How a major insurance group replaced seven years of stalled legacy IGA with a unified automated identity governance platform, connecting 12+ systems, eliminating orphaned accounts, and cutting audit preparation from weeks to hours.
This major insurance group had invested heavily in identity governance for the better part of a decade. The licences were paid, the professional services teams were engaged, and the roadmaps were presented. Yet when the organisation's security leadership took stock in late 2024, the reality was stark: after seven years on a legacy IGA platform, only 10% of the target systems were meaningfully connected, ServiceNow integration was effectively broken, privileged access management operated in a silo entirely outside the governance lifecycle, and the organisation had no reliable, real-time picture of who had access to what.
This was not a story of a vendor that failed to deliver a single feature, It was a pattern of compounding shortfalls, each one manageable in isolation, but collectively leaving the organisation exposed, operationally burdened, and increasingly unable to meet its regulatory obligations.
After 18 months of implementation, only 10% of the target systems were connected. Every platform upgrade required a fresh professional services engagement and months of re-testing.
The ServiceNow integration was one-directional. Tickets were raised but never automatically fulfilled. IT staff spent hours each week manually reconciling records across both systems.
Privileged accounts were managed entirely outside the IGA lifecycle. When a senior administrator departed, their privileged access persisted undetected and was discovered only in a manual audit weeks later.
Regulators requested a full access report. The platform could account for only 10% of the systems. Three weeks of manual extraction still produced an incomplete picture.
Seven years in, only 10% of the target systems were connected. The board mandated a full replacement, one that could connect every system, deliver a working ServiceNow integration, bring PAM into the governance lifecycle, and provide real-time visibility across the entire organisation.
The organisation's identity landscape had grown into a patchwork of legacy policy platforms, HR systems, cloud applications, and on-premises directories, each holding its own identity records with no synchronisation between them. The consequences were felt across every part of the business.
With 12+ disconnected systems, there was no single source of truth for who held access to what. Answering a basic access question required manual queries across multiple platforms and often took days.
New hires waited between three and five business days for access to the systems they needed on day one. Every role change required a manual IT ticket, creating backlogs and security gaps simultaneously.
Preparing for SOX and state insurance regulatory audits required weeks of manual data gathering across disconnected systems. There was no guarantee of completeness, and the process consumed significant IT and compliance resource every quarter.
When employees or contractors departed, access revocation was manual and inconsistent. Former staff regularly retained access to sensitive policy administration and claims systems for weeks or months after their departure.
"We had invested in identity governance for seven years and still could not tell a regulator with confidence who had access to our most sensitive systems. That was no longer acceptable."
Following a structured evaluation, the organisation selected ObserveID as its converged identity security platform. The decision was driven by ObserveID's ability to connect all 12+ systems through pre-built connectors, deliver a bidirectional ServiceNow integration, bring privileged access management into the same governance lifecycle as standard identities, and provide real-time visibility across the entire identity estate from day one.
Deployment followed a phased, objective-based approach designed to deliver measurable value at each stage without disrupting insurance operations. System discovery and entitlement mapping came first, followed by connector deployment, role-based access policy configuration, lifecycle automation activation, and finally compliance and audit readiness.
Pre-built connectors linked all 12+ systems including legacy policy platforms, Active Directory, Workday, ServiceNow, and cloud applications, into a single identity fabric with real-time synchronisation.
Policy-based automation triggered provisioning, role changes, and full access revocation in real time as HR system events occurred. No manual tickets.
For the first time, access requests raised in ServiceNow were automatically fulfilled by ObserveID, eliminating the manual reconciliation that had consumed IT resource for years.
Privileged accounts were brought under the same IGA policies as standard identities. Privileged access is now provisioned, reviewed and revoked through the same automated workflows.
Every access event is automatically logged and pre-formatted for SOX, state insurance regulations, and internal audit requirements. Access certifications run on schedule with no manual preparation.
| Specifications | BEFORE ObserveID | AFTER ObserveID |
|---|---|---|
| Identity Visibility | Siloed across 12+ systems | Single unified view |
| Onboarding Time | 3-5 business days | Same day, automated |
| Offboarding | Manual, inconsistent, days | Instant complete revocation |
| ServiceNow | Oneway, manually reconciled | Bidirectional, fully automated |
| PAM Governance | Entirely outside IGA policies | Unified under same lifecycle |
| Audit Preparation | 2 weeks of manual effort | Automated, always ready |
| Orphaned Accounts | Persistent and undetected | Zero, continuously monitored |
| Compliance Posture | Reactive, gap-ridden | Proactive: pre-aligned |
The following results were achieved by this insurance group following ObserveID deployment.