Read Before You Buy:
What IAM Vendors Don't Tell You

About HWA AG

HWA AG is an expert in the field of automotive racing and high-performance vehicle engineering. The company was founded in 1998 by Hans Werner Aufrecht (hence the name – “HWA”) and has its headquarters today in Affalterbach, Germany, where it currently employs around 300 people. HWA’s services range from vehicle components design to car production as well as covering logistics, aftersales and customer support.

HWA’s Review of tenfold

“Personally, I was very much impressed by tenfold’s intuitive and user-friendly architecture. The technical capabilities and features it includes are particularly valuable to us. tenfold provides interfaces to all important HWA systems. We now have a huge margin for potential savings for tasks we previously had to complete manually.

We were specifically looking for a product that can be used by people from non-IT departments – and tenfold fully lived up to our expectations! tenfold was well received across all departments and is now an integral part of our processes and daily routines.

The approach tenfold and its solution partner Bechtle IT System House Neckarsulm took was outstanding. Although the features we requested for the initial launch were extensive and also very specific, they completed the project well within the planned budget and timeframe.”

Florian Schüle
Head of IT

Overview

Location
Germany

Founding Year
1998

Employees
approx. 300

Industry
Car manufacturing

Product
tenfold Enterprise Edition

Free Trial

Our No-Code Solution Makes IAM Easy.
Start Your Free Trial Today!

HWA Before tenfold

Frustrated with the standard tools available for managing access rights and feeling let down by major system providers, HWA were at their wit’s end. In light of the complexity they faced on a daily basis, their access management strategy had reached the end of the line. HWA’s IT experts thus set out in search of a solution that would help them stay on top of the growing privilege chaos.

Their main focus was to find a product that would enable them to govern access to Windows file servers more easily. They also wanted a tool that would allow individual department heads and managers to control access to data directly, rather than having to go through IT for every permission.

While it is possible to control access rights using the available standard tools, such technical functions are usually reserved for IT admins only, not for the “general population”. Without an extra tool, it is impossible to implement user-friendly workflows for users who do not have an IT background.

HWA before tenfold (c) Looker_Studio
HWA before tenfold (c) Looker_Studio

Choosing the Right Tool – User Lifecycle Management

In their search, HWA circled in on two auspicious products. Both providers promised they could simplify permission assignment processes by delegating responsibilities away from IT to other departments/managers. Both also affirmed their products would provide admins with a good, clear, and structured visual overview of existing permissions. In other words, both products promised to cover the basic requirements as outlined by HWA.

After examining both options in depth, HWA finally opted for tenfold, an Austrian-based software developer and product of the same name. The final push toward tenfold was made because of its user lifecycle management (ULM) feature, an aspect that had initially not been on HWA’s radar at all, but proved to be of great value.

While of course better reporting options and simplified access management workflows are indeed an enormous improvement for any business, they are in the end mere plasters on an open wound. They do not grasp the problem at the root. If you properly want to optimize IT security in your company, you must be able to adequately model user and permission processes. Also, granting and revoking permissions should be largely rule-based and automated processes.

Joiner-Mover-Leaver Processes

tenfold’s approach to solving HWA’s problems was to tackle said problems at the root – the root in this case being their chaotic user management strategy (if you can call it a strategy). tenfold’s user lifecycle management feature served as the basis for deployment at HWA. If you want to manage users and their accounts and permissions correctly, it is absolutely essential that your IT and HR departments work very closely together. Information needs to flow continuously and smoothly from HR to IT: who will be hired and when, whose account needs adapting, who is planning to leave the company? Relaying this information in time and without mistakes is not an easy task.

With tenfold, HWA’s HR department are now able to create new users independently using the web interface. This requires no administrative IT privileges whatsoever, as tenfold allows for granular control even on a basic user level. A service account with the necessary system authorizations then takes care of the technical implementation. All other joiner-mover-leaver processes that are part of the user lifecycle can also be handled independently, as no specific IT knowledge is needed for such operations in tenfold.

There are some extra settings available for events like parental leave or sabbaticals, where people leave the company for a specific timeframe. For such cases, resources like distribution groups, for example, are automatically removed when the leave begins and later automatically reassigned when the user returns to work.

Automated Data Imports

Automating the provision of necessary standard accounts and permissions helps save IT resources. While that is a great thing, of course, there is another process that is often neglected, but absolutely essential in ensuring data security: permissions that have been assigned must be removed again as soon as they are no longer needed (e.g. when an employee switches to another department). tenfold employs a rule-based profile system that automatically detects when users change departments and also allows you to set a transition period for such events. This stops users from accumulating excess permissions that are never removed, also known as a “privilege creep”. HWA is not the only company that once found itself caught in the vortex of a privilege creep.

Regarding HR processes, HWA deliberately chose not to tap into tenfold’s full potential from the get-go. Once a new user and/or their contract data have been entered into the HR system, all associated IT processes are automatically taken care of. HWA has been able to maintain good control over the current level of employee movement using this strategy. Should the level of joiner-mover-leaver processes increase in the future, HWA will reconsider using the automated data import option offered by tenfold.

Plugins for Additional Software

Sooner or later, every user requires additional rights on top of the standard set they were given upon joining the company. They may be working on projects that involve multiple departments and need access to data from those departments. At HWA, there previously was no other way than to go through IT to get additional rights. And the IT department then had their hands full trying to stay on top of every single of those requested rights manually.

With tenfold, users and managers can now simply request extra rights directly using tenfold’s built-in self-service portal. For this purpose, Active Directory and SAP ERP were integrated with tenfold’s services. The reason this did not completely blow the budget is because tenfold can be very easily integrated with most third-party systems. tenfold has plugins available for SAP and many other common and widely-used systems, which can simply be connected via standardized interfaces.

The self-service portal works as follows: first, you must appoint “data owners” for each object or resource. A data owner is usually a department manager or someone of equal authority. The data owners are then in charge of “their” resources and for controlling access to these. To make sure nothing slips under the radar, the approved and assigned access rights can be subjected to a regularly recurring process known as “user access review” or “recertification”, as tenfold calls it. In this process, data owners are prompted to re-approve or terminate access to their resources.

Permissions on Request

tenfold’s self-service screen is held as simple as possible and works much like an online shop. Experience has shown that even users who are not tech-savvy get the hang of it quickly. A self-service portal lives and dies with the user experience. If users aren’t happy, the service will not be accepted and therefore have failed its purpose. When a request has been made through the portal, the associated data owner is automatically informed about it by email. The email contains a link the data owner can use to either approve or reject the request. It really is that simple! Only if the request has been approved by all concerned parties (you can set multiple data owners for an object or resource) will the requested permissions be distributed automatically via the interface the concerning program is connected to.

The benefits for HWA are first off that their human resources in the IT apartment are freed from having to complete redundant manual tasks, like updating changes in user permissions across multiple systems. It’s a huge time-saver in that respect. Moreover, communications between IT, HR, managers and employees are now entirely automated, which again is a big time-saver and therefore a benefit for the entire organization.

Better Transparency

One aspect HWA was significantly able to improve by introducing tenfold was the level of transparency with regard to permission assignments. Prior to tenfold, HWA, like many other companies, simply used emails and tickets to handle permissions and requests – an approach that is not just very time-consuming, but also highly prone to errors. There’s hardly a way of keeping a good overview of who has what permission, who granted it and for what reason. A complete lack of transparency was a central issue HWA were struggling with.

Now, every change is documented as part of the request workflow and all important information can be instantly retrieved. The logs show exactly who made the request, who approved or declined it and when. Also, every user must supply a reason for making a request and data owners must provide a reason for their decision (approval or rejection). This allows companies to retrace all decision making processes.

Conclusion

HWA are currently planning to expand on further tenfold features, for instance its role-based concept. In future, the plan is to use tenfold’s profile system to model access rights. tenfold comes with a so-called “profile wizard,” whose very purpose it is to help derive suitable standards for departments, teams and locations on the basis of existing access structures. Further included in HWA’s roadmap is the use of tenfold’s self-service features as well as workflows for requesting and providing additional resources and IT systems.

Video Overview

See tenfold in Action With Our Feature Video

Book a 1:1 Demo

Schedule a Live Demo With One of Our Experts

Free Trial

Put tenfold to the Test With Our Free Trial!