The situation
The group ran identity the way most manufacturers do: a directory for employees, a separate arrangement for the plants, and a long tail of accounts for dealers, suppliers and maintenance crews. Previous IAM tooling had been added over time and had become the thing everybody worked around — slow, hard to change, and unreliable at the moments that mattered most.
Three constraints shaped the design, and none of them appear in a standard IAM requirement list:
- Shared terminals on the line, used by several people across three shifts.
- Systems on segmented networks that were never going to reach the internet.
- A partner population employed by other companies, changing constantly.
What was done
Monokee was placed in front of the existing estate rather than in place of it. The directories stayed where they were; applications were moved to single sign-on one at a time, and each journey was designed on the canvas so the authentication asked of a person could depend on where they were and what they were reaching.
Dealers and suppliers were given their own domains, with their own administrators operating inside limits set centrally.
After years of instability and performance issues caused by previous IAM solutions, Monokee finally gave us the reliability, scalability, and responsiveness we needed to support our business.
— CISO of a leading automotive group
What changed
- One access layer for office, plant and partner populations, with different journeys behind it.
- No directory migration: the estate modernised application by application.
- Authentication on the line designed against the constraints that actually exist there.
Where to go next
The industry-specific version of this argument is on the Automotive and Manufacturing page; the incremental approach is described in IAM modernisation.