
Identity and Access Management oversees users, roles and permissions with a unified approach
In most organizations, users and access rights are spread across many different systems. This makes it difficult and time-consuming to grant and revoke user rights, and has implications for both work efficiency and security. With a well-functioning Identity and Access Management solution, we help you ensure that the right users have the correct access at the right time.

IDENTITY AND ACCESS MANAGEMENT
From fragmented access management to a single, unified overview
Years of piecemeal digital development often result in users and access rights being managed differently from system to system. Each system typically has its own user list and may also have different definitions of what even constitutes a user.
In some systems, the supplier creates users manually, directly in the database. Elsewhere, staff may have to log in twice to gain access. And in some cases, former employees’ accounts remain active for several years after they have left.
This fragmented management makes it difficult to document who has access to what. It undermines both security and the ability to demonstrate compliance.
With Identity and Access Management (IAM), you consolidate the management of identities and access into a single solution. That makes day-to-day operations easier and enabling the security department to manage policies centrally.
Our Identity and Acces Management-services
Federation and single sign-on
When users have to work across multiple systems, access needs to be straightforward. With federation technology and single sign-on, you can manage logins from a single point. We help you integrate new systems and public login solutions such as MitID and MitID Erhverv without having to build new integrations each time. Through eIDAS, you can also grant users from other EU countries access using their national electronic identity. We typically build the IAM solution on Safewhere Identify – our own identity product – or Keycloak. In both cases, you’ll receive a solution that you can continue to operate yourselves without user-based licences or exit costs built into the contract.
Roles, permissions and lifecycle
We help define who is authorized to do what, and who approves it. Permissions must follow the employee throughout their time in the organization. It is important that access rights are updated when roles or responsibilities change and revoked upon leaving the organisation, so that old access rights do not remain active.
Migration
When organizations embark on an IAM journey, they usually already have a range of solutions and systems in place. We draw up a plan to transition from decentralized users, local passwords and existing identity solutions to a single, unified IAM solution. The systems are integrated one at a time, so that the migration can be carried out without disrupting day-to-day operations.
Start with one system, not the entire portfolio
Initially, it may be tempting to try to design the perfect access model for the entire organization by mapping out all users, roles and permissions, as well as the relationships between them.
One pitfall of this approach is that, instead of a fine-meshed net, you end up building an impenetrable web that provides neither an overview nor enhanced security.
The second common disadvantage of this approach is that the grand, elaborate access model will never be finished, because reality changes faster than it can be described. You therefore risk embarking on a never-ending project where the endpoint is constantly shifting.
Our approach to IAM is to start small. Build the foundation, and then you can connect the first line-of-business system. This exercise reveals the actual requirements – what types of users exist, what governs access rights, and where the exceptions lie.
The experience gained from the first system makes it quicker to connect the next one. This process continues until connecting new systems becomes a routine task requiring fewer and fewer resources.
Remember that the foundation must take into account that it is not only people who need to be identified and granted the correct access. Services also communicate directly with one another and must be able to document who they are and what they have access to.
The rule of thumb in Identity and Access Management is, it’s better to keep it simple than to over-engineer an IAM solution.

Selected technologies and tools
- Safewhere Identify (our own identity product, which is open source and has been tried and tested in the Danish public sector federation on a national scale)
- Keycloak (an open-source solution for identity and access management)
- Microsoft Entra ID (Microsoft’s identity and access management solution)
- MitID and MitID Business
- eIDAS (enables citizens and businesses from other EU countries to log in using their national electronic identity)
- OpenID Connect, SAML and OAuth 2.0 (standards and protocols for login, identity exchange and access management)
Impact
View cases and insights
74 results







