By NHI Mgmt Group Editorial TeamBased on SailPoint: “Identity security as the backbone of The Social Hub’s growth” (March 3, 2026)

TL;DR: As The Social Hub expanded across more than 20 properties, manual onboarding and offboarding could no longer keep pace with employees, contractors, vendors and partners needing access to systems, according to SailPoint. Identity became the control plane for scaling securely, not just an administrative task.


At a glance

What this is: This is a customer story about how identity security supports access governance across a fast-growing, multi-site hospitality business.

Why it matters: It matters because IAM teams scaling across locations, contractors and partners need governance that can keep pace with onboarding, offboarding and data protection without relying on manual processes.


Context

The core problem is access governance at operational speed. When a business expands across many sites, with employees, contractors, vendors and partners all needing access, manual joiner-mover-leaver handling becomes too slow to keep systems aligned with real-world work.

In this case, identity security is the control point that connects scale to security. The article frames identity as part of day-to-day operations, not a back-office task, because access decisions now have to support real-time onboarding and offboarding while protecting sensitive customer data.


Key questions

Q: How should teams govern access across multiple sites and business units?

A: Use one lifecycle model for all sites, then vary access by role, location and relationship. The goal is to make onboarding and offboarding consistent enough that expansion does not create local exceptions that outlast their business purpose.

Q: Why do manual onboarding and offboarding processes fail as organisations grow?

A: They depend on people noticing change quickly enough to update access before risk accumulates. In multi-site operations, that assumption breaks because roles, contractors and partners change too often for ticket-based handling to stay accurate.

Q: What are the signs that access governance is not keeping pace with changing roles?

A: Common warning signs include permissions that remain unchanged after transfers or departures, frequent over provisioning, manual access reviews that lag behind reality, and limited visibility into user activity. If teams struggle to produce current access evidence or keep certifications on schedule, governance is no longer aligned with how access is actually used in the organization.

Q: How do organisations keep sensitive customer data protected while scaling access?

A: Limit access to the shortest business-needed duration, review it when roles change, and remove it when relationships end. Customer-data protection depends on lifecycle discipline, not just login controls or periodic audits.


Technical breakdown

Why manual onboarding and offboarding break at multi-site scale

Manual joiner-mover-leaver processes depend on people keeping pace with organisational change. In a multi-property business, access must reflect location, role, partner status and timing, often at the same time. If provisioning and deprovisioning remain ticket-driven or spreadsheet-led, access lags behind operational reality and creates avoidable exposure. Identity security becomes the mechanism that lets the organisation treat access as a governed lifecycle rather than a clerical task. The control problem is not just volume, but coordination across sites and populations.

Practical implication: model onboarding and offboarding as a lifecycle process that must work across every site, not as separate local admin tasks.

Identity as the control plane for employees, contractors and partners

When multiple identity populations need access to the same business systems, the central challenge is not simply authentication. It is ensuring that each identity type receives the right entitlement scope, for the right duration, with the right offboarding trigger. That is a governance problem spanning human IAM, third-party access and lifecycle enforcement. In practice, identity becomes the decision layer that translates business context into access. Without that layer, the organisation relies on inconsistent local judgement and delayed revocation, both of which weaken control.

Practical implication: define access rules by identity population and business context so each group is governed consistently across all properties.

Protecting sensitive customer data while scaling access

Growth increases the number of access paths to customer data. The security issue is not only who can log in, but whether the organisation can prove that access remains appropriate as roles and relationships change. Identity security helps by tying access grant, review and removal to business events instead of static assumptions. That matters in service-heavy environments where temporary staff, vendors and partners may have legitimate but limited access. The tighter the operational tempo, the more important it is to align data access with lifecycle governance.

Practical implication: tie access reviews and revocation to real business events so customer data access does not outlive its purpose.


NHI Mgmt Group analysis

Multi-site growth turns identity from an admin function into an operational control plane. Once access spans employees, contractors, vendors and partners across more than one location, the security question is no longer whether accounts exist, but whether they are governed at the pace the business changes. Manual processes fail because they cannot reliably track movement across sites and roles. The implication is that identity governance becomes part of service delivery, not just security.

Access governance for hospitality-style operations is really lifecycle governance under pressure. Onboarding and offboarding are not edge cases in a growth story; they are the mechanism that keeps access aligned to work. This is where JML discipline matters most, because the risk rises when temporary access, partner access and location-based access accumulate faster than the business can revoke them. Practitioners should treat lifecycle control as a scaling requirement, not an afterthought.

Third-party and partner access introduces governance complexity that local admin teams usually absorb poorly. Contractors, vendors and partners do not fit neatly into employee-oriented access models, especially when multiple sites share systems. The result is often inconsistent approvals, uneven revocation and fragmented accountability. Identity security is the only practical way to make those populations governable across an expanding footprint.

Multi-property expansion exposes an identity security debt that grows with every new site. The more locations, roles and external parties an organisation adds, the more fragile manual access processes become. That debt shows up as delayed provisioning, stale access and weaker control over sensitive data. The practitioner lesson is to measure identity operations as part of growth readiness, not just security maturity.

Identity security matters here because scale changes the unit of risk. In a single site, teams can sometimes manage access informally. Across a distributed business, the unit of risk becomes the access model itself, because inconsistency multiplies quickly. The practical conclusion is to standardise identity governance before expansion makes exception handling the default.

What this signals

Identity lifecycle governance is what makes distributed growth manageable. When access spans many properties and external parties, the real control failure is not authentication but lifecycle drift. Teams should expect the pressure to move from provisioning speed to revocation accuracy as the business footprint expands.

Third-party access becomes harder to govern when local operations scale faster than central policy. The practical signal for IAM and IGA teams is that contractor and partner access must be designed as a governed population, not treated as an exception to employee processes.


For practitioners

  • Standardise joiner-mover-leaver workflows Replace site-specific onboarding and offboarding with one governed process that handles employees, contractors, vendors and partners consistently across every property.
  • Separate access rules by identity population Define different approval, duration and revocation rules for staff, third parties and partners so access reflects the business relationship, not just the system request.
  • Tie offboarding to operational events Trigger revocation when a role, contract or relationship ends, rather than waiting for periodic clean-up that may miss temporary access at busy sites.
  • Review customer-data access continuously Check that people with access to sensitive customer data still need it as they move between sites, projects and partner relationships.

Key takeaways

  • Multi-site expansion changes identity from an administrative function into a core operating control for access and data protection.
  • Manual onboarding and offboarding cannot keep pace when employees, contractors, vendors and partners all need timely system access.
  • The governance answer is a single lifecycle model that standardises access decisions across properties while still reflecting each identity population's business role.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 and SOC 2 (AICPA) define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article centres on governing access rights across many users and sites.
Recommendation — Apply PR.AA-05 to standardise entitlement decisions and removals across every property.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeMulti-site growth increases the risk of broad, stale access rights.
Recommendation — Enforce AC-6 so each identity only retains access needed for its current business role.
CIS Controls v8CIS-5 — Account ManagementThe story is fundamentally about lifecycle governance for accounts and access.
Recommendation — Use CIS-5 to govern provisioning, changes and removal across employee and third-party accounts.
ISO/IEC 27001:2022A.5.15 — Access controlThe article discusses organising access control as an enterprise governance capability.
Recommendation — Implement A.5.15 to define consistent access control rules for distributed operations.
SOC 2 (AICPA)CC6.1 — Logical Access Security Software and InfrastructureThe customer-data angle makes logical access controls relevant to service assurance.
Recommendation — Use CC6.1 to restrict and review logical access to systems handling customer data.

Key terms

  • Identity Security: Identity security is the discipline of governing who and what can access systems, data, and tools, then proving those decisions are enforced. In practice it spans human users, service accounts, tokens, certificates, and AI agents across the full access lifecycle.
  • Joiner Mover Leaver: Joiner Mover Leaver is the identity lifecycle process for creating, changing, and removing access as people enter, change roles, or leave an organization. It governs provisioning, modification, and deprovisioning across systems, ensuring access matches current job needs and reducing orphaned accounts, privilege creep, and residual access risk.
  • Third-Party Access: Third-party access is access granted to vendors, contractors, or support partners who are not direct employees of the organisation. It is higher risk than internal access because accountability, device assurance, and access duration are harder to control, so it usually requires tighter time limits and stronger auditability.
  • Access Governance: Access governance is the policy and workflow layer that manages how access is requested, approved, certified, and revoked. In SaaS environments it helps standardise control across many applications, reducing inconsistency between teams. It is most effective when it covers both human accounts and non-human identities.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org