The result is an access rights management approach that combines regulatory compliance, IT security, and operational efficiency.

Further Resources

NBank Gebäude
NBank

Identity Management Starts with Expert Guidance

75
Systems Connected
1.000
Roles Created
< 5%
Rights Assigned Directly
Gebäude der KGAL GmbH & Co. KG
KGAL GmbH & Co. KG

Enhanced Security and Compliance with IAM at KGAL

Flexible Role Models
Automated Processes
Simplified Recertification

Let’s Talk Business!

Are you facing challenges in cyber security, automation, or compliance? In a compact strategy meeting, we will clarify which IAM approaches make sense for your company.

What you can expect:

  • Discussion of your individual requirements

  • Practical insights into our identity management software

  • Q&A and recommendations for the next steps

More than 6.16 million managed identities worldwide
A man in a white shirt, holding a yellow folder, smiles while speaking into a smartphone, standing beside a window with soft light.