Gebäude der IFB Hamburg
IFB Hamburg

From Concept to Centralized Identity & Access Management in Five Months

Success Story6 min read
70
Systems Integrated
100+
Business Roles
5
Months to Go-Live

Hamburgische Investitions- und Förderbank (IFB Hamburg), the regional promotional bank for the German state of Hamburg, wanted to fundamentally modernize its access rights management. Manual processes, Excel spreadsheets, and application-specific access concepts were to be replaced by a centralized IAM solution providing greater transparency, more efficient processes, and reliable access governance.

The key to the project’s success was its approach: The bank defined business roles, governance, and approval processes before implementing the technology. As a result, Garancy went live after just five months.

The Case at a Glance

  • Challenge: Manual processes and application-specific permissions made centralized, compliant access rights management difficult.

  • Approach: IFB first defined its Governance framework, processes, and business roles before implementing them with Garancy.

  • Success: Garancy went live after just five months, with 103 business roles providing the foundation for centralized access rights management across around 70 systems.

From Manual Processes to Centralized IAM

The project was driven by banking supervisory requirements for IT (BAIT), with access rights management emerging as one of the key areas requiring action. Until then, IFB had managed access rights through application-specific concepts, Excel spreadsheets, and manual processes. Templates were used for access requests, while Microsoft Active Directory and SAP already contained initial role-like structures and composite roles.

The starting point was therefore far from unstructured. What was missing was a cross-application approach that consistently derived access rights from employees’ business responsibilities and made them centrally manageable.

Existing roles were sometimes combined individually, meaning that when responsibilities changed, permissions could be tied more closely to individuals than to clearly defined functions. Individual and group permissions existed side by side.

IFB wanted to fundamentally change this approach: Business departments would take greater responsibility for defining the access rights they needed, while a centralized IAM platform would provide the technical implementation and governance framework.

Governance and Roles First, Technology Second

One of the key success factors was the order in which the project was approached. Rather than selecting IAM software first and adapting internal processes afterward, IFB began by developing the organizational and methodological foundation.

The approach consisted of three core elements:

  1. Defining internal policies, Governance, processes, and rules for access rights management

  2. Developing business roles in close collaboration with the business departments

  3. Implementing the completed concept with Garancy

Business responsibilities were identified based on organizational processes, job descriptions, and workshops with the departments, and then grouped into clearly defined roles. As a result, much of the functional concept was already complete before Garancy was implemented.

103 Business Roles Instead of an Unmanageable Role Landscape

When developing the role model, IFB was able to build on existing structures in Windows and SAP. Rather than replacing them entirely, the bank incorporated them into a broader, cross-application concept.

Permissions for smaller applications were also incorporated into the business roles. At the same time, the project team deliberately kept the number of roles manageable.

The result was 103 clearly defined business roles that provide a structured way to map responsibilities to the access rights employees need.

Approval processes were also defined before the technical implementation. Rules governing who can request access, who must approve it, and how permissions should be assigned were documented in workflows and subsequently implemented in the Garancy Process Center.

Segregation of Duties Built In from the Start

IFB also incorporated Segregation of Duties (SoD) into its governance framework from the outset. Permissions can be grouped into roles, but they must be derived from actual business responsibilities. At the same time, combinations of access rights must not violate defined separation-of-duties requirements.

Critical permissions were addressed early in the project as well. Rather than managing them solely as individual permissions, IFB grouped relevant access rights into critical business roles.

This meant that key governance rules were already defined before they were technically implemented in Garancy.

Live in Just Five Months

The thorough preparation paid off during the technical implementation. Garancy received a largely complete role and rules framework consisting of 103 business roles, defined approval paths, and clearly structured processes.

Because the processes had deliberately been kept straightforward, they could largely be implemented using standard Garancy functionality. The new identity management system went live after a project duration of just five months.

The key difference compared with many IAM projects was simple: IFB did not start with the technology. The bank had already defined how its future access rights management should work before implementation began.

Centralized Business Roles Across Different Systems

The central systems connected to Garancy include SAP as well as Microsoft Active Directory and Exchange. HR data is also incorporated into the IAM processes. For these central applications, business departments can assign, modify, and revoke access rights through Garancy in accordance with the defined approval rules.

Additional applications can be incorporated into the overarching access rights management framework. Where permissions cannot be provisioned directly, Garancy supports Order-to-Admin processes: If a business role includes a permission for one of these systems, the responsible IT administrator is notified so that the assignment can be completed.

This creates a centralized role model that brings automated and administrator-managed access rights together under a common Governance framework.

Giving Business Departments Greater Responsibility

With Garancy, IFB deliberately shifts part of the responsibility for access rights to the business departments. Managers can oversee employee access based on defined roles and approval rules, while the centralized IAM platform ensures that the established Governance processes are followed.

An additional link between business requirements and technical operations is the Access Rights Manager. This role acts as an interface between the business departments and technical operations, oversees the approval of access concepts, and can serve as an additional control point for certain role assignments or changes.

Recertification Integrated into IAM

Centralized access rights management also includes regular reviews of existing permissions. With the Garancy Recertification Center, business roles and the employees assigned to them can be systematically reviewed and confirmed. The first recertification campaign was completed within three weeks.

This allows IFB to combine the assignment and modification of access rights with regular reviews within a single IAM framework.

Results at a Glance

  • Implementation completed in just five months

  • 103 business roles forming the foundation of access rights management

  • Around 70 systems within the documented implementation scope

  • Around 350 managed user accounts

  • Centralized, cross-application business roles

  • Defined approval processes and Segregation of Duties

  • Greater responsibility for business departments

  • Integrated recertification with the Garancy Recertification Center

  • Automated access rights processes for joiners, leavers, and changes in responsibilities

Preparation as the Key to Successful IAM

The IFB Hamburg success story demonstrates that a successful IAM project does not have to start with software. The decisive step was to define Governance, responsibilities, roles, and processes first – and only then implement the technology.

This gave the bank a well-designed functional foundation that could be translated into Garancy within a remarkably short implementation period.

The centralized role model provides the foundation for structured access rights management across different applications, greater involvement of business departments, and regular reviews integrated directly into IAM processes.

Further Resources

NBank Gebäude
NBank

Identity Management Starts with Expert Guidance

75
Systems Connected
1.000
Roles Created
< 5%
Rights Assigned Directly
Gebäude der KGAL GmbH & Co. KG
KGAL GmbH & Co. KG

Enhanced Security and Compliance with IAM at KGAL

Flexible Role Models
Automated Processes
Simplified Recertification

Let’s Talk Business!

Are you facing challenges in cyber security, automation, or compliance? In a compact strategy meeting, we will clarify which IAM approaches make sense for your company.

What you can expect:

  • Discussion of your individual requirements

  • Practical insights into our identity management software

  • Q&A and recommendations for the next steps

More than 6.16 million managed identities worldwide
A man in a white shirt, holding a yellow folder, smiles while speaking into a smartphone, standing beside a window with soft light.