Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

LIXIL identity governance at scale: what changes for global IAM teams


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15984
Topic starter  

TL;DR: At scale, identity governance breaks down first, where local exceptions, language requirements, and third-party access create control drift long before the technology stack runs out of capacity, according to Saviynt. Saviynt’s LIXIL customer story describes how 70,000 identities across 150+ countries forced a move away from manual processes and scratch-built identity tooling toward centralized governance, faster onboarding and offboarding, and improved audit readiness.

NHIMG editorial — based on content published by Saviynt: Behind the Scenes of an Identity Security Transformation: Our Journey with LIXIL

Questions worth separating out

Q: How should organisations govern employee and third-party access across global regions?

A: Use one policy model for onboarding, review, and offboarding, then allow only tightly controlled local variations.

Q: Why do scratch-built identity systems create audit and lifecycle problems?

A: Because custom workflows often bury approval logic, provisioning rules, and deprovisioning steps inside local code or isolated tools.

Q: What breaks when access rights are tied too closely to local organisational structures?

A: Central governance breaks because local role, seniority, and department rules rarely map cleanly across countries or business units.

Practitioner guidance

What's in the full article

Saviynt's full blog post covers the operational detail this post intentionally leaves for the source:

  • The phased deployment approach used to modernise LIXIL’s identity environment without disrupting business operations.
  • The practical handling of Japanese-language user interfaces and regional compliance requirements during rollout.
  • The internal stakeholder alignment that supported onboarding, offboarding, reporting, and audit control changes.
  • The customer perspective on how centralized visibility changed day-to-day identity operations.

👉 Read Saviynt’s customer story on LIXIL’s identity governance transformation →

LIXIL identity governance at scale: what changes for global IAM teams?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15569
 

Global identity governance fails first at the exception layer. LIXIL’s story shows that the real control problem is not simply provisioning volume, but the accumulation of local identity rules that cannot be governed consistently across 150+ countries. Once access decisions depend on regional workarounds, lifecycle control becomes fragmented and auditability degrades. The practitioner lesson is to treat exceptions as a governance risk, not an operational convenience.

A few things that frame the scale:

  • 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to Ultimate Guide to NHIs.
  • 79% of organisations have experienced secrets leaks, and 77% of those incidents caused tangible damage, according to Ultimate Guide to NHIs.

A question worth separating out:

Q: Who should own offboarding for vendor and non-human access?

A: Offboarding should sit with the same governance model that approved the access in the first place, with a named owner for each identity and a tracked removal action. If the business owner, technical owner, and security reviewer are not explicit, vendor and non-human accounts tend to survive contract changes, role changes, and project closure.

👉 Read our full editorial: LIXIL’s identity governance transformation shows the limits of local tooling



   
ReplyQuote
Share: