TL;DR: Beach Energy says its identity security programme was hampered by overly manual onboarding, offboarding and user management, poor user experience, and limited access visibility before it reworked its approach with SailPoint. The case shows that identity operations become a security control, not an administrative task, as programmes scale.
NHIMG editorial — based on content published by SailPoint: Beach Energy builds sustainable identity security
Questions worth separating out
Q: How should security teams reduce manual effort in identity onboarding and offboarding?
A: Security teams should move common access changes into governed workflows with standard approvals, role mapping, and automatic revocation triggers.
Q: Why does access visibility matter so much in IAM programmes?
A: Access visibility matters because teams cannot govern entitlement risk if they do not know what access exists in the first place.
Q: What do organisations get wrong about manual identity processes?
A: They often treat manual workflows as a temporary operational issue, when in fact those workflows create control debt over time.
Practitioner guidance
- Standardise joiner-mover-leaver workflows Map onboarding, transfer, and offboarding to a single governed workflow so access decisions are repeatable and auditable rather than handled case by case.
- Build an authoritative access inventory Create a current view of who has access, what that access supports, and when it was last reviewed so removals and certifications are based on facts.
- Reduce manual approval bottlenecks Use policy-based approvals for common access paths so IT can grant access rapidly without losing control over entitlement scope and revocation.
What's in the full article
SailPoint's full blog post covers the operational detail this post intentionally leaves for the source:
- Aaron Finnis's direct commentary on why Beach Energy prioritised identity security in its programme
- The business context behind the organisation's onboarding, offboarding, and user management transformation
- The short video interview that expands on Beach Energy's access and compliance priorities
- The source article's own framing of how SailPoint supported the change
👉 Read SailPoint’s blog on Beach Energy’s identity security transformation →
Manual onboarding and offboarding: what IAM teams should fix first?
Explore further