logo
hamburger-menu-icon
Back to Projects

Financial Services Firm

Centralizing Access Across Enterprise Systems

A financial services firm, formerly part of a global bank and now under new private equity ownership, needed a new identity system as part of a broader transformation led by an outside firm. Ollon implemented Okta, migrating hundreds of users onto single sign on across 15 off the shelf tools and 10 custom applications. The firm now runs on one centralized, secure identity system across all 25 applications.

A financial services firm, formerly part of a global bank and now operating under new private equity ownership, required a comprehensive modernization of their systems following their transition to a private equity firm. As part of a broader transformation initiative led by an outside consulting firm, Ollon was engaged specifically to lead the implementation of a new Identity and Access Management (IAM) system. The objective was to establish secure, centralized user access through single sign-on (SSO) across internal and external applications.

Ollon implemented Okta to manage identity and access, aligning with the firm's new security and operational requirements. The team migrated hundreds of users to the new system, enabling SSO across 15 off the shelf software solutions and 10 custom applications. This effort involved close coordination with multiple development teams and agencies to ensure seamless integration and minimal disruption.

The migration went smoothly, providing a cohesive user experience, while maintaining strict security standards, safeguarding user data and system integrity. Despite the challenges of working with a large organization and multiple agencies, Ollon's collaborative approach ensured effective communication and timely implementation of all necessary changes to successfully implement the new system.

Okta, Azure, .NET Core, Angular, Python

Our Expertise in Action

Post-acquisition transition

A financial services firm was working through a modernization effort after moving from a global bank's ownership to a private equity firm, with an outside consulting firm leading the broader transformation program. Ollon was brought in specifically to lead one piece of that larger effort, building a new identity and access system to replace whatever access controls the firm had inherited from its previous ownership. That focus meant Ollon's work had to fit inside a transformation being run by other parties, coordinating around their timeline and requirements instead of setting the pace itself. The identity work became the piece of the transition that gave the firm centralized, secure access from day one under its new ownership.

Security and compliance consulting

Once a financial services firm's new private equity owner started reviewing the company's security posture directly, admin access inside the new identity system needed a level of scrutiny it had not gotten during initial rollout. Ollon audited every admin account, built out granular permission levels so each admin only had access to the applications their role actually required, prepared the security checklist the new ownership had requested, and set up automated checks to catch external users who had never activated their accounts. That hardening work gave the new ownership a system they could review and trust, not just one that worked.

Identity and Access Management

A financial services firm needed one identity system to replace whatever access controls existed across dozens of internal and external applications inherited from its previous ownership. Ollon implemented Okta as that central system, configuring OAuth2 and SAML protocols, building login workflows that supported both embedded and redirect based sign in depending on what each application needed, and creating the logic for bulk importing users with group rules that automatically assigned people to the right applications based on their role. The result was a single identity layer standing behind every application instead of each one managing its own separate access.

SSO Integrations

Getting single sign on working for a financial services firm meant going application by application, since each of the 25 systems involved had its own quirks for how authentication needed to connect. Ollon worked through custom solutions for specific applications, including an Org2Org connection for one system and a SAML based integration for another, then untangled a case where one application had two separate instances needing the right environment pointed to. Each integration surfaced its own questions from that application's development team, worked through directly instead of one generic solution applied everywhere. That effort is what got 25 systems behind a single sign on experience.

Team augmentation and staff scaling

A financial services firm's identity project needed a larger team during the intensive initial rollout, when dozens of applications had to be integrated at once, but far less capacity once the core system was live and stable. Ollon staffed the engagement with several developers and a project manager during that first push, then scaled down to a single specialist who carried the remaining support and application requests through to the project's close. That specialist ran formal knowledge transfer sessions with the firm's team before stepping away, instead of leaving support without a handoff. The staffing matched the actual workload at each stage instead of keeping a large team in place after the heaviest work was done.

Platform migration

Migrating hundreds of existing users into a financial services firm's new identity system meant more than creating accounts, since every user needed to land in the right groups with the right application access from day one. Ollon automated the import so users were assigned to their correct applications by role, then backed up all existing users before making further changes so nothing could be lost partway through. External clients needed their own onboarding path, including a way to prompt anyone who had not yet set up an account to activate it. That work is what let hundreds of users move onto the new system without anyone losing access or falling through the cracks.