TL;DR: At scale, identity governance breaks down first, where local exceptions, language requirements, and third-party access create control drift long before the technology stack runs out of capacity, according to Saviynt. Saviynt’s LIXIL customer story describes how 70,000 identities across 150+ countries forced a move away from manual processes and scratch-built identity tooling toward centralized governance, faster onboarding and offboarding, and improved audit readiness.
At a glance
What this is: This is a customer story about LIXIL’s identity governance transformation, with the key finding that global scale exposed the limits of manual and locally built access processes.
Why it matters: It matters because IAM, IGA, and third-party access teams must govern employee and vendor access consistently across regions, languages, and compliance boundaries without losing operational control.
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts, according to NHI Mgmt Group research.
- 71% of NHIs are not rotated within recommended time frames, increasing the risk of compromise over time, according to NHI Mgmt Group research.
👉 Read Saviynt’s customer story on LIXIL’s identity governance transformation
Context
Identity governance becomes harder when a global enterprise relies on manual workflows, local automation, and bespoke systems that were built for one region rather than a common control model. LIXIL’s story is a good example of how IAM, IGA, and third-party access programmes can drift when the operating model expands faster than the governance fabric.
The article also highlights a familiar enterprise pattern: access rights tied to department, role, and seniority may work inside a single organisational culture, but they become difficult to standardise across countries, languages, and compliance regimes. That is why identity governance, not just provisioning speed, becomes the real constraint in global transformation.
For NHI and vendor-access teams, the broader lesson is that the same governance weaknesses seen in human identity programmes often reappear when external users, contractors, and service-like accounts are managed through fragmented processes. The control question is whether one operating model can enforce consistent lifecycle rules everywhere, not whether the local toolset can handle one site at a time.
Key questions
Q: How should organisations govern employee and third-party access across global regions?
A: Use one policy model for onboarding, review, and offboarding, then allow only tightly controlled local variations. The goal is not identical process everywhere, but one accountable lifecycle with consistent ownership, evidence, and revocation rules. If regions create their own approval chains, identity governance becomes impossible to certify at scale.
Q: Why do scratch-built identity systems create audit and lifecycle problems?
A: Because custom workflows often bury approval logic, provisioning rules, and deprovisioning steps inside local code or isolated tools. That makes it harder to prove who approved access, whether it was removed on time, and whether the same control is applied everywhere. Lifecycle governance becomes fragmented long before the organisation notices a security issue.
Q: What breaks when access rights are tied too closely to local organisational structures?
A: Central governance breaks because local role, seniority, and department rules rarely map cleanly across countries or business units. Attestation becomes inconsistent, exceptions accumulate, and access reviews stop reflecting the actual business need. Over time, the programme can still issue access, but it cannot reliably explain or defend it.
Q: Who should own offboarding for vendor and non-human access?
A: Offboarding should sit with the same governance model that approved the access in the first place, with a named owner for each identity and a tracked removal action. If the business owner, technical owner, and security reviewer are not explicit, vendor and non-human accounts tend to survive contract changes, role changes, and project closure.
Technical breakdown
Why affiliation-based access models get harder to govern globally
Affiliation management ties access to department, role, and seniority rather than treating identity as a simple user record. That can be stable inside one organisational culture, but it becomes brittle when business units, languages, and regulatory expectations differ across regions. In practice, the model creates many local exceptions that are hard to certify centrally, especially when joiner, mover, and leaver workflows depend on people remembering how each country works. The result is not just administrative overhead. It is a governance model that scales by exception and eventually loses control consistency.
Practical implication: map where affiliation rules are still handled manually and decide which of them must be standardised before the next access review cycle.
How scratch-built identity systems create lifecycle and audit friction
Scratch-built systems are bespoke identity workflows developed in-house over many years. They often solve local business problems well, but they also make change expensive because provisioning logic, approvals, and reporting are embedded in custom code or isolated tools. That makes offboarding, attestations, and audit evidence harder to standardise. When legacy identity logic is scattered across home-grown systems, teams can prove that access was granted, but not always that it was revoked on time or consistently across all populations. This is a lifecycle governance problem as much as a tooling problem.
Practical implication: inventory every local identity workflow that bypasses central governance and rank it by its impact on provisioning, revocation, and audit evidence.
Third-party access governance depends on one control plane
The story points to a mixed population of employees, vendors, and partners all needing secure access. That matters because third-party identity governance fails when external users are treated as an exception process rather than a governed population with lifecycle rules. Without a single control plane, access reviews fragment, entitlement ownership becomes unclear, and offboarding depends on local follow-up instead of enforceable policy. This is where human IAM and NHI governance start to converge: if the identity is external to the core workforce, the lifecycle discipline has to be even tighter, not looser.
Practical implication: require one authoritative process for third-party onboarding, review, and deprovisioning instead of allowing region-specific exceptions.
Threat narrative
Attacker objective: The practical objective is to retain unnecessary access long enough to exploit weak governance, evade timely revocation, or move through uncontrolled third-party pathways.
- Entry begins when access is provisioned through manual processes or local automation that cannot enforce consistent lifecycle controls across regions and external users.
- Escalation occurs when stale entitlements, unclear ownership, or delayed offboarding allow access to persist beyond the business need that justified it.
- Impact appears as audit friction, compliance exposure, and a wider attack surface across employee and third-party identities that should have been centrally governed.
Breaches seen in the wild
- JetBrains Marketplace AI Plugin Campaign — 15 malicious JetBrains Marketplace plugins steal AI API keys from 70,000+ developers via supply chain attack.
- Code Formatting Tools Credential Leaks — Widely used code formatting tools cause massive credential and secrets leaks in enterprise environments.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Global identity governance fails first at the exception layer. LIXIL’s story shows that the real control problem is not simply provisioning volume, but the accumulation of local identity rules that cannot be governed consistently across 150+ countries. Once access decisions depend on regional workarounds, lifecycle control becomes fragmented and auditability degrades. The practitioner lesson is to treat exceptions as a governance risk, not an operational convenience.
Scratch-built identity workflows create invisible lifecycle debt. Bespoke systems can function well for a time, but they often preserve historical decisions that no longer fit modern compliance, cloud, or audit requirements. That is how onboarding, offboarding, attestations, and reporting become partially automated but not truly controlled. The key implication is that custom identity logic should be measured by revocation certainty, not by how long it has served a local need.
Third-party access governance should be designed as a lifecycle discipline, not a permissions project. LIXIL’s mix of employees, vendors, and partners is common in global enterprises, and it exposes the weakness of treating external access as a separate workflow. The same control logic has to cover joiner, mover, and leaver events for every population that can reach business systems. Practitioners should judge their programme by whether one process can enforce ownership, review, and offboarding across all identity types.
Central visibility is the prerequisite for standardising identity governance across cultures and regions. The story makes clear that translation, compliance alignment, and business continuity are not side issues but part of the identity operating model. When local teams cannot see the same access picture, they cannot certify it consistently or remediate it at speed. The field should read this as a reminder that identity governance maturity is measured by control consistency, not by the number of local tools in place.
From our research:
- 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to Ultimate Guide to NHIs.
- 79% of organisations have experienced secrets leaks, and 77% of those incidents caused tangible damage, according to Ultimate Guide to NHIs.
- For lifecycle governance depth, Ultimate Guide to NHIs , Lifecycle Processes for Managing NHIs is the most relevant next resource.
What this signals
Lifecycle control is now the real differentiator in identity programmes. Organisations can modernise provisioning tools and still fail if revocation, attestation, and exception handling remain fragmented across regions. The question for practitioners is whether one operating model can sustain global growth without allowing local identity logic to become a shadow governance layer.
Identity governance maturity is measured by consistency, not volume. A programme that can handle more identities is not necessarily a programme that can govern them better. The stronger signal is whether access decisions, reviews, and offboarding remain explainable when the business expands into new geographies and operating models.
Global operating models need a single identity narrative. If different teams describe the same access lifecycle in different ways, the programme has already lost control coherence. That is why standardisation, central evidence, and reviewable ownership should be treated as baseline requirements, not post-project clean-up.
For practitioners
- Map local identity exceptions by control impact Catalogue every region-specific provisioning, attestation, and offboarding variation, then rank each one by how much it weakens central lifecycle governance and audit evidence.
- Consolidate external access into one governed process Bring vendor and partner onboarding, review, and deprovisioning under a single policy model so regional teams cannot improvise separate lifecycle rules for third parties.
- Measure revocation certainty, not just provisioning speed Track whether access removal is completed consistently across all user populations and whether the evidence can be produced without manual reconciliation.
- Retire custom identity logic that blocks standard auditability Identify scratch-built workflows that cannot prove who approved access, when it was removed, or why a local exception still exists.
- Align IAM operating models to one global control narrative Use a common joiner, mover, and leaver framework so local process differences do not create separate governance truths for the same identity population.
Key takeaways
- LIXIL’s story shows that identity governance breaks down when local workarounds outgrow the central control model.
- The scale evidence matters because 70,000 identities across 150+ countries and a large third-party population demand lifecycle consistency, not just faster provisioning.
- The control that changes outcomes is one accountable lifecycle process for onboarding, review, and offboarding across every identity population.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 and GDPR define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | The article centres on access management across global identities and third parties. |
| NIST SP 800-53 Rev 5 | AC-2 | Account management is central to joiner-mover-leaver and third-party access governance. |
| ISO/IEC 27001:2022 | A.5.15 | Access control policy is directly implicated by standardising governance across regions. |
| GDPR | Art.32 | The article explicitly mentions GDPR data residency requirements and global compliance. |
Map identity approvals and recertification to PR.AC-4 and standardise entitlements across regions.
Key terms
- Identity Governance: Identity governance is the set of controls that defines who approves access, who owns it, how it is reviewed, and when it is removed. In practice, it turns identity management from a deployment task into a durable control system that can withstand audits, organisational change, and operational growth.
- Affiliation Management: An access model that ties rights to an employee’s department, role, or seniority rather than treating each entitlement as an isolated decision. It can work well inside a single organisational culture, but it becomes difficult to standardise when governance must span countries and business units.
- Scratch-Built Identity System: A bespoke identity workflow or platform created in-house over time to solve local business needs. These systems often fit regional processes well, but they tend to make auditability, change management, and integration with modern governance controls harder as the environment grows.
- Third-Party Access Governance: Third-party access governance is the control set that tracks, approves, reviews, and revokes access granted to external vendors and partners. It becomes an identity problem when suppliers operate through shared credentials, delegated workflows, or persistent machine access that outlives the business need.
What's in the full article
Saviynt's full blog post covers the operational detail this post intentionally leaves for the source:
- The phased deployment approach used to modernise LIXIL’s identity environment without disrupting business operations.
- The practical handling of Japanese-language user interfaces and regional compliance requirements during rollout.
- The internal stakeholder alignment that supported onboarding, offboarding, reporting, and audit control changes.
- The customer perspective on how centralized visibility changed day-to-day identity operations.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
Published by the NHIMG editorial team on August 17, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org