Success story
One access model across 100+ sites
How a major manufacturer automated more than 90% of identity-management processes across its Canadian and U.S. operations.
- 90%+
- of access request operations automated
- 15 min
- to provision an access, down from five days
- 100+
- sites across Canada and the United States

The situation
The client is a leading pulp-and-paper manufacturer operating across Canada and the United States, with tens of thousands of employees spread over more than a hundred sites. Access was granted and revoked by hand.
The IT estate made that harder than it sounds. Legacy mainframe and minicomputer systems ran alongside classic on-premises applications, while the organization was moving to a SaaS-based architecture.
The challenge
Manual access requests were slow enough to hold up people who had already started work, and inconsistent enough to be a security problem in their own right.
- Identities and their access rights were spread across many locations and prone to error.
- Granting and revoking access by hand delayed employees and cost IT time.
- Inconsistent practice raised the risk of improper access to sensitive systems.
- With no formal access model, approval workflow or review process, compliance could not be demonstrated.
The objective
The client set one critical objective: automate more than 90% of all access request operations. The aim was to cut the cost, the effort and the errors of managing access by hand, and to remove the delays that were holding employees up.
Beyond access requests, the identity lifecycle itself had to be automated: onboarding, lateral moves and departures, so that employee transitions were consistent and free of error.
What was built
OKIOK designed and implemented an enterprise-wide, role-based access model fitted to the organization’s structure and its mixed technology estate.
Thousands of business rules were defined with it, including separation-of-duty rules, so that access was granted and reviewed consistently across the whole identity lifecycle.
How it was done
The client engaged OKIOK as a strategic partner rather than a supplier, and the team assigned to it had already delivered access management work at this scale in banks and utilities.
The access model itself came out of hundreds of workshops held with representatives of every entity over several months. It was delivered and implemented gradually rather than in one cutover, on schedule and on budget.
The result
More than 90% of access requests are now automated, along with the identity lifecycle processes around them: onboarding, role changes and offboarding.
- Substantial cost reduction, from removing manual effort and IT involvement.
- Faster onboarding and offboarding, with fewer delays for the employee.
- Fewer provisioning errors, and less exposure from over-privileged accounts.
- Access review campaigns can be run at the granularity and frequency the risk warrants.
