IT & Business Services

Automated Access Recertification at Beiersdorf Shared Services – Event-Driven Identity Governance with NEXIS

Beiersdorf Shared Services implemented NEXIS to automate event-driven access recertifications and establish clear, auditable identity governance processes across its global IT operations.

IT & Business Services

About Beiersdorf Shared Services

Beiersdorf Shared Services GmbH (BSS) has been a wholly owned subsidiary of Beiersdorf AG since 2003. It serves as the central IT and accounting partner for Beiersdorf’s global business operations.

BSS provides highly efficient services across accounting, infrastructure, application management, and strategic consulting – all from a single source. With a global footprint, the organization must maintain consistant and controlled access governance across a complex digital environment.

As the number of digital identities grows and employees frequently change roles or departments, ensuring accurate and compliant entitlement management has become a critcal operational and regulatory requirement.

  • Headquarters: Hamburg, Germany
  • Employees: 340+
  • Parent Company: Beiersdorf AG
  • Operations: Global

With NEXIS, Beiersdorf Shared Services was able to

Automate Event-Driven Recertifications

Trigger recertification processes automatically whenever employees change roles or departments

Eliminate Manual Entitlement Reviews

Replace error-prone manual processes with structured, workflow-based governance

Ensure Timely Removal of Excess Rights

Guarantee that outdated entitlements are removed after every organizational change

Improve AD Group Data Quality

Establish accurate and up-to-date responsibility ownership for all Active Directory groups

Achieve Full Audit Traceability

Document every entitlement change with comprehensive, auditable records in NEXIS

Enable Business Departments to Self-Govern

Configure intuitive, department-facing UI for independent task processing without IT involvement

The Challenge

As Beiersdorf Shared Services grew its digital operations, managing employee entitlements across Microsoft Active Directory became increasingly complex. The rising number of digital identities – combined with frequent role and department changes – created significant risk of outdated or incorrect access rights remaining in place.

Existing processes relied on manual reviews that were difficult to coordinate, slow to execute, and hard to audit. When employees moved between departments, there was no automated mechanism to trigger a review of their existing AD group memberships and responsibilities. This left access rights unmanaged for extended periods and increased compliance exposure.

Extending the existing IAM system through customization or an in-house add-on would have been costly and difficult to maintain long-term.

The goal was to:

  • Introduce event-driven, automated recertification triggered by organizational changes
  • Ensure employees carry only the entitlements relevant to their current role
  • Transfer AD group responsibilities correctly when responsible parties change departments
  • Implement a solution that integrates with the existing IAM system without requiring fundamental changes
  • Establish a sustainable, low-maintenance governance process

The Approach

BSS and Nexis designed automated governance workflows that integrate directly with the existing IAM infrastructure via REST API – triggering recertification precisely when organizational changes occur.

1. Event-Triggered Workflow Integration

The existing IAM system triggers an API call to NEXIS via a standardized REST connection whenever an employee changes posts, activating two separate recertification workflows automatically.

2. Automated AD Group Recertification

When an employee moves to a new department, NEXIS launches a targeted recertification of all current AD group assignments using a purpose-configured review interface.

3. Responsibility Transfer Workflow

When an AD group owner changes departments, NEXIS initiates a review workflow for their direct superior to confirm or reassign group responsibilities.

4. Multi-Level Approval Processes

Custom multi-level approval chains - including optional escalation paths - were configured within the NEXIS workflow engine to match BSS's internal governance requirements.

5. Department-Facing UI Configuration

The recertification interface was iteratively configured and tested in the NEXIS environment to ensure intuitive, self-sufficient task processing by non-technical business departments.

The Results

The implementation of NEXIS enabled Beiersdorf Shared Services to replace fragmented, manual entitlement reviews with a fully automated, event-driven governance process – deployed rapidly using NEXIS standard capabilities with minimal customization effort.

The solution integrates directly into the existing IAM infrastructure and triggers precisely when needed: at the moment of organizational change. Business departments now manage their own recertifications through an intuitive interface, reducing dependency on IT and accelerating decision cycles.

  • Process simplification: Automated recertification replaces error-prone manual coordination across departments
  • Improved data quality: AD group responsibilities are now accurately maintained and regularly validated
  • Audit traceability: Every entitlement change is documented and traceable in NEXIS for past and current employee changes
  • Fast time-to-value: The solution was configured and live within days using NEXIS best-practice templates and Nexis consulting expertise
  • Sustainable architecture: The existing IAM system was extended, not replaced – keeping the implementation lightweight and maintainable long-term

See How Structured IAM Governance Enables Business at Scale

See how NEXIS helps large organizations improve role governance, increase recertification coverage, and reduce operational complexity across a growing identity landscape.

Read more Success Stories