Yeah, thank you for the introduction. So, as I said, we are working for SPAR, especially for SPAR ICS, the IT unit of the SPAR Austria Group.
So, my name is Thomas Zarnhofer. I'm working as architect and strategy lead for IAM at SPAR and I've brought two colleagues with me. I'm the other Thomas, Thomas Lerchner. I'm the solution architect for the IAM Workforce Solution. I'm Thomas Chandra, no, sorry, joking, Praneet Chandra, working at SPAR as a service owner.
So, yeah, responsible for complete identity governance and IGA area. Yeah, today we will talk about our Identity Governance Transformation Project we have started some years ago.
So, maybe some of you know, Identity Governance Transformation Projects are not only technology projects. So, you have to deal with data, with data models, with processes, especially governance processes, of course. You have to deal with operational responsibility changes.
And, of course, you also have to change maybe how people collaborate in the organization, especially in identity projects. Shortly, for everybody who doesn't know us, so SPAR Austria Group is operating in two main business areas.
So, we are operating in Austria and four neighboring countries, over 3,000 retail grocery stores, and also managing 32 shopping centers over the same countries and one more. So, our vision is clearly to establish one modern IGA platform, where we then really govern the access for all our employees over all countries, over all business units.
So, as you have seen before on the slide, we have approximately 90,000 employees, which results in, including also external workforce, over 100,000 identities in total then, when we fully establish the platform at some point of time. But now let's talk, why did we decide for a change here?
Yeah, at some morning in 2022, we were waking up and saying, yeah, it's so much fun to do an identity project. Let's start one.
No, clearly not. So, we had several problems with our legacy infrastructure, with our legacy on-premise system. And we also wanted to profit around the benefits of modern cloud solutions. One of the biggest problems we had in the past was maintaining our legacy system.
So, as all of you know, an on-premise legacy system requires a lot of upgrades. You have to do all the security patching. We had a lot of customization also in our tool. And therefore, each release cycle required months of testing. And we were just dealing with, let's say, operations and not really doing innovation in the identity area for us. We also had a, let's say, wrong identity model. The expectations, how we should manage the lifecycle processes were not fitting to the identity model we had.
So, if a person had multiple contracts in our HR systems, we had multiple identities. That was a big pain point for us. We also had five HCM systems for our countries, which were all connected to the legacy solution as single systems. That was also a big issue. No global identifier. I've also heard that in another session today already. That was also a big topic for us. I would say we also didn't really govern our identities. We reconciled from five different systems. We conciled from our identity provider and some applications. But there were no clear processes established.
A lot of manual tasks we also had in place. That was also one of the biggest issues. Join a process required manual steps. At our scale, of course, when we want to start managing personalized identities and personalized accounts for everybody who is working on our shop floors and in warehouse and in production sites, that's not really scalable to have manual processes in there. But of course, as I said before, we also want to profit about the benefits which cloud products bring with them.
So, always current. Of course, if a SaaS or PaaS identity governance product vendor tells you you don't have to deal with anything around the updates, that's a lie. You still have to deal with a lot of testing, of course, but not all the other operational overheads we had before with the on-premise system.
So, I would say the efforts went significantly down after we established Savient. So, why Savient? There were some reasons. I don't want to go into all details now why we chose Savient back then in 2023. But one of the, I would say, most important things for us was we were coming from a very customized on-premise tool and we're going to the cloud. Several other tools in the cloud were very unflexible. Completely no customization possible. And we said, yeah, Savient is, let's say, somewhere in the middle. More flexible customization than in other products.
It had the multi-tenant architecture, which also was a better selling argument for security and compliance departments. And also the modern UI and UX were, let's say, one of the main reasons.
To AI, I will speak a little bit about that later. But now, Thomas, can you tell us what was one of the major steps we also achieved in our transformation project?
Sure, I can. As we started with the project and said we want to get started with that whole thing, we started to rethink about our identity model, as you mentioned earlier. And that was, for us, a major improvement.
We, as Thomas said, we had the problem that we had a contract-centric HR system. So, meaning, every time a person gets a new employment contract, we get a new identity. That makes the handling of the identity later on really pain.
So, we wanted to switch that around to a person-centric, that we have the same person over and over again. And these accounts are working as they should. Second thing was, as Thomas mentioned, we had five identity HR systems connected to our identity system. Which made some things and some processes rather complicated. Because we have a business requirement that people are working in one country and are paid of another country. And secondly, we have also transfers within international companies from one country into another country.
And how do you detect which, is this still the same person or is it a different person? Because there are many, maybe many Thomas Lerner's around.
So, that was one of the first things that we decided and that was important for us to accomplish. And so, how do we get about to get in this transfer or transformation from one system to another without major business interruptions? And that the whole thing is still handleable with a rather small team. We divided our project or this transformation in three phases.
First, we were very keen on getting our foundation right. So, when you start building a house, you don't start with the roof, you start with the foundation. And second, we migrated all the existing applications, processes and data from one system to another. And of course, as you know, IAM is not a project.
So, it's not time limited, it's a program, it keeps on going. So, we have an adoption phase where we add on new features, get everything further. Let's have a closer look to that. The foundation, as Tom already mentioned, was one of the parts was selecting our partners, tools that we want to use.
Also, getting the fine granular requirements that we had, that we needed. Of course, in a new environment, you have to fit into your IT architecture. And connected. And most importantly for us was the step to connect these different authoritative sources for different data types. And information that we need in our IAM solution. And our most important IDP connections. As this foundation was laid, we continued with the migration, putting new applications to that, building on top of that. This was a bit challenging because in parallel, you don't do that in a big bang.
You do that in steps, ensuring all the time that the system is running, up and running. And we provide the business services as they are needed. And making sure that we're not getting into conflicts or race conditions between these two systems that are managing our identities at that stage. We onboard applications in waves, meaning each application that is ready to go, we deploy. Sometimes we do packages where we do applications built together.
Of course, the policies and the roles need to be updated and upgraded. We decided for an approach to say, we're not copying one-to-one everything from old system to new system.
We, of course, wanted to detect what are the benefits of Sabient and what does Sabient do differently than to our legacy application. And workflows and governance processes were also adopted in the same, likewise.
We, for example, have a role-centric approval workflow. And the last phase that we're going to have is the adoption where we keep on new applications. We finally can switch off our legacy application and we optimize our processes, getting to better places and tune our reports and governance measures. At that stage, we also finalized the hypercare and the stabilization that we need to do. And as we are in this EIM arena, you know, it's a lot of blood, sweat, and tears that we experience. And Praneet, why don't you tell us a bit about our tears? My pain as a service owner. Tears. Yeah.
Anyways, so we have pitfalls, we have lessons learned, no product is perfect. As everyone knows, we say shift to the left, doesn't work. Major problem that we face initially, transformation. Big data kills us. IGA is a data project, not identity related. We need to focus on data, data quality, consistencies, duplicated records, duplicated organizations, structures, not structured at all, and so on. Then we have the next problem, one-to-one migration. Can we migrate everything one-to-one there? No. You cannot migrate from one solution to the next solution the same way.
You're going from on-prem to SaaS. Different solution, different platform, different everything. So don't copy, think about it, because you're going to take lots of mis-debt, old debt with you into a new system. That's not required. Then the IGA is never their problem. You know this phase, everyone knows this. We need to work together with each application owner, service owner, product owners, application lead, to understand what they exactly need, what are the requirements, with the business department, to have a clear understanding of what needs to drive the engagement further.
To bring it to the point, we say, yes, now we have governance. But we did learn something better as well. What we did is running parallel, meaning make it ease on the end users. So not say, tomorrow we cut off this old system, now you use this system.
No, we go parallel business, because then you have the customer, the end users, using the workforce on the old system, but the new system is actively running behind that. So when they move to a new system, they don't face new challenges, because the end users, especially in retail, are not that IT educated or proficient. It's not that there. And secondly, identity model. We're talking about that today. We have heard about that. Very important. It helps us. It has improved our quality now. We have one employee, one identity.
Very relevant where you are, because five countries, they keep on moving. We have management moving from A to B. It keeps on happening, and that way they lose access, they don't lose anymore. That's there. Another key lesson, automate. We need to automate quicker, faster, because it helps us in operations, bringing new things live, bringing new things operational ease, and so we can also focus on the future, what we want to do.
So, where do we stand now? Thomas, where do we stand now? Right next to you.
So, as I pointed out a bit earlier, we're in phase two at the moment, and we consider Sabient already live in our system, although it's not covering 100% of what we had in our legacy system. But it's doing live provisioning. We already implemented the new identity model that I mentioned before and elaborated on, which helps us a good deal in solving a lot of problems that we had in the past. We automated the provisioning of basic account configuration.
So, when a person is joining our company, then we already have their accounts basically ready to use on the first day. Of course, the detailed permissions still need to be requested or added. We have request flows when people requesting roles, business roles in our case, that they are automatically assigned and their approvals are given. And we have several business applications that are already available that people can request them in roles for, and we are provisioning them into the target system.
And our list of what we need to do is quite long, and Praneet, maybe you want to tell us a bit what's coming up. Sure. What's coming next? It doesn't end here. Going further, new application onboarding.
Next part, as I said, automation. We're going to expand automation now using Terraform. That's the next step.
So, we have a connector lifecycle, connector versioning, and so on, plus also workflow versioning, which is going to come up. Then, access certification. We need to certify all the users, which has not been done over 10 years.
So, that will be a big pain. Next conference, maybe.
So, yeah, automated move-up process, that's also coming up. And what I'm very happy about is finally getting rid of my legacy environment after 15 years, which has been a pain and running parallelly. Might get rid this year, November. And we are, on a verge, creating new reporting dashboard for our KPI management, for our management, to make them happy and look them happy.
AI, we've been talking about that. Yes, it also impacts us. We already have thousands and thousands of agents running, not controlled. It is there, but yes, it will be coming up to hit us as well.
And Tom, being lead, he will see how we go further. Of course, at this conference, I think there is no slot where AI is no topic.
So, I've seen it in every slot where I've been sitting. So, I would say, of course, also, as Praneet said, managing agent identities will also be in our roadmap and non-human identities and all that stuff. But at the moment, I think we are concentrating how to really establish Sabient as our one IJA platform and also how to use AI that we improve really our processes there. At the moment, there are still a lot of manual requests. There is manual recertification activities. Users have to request roles.
So, I think we have to rethink how we really come to the situation that we say we have an intelligent, proactive governance and not do just reactive auditing anymore. Because at the moment, it's nothing else what we are doing. It's really reactive. It's just auditing sometimes.
So, the platform, from my perspective, should know in the future what the user needs. So, when the user asks, I need a permission, the platform should already know.
Oh, you got an email maybe yesterday. Your boss assigned you a new task. I already looked up. This is the role for you. I would expect something like that in the future versions of Sabient also.
That, for example, the AI then really looks on your emails, looks on your duties, on your schedule, on your calendar, and maybe already gives intelligent proposals or already tells the boss, your new employee will most likely need these roles for his job. I will provision that. If you need anything else, just tell me.
So, from my perspective, that's one other important AI topic for us. Of course, on short term, we will now also look on how to maybe use AI in access recommendation. We will explore that field also, of course, as it is supported. Enable detection will also be a thing we will look onto, of course.
But also, as I said before, how to automate self-service at the first step. Maybe let's look how we can do natural language processing, how somebody can talk to an AI agent and say, please tell me which roles may I need. And then maybe also ask, should I request them for you? All that stuff, yeah, I think could change the way how we manage identities, really. And our goal is really intelligent governance for the future.
Yeah, then thank you all for your attention. Thank you for being here. Our transformation, I think, is never over.
So, as my colleague said before, it is a transformation project. It's not only a project, it's a program, as everybody also knows in here.
Yeah, and I think with AI, we also have to rethink identity governance completely. So, we are happy to take your questions. Thank you. Thank you.
Well, thank you very much. I'm afraid we only have time for one question.
Yes, thank you. Well, we've initiated and started our journey to migrate from a legacy IGA to a more modern one. It's been a few years in the making, but along the way, we found out that we are more functioning as archaeologists than actual IT consultants. How was your journey in dealing with the archaeological bit of an ancient HR? We have similar experiences that we need to find out what we do, and you scratch always on the top. That's at least the feeling.
I found it more effective than we say, forget about the legacy, let's talk about what is now, what we want now, because we found sometimes, I find it a very important question, do I want to do it as it was in the past, 15 years ago, or do I want to rethink it because 15 years ago the requirements were different and the possibilities were different. But it was also hard work, I would say.
We did a lot of Excel comparison between HR data, data in the old identity management system, data in our identity providers, compared attributes, did analysis on that, talked with the business, what are the right values, what should we put in there, correct HR data. So it was a pain. I can't tell you there is an easy solution. Unfortunately, it's painful. I can say one point about that. We had a journey from 2023 to 2025 to get to one identity part.
So two years, so you can imagine how we dig into that problem, how to understand what we need to do, and as I mentioned, understand what the new requirements are and forget the legacy. Try to think of a semi-greenfield. That's the best approach to go ahead. You have something but you need to think about how to make it clean now.
Okay, awesome guys. Great job. Thank you very much again. Thank you. See you around.