Case Study

How a Global Mobile Insurance Provider Extended Identity Governance into Oracle ERP

  • Industry: Mobile device insurance
  • Footprint: United States, with expansion into the United Kingdom and Japan
  • Technology environment: Workday, Okta, SailPoint, Oracle ERP, and ServiceNow
    Focus: Extending enterprise identity governance into Oracle-specific access controls, segregation of duties (SOD) monitoring, privileged-access governance, and remediation workflows
Outcomes
  • 663 of 15,703 users held privileged Oracle access, creating a clearly defined population for focused monitoring and governance
  • 118 users were associated with more than 51,000 Oracle segregation of duties policy violations identified through Oracle-specific analysis
  • A federated governance model extended existing identity governance into Oracle ERP without replacing the organization’s SailPoint environment
  • One repeatable control model was designed for deployment across the United States, United Kingdom, and Japan rather than rebuilt region by region
The Challenges

The company used SailPoint as part of its enterprise identity-governance environment, alongside Workday for HR, Okta for authentication, Oracle ERP for financial operations, and ServiceNow for IT service management.

As the company expanded Oracle ERP operations from the United States into the United Kingdom and Japan, it needed to extend its governance model beyond identity records and general access processes. The existing SailPoint implementation did not provide the Oracle-specific visibility required to evaluate responsibilities, functions, concurrent programs, organizational scope, privileged entitlements, and segregation-of-duties risk.

This is a practical example of the SailPoint value gap: enterprise identity governance was in place, but coverage had not yet reached the application-native entitlements and financial-risk controls inside Oracle ERP.

That created a growing governance challenge. Without a consistent Oracle-specific control layer, each regional expansion could introduce new access risks, different operating processes, and additional remediation effort.

The company needed a scalable way to:

  • Maintain SailPoint as the enterprise identity system of record
  • Govern Oracle entitlements and financial-risk access combinations
  • Identify and prioritize privileged access and SOD risk
  • Route remediation through an established IT service-management process
  • Replicate a consistent governance model across new regions

Application coverage, entitlement visibility and disconnected remediation are among the five warning signs that a SailPoint program may still be leaving compliance gaps

A Five-Step Oracle Access Risk Lifecycle

Customer Success

The company implemented SafePaaS to extend its existing identity-governance architecture into Oracle ERP. SailPoint remained the enterprise identity system of record, while SafePaaS provided Oracle-specific access governance, policy analysis, lifecycle workflows, and remediation support.
This federated governance model enabled the company to identify, prevent, monitor, remediate, and sustain Oracle access controls without creating a duplicate identity environment.

1. Identify Oracle access risk

The company assessed Oracle access across responsibilities, functions, concurrent programs, organizational scope, privileged entitlements, and SOD policies.

This analysis identified a concentrated risk population. Of 15,703 total users, 663 held privileged access associated with high-risk financial activities, including supplier creation, one-off supplier payments, and journal entries.

The assessment also found that 118 users were associated with more than 51,000 Oracle SOD policy violations. Rather than treating risk as evenly distributed across the workforce, the company could focus governance and remediation effort on the users and entitlements creating the greatest exposure.

2. Prevent inappropriate access

The company centralized Oracle provisioning and lifecycle management through a policy-driven governance process. When a user was created in SailPoint, an API-based integration created the corresponding Oracle-governance record without introducing a second identity system to maintain.

Oracle access decisions could then be evaluated through defined governance workflows rather than disconnected, one-off provisioning processes. This created a more consistent control point before Oracle access was granted or changed.

3. Monitor risk continuously

The organization established continuous, rules-based monitoring of Oracle SOD policies and privileged entitlements. The monitoring process gave the team more timely visibility into access conflicts and policy exceptions across the Oracle environment.

Rather than relying on audit activity or isolated reviews to reveal risk, the company could identify violations promptly and prioritize them according to the affected user, entitlement, policy, and financial-risk context.

This illustrates why continuous controls monitoring matters after a SailPoint implementation: periodic identity reviews cannot detect every Oracle access conflict or privileged-access change that appears between certification cycles.

4. Remediate through defined ownership

The company connected Oracle access-risk findings to its existing ServiceNow environment. Defined workflow swim lanes gave remediation a clearer path for assignment, investigation, documentation, and resolution.

This replaced fragmented email-based coordination with a more structured process for managing policy exceptions and access-risk findings. It also created a foundation for measuring remediation performance as the governance model matures.

That complete path from detection through investigation and resolution matters because auditors are not simply asking whether an organization has SailPoint; they need evidence that access risks were identified, assigned, remediated and closed.

5. Scale and sustain governance

The company created a single federated governance model designed for use across its United States, United Kingdom, and Japan operations. SailPoint continued to serve as the enterprise identity system of record, while SafePaaS extended governance into the Oracle access layer.

This approach allowed the organization to apply a consistent Oracle control model as it expanded internationally, rather than rebuilding governance processes, policy structures, and remediation workflows for each region.

From Fragmented to Federated Governance

Area

Before

After

Identity and Oracle governance

Identity governance did not provide sufficient Oracle-specific entitlement visibility

Federated governance extends enterprise identity processes into Oracle access controls and financial-risk analysis

Oracle provisioning

Disconnected or one-off provisioning processes

Centralized, policy-driven Oracle provisioning and lifecycle workflows

SOD visibility

Conflicts could be discovered during audits or isolated review cycles

Continuous, rules-based monitoring of Oracle SOD policies

Privileged access

Privileged Oracle entitlements lacked a consistent Oracle-specific governance process

663 users with privileged Oracle access identified and brought into defined monitoring and governance processes

Risk prioritization

Risk was difficult to isolate across a large user population

118 users associated with more than 51,000 policy violations identified for focused investigation and remediation

Remediation

Email-based coordination and unclear ownership

ServiceNow-connected workflows for assignment, investigation, documentation, and resolution

Global expansion

Governance processes risked being recreated for each new region

One repeatable model designed for deployment across the United States, United Kingdom, and Japan

Business Impact

The company preserved its existing SailPoint investment while extending governance into the Oracle ERP entitlement layer, where financial-risk access decisions occur.

The distinction is important because identity governance and SOX are different programs: identity lifecycle coverage does not automatically provide the Oracle-specific SoD analysis, control operation and evidence required for financial compliance.

The Oracle-specific analysis gave the organization a clearer view of its risk concentration. Of 15,703 users, only 118 were associated with more than 51,000 policy violations, allowing the team to focus governance activity on the users and entitlements with the greatest potential impact.

Centralized Oracle lifecycle workflows and continuous monitoring improved consistency across provisioning, SOD analysis, privileged-access governance, and remediation. ServiceNow integration gave findings a defined ownership path, helping the organization move from fragmented coordination toward a more repeatable resolution process.

Rather than treating identity governance or SOD reporting as the end state, the company established a continuous Oracle access-risk lifecycle for identifying, preventing, monitoring, remediating, and sustaining controls.

The resulting model demonstrates why identity governance does not automatically equal compliance: compliance depends on whether controls operate continuously and produce complete, defensible evidence across the applications in scope.

What’s Next

The next phase is designed to further connect Oracle lifecycle management and ServiceNow remediation workflows. When an SOD violation or inappropriate privileged entitlement is identified, the planned process will automate ticket creation and support controlled deprovisioning actions in Oracle.

Once this phase is live, the company can measure operational outcomes such as:

  • Time from policy-violation detection to closure
  • Percentage of violations resolved within defined service-level targets
  • Reduction in manual remediation effort
  • Reduction in the window of exposure between detection and access removal

Organizations considering a similar approach can use the SailPoint Governance and Compliance Coverage Scorecard to assess application coverage, certification quality, audit evidence, process integrity and business adoption around their existing deployment.

Related SailPoint resources