Competence detail

Authorization Management & Access Governance

Authorisation structures are the foundation of every secure IT landscape – and in reality they are often historically grown, redundant and hard to trace. Vetrexa analyses, cleans up and optimises your role and access structures cross-system, governance-compliant and audit-ready. We combine functional role modelling (RBAC, ABAC, PBAC), robust Segregation-of-Duties rule sets and effective recertification campaigns into a coherent access governance target picture. As Silver Partner of the NEXIS Platform we activate the IVIP core for identity, role and entitlement analytics and dovetail it with your existing Identity Governance and Administration (IGA) stack – from SailPoint through SAP GRC to Active Directory. From baseline assessment through to continuous operation we deliver defensible results: audit-proof, KPI-based and compliant with MaRisk AT 4.3.1 / AT 7.2, BAIT and DORA Chapter II. Entitlements thereby move from being a compliance cost centre to a measurable steering and security lever within your organisation.

Overview

Why structured authorization management is now indispensable.

Regulated industries face the challenge of managing thousands of identities, roles and entitlements consistently, in an audit-proof way and efficiently across hybrid system landscapes. Lack of transparency, over-privileged accounts and unresolved SoD conflicts are among the most common audit findings – and among the largest attack surfaces in cybersecurity.

We combine functional consulting, deep tooling know-how (including the NEXIS Platform, IVIP and SailPoint IIQ) and regulatory expertise into an integrated approach. The result: clear role models, clean entitlements, effective recertifications and KPI-based reporting that convinces the board, internal audit and supervisors alike.

Complexity here grows out of several structural drivers at once. Cloud migration (Microsoft Entra ID, AWS IAM, Google Cloud IAM, SaaS portals) practically doubles the number of target systems to be governed overnight and introduces new entitlement models beyond classical AD groups. Mergers, acquisitions and carve-outs force the consolidation of heterogeneous role models, the resolution of naming conflicts and the clean separation of regulatory responsibilities. Specialist career paths and lateral moves lead to entitlement accumulation ("privilege creep") when legacy rights are not consistently revoked on role change. Technical users, service accounts and Non-Human Identities (NHI) – from RPA bots through Kubernetes workloads to API clients – are, in many organisations, growing in numbers faster than human identities while remaining the most weakly documented. On top of this come third-party access (ICT third-party providers in the DORA sense), break-glass accounts and time-boxed Just-in-Time access rights, each of which requires its own governance rules. A modern access governance target picture must reflect this diversity in a coherent IGA data model so that recertification, SoD analysis and reporting do not collapse into silos.

Services

What we deliver.

Six building blocks for consistent, audit-ready and economically sustainable authorisation management.

Analysis and clean-up of existing entitlements

We create transparency over grown entitlement landscapes, identify redundancies and remove legacy baggage across systems. Using role mining and peer-group analysis from the IVIP core of the NEXIS Platform, we quantify over- and under-entitlement on a factual basis. Clean-up proceeds in controlled waves, each with defined success and rollback criteria.

  • Baseline capture and inventory of all entitlements
  • Detection of orphaned and redundant accounts
  • Analysis of over-privileged users and toxic combinations
  • Cross-system evaluations (SAP, AD, ServiceNow, cloud)
  • Prioritised remediation measures and quick wins
  • Peer-group analysis and statistical outlier detection
  • Controlled rollback capability for each clean-up wave

RBAC modelling and role design

We design robust role models that reflect business processes while remaining technically efficient to operate. Business roles bundle functional task profiles, technical roles encapsulate system entitlements – between them we build a clear, multi-tier role hierarchy that cleanly separates inheritance, exceptions and owner delegation. We additionally integrate attribute-based control (ABAC) and policy-based models (PBAC) wherever static roles are not sufficient.

  • Role concepts based on business processes
  • Role mining and role consolidation with NEXIS
  • Separation of business and IT roles
  • Approval and request workflows
  • Governance model including role ownership
  • Multi-tier role hierarchy with clean inheritance
  • Combination of RBAC, ABAC and PBAC per use case

SoD analysis and conflict remediation

We identify, assess and remediate segregation-of-duties conflicts – rule-based and fully traceable. The SoD matrix is derived process-orientated from functional risk scenarios (e.g. vendor creation / release, purchase order / goods receipt, payment initiation / account maintenance) and validated across SAP, Active Directory and cloud roles. For unavoidable conflicts we establish documented, mitigating controls with clear ownership and regular effectiveness evidence.

  • Definition and maintenance of the SoD rule set
  • Cross-system conflict analysis
  • Risk assessment and prioritisation
  • Mitigating controls for exceptions
  • Continuous SoD monitoring
  • Process-orientated SoD matrix with risk scenarios
  • Evidence of control effectiveness (design & operating effectiveness)

Recertification campaigns and access reviews

We design and operate audit-proof recertifications – from campaign planning to result analysis. Standardised access review templates, clearly defined escalation rules and legally sound attestation workflows ensure that every decision is documented, attributable and retrievable. We additionally establish micro-certification for privileged and high-risk roles with significantly shorter cycles.

  • Campaign design by risk and system class
  • Owner reviews and escalation logic
  • Automated reminders and deadline management
  • Audit-proof documentation and audit trail
  • Analysis and derivation of corrective actions
  • Access review templates with owner delegation
  • Micro-certification for privileged access

NEXIS Platform rollout and IVIP activation

As NEXIS Silver Partner we accompany you from tool selection through to productive operation of the NEXIS Platform with IVIP at its core. We consolidate identities and entitlements from SailPoint, SAP, Active Directory and cloud directories into a single analytics model and activate role mining, peer-group analysis and continuous SoD monitoring. Rollout proceeds incrementally with clearly scheduled data-load waves and measurable governance milestones.

  • Fit/gap analysis and business case
  • Connection of source systems and data quality
  • Configuration of IVIP, role mining and reviews
  • Integration into your existing IAM/IGA landscape
  • Enablement and knowledge transfer to your business
  • Consolidated analytics model across hybrid sources
  • Scheduled data-load waves with clear governance milestones

Governance reporting and KPI dashboards

We deliver metrics and reports that create steering capability for business, IT, internal audit and supervisors. Core KPIs such as "time to certify", "SoD conflicts open / mitigated", "orphaned accounts per system" and "recertification response rate" are visualised in Power BI and backed with defined thresholds. We also generate supervisor-ready ad-hoc reports available at the push of a button during audits.

  • Definition of risk-oriented KPIs
  • Power BI dashboards for management and audit
  • Regulatory reports (MaRisk, BAIT, DORA)
  • Trend analyses and maturity measurement
  • Automated data preparation from IGA sources
  • Threshold-based alerts and escalation
  • Supervisor-ready ad-hoc reports on demand

Approach

Our approach in 4 phases.

A clearly structured path from analysis through to sustainable operation – iterative, transparent and audit-ready.

Analysis

Baseline capture of all identities, roles, entitlements and processes. Assessment of SoD conflicts, over-privileged accounts and governance gaps. Outcome: a defensible situation view and prioritised action plan.

Design

Target design: RBAC/ABAC model, SoD rule set, recertification process, role governance and tooling architecture (e.g. NEXIS Platform, SailPoint IIQ). Sign-off by business, IT and compliance.

Implementation

Configuration, role rollout, clean-up, connection of source systems, build-out of reports and training of role owners. Delivery in cleanly cut waves with defined success criteria.

Continuity

Operation of recertification campaigns, continuous monitoring, KPI reporting and iterative evolution of the role model – as a managed service or anchored within your organisation.

Regulation

Regulation & compliance in detail.

How authorisation management maps concretely to the relevant requirements.

MaRisk / BAIT

MaRisk AT 7.2 and BAIT chapter 5 (user access management) require documented needs assessment, the four-eyes principle for granting and modifying rights and a regular, risk-orientated recertification. We implement this via technically enforced separation of requester and approver, defined cycles for standard and privileged rights and an audit-proof chain of evidence in NEXIS and SailPoint. Requirements for emergency and break-glass access (AT 7.3, BAIT 6) are addressed consistently.

DORA

The Digital Operational Resilience Act (DORA), chapters II and V, addresses in particular ICT risk management and ICT third-party access governance. We consolidate access rights of external ICT providers into a shared entitlement register, link them to the contractual and concentration-risk register and ensure that access rights are demonstrably minimal, purpose-bound and time-limited in line with the RTS on ICT Risk Management. Reportable incidents (Art. 17 ff.) become directly evidenceable via the access governance audit trail.

ISO 27001:2022

The revised controls A.5.15 to A.5.18 consolidate access control, identity management, authentication information and access rights. We translate the controls into concrete process building blocks – request, approval, assignment, review, revocation – and document them in a control matrix that can be used directly for ISO 27001 audits and the Statement of Applicability (SoA). Evidence is generated automatically from IGA and the NEXIS Platform.

Project experience

Selected projects.

Representative reference projects – without naming clients.

Banking

Entitlement clean-up and RBAC rollout

Cross-system clean-up of legacy entitlements, role consolidation with NEXIS/IVIP, build-out of governance and KPI reporting.

NEXIS · IVIP · SailPoint IIQ · SAP · AD · Power BI · MaRisk

Insurance

Audit-proof recertification

Design and operation of half-yearly campaigns. Owner reviews, escalation logic, audit trail and automated reporting.

SailPoint IIQ · ServiceNow · Confluence · Requirements Engineering

Insurance

DORA level 2 access governance

Standalone DORA case: consolidation of some 12,000 entitlement rules into a single target model, an RTS-compliant ICT risk register directly linked to third-party access rights and automated evidence for supervisors and external auditors.

DORA RTS · NEXIS · IVIP · SailPoint IIQ · ServiceNow · Power BI

IT Services

SoD rule set and conflict remediation

Build-out of a group-wide SoD rule set, cross-system conflict analysis and establishment of mitigating controls.

NEXIS · SAP GRC · Jira/XRay · Power BI · COBIT

Automotive

Data-centre entitlement clean-up

Cross-system clean-up of privileged access in data-centre environments: analysis of admin accounts, just-in-time access design and hardening of break-glass processes with PAM tooling.

Active Directory · PAM · SailPoint IIQ · ServiceNow · ISO 27001

Industry

NEXIS rollout with IVIP

End-to-end rollout of the NEXIS Platform with the IVIP core across hybrid SAP, AD and cloud directories. Role consolidation, role mining and build-out of a group-wide recertification process delivered as a managed service.

NEXIS · IVIP · SAP · AD · Microsoft Entra ID · Power BI

Toolset & frameworks

What we work with.

Proven tools and frameworks for authorization management and access governance.

Related competences

Goes well with.

Follow-on topics from the Vetrexa portfolio.

IAM & Security

Target architecture, IGA, PAM and Zero Trust – the strategic frame around your authorisation management.

To detail page →

Managed Services

Operation, monitoring and continuous evolution of your IAM and entitlement landscape.

To detail page →

Partner NEXIS Platform

Silver partnership with NEXIS – analysis and governance of entitlements with the IVIP core.

To our partners →

Best practices

Role modelling — best practices.

Four guardrails from field practice – what works, and what reliably leads to role explosion.

Business roles before technical roles

Role models typically fail when they are constructed backwards from technical entitlements. The starting point is always the functional task cut ("corporate credit officer", "HR recruiter"). Technical roles (SAP profiles, AD groups, cloud roles) are only bundled underneath and linked via assignment logic – not the other way round.

Role hierarchy with restraint

Two to at most three hierarchy tiers are manageable in practice: base role, business role, supplementary role. Deeper inheritance trees generate hidden entitlements that neither owners nor internal audit can reliably oversee. Inheritance is a tool – not an end in itself.

A reject attitude towards redundancy

Every new role is actively validated against the existing catalogue: coverage, overlap, similarity. Redundant roles are consistently rejected or consolidated with existing ones. Without this discipline the role model grows linearly with the number of requesters – and becomes unmaintainable.

Minimal SoD, consistently enforced

An SoD rule set with ten highly relevant rules that are consistently monitored and enforced works better than a catalogue of hundreds of rules nobody maintains anymore. Prioritisation by process risk and materiality is mandatory. Exceptions receive ownership, a compensating control and an expiry date.

FAQ

Frequently asked questions.

How is RBAC different from ABAC?

RBAC (Role-Based Access Control) grants entitlements based on defined roles – structurally clear, easily auditable and well suited to stable organisations. ABAC (Attribute-Based Access Control) decides dynamically based on attributes such as department, location, time of day or risk class, and is more flexible for complex, context-dependent access decisions. In practice we frequently combine both: RBAC as the backbone, ABAC for fine-grained exceptions and risk-based decisions.

How do RBAC, ABAC and PBAC differ?

RBAC grants rights via defined roles and is static, auditable and easy to explain. ABAC (Attribute-Based Access Control) takes decisions dynamically based on user, resource and context attributes and suits fine-grained, situation-dependent access. PBAC (Policy-Based Access Control) lifts control to the level of declarative policies – policies aggregate multiple attributes and roles and are evaluated centrally in a policy engine. In practice we use RBAC as the foundation, ABAC for exceptions and PBAC particularly in zero-trust and cloud architectures.

What is the benefit of the NEXIS Platform versus built-in tools?

The NEXIS Platform, powered by IVIP, provides a cross-system view of identities, roles and entitlements including visualisation, role mining and automated recommendations. Built-in tooling of individual systems (SAP, AD, ServiceNow) only shows its own slice and rarely uncovers SoD conflicts, orphaned accounts or redundancies across systems. NEXIS significantly accelerates clean-up, recertification and reporting.

How often should recertifications be run?

For critical systems and privileged access we recommend at least half-yearly recertifications, and annual campaigns for standard entitlements. Event-driven reviews (mover, leaver, reorganisation) and risk-based ad-hoc recertifications complement the regular cycle and meet the requirements of MaRisk AT 4.3.1 and DORA Art. 9.

How often should IGA reviews be run?

Beyond pure recertification, we recommend a tiered review model: quarterly reviews for privileged access and critical applications, half-yearly reviews for standard systems in regulated areas and at least annual reviews for the bulk standard. The model is complemented by event-driven reviews (role change, reorganisation, leaver), risk-based ad-hoc reviews and continuous IGA control through analytics in NEXIS and SailPoint – producing a rhythm that is both supervisorily defensible (MaRisk, DORA) and operationally sustainable.

How do you handle hundreds of thousands of entitlements?

Dealing with very large entitlement volumes – typically several hundred thousand entitlements across SAP, Active Directory, cloud and business systems – only succeeds with a clear analytics approach. We first build a consolidated data model in the NEXIS Platform, classify entitlements by risk, usage and redundancy, and derive candidate roles via role mining and peer-group analysis. Recertifications are made economically viable through owner delegation, risk-based sampling and micro-certification; clean-ups proceed in waves with clear success criteria rather than as a big bang.

How do you ensure MaRisk and DORA compliance?

We align authorisation processes rigorously with MaRisk AT 7.2, BAIT and DORA Chapter II: documented role models, traceable request and approval workflows, audit-proof recertifications, SoD controls, KPI reporting and full audit trails. Controls are surfaced as evidence via Power BI and the GRC tool and are regularly confirmed by internal audit and external auditors.

Entitlements under control. Governance demonstrable.

Talk to us about your authorisation structures – we show you the fastest path to transparency, compliance and economically sound operation.

Request consultation