From Manual Processes to Centralized IAM
The project was driven by banking supervisory requirements for IT (BAIT), with access rights management emerging as one of the key areas requiring action. Until then, IFB had managed access rights through application-specific concepts, Excel spreadsheets, and manual processes. Templates were used for access requests, while Microsoft Active Directory and SAP already contained initial role-like structures and composite roles.
The starting point was therefore far from unstructured. What was missing was a cross-application approach that consistently derived access rights from employees’ business responsibilities and made them centrally manageable.
Existing roles were sometimes combined individually, meaning that when responsibilities changed, permissions could be tied more closely to individuals than to clearly defined functions. Individual and group permissions existed side by side.
IFB wanted to fundamentally change this approach: Business departments would take greater responsibility for defining the access rights they needed, while a centralized IAM platform would provide the technical implementation and governance framework.
Governance and Roles First, Technology Second
One of the key success factors was the order in which the project was approached. Rather than selecting IAM software first and adapting internal processes afterward, IFB began by developing the organizational and methodological foundation.
The approach consisted of three core elements:
Defining internal policies, Governance, processes, and rules for access rights management
Developing business roles in close collaboration with the business departments
Implementing the completed concept with Garancy
Business responsibilities were identified based on organizational processes, job descriptions, and workshops with the departments, and then grouped into clearly defined roles. As a result, much of the functional concept was already complete before Garancy was implemented.
103 Business Roles Instead of an Unmanageable Role Landscape
When developing the role model, IFB was able to build on existing structures in Windows and SAP. Rather than replacing them entirely, the bank incorporated them into a broader, cross-application concept.
Permissions for smaller applications were also incorporated into the business roles. At the same time, the project team deliberately kept the number of roles manageable.
The result was 103 clearly defined business roles that provide a structured way to map responsibilities to the access rights employees need.
Approval processes were also defined before the technical implementation. Rules governing who can request access, who must approve it, and how permissions should be assigned were documented in workflows and subsequently implemented in the Garancy Process Center.
Segregation of Duties Built In from the Start
IFB also incorporated Segregation of Duties (SoD) into its governance framework from the outset. Permissions can be grouped into roles, but they must be derived from actual business responsibilities. At the same time, combinations of access rights must not violate defined separation-of-duties requirements.
Critical permissions were addressed early in the project as well. Rather than managing them solely as individual permissions, IFB grouped relevant access rights into critical business roles.
This meant that key governance rules were already defined before they were technically implemented in Garancy.
Live in Just Five Months
The thorough preparation paid off during the technical implementation. Garancy received a largely complete role and rules framework consisting of 103 business roles, defined approval paths, and clearly structured processes.
Because the processes had deliberately been kept straightforward, they could largely be implemented using standard Garancy functionality. The new identity management system went live after a project duration of just five months.
The key difference compared with many IAM projects was simple: IFB did not start with the technology. The bank had already defined how its future access rights management should work before implementation began.
Centralized Business Roles Across Different Systems
The central systems connected to Garancy include SAP as well as Microsoft Active Directory and Exchange. HR data is also incorporated into the IAM processes. For these central applications, business departments can assign, modify, and revoke access rights through Garancy in accordance with the defined approval rules.
Additional applications can be incorporated into the overarching access rights management framework. Where permissions cannot be provisioned directly, Garancy supports Order-to-Admin processes: If a business role includes a permission for one of these systems, the responsible IT administrator is notified so that the assignment can be completed.
This creates a centralized role model that brings automated and administrator-managed access rights together under a common Governance framework.
Giving Business Departments Greater Responsibility
With Garancy, IFB deliberately shifts part of the responsibility for access rights to the business departments. Managers can oversee employee access based on defined roles and approval rules, while the centralized IAM platform ensures that the established Governance processes are followed.
An additional link between business requirements and technical operations is the Access Rights Manager. This role acts as an interface between the business departments and technical operations, oversees the approval of access concepts, and can serve as an additional control point for certain role assignments or changes.
Recertification Integrated into IAM
Centralized access rights management also includes regular reviews of existing permissions. With the Garancy Recertification Center, business roles and the employees assigned to them can be systematically reviewed and confirmed. The first recertification campaign was completed within three weeks.
This allows IFB to combine the assignment and modification of access rights with regular reviews within a single IAM framework.
Results at a Glance
Implementation completed in just five months
103 business roles forming the foundation of access rights management
Around 70 systems within the documented implementation scope
Around 350 managed user accounts
Centralized, cross-application business roles
Defined approval processes and Segregation of Duties
Greater responsibility for business departments
Integrated recertification with the Garancy Recertification Center
Automated access rights processes for joiners, leavers, and changes in responsibilities
Preparation as the Key to Successful IAM
The IFB Hamburg success story demonstrates that a successful IAM project does not have to start with software. The decisive step was to define Governance, responsibilities, roles, and processes first – and only then implement the technology.
This gave the bank a well-designed functional foundation that could be translated into Garancy within a remarkably short implementation period.
The centralized role model provides the foundation for structured access rights management across different applications, greater involvement of business departments, and regular reviews integrated directly into IAM processes.
:quality(100))
:quality(100))
:quality(100))
:quality(100))
:quality(80))