Yeah, welcome, good morning and thanks for participating our session about Identity Serenity and why just another software isn't the future of IAM at Schwarz. Some facts about us, the Schwarz group, mainly you know us from our retail units Lille and Kaufland which were in 32 countries having more than 14 000 stores worldwide but we are also in recovery and recycling and in production so we are manufacturers of breads, ice creams, coffees, beverages and much more. Where are we located? Schwarz Digits.
We provide digital IT and digital and IT solutions for our internal businesses but also on the external market, IT solutions, cloud solutions, AI and and more for the e-commerce. Who are we? My name is Patrick, I'm the engineering lead for Identity and Access Management and I'm Dorian, I'm the domain product owner for Workforce Identity and Access Management at Schwarz. Yeah and we are looking forward to speak today about our challenges, our roadmap and our self-made components that lead us to Identity Serenity. So the challenges in the in the early days.
We started in 2015 building a very big IAM solutions for all employees of our group. Started with a on-premise vendor solution for sure, with multi-talent architecture, it was directory based, it was one user store for all employees with the first small HR interface for identity for automatic identity life cycles and first identity provider that provides the first authentications for all employees and we started with multiple smaller tools and user interfaces for specific purposes. So what happens if you have a good product?
People start building trust in it, people start using it and that's what happened to us, a good thing. We call this the phase of rapid expansion. So within the years from 18 to 20, 21, our tool got more and more use cases that we started looking at. Not only that the Schwarz group grow beyond what it used to be, the set of identities we administered grew from roughly 50,000 identities we quickly grew to more than 500,000 identities. We supported many many new use cases like multi-factor authentication for store employees to push digitalization down to the blue-collar workers.
We added functionality for role management via API because new cool modern products didn't want to administrate their permission sets manually somewhere, they wanted to do that through APIs. Of course we had to implement our business logic so we had to extend our feature set there. We added directories for the store apps to cope with the workload that suddenly emerged when our IT department started rolling out functionality down to the store level. When goods management didn't end at the warehouse but went right down to the store shelves.
So what happened to our identity and access management solution? You can see that in this picture. We added functionality, it grew, it grew, it grew. The monolithic solution that we used grew. The monolithic solution that we used became more and more complex to administrate up to a point where we felt like we're not moving forward anymore. Our whole process, our whole development came to a full stop. So what did we do? We took a step back and we asked ourselves what is identity and access management? At Schwarz, not in general, not on a high-cost management slide. What is it for us?
What is important for us as a retailer, as a Schwarz group, as a producer in identity and access management? This is what we came up with. Five different capabilities and I'm not going to read through all of them but I'll focus on one, the first one, identity lifecycle. We are today administrating 850,000 identities plus minus. Out of these, 750,000 and a few more are real people.
650,000 are internal employees. We have 20 to 25,000 on and off boardings every month and this for us is not just nice to have, it's a business enabler. If I'm able to authenticate on my first working day, even down in the store, this gives us a market advantage. So identity lifecycle for us is a crucial component not only of identity management but of our business model. That's what we did with all these capabilities and then we matched them to what is on the market. How can that function with our requirements? We realized it's not always that easy. For many things, we are special.
Our number of identities, that's a challenge for many vendors. The workflow, the logic, the 50 different data sources with 50 different HR departments behind it, that's knowledge that only we have. We realized we don't just need another piece of software, we need a fundamental change. We need to do things differently than what we used to do. Before we started working on that and before we started moving into our sovereign solution, we talked to ourselves, what is our motivation? What is it that we want to achieve? What is that fundamental change for us? We realized digitalization.
I said that as a retailer, at our scale, digitalization is not just nice to have, it's a market advantage. It gives us a benefit that others don't have. We can save real money and improve there. We want to be able to keep pace or even be faster with identity to enable this digitalization. Identities, for us, are a core security feature. Not only because identity first is a nice password, because really everything in the digital world evolves around your identity. Trust is built around this identity. Trust in the processes we live is built around the identity.
Security and trust are a key component. Serenity. This is nothing that we came up with because now, especially with the current situation in the United States, the market likes that, but it's a long-going story for us at Schwartz Group. It's built into our DNA. As retailers, we are dependent on many things. People delivering goods to us so we can provide them in the stores. An empty store, no water in a Lidl store, no bread in a Lidl store, would result in people not buying. This is nothing new to us. This is something that we always had in our DNA.
That is something that we want to set for identity as well. Vendors impose risks. We want to minimize these risks for us. Last but not least, long-term cost stability. Just do the simple math.
850,000 identity times, say, one euro per user a month. That's quite a lot of money that we would have to pay licenses and that would be rather cheap. Cost stability is a core motivation for us to move forward. We decided to establish some strategies. One of our strategies is our identities belong to us. The digital identity is the master key for every employee at us and we need to keep this safe. Another principle is make, don't buy. We at Schwartz have a very strong framework and many reference architectures that allow us to build compatible solutions from scratch really fast. Stack it only.
We have our own hypervisor, our own cloud and we are cloud natives and stack it only. And not only software changes or technology changes, also the people changes.
So, we established a product organization. We changed the mindset of all of our employees, all of our employees, make them fully responsible end to end.
So, some years later, new ways. We reduced the complexity. We established the principles like API first. We developed new end-user self-service solutions. Focus was on fixing bugs and simplification codes really fast. And like I mentioned just before, not only the technology changes, also the people changes from an administrator to an engineer, being end to end fully responsible in eight dedicated products for the individual capabilities.
So, let's talk a bit about the solution we built. One view on the roadmap, where are we at the moment? Is that all implemented? Are you done? No vendors have left?
No, we're still in the journey. We call that phase we are in at the moment, the our identities belong to us phase. We'll look at the solution in a second, but we're in a phase migration. We're shifting the workload out of the old solutions, which are simplified, which already have integrated API layers in between, but we're shifting towards the own make solution. I would say that today, roughly 30 to 40 percent of the workload are already happening in our own solution in the cloud native world.
Yeah, 60 something percent still in the on-premise world. Our target here is to, within the next 18 to 24 months, to complete this journey, and we're very positive that this is going to happen. What is this identity core for us? What do we consider as truly owned by us, where we want to own the intellectual property, where we want to own the identities from end to end? That is identity lifecycle. I explained that before. It's really important to us. It's role and role assignment lifecycle. How do I get access?
We have really strong role-based access controls at Schwarz with thousands of applications, hundreds of thousands of roles, millions of automated life cycles based on job profiles, etc. You can imagine that in a store, nobody orders a role, and of course, authentication. Let's go through what the solution is for us, not in technical detail, but an overview of the components that we've built and we're building.
First up, and that was where our journey started, is the identity input interface. That was our solution to solve the problem of HR data, HR data quality, and bad HR processes. We'll talk about Role Engine in a second, where we do role assignments, but data quality is a key functionality for us. I can only run automated process. I can only run automated role assignments. I can only automate my whole onboarding process for those 20,000 to 25,000 users if I have perfect data quality. Not 99% do the mass, 850,000 users, 1% are still a ton of people not being able to work. I need 100% data quality.
I need full transparency to all source departments where that data comes from, why something isn't working. I need to be super fast, and we need to scale because on and off boardings, identity life cycle events tend to happen on a very few days within a month, so we need a scaling architecture. That is what identity input interface does. Role Engine, the second big component, that's our role and role assignment core. I've said that a couple of times. In our stores, in our blue-collar world, nobody orders a single role. Everything is fully automated.
Because you are store manager for a Lidl store in Lidl UK, we know exactly what permissions you need. You get them assigned, you get them revoked based on your job, and that job changes on a daily basis. You get store manager for two days because somebody else is off, so you're store manager now. Two days afterwards, you're back to deputy store manager. That changes super fast. We need to keep pace.
Again, speed, size, scaling is truly important for us. Future readiness. Authorization, modules, methods are evolving. It's been a few years that at a conference like this one, we've been talking about policy-based access controls, not role-based access control only. We try to build a solution that is able to cope with these functionalities in the future as well. Hard to say because I just said we're using largely role-based access control at the moment, but the mindset is future-ready. Something you might have missed on all these slides so far is governance. You're right.
We're a retailer, not a bank. Governance requirements are not different than what basically every standard software delivers because they're all focused on banks and insurance and stuff like that. That's 20 times more than what we need because we're a retailer. But of course, we need governance. We must be able to do that. We need to be able to be able to answer the question, who had which access at what point of time and why? That is also functionality built into here, so we're able to answer these basic questions, but it's not a key component for us and a key functionality. Output API.
Maybe you missed the provisioning part. We changed it. There's no provisioning. There's no connector. There's no interface. Using a middleware or something, we completely changed this back from old provisioning to a new output API so the applications and the systems get data from our API and from a SCIM solution. This makes us very fast by using a standardization and very secure and stable.
Also, imagine if you have a Tier 0 or Tier 1 Active Directory environment and at the moment, you push from an IDM system using a connector to this environment so you are the administrator of the Tier 0 system using an identity management system. We changed this way to an output API. We also changed the management API of our own IAM solution so we can manage by using API first principles our own identity and access management. We implemented very sexy user interfaces that make that focuses on the user experience because this also makes us much faster by onboarding changes and so on.
Last thing and maybe you missed a decade here is authentication. Nevertheless, we are going completely passwordless by using only modern authentication methods. Employees are using pass keys in a zero trust environment and we are protecting by storing the public keys in our own FIDO servers in an open source software.
Let's recap a bit on that journey from the early days where we created an IDM project like everyone used to do 11 years ago, times flying, to that rapid expansion phase where we added functionality on the stack where the solution crew, where the interconnection of everything crew, but also the complexity crew beyond what we could manage to the new ways area where we started developing our first own components to our identities belong to us where we are at the moment and then in a second let's talk about what's next.
So key takeaways maybe would my recommendation now for all of you in this room be go home, throw away your vendor software, start developing your own identity and access management solution on StackIt. My StackIt sales colleagues would probably like that, use StackIt, that's a good idea, but no that's not the idea behind it and that's not our key takeaway. Very important for us was to understand what is crucial for us in identity and access management. For us it wasn't the governance part, it was the human identity.
That could be completely different for you, you could have more machine identities than humans, you could be running a lot on agentic AI like we heard in the keynotes today and yesterday, that could be what drives your business, that should be what you focus on. Then validate, is the vendor solution the right thing? Maybe with all customizing you're putting into it, building some modules yourself is the way forward. From our perspective, from a sovereign perspective, also thinking about modular, individual modules for components is a good way to go.
There are vendors and there are clients for where the best of suite and an integrated solution is the best thing. For us it's not, we need building bricks, we need modules. Second key takeaway, this was a journey. We didn't wake up one morning and say, hey let's start developing everything by ourselves. We learned from good experience, we build trust into what we're doing. So embrace this journey, maybe start looking left and right, maybe be critical about what you're doing at the moment. For us the journey continues, full force ahead, make don't buy it, that is our mantra.
That doesn't mean that we don't have partners, we surely do. Strong ones, Kinoxa, Cedars, Silverthorpe to name a few where we collaborate with, because they have great add-ons to our core functionalities of identity and access management. We'll start focusing on governance and security functionality, because even as a retailer the world moves forward and governance becomes important.
And yeah, a few more things, pushing self-service, machine-to-machine communication, AI, finally name it. Those are the topics we'll look at in the years to come. Thank you for joining us and looking forward to your questions. I don't think we have time left because that thing says zero. Thank you very much, Doreen and Patrick, unfortunately. Thank you. First of all, let me say that my first word after listening to this was pretty impressive. My second word was, this is crazy. So you should probably write a book or two about this.
Unfortunately we don't have time for questions, but again you are probably around so people can approach you all the time. Thank you very much again.