Simple User Administration at DEVK – Even Without IT Assistance

Success Story·3 min
DEVK Logo
DEVK
Insurance

Find out more

Thanks to being able to outsource more and more standard tasks to the specialist departments – which is further facilitated by the Garancy Process Center – the IT team now has more time to tend to core tasks and can administrate a much larger user base with the same number of people.

Today, access governance is a top priority for DEVK. Garancy IDM makes it much easier for DEVK to comply with access governance requirements.

DEVK Logo
Senior Specialist IAM Architecture
DEVK

Initial Situation

DEVK has been insuring German policy holders against the risks of everyday life for over 125 years. At present, the DEVK Group is tending to approximately 4 million customers, insuring them against 14 million risks across all segments. A total of over 6,000 employees go the extra mile to provide customers with quick and effective assistance. DEVK’s goal: significantly simplify and accelerate access rights allocation across all corporate IT systems. Even employees with little or no technical background should be able to take on certain user administration tasks.

Challenge

The IT department of DEVK had to connect a large number of sales representatives to the central, home-grown master data management application at short notice. Manual administration of these new clients would have resulted in a significant increase of the workload, which would have forced the insurer to substantially expand the IT team.

Implementation

The sophisticated role scheme of DEVK combines specialist competencies of the SAP system with the superordinate Garancy Identity Manager authorization management. A workgroup creates the specific SAP roles together with the specialist departments and then hands them over to the IT service and operations team.

This means that the SAP team is only responsible for defining the roles, but it does not allocate any users to them. This is the sole domain of the IAM system, which takes these SAP roles and combines them with authorizations for additional IT systems by creating high-level Garancy roles.

“The Garancy role has the highest authority; it bundles the entire specialist function range of each employee,” explains DEVK IAM Architecture Specialist Lutz Becker. Using this approach, the authorizations needed for IT systems such as SAP, the insurance application or Windows depending on the specific task profile are defined as roles. In the Garancy Identity Manager, these roles are then linked with the personal authorization profile of each respective employee.

Given this setup, authorization management basically maps the entire organizational structure of the insurance company. This allows specialist departments to rapidly assign individual access rights to new employees. All that is left to do for IT staff is to clarify open issues in collaboration with the specialist department.

Previously, new employees sometimes had to wait for up to five days before they had been properly and fully set up in the IT systems. Now it takes only two to three hours before they are connected to all systems they need to do their jobs.

Outcome

Thanks to the new version, it will become much easier for DEVK to comply with access governance requirements – a high-priority topic for the insurance company. Garancy IDM from Beta Systems offers the option of defining dedicated risk parameters and information for the various entities: groups, roles and users. Given this capability, DEVK is planning to introduce user classes once the new version is in place.


Get Advice from Our Experts

Would you like to learn how your company benefits from Identity Access Management and how to implement an IAM solution in a pragmatic and efficient manner?

Send us a message and we will respond to you shortly. We look forward to hearing from you!

Customer

DEVK Logo
Year of foundation
1886
Number of employees
7,500
Head office
Cologne
Sector
Insurance
DEVK
Riehler Straße 190
50735 Cologne
Germany

Further Resources

Webinar
nis2-requirements-for-critical-infrastructure.jpg

Practical NIS-2 Requirements for Critical Infrastructure Operators in Public Services

The NIS-2 Directive significantly tightens cybersecurity requirements for operators of critical infrastructure and essential public services across the EU ‒ including energy, water supply, and municipal utilities. But what does this mean in practice for organizations affected today? This on-demand webinar shows you exactly how to interpret and implement NIS-2 requirements effectively.
Webinar
iam-project-management-insights.jpg

Action Over Planning – IAM Project Management Tips and Insights (DE)

Identity and Access Management (IAM) isn’t just an IT initiative – it’s a strategic enabler of security, operational efficiency, and compliance in modern digital businesses. Yet too many IAM projects stall before they begin: over-planning, uncertain priorities, regulatory complexity, and limited resources can slow progress and undermine results.
Whitepaper
Whitepaper Titelbild: NIS-2 und der strategische Wert von Identity & Access Management

Turning Obligation into Advantage: NIS-2 and the Strategic Value of Identity & Access Management

The NIS-2 Directive significantly raises the bar for cybersecurity across Europe, placing Identity & Access Management at the center of compliance and security efforts. This whitepaper explains why IAM under NIS-2 is not merely a regulatory obligation, but a strategic foundation for resilience, transparency, and control. Developed in collaboration with egerer Consulting, it brings together regulatory insight and strategic consulting expertise with practical guidance on implementing NIS-2 requirements using a modern IAM solution.