Competence detail

Authorization Management & Access Governance

Authorisation structures are the foundation of every secure IT landscape – and in reality they are often historically grown, redundant and hard to trace. Vetrexa analyses, cleans up and optimises your role and access structures cross-system, governance-compliant and audit-ready. From baseline assessment through to continuous operation we deliver defensible results – compliant with MaRisk, BAIT and DORA.

Overview

Why structured authorization management is now indispensable.

Regulated industries face the challenge of managing thousands of identities, roles and entitlements consistently, in an audit-proof way and efficiently across hybrid system landscapes. Lack of transparency, over-privileged accounts and unresolved SoD conflicts are among the most common audit findings – and among the largest attack surfaces in cybersecurity.

We combine functional consulting, deep tooling know-how (including the NEXIS Platform, IVIP and SailPoint IIQ) and regulatory expertise into an integrated approach. The result: clear role models, clean entitlements, effective recertifications and KPI-based reporting that convinces the board, internal audit and supervisors alike.

Services

What we deliver.

Six building blocks for consistent, audit-ready and economically sustainable authorisation management.

Analysis and clean-up of existing entitlements

We create transparency over grown entitlement landscapes, identify redundancies and remove legacy baggage across systems.

  • Baseline capture and inventory of all entitlements
  • Detection of orphaned and redundant accounts
  • Analysis of over-privileged users and toxic combinations
  • Cross-system evaluations (SAP, AD, ServiceNow, cloud)
  • Prioritised remediation measures and quick wins

RBAC modelling and role design

We design robust role models that reflect business processes while remaining technically efficient to operate.

  • Role concepts based on business processes
  • Role mining and role consolidation with NEXIS
  • Separation of business and IT roles
  • Approval and request workflows
  • Governance model including role ownership

SoD analysis and conflict remediation

We identify, assess and remediate segregation-of-duties conflicts – rule-based and fully traceable.

  • Definition and maintenance of the SoD rule set
  • Cross-system conflict analysis
  • Risk assessment and prioritisation
  • Mitigating controls for exceptions
  • Continuous SoD monitoring

Recertification campaigns and access reviews

We design and operate audit-proof recertifications – from campaign planning to result analysis.

  • Campaign design by risk and system class
  • Owner reviews and escalation logic
  • Automated reminders and deadline management
  • Audit-proof documentation and audit trail
  • Analysis and derivation of corrective actions

NEXIS Platform rollout and IVIP activation

As NEXIS Silver Partner we accompany you from tool selection through to productive operation of the NEXIS Platform with IVIP at its core.

  • Fit/gap analysis and business case
  • Connection of source systems and data quality
  • Configuration of IVIP, role mining and reviews
  • Integration into your existing IAM/IGA landscape
  • Enablement and knowledge transfer to your business

Governance reporting and KPI dashboards

We deliver metrics and reports that create steering capability for business, IT, internal audit and supervisors.

  • Definition of risk-oriented KPIs
  • Power BI dashboards for management and audit
  • Regulatory reports (MaRisk, BAIT, DORA)
  • Trend analyses and maturity measurement
  • Automated data preparation from IGA sources

Approach

Our approach in 4 phases.

A clearly structured path from analysis through to sustainable operation – iterative, transparent and audit-ready.

Analysis

Baseline capture of all identities, roles, entitlements and processes. Assessment of SoD conflicts, over-privileged accounts and governance gaps. Outcome: a defensible situation view and prioritised action plan.

Design

Target design: RBAC/ABAC model, SoD rule set, recertification process, role governance and tooling architecture (e.g. NEXIS Platform, SailPoint IIQ). Sign-off by business, IT and compliance.

Implementation

Configuration, role rollout, clean-up, connection of source systems, build-out of reports and training of role owners. Delivery in cleanly cut waves with defined success criteria.

Continuity

Operation of recertification campaigns, continuous monitoring, KPI reporting and iterative evolution of the role model – as a managed service or anchored within your organisation.

Project experience

Selected projects.

Representative reference projects – without naming clients.

Banking

Entitlement clean-up and RBAC rollout

Cross-system clean-up of legacy entitlements, role consolidation with NEXIS/IVIP, build-out of governance and KPI reporting.

NEXIS · IVIP · SailPoint IIQ · SAP · AD · Power BI · MaRisk

Insurance

Audit-proof recertification

Design and operation of half-yearly campaigns. Owner reviews, escalation logic, audit trail and automated reporting.

SailPoint IIQ · ServiceNow · Confluence · Requirements Engineering

IT Services

SoD rule set and conflict remediation

Build-out of a group-wide SoD rule set, cross-system conflict analysis and establishment of mitigating controls.

NEXIS · SAP GRC · Jira/XRay · Power BI · COBIT

Toolset & frameworks

What we work with.

Proven tools and frameworks for authorization management and access governance.

Related competences

Goes well with.

Follow-on topics from the Vetrexa portfolio.

IAM & Security

Target architecture, IGA, PAM and Zero Trust – the strategic frame around your authorisation management.

To detail page →

Managed Services

Operation, monitoring and continuous evolution of your IAM and entitlement landscape.

To detail page →

Partner NEXIS Platform

Silver partnership with NEXIS – analysis and governance of entitlements with the IVIP core.

To our partners →

FAQ

Frequently asked questions.

How is RBAC different from ABAC?

RBAC (Role-Based Access Control) grants entitlements based on defined roles – structurally clear, easily auditable and well suited to stable organisations. ABAC (Attribute-Based Access Control) decides dynamically based on attributes such as department, location, time of day or risk class, and is more flexible for complex, context-dependent access decisions. In practice we frequently combine both: RBAC as the backbone, ABAC for fine-grained exceptions and risk-based decisions.

What is the benefit of the NEXIS Platform versus built-in tools?

The NEXIS Platform, powered by IVIP, provides a cross-system view of identities, roles and entitlements including visualisation, role mining and automated recommendations. Built-in tooling of individual systems (SAP, AD, ServiceNow) only shows its own slice and rarely uncovers SoD conflicts, orphaned accounts or redundancies across systems. NEXIS significantly accelerates clean-up, recertification and reporting.

How often should recertifications be run?

For critical systems and privileged access we recommend at least half-yearly recertifications, and annual campaigns for standard entitlements. Event-driven reviews (mover, leaver, reorganisation) and risk-based ad-hoc recertifications complement the regular cycle and meet the requirements of MaRisk AT 4.3.1 and DORA Art. 9.

How do you ensure MaRisk and DORA compliance?

We align authorisation processes rigorously with MaRisk AT 7.2, BAIT and DORA Chapter II: documented role models, traceable request and approval workflows, audit-proof recertifications, SoD controls, KPI reporting and full audit trails. Controls are surfaced as evidence via Power BI and the GRC tool and are regularly confirmed by internal audit and external auditors.

Entitlements under control. Governance demonstrable.

Talk to us about your authorisation structures – we show you the fastest path to transparency, compliance and economically sound operation.

Request consultation