So, welcome everyone. Thanks for joining me today. My name is Stanca Hauenstein and I am the Product Owner of Identity Access Management Solution by MediaMarktSaturn. So for those of you managing enterprise scale identity environments, you know a fundamental truth. IAM landscapes don't just happen.
They grow, they adapt, and over time they become highly complex and heavily customized. Today I want to take you inside MediaMarktSaturn's ongoing transformation journey. We are transitioning from a 16 years old, highly customized legacy architecture to what we call our Next IAM. A platform that is leaner, smarter, and of course more secure. Over the next 15 minutes I will walk you through our strategic approach, our architectural trade-offs, and how we are executing this massive shift.
I hope our experiences can offer you at least some valuable insights for your own identity modernization journey. Here's how we will structure today's deep dive. Four topics, four chapters of our story.
First, where we come from and where we are heading. Then the architecture decisions we made and deliberately didn't make. And then how we are executing the transformation without a big bang. And finally, an honest look at IAM, at AI in IAM of course, the big topic. What is real? What is hype from our point of view? So let's start with the why. Let me start with a question. How many of you are managing an IAM landscape that has grown organically over the last 5, 10, 15 years? Yeah! How many of you are using SAP IDM?
Oh, two, three, okay. I thought so. We are all in the same boat. IAM landscapes don't get complex overnight. They grow slowly, system by system, work around by work around, until one day you look up and realize you've built a beautiful, highly automated, but deeply complex machine. That is very expensive to operate and very hard to change. And here's why this matters so much now. We have three forces that are converging simultaneously. Number one, the 80% fact. More than 80% of security incidents today are identity-related. Think about that. The parameter is no longer the firewall.
Identity is the network. Zero trust is not a marketing concept. It is reality of how modern enterprises need to operate. Every access decision, every entitlement, every account, these are security decisions. The second one is SAP IDM end of life. SAP has announced mainstream support for SAP IDM. Ends December 2030 with no design successor. And the transformation of this scale takes a minimum of 24 months up to 36 or more, depending on the complexity of your solution. That means if you haven't started yet, you're already late. The clock is ticking faster than we think. But let me be clear.
We do not view this end of life as a problem. We view it as an opportunity. And last but not least, the regulation. The compliance pressure on identity is increasing across the board, even if not all regulations apply to a retailer like us. Regulators want auditability. They want traceability. And they want governance. IAM sits right at the center of it all. So for us at Media Markt Zatun, these three forces made one thing crystal clear. Complexity reduction is not a nice to have. It is a strategic imperative.
We simply cannot govern hundreds, thousands of roles and meet tomorrow's regulatory demands using yesterday's customized legacy code. So how did you approach this? We did not jump straight to a solution. We started with a rigorous assessment of our processes, systems, and interfaces. And what we found confirmed our suspicion. We had built something that was highly automated, yes, but also highly customized and therefore highly fragile and expensive to maintain. Sorry. Let me give you a sense of scale because I think it illustrates the challenge very well.
We manage over 60,000 workforce identities, around 20 percent of which are external, plus a monthly growing number of non-human identities. We manage over 1,000 brick and mortar stores across 11 countries. But here's where the complexity truly lies. We are currently managing over 100,000 roles and over 240,000 entitlements, resulting in roughly 6.5 million assignments. That massive number of roles is largely due to our high granular and context-based roles required for each individual store and department. We manage all of this with a 93 percent of automation.
Otherwise, it would not be possible. Additionally, processing an average of roundabout 8,000 manual requests per month. We've been running SAP IDM since 2010. That's 15 plus years of growth, customization, and accumulated complexity. The pain points we uncovered were significant. We have a high share of custom development. A lot was built, custom made, which means it's expensive to change. We have an outdated and unresponsive user interface that frustrated users and administrators, both. We have inflexible approval workflows with no ability to reassign approvers.
We have limited transparency in workflows and error analysis. No native segregation of duty, capabilities, overall applications. No privileged access management integrated. And last but not least, and then we have enough pain points, we have a highly complex application integrations that require deep special knowledge to maintain. With all this on the table, we made three fundamental decisions. The first one, we evaluate on-premise versus cloud rigorously and kept this decision deliberately flexible. More on that in a moment. The second one was standards before custom code.
After years of building custom everywhere, we committed scheme, YDC, SAML, standard protocols, wherever possible. Custom code is the exception, not the default. And the third one, wave principle instead of a big bang. No single cut over, a structured iterative rollback waves. And our guiding design philosophy defined all of it.
Of course, simplicity is not a shortcut. It's the goal. After 15 years of adding complexity layer by layer, simplicity is the hardest and the most valuable thing we can build. One of the hardest questions in any transformation is this, what do you decide or commit early and what do you deliberately leave open? Get this wrong in either directions and you are in trouble. Commit too much too early, you are locked into decisions you'll probably regret. Keep too much open, you are paralyzed, unable to move. Here's how we navigated this tension.
What we decided early, we decided that we are going to have a wave-based transformation approach. Data sovereignty is defined, GDPR, UI, AI, UI act, and so on. We need to, yeah, sorry. Where data lives and who owns it, it is defined upfront, especially important especially important in an European regulatory context. What we deliberately kept open, the tool selection for IGA and later PAM. We are running a formal RFP process supported by leading independent IAM analysts with structured requirements engineering. We evaluate regularly. Another thing that we kept open is the operating model.
Well, it's still evolving at the moment. Build versus SaaS. For some areas, a SaaS solution makes perfect sense. For others, we need more control and sovereignty. We are not forcing on one size fits all answer. And AI patents.
Okay, the market is genuinely still maturing. It would be premature to lock in AI-specific architectural decisions right now. More on that in a moment.
Now, let me get very concrete about the how we are executing this transformation. We call it the wave principle and it has three defining properties. It is iterative, dependency aware, and rollback ready.
So, here's the structure. The first one, the wave one, the foundation, everything starts here. It's our connector, identity life cycle, the core, join or move, lever processes, birthright, access provisioning, and so on. You can say bingo.
And, of course, the critical applications. You cannot build anything meaningful on top of what's already critical applications. You cannot build anything meaningful on top without getting this right. The foundation must be first, always. The second wave, the self-service, once this foundation is solid, we unlock self-service capabilities, role-based approvals, self-service access requests, and the onboarding of lower risk applications. This is where users really feel the difference.
A modern, responsive interface, intuitive request flows, faster turnaround on access decisions. The third wave, governance, very important.
We layer, now we layer in governance. The segregation of duty monitoring, recertification campaigns, full access governance capabilities. This is where we shift from simply managing access to truly govern it and with transparency, auditability, and real accountability. And last but not least, the advanced wave, the final one. Privileged access management, AI enablement. We deliberately place AI last, not because we are not excited about it, but because AI is only as good as the data and governance beneath it. We'll come back to this in a moment.
Now, one concept that is critical and often underestimated is the planned coexistence. Our legacy system, SAP IDM, runs in parallel with a new platform throughout the entire transformation. This is not an oversight. It is a deliberate architectural decision. Why? Because rollback capability is not optional when you manage access for 60,000 identities across business critical systems. If something goes wrong during a wave, you need to step back safely. No burning ship mentality, no hierarchs. The guiding principle is clear separation, rollback capability, and know everything at once.
And now the topic everybody is talking about, AI in IAM. Let me be honest with you from the start. I find AI genuinely exciting. And I also find it genuinely overhyped, both at the same time. So let me try to separate the signal from the noise based on what we are actually seeing and doing. So what do we have ready to use today and what we can do in the future? What we definitely can use is the self-service chatbot with natural language access requests.
I mean, user can say in plain language, I need access to the finance reporting tool. The system understands the intent, routes the request, initiates the approval workflow, understands, sorry, this is not science fiction. It is deployable today. And it genuinely reduces friction for end user. Another topic is the recertification recommendations. Instead of a reviewer staring at 500 permissions and clicking approve on all of them, which let's be honest, we know it happens. AI services, the one that look anomalous, unused or risky. This is real value and this is available today.
What is too early for now? I think the full automated access decision, that is something that still needs to mature a little bit. Then we have the fully automated anomaly detection with direct consequences. This is also a topic that I think it needs to mature. AI is excellent at surfacing the signals, but a human must remain in the loop for any inconsequential action. This is also a regulatory reality. The EU IA Act, explicit mandates, human oversight and explainability for high risk AI applications and access control decisions absolutely fall under this category.
One final thought I want to leave with you on this topic. Modern IAM makes AI usage possible and secure, but only if the foundation is right first. This is precisely why AI sits in wave four. If your identity data is incomplete, your governance is inconsistent and your processes are poorly defined, adding AI on top does not fix those problems, it amplifies them. Get the foundation right, then AI becomes a genuine force multiplier. And that brings me to the end of our story.
Well, rather at the beginning of it, because this transformation is very much in progress. We are living it every single day. Making decisions, learning from what doesn't work, adjusting and moving forward wave by wave. Here's what I hope you take away from today. Leaner does not mean doing less, it means doing the right things with less friction, less technical depth and less complexity. Smarter doesn't mean throwing AI at every problem. It means making better decisions with better data, better processes and better governance. And more secure does not mean adding more controls.
It means building a foundation that is by design auditable, governable and trustworthy. If you are on a similar journey, we're about to start one. I would genuinely love to compare notes. Thank you very much for your attention and now let's go.
Wow, thank you very much Sanka. Does anybody want to ask questions?
Yes, they actually do have a question. Right. Super great contribution. I'm curious about your timeline. I saw the timestamp of 2030, then SAP IDM is completely end of life. So what is your time schedule in regards of the phase one, the famous phase one implementing? And especially in regards of the transition phase, of course, at the end of the day, it's a big migration project you have on your agenda. So maybe you can give some key figures about your timeline, please. Thank you. Okay. So like I said, we are doing it step by step.
We started on RFP, we started on SAP IDM, we started on SAP IDM, we started on SAP IDM, it's step by step. We started an RFP process where we are choosing our next partner for the next 15 years at least. And we plan to have our next IAM with a contract ready signed by the end of this year. And then we start together with our new partner planning how we are going to build the new identity management. But I think what we plan is to have like one or two years where we actually build the foundation and then start with a new system.
But this is always going to be a parallel coexistence between the two systems. And very important, we are also going to need to establish new processes like, of course, because the business has demands and they are not going to sit back and say, well, you are starting a new project, we do not want anything from you anymore. So we need also to establish a process. What are we going to onboard on the SAP IDM? Because of the regulation, it's necessary and it needs to be done. And what we are going to bypass SAP IDM and just postpone it until we have the new platform.
So this is actually an ongoing process. Okay, if you don't have any further questions, then thank you very much again. And with that, we are coming to the end of this track. Thank you very much for sticking with us today.