PortfolioDP.

Enterprise transformation · Authorization blueprint

S.W.I.T.C.H.User Management

Defined the authorization foundation for consolidating more than 50 internal systems into one end-to-end platform with three modules.

Role
IT Functions Workstream co-leadUser management lead
Duration
2019 — 2022
Milestone
First release delivered
The consolidation result
50+Legacy systems
1End-to-end platform
OSSOperations supportBSSBusiness supportReportingBusiness intelligence
Authorization, treated as a product model

One identity entry point.Three independent access questions.

A unified platform spanning subsidiaries, locations, and business functions needed one coherent authorization concept—without losing the operational restrictions embedded across the legacy landscape.

Active policy lens

What can this person do?

Reusable business roles translated responsibilities into explicit operation-level permissions.

ViewEditApprove

The platform boundary

One platform.
Three modules.
Clear ownership.

The target separated customer and commercial work, operational delivery, and reporting—while identity and authorization remained shared foundations across the platform.

End-to-end platformShared product backbone
01OSSOperations support

Service delivery and operational workflows

02BSSBusiness support

Customer, commercial, and presales workflows

03ReportingBusiness intelligence

Shared insight, controls, and decision support

Shared foundationIdentity · authorization · audit context

My accountability

From business responsibility to enforceable access.

  • 01Co-led the IT Functions workstream on behalf of the customer organization
  • 02Owned user management and the authorization concept
  • 03Translated business responsibilities into roles, operations, and access rules
Decision ledger
Decision 1

I decided which legacy roles represented the same business responsibility and could be consolidated without widening access.

Decision 2

I mapped each consolidated role to the exact operations it required—including view, edit, approve, and domain-specific actions.

Decision 3

I separated role permissions from location and subsidiary rules so roles remained reusable across contexts without exposing the wrong content.

Decision 4

I used Microsoft Entra SSO as the shared identity entry point while keeping authorization decisions inside the business access model.

Operational impactOne access model. Less maintenance.

What changed after consolidation

  • Consolidated a landscape of more than 50 internal systems into one platform with three core modules.
  • Established a single authentication and authorization point, reducing the associated maintenance costs by more than half.
  • Reduced manual administration and the overhead of maintaining fragmented access logic across the legacy landscape.
  • Implemented more than 50 business roles with operation-level permissions, contextual restrictions, and Microsoft Entra SSO.
Authorization is not a technical afterthought. It is a product model of how the organization actually works—and it becomes more durable when business owners can see their actual responsibilities reflected in it.

Evidence note · Consolidation and maintenance figures reflect the supplied project outcomes; vendor details and proprietary architecture remain confidential.

Continue exploring
Next case study

CDP Foundation

Start a conversation

Let's find what's
worth building.

I am open to conversations about complex product ownership, business analysis, supplier evaluation, and delivery work that needs a steady bridge between business and engineering.