🔥 Free Identity Risk and Compliance Assessment for Human, Non-Human Identities and AI Agents. See the announcement →

Accounting software company removes standing admin access with just-in-time, purpose-based access

Fast-growing accounting software company used BalkanID to automate joiners and leavers during its move to a new identity provider, then replaced standing admin privileges with just-in-time access granted for a stated purpose and removed automatically.

Key Results

  • Joiner and leaver flows automated during the identity provider migration. The team was "very impressed with the offboarding flow."
  • Standing admin access replaced by time-bound, purpose-based access for developers and IT, used regularly.
  • Elevated access to deployment tooling provisioned in about one minute on request, and removed automatically.
  • Renewed for a second year, expanding into access reviews and campaigns.

A fast-growing accounting software company used BalkanID to automate joiners and leavers during its move to a new identity provider, then replaced standing admin privileges with just-in-time access granted for a stated purpose and removed automatically.

Systems

PeopleForce (HR), Okta, Google Workspace, secure enterprise browser, Slack, GitHub, Jira Service Management, AWS

Drivers

Minimize time spent on onboarding and offboarding; remove standing privileged access for developers and IT

Challenges before BalkanID

  • The company was building identity operations in-house while migrating from Google to Okta, with a lean security team.
  • Joiners and leavers depended on manual steps across the HR system, Google and Okta.
  • Developers and IT held standing admin access across hundreds of groups. As the admin put it: "You've seen these hundreds of groups. This is completely unmanageable."

What they implemented

  • Joiner: an HR webhook generates the corporate email, creates the user, and three days before the start date raises an access request that maps job title to Google and Okta groups, with approval in Slack.
  • Leaver: daily termination check that suspends the user in Google and Okta.
  • Group sync from Okta to the enterprise browser policy platform.
  • JITPBAC for admin privileges: users start and stop a "purpose" in Slack, access is provisioned automatically, and it expires after at most 24 hours.
  • The customer's own admins configure purposes and approval policies without BalkanID help.

Outcomes

  • Joiner and leaver flows automated during the identity provider migration. The team was "very impressed with the offboarding flow."
  • Standing admin access replaced by time-bound, purpose-based access for developers and IT, used regularly.
  • Elevated access to deployment tooling provisioned in about one minute on request, and removed automatically.
  • Renewed for a second year, expanding into access reviews and campaigns.

Company Overview
Industry
B2B SaaS (accounting practice management)
Headquarters
USA
Employees
~500
BalkanID IGA Capabilities
Lifecycle (joiner and leaver), Just-in-time purpose-based access control (JITPBAC), Access Reviews
Number of Identities Managed
2000+
Number of Entitlement
10,000

Get your complimentary identity risk assessment.

As part of our extended Cybersecurity Awareness initiative, BalkanID is offering organizations a one-time complimentary ISPM Analysis.