Vertex Agility helped transform a legacy, infrastructure-heavy identity environment into an automated, cloud-native Identity Governance model – reducing recurring technology costs by approximately $720K annually while strengthening lifecycle automation, access governance, auditability, and the organisation’s Zero Trust security architecture.
Industry: Global Professional Services
Transformation: Identity Governance & Administration (IGA) Modernisation
Technology: Okta Identity Governance
Focus: Identity lifecycle automation, Zero Trust governance, access management, compliance, and legacy decommissioning
The Challenge
A global enterprise was operating a long-established legacy Identity and Access Management platform that had become increasingly expensive, complex, and difficult to scale.
The existing solution relied heavily on on-premises infrastructure, directory services, databases, and tightly coupled provisioning processes. Core identity activities – including employee onboarding, role changes, terminations, and downstream account provisioning – depended on a combination of legacy workflows, custom scripts, and manual operational processes.
The architecture also created dependencies between identity systems. In several scenarios, one platform had to create or update an identity before provisioning could continue across downstream applications.
As the organisation expanded its SaaS estate and strengthened its security strategy, this operating model was becoming increasingly difficult to sustain.
The key challenges included:
- high recurring licensing and infrastructure costs
- tightly coupled legacy IAM architecture
- significant manual effort across Joiner-Mover-Leaver processes
- complex onboarding, rehire, and termination scenarios
- fragmented identity and access governance
- inconsistent governance of privileged and service accounts
- connector limitations across cloud and enterprise applications
- fragmented audit and compliance information
- increasing difficulty supporting modern Zero Trust security principles
The legacy environment alone represented approximately $720,000 in annual recurring product and maintenance costs, before considering the additional infrastructure and operational effort required to support it.
The objective therefore wasn’t simply to replace an identity product.
The organisation needed to establish a modern Identity Governance and Administration model capable of automating the identity lifecycle, supporting Zero Trust access governance, and eventually removing the legacy environment without disrupting business operations.
The Approach
Vertex Agility supported the transition from the legacy identity management platform to Okta Identity Governance, introducing a modern, cloud-based IGA architecture and progressively transferring identity lifecycle responsibilities away from the legacy environment.
Rather than implementing a high-risk enterprise-wide cutover, the transformation was delivered through a phased coexistence and migration strategy.
1. Moving from Legacy IdP to Modern IGA
The target architecture repositioned Identity Governance as the central orchestration layer for enterprise identities.
Instead of relying on the legacy platform to initiate downstream provisioning, Okta Identity Governance was progressively integrated directly with authoritative identity sources and enterprise applications.
The architecture evolved towards:

This significantly reduced the architectural dependencies that had accumulated around the legacy IAM platform.
2. Automating the Identity Lifecycle
A major part of the programme focused on increasing automation across Joiner-Mover-Leaver (JML) processes.
Previously manual or highly customised activities were redesigned as automated identity workflows.
The new model supported automation around:
- employee onboarding
- identity creation
- enterprise identifier generation
- directory account provisioning
- birthright access allocation
- SaaS application provisioning
- role and organisational changes
- access updates
- termination processing
- immediate access removal
- downstream account clean-up
- account ownership reassignment
- rehire scenarios
- identity reconciliation
- privileged and service-account lifecycle management

Where standard connectors couldn’t address complex enterprise requirements, targeted workflows were introduced to automate the required business logic.
This allowed the organisation to modernise without losing important controls that had developed over many years within the legacy environment.
3. Embedding Zero Trust into Identity Governance
The transformation also strengthened the organisation’s ability to implement Zero Trust-aligned identity and access policies.
Rather than treating identity simply as an account provisioning function, the new architecture established Identity Governance as a central security control.
Access could increasingly be governed according to:

Governance was extended across multiple identity categories, including:
- standard workforce identities
- privileged identities
- service accounts
- specialist administrative identities
- application access
- device-related access
- physical access systems
This provided stronger foundations for least-privilege access, lifecycle-based access control, and continuous governance, key principles within a Zero Trust security model.
4. Introducing Self-Service and Automated Access Governance
The programme also moved access management away from dependency on manual IT support.
The target IGA model introduced capabilities for:
- self-service access requests
- automated approval workflows
- multi-level approval processes
- policy-driven provisioning
- automated access removal
- access certification and review
- centralised governance and reporting
Instead of access requests moving through disconnected operational processes, identity governance increasingly became a standardised, auditable workflow.
This improved both user experience and security control.
5. Phased Migration to Minimise Business Risk
Replacing a deeply embedded IAM platform through a single cutover would have introduced significant operational risk.
Vertex Agility therefore used a phased migration strategy.
Initial migration waves focused on lower-risk applications before progressively introducing more business-critical identity services and integrations.
Each wave followed a structured lifecycle:

The legacy and target environments temporarily operated in parallel, allowing the team to progressively validate the new architecture under real production conditions.
A feature freeze was also introduced on the legacy platform to prevent new functionality from increasing migration complexity.
6. Establishing a Repeatable Application Onboarding Framework
A standardised application onboarding model was introduced so that each application integration followed the same governance and delivery framework.
Application owners, security teams, IAM specialists, and business stakeholders worked through a repeatable process covering:
- requirements
- identity model
- provisioning rules
- access policies
- integration design
- security controls
- testing
- production readiness
- cutover
This reduced variability between application migrations and created a scalable framework for onboarding future systems into the IGA platform.
7. Improving Audit and Compliance
The modernisation programme also addressed fragmented audit information.
Identity events, provisioning activity, and governance records were integrated with central monitoring and long-term reporting capabilities.
This improved support for:
- security monitoring
- compliance reporting
- access reviews
- access certifications
- incident investigations
- historical audit requirements
Moving audit information away from dependency on the legacy IAM infrastructure was particularly important because it allowed the old platform to eventually be retired without losing historical governance evidence.
8. Controlled Legacy Decommissioning
Legacy decommissioning was treated as a dedicated transformation workstream rather than simply shutting down the old environment.
Before major cutovers, comprehensive backup and recovery procedures were established for identity information, configurations, and historical records.
Following the final migration, the legacy environment entered a controlled dormant state before permanent infrastructure retirement.
This provided a fallback window while ensuring business operations, audit history, and identity information remained protected throughout the transition.
The Benefits
~$720K Annual Recurring Cost Reduction
Retiring the legacy identity platform removes approximately $720,000 in annual recurring product and maintenance costs.
Further savings are generated through the retirement of associated on-premises infrastructure, databases, and supporting technology.
The programme therefore delivers both direct licensing savings and longer-term reductions in infrastructure and operational overhead.
Increased Identity Automation
Automation significantly reduces the manual effort required to manage the workforce identity lifecycle.
Employee onboarding, provisioning, access changes, and termination activities can increasingly be executed automatically based on authoritative identity information and governance policies.
This reduces operational workload while improving consistency.
Faster Employee Onboarding
Automated identity creation and birthright provisioning allow new employees to receive required access more quickly.
Instead of multiple manual support activities, identity provisioning can begin automatically from trusted source information.
Stronger Leaver Controls
Automated termination workflows improve the speed and consistency with which access is removed when employees leave the organisation.
This reduces the security risk associated with orphaned accounts, delayed deprovisioning, and excessive residual access.
Zero Trust-Aligned Access Governance
The new identity architecture provides stronger foundations for Zero Trust by centralising identity governance and supporting:
- least-privilege access
- policy-driven provisioning
- privileged-access governance
- lifecycle-based access control
- automated access removal
- access certifications
- auditable approval processes
Identity becomes a core security control rather than simply an administrative provisioning function.
Reduced Operational Overhead
Automation and self-service capabilities reduce dependency on IAM engineering and IT support teams for routine access-management activities.
This allows specialist teams to focus more of their time on security, architecture, and complex identity requirements rather than repetitive provisioning tasks.
Improved Compliance and Auditability
Centralised identity governance provides greater visibility into:
who has access, what they can access, why access was granted, how it was approved, and when it should be removed.
This simplifies compliance reporting, access reviews, investigations, and audit preparation.
Greater Scalability
Moving from an infrastructure-heavy legacy IAM platform to a cloud-based, API-driven IGA model provides a much more scalable foundation for future business growth.
New SaaS and enterprise applications can be incorporated into a common identity governance framework rather than creating additional standalone provisioning processes.
Business Impact
The transformation moved the organisation from a legacy identity-management model centred around maintaining infrastructure and custom workflows to a modern model based around automated Identity Governance, policy enforcement, and lifecycle orchestration.

Key Outcomes
- ~$720K annual recurring product and maintenance cost reduction
- Migration from legacy on-premises IAM to Okta Identity Governance
- Automated Joiner-Mover-Leaver lifecycle management
- Reduced manual IAM and IT support effort
- Faster employee onboarding and access provisioning
- Automated termination and account clean-up
- Centralised privileged and service-account governance
- Self-service access request and approval capabilities
- Improved auditability and compliance visibility
- Identity architecture aligned with Zero Trust principles
- Reduced dependency on legacy infrastructure
- Scalable foundation for future enterprise and SaaS integrations
Want to find out how Vertex Agility can help you modernise identity governance?
Get in touch now or take a look at our Cloud & Platform services to find out more.