Growing Requirements Call for a New IAM Approach
Thüringer Aufbaubank is the development bank of the German state of Thuringia. It supports businesses, municipalities, and technology initiatives and works closely with the state government, banks, and other financing partners.
For a bank operating in this environment, transparent and controlled access rights management is essential. TAB already had a centralized tool for managing digital identities and access rights. As regulatory requirements increased, however, it became clear that the existing solution would no longer be sufficient in the long term.
An audit under Section 44 of the German Banking Act (KWG) confirmed the need for action. TAB therefore decided to rethink its existing IAM concept and introduce a new identity management solution. In addition to supporting regulatory requirements, good usability was a key consideration. Positive experiences with Garancy reported by other banks also contributed to the decision.
“No Permission Without a Role” as the Guiding Principle
The central principle behind the new access rights management approach is clear: No permission without a role. As a rule, permissions are requested and assigned through roles. Individual permissions are reserved for exceptions, such as temporary read or write access to project directories.
TAB had already used roles and profiles in its access rights management. With Garancy, however, the bank was able to apply this approach much more consistently and at a greater level of detail. Roles are aligned with business responsibilities, positions, and functions, providing a more systematic implementation of the need-to-know principle.
With Garancy, we can design access rights based on roles and manage role adjustments and role concepts at a level and depth that our previous IAM system did not allow.
:quality(50))
Basic, Organizational, Business, and Functional Roles Create Structure
Access rights concepts are defined for applications with user administration. Individual permissions – such as read, write, or administrative access – are then bundled into different types of roles. TAB distinguishes in particular between:
Basic roles for fundamental access such as time tracking, email, Active Directory, and network drives
Organizational roles for specific organizational units
Business roles derived from job descriptions and business responsibilities
Functional roles for cross-departmental functions
Employees with the same job description and responsibilities therefore generally receive the same business role and the corresponding access rights.
This creates a transparent role model that connects the bank’s organizational structure with technical access provisioning.
Reducing Administrative Effort for Access Provisioning
The role-based approach particularly simplifies access provisioning for new hires and employees whose responsibilities change. Instead of assembling individual permissions for each person, the appropriate profile can be selected from an existing set of roles and access rights.
Basic, business, organizational, and, where required, functional roles combine to form the employee’s permission profile. This significantly reduces the administrative effort involved in assigning access rights.
The objective is to derive roles as directly as possible from organizational information. If the HR system reports a new employee together with their organizational unit and job description, the appropriate organizational and business roles can be derived from this information.
Criticality Determines the Level of Control
Another important element of TAB’s IAM concept is the assessment of critical access rights. Not every permission carries the same level of risk. Administrative rights, for example, can be particularly critical. The same applies to technical users or business permissions that allow sensitive transactions to be performed.
TAB uses information containers to group similar information and data. Permissions in the relevant systems are mapped to these containers. This makes it possible to transfer the criticality of the information being processed to the corresponding access rights and, ultimately, to the roles themselves.
The criticality level also determines how frequently a role must be recertified. The intervals described in the reference range from every six months to annually or every three years. This allows TAB to directly connect business-level protection requirements with access rights management.
Three Organizations Within One IAM Structure
Another challenge was the need to incorporate not only Thüringer Aufbaubank itself but also two subsidiaries into the IAM environment.
Garancy therefore supports three organizationally separate tenants within the shared IAM structure. This multi-tenant approach allows common IAM principles to be applied across multiple entities while still accommodating their organizational differences.
Integrating Core Systems and Additional Applications
The central IAM landscape includes SAP with relevant master and HR data, Microsoft Active Directory, and custom-developed applications for processing grants and loans. It also incorporates TAB’s information systems, which provide data for analysis and reporting, as well as a portal solution used for communication with applicants.
Additional applications can be integrated into access rights management through Garancy. Each system first requires a defined access concept specifying which permissions exist and how they are represented through roles. This creates a centralized IAM structure spanning around 65 systems.
Results at a Glance
Around 65 connected systems
5,540 technical roles
12,700 individual permissions
Around 1,100 managed accounts, including technical users and external staff
Role-based access assignment following the principle “No permission without a role”
Basic, organizational, business, and functional roles for structured access assignment
Risk-based recertification intervals according to access criticality
Three tenants within a shared IAM structure
Reduced administrative effort for access provisioning
Access Governance with Clear Responsibilities
For TAB, introducing Garancy was more than a technology project. One of the key objectives was to place greater responsibility for access rights with the business functions where those permissions originate.
Business departments understand the applications, data, and responsibilities of their employees and are therefore expected to take ownership of how the corresponding access rights are designed. IT Governance, organizational management, technical teams, and business departments work together within a shared IAM framework.
In this way, Thüringer Aufbaubank combines regulatory requirements with a practical Governance model: Access rights are derived from business responsibilities, structured through roles, and reviewed according to their criticality.
Role-Based IAM as the Foundation for Secure and Efficient Processes
The Thüringer Aufbaubank success story demonstrates how access rights management can evolve from a technical, system-by-system approach into a business-driven Governance process.
With Garancy, TAB consistently applies the principle “No permission without a role.” Access rights are structured according to responsibilities, positions, and functions, critical permissions are subject to targeted controls, and different entities and systems are brought together within a shared IAM structure.
The result is an access rights management approach that combines regulatory compliance, IT security, and operational efficiency.
:quality(100))
:quality(100))
:quality(100))
:quality(100))
:quality(80))