Service delivery and operational workflows
Enterprise transformation · Authorization blueprint
S.W.I.T.C.H.User Management
Defined the authorization foundation for consolidating more than 50 internal systems into one end-to-end platform with three modules.
- Role
- IT Functions Workstream co-leadUser management lead
- Duration
- 2019 — 2022
- Milestone
- First release delivered
One identity entry point.Three independent access questions.
A unified platform spanning subsidiaries, locations, and business functions needed one coherent authorization concept—without losing the operational restrictions embedded across the legacy landscape.
What can this person do?
Reusable business roles translated responsibilities into explicit operation-level permissions.
The platform boundary
One platform.
Three modules.
Clear ownership.
The target separated customer and commercial work, operational delivery, and reporting—while identity and authorization remained shared foundations across the platform.
Customer, commercial, and presales workflows
Shared insight, controls, and decision support
My accountability
From business responsibility to enforceable access.
- 01Co-led the IT Functions workstream on behalf of the customer organization
- 02Owned user management and the authorization concept
- 03Translated business responsibilities into roles, operations, and access rules
I decided which legacy roles represented the same business responsibility and could be consolidated without widening access.
I mapped each consolidated role to the exact operations it required—including view, edit, approve, and domain-specific actions.
I separated role permissions from location and subsidiary rules so roles remained reusable across contexts without exposing the wrong content.
I used Microsoft Entra SSO as the shared identity entry point while keeping authorization decisions inside the business access model.
What changed after consolidation
- Consolidated a landscape of more than 50 internal systems into one platform with three core modules.
- Established a single authentication and authorization point, reducing the associated maintenance costs by more than half.
- Reduced manual administration and the overhead of maintaining fragmented access logic across the legacy landscape.
- Implemented more than 50 business roles with operation-level permissions, contextual restrictions, and Microsoft Entra SSO.
Authorization is not a technical afterthought. It is a product model of how the organization actually works—and it becomes more durable when business owners can see their actual responsibilities reflected in it.
Evidence note · Consolidation and maintenance figures reflect the supplied project outcomes; vendor details and proprietary architecture remain confidential.
Start a conversation