Practitioner's guide to the future of identity — new maturity model
Access the guide

A Fortune 500 financial services firm right-sizes access to confidential data with usage-aware governance

See how a Fortune 500 financial services firm found that only 50 of 50,000 users actually used their access to confidential files, and how Oleria helped them close the gap.

Watch video

50

of 50,000 Users

With standing access to confidential repositories who actually opened them

25,000+

SharePoint sites

Mapped for direct, inherited, and externally shared access

1.5

FTEs reclaimed

Engineering capacity freed from manual log-analysis scripts

50 of 50,000

Users with standing access to confidential repositories who actually opened them

25,000+ SharePoint sites

Mapped for direct, inherited, and externally shared access

1.5 FTEs reclaimed

Engineering capacity freed from manual log-analysis scripts

Industry

Financial services

Use Cases

Usage-aware access governance

Leaver risk

Data exposure reduction

Regulatory context

SEC

FINRA

SOX

GLBA

Employee size

30,000+

50,000 users had access to confidential files. Only 50 used it. Oleria connected permissions to real activity across 25,000+ SharePoint sites, automated leaver monitoring, and returned 1.5 FTEs of engineering capacity to the security team.

About the organization

The firm provides brokerage, banking, advisory, and asset management services to millions of retail and institutional clients. It operates under SEC, FINRA, SOX, and GLBA oversight. Its workforce runs on a Microsoft and Salesforce estate built over several decades.

The challenge

Decades of growth produced a multi-forest Active Directory, more than 25,000 SharePoint sites, and file permissions managed by individual site administrators. The security team needed a reliable answer to a basic question: who can open a given document, and why.

  • Access far exceeded use. 50,000 users held standing access to confidential document repositories. Activity logs showed that 50 of them opened those files. Most SharePoint resources saw no activity in a typical month.
  • Leaver windows were hard to watch. Hundreds of employees and contractors leave each month. Reviewing their activity between HR termination and directory cutoff depended on spreadsheet exports and manual analysis.
  • Reviews lacked usage context. Managers certified access at very high volume with no data on whether people used it, so approvals defaulted to yes.
  • Scripts consumed engineering time. The equivalent of 1.5 full-time engineers wrote and ran log-analysis scripts that still covered only part of the application portfolio.

"Oleria gave us the clarity we had been chasing for years. Connecting permission paths to real activity across tens of thousands of SharePoint sites showed us exactly where access outran need, and it replaced script-heavy offboarding reviews with continuous, evidence-backed governance."

Managing Director, Identity and Access Management, Fortune 500 financial services firm

“People are really, really good at sharing things — but not so good at revoking those privileges once they’re no longer needed.”

Peter Clay
CISO, Aireon

The solution

The firm deployed Oleria across Microsoft Entra ID, SharePoint Online, and Salesforce. Oleria's Access Knowledge Graph maps every direct and inherited permission and pairs it with real user activity, so the team sees who has access, how they got it, and whether they use it.

  • Usage-aware access graph covering 30,000+ workforce identities and 25,000+ SharePoint sites, including inherited rights and anonymous sharing links.
  • Automated leaver monitoring that builds an activity timeline for each departing user and alerts security operations to unusual data access before final cutoff.
  • Usage-aware access reviews that show managers activity, peer comparisons, and HR status for every entitlement they certify.
  • Continuous posture checks that surface unmonitored applications connected to the identity provider, dormant accounts, stale admin credentials, and empty groups.

How the engagement ran

  • Aligned with executive stakeholders on the problem.
  • Scoped the highest-friction use cases.
  • Cleared the firm's internal security and governance review.
  • Connected Oleria and validated findings against production data, with three focus areas running in parallel.

Each focus area targeted a problem the team had already tried to solve with other tools or in-house scripts at this scale.

Business outcomes

The firm now governs access to sensitive data with evidence of use.

  • Exposure on confidential data quantified. The 50,000-to-50 finding gives the team the evidence to limit access to sensitive repositories to the people who use them.
  • Continuous leaver monitoring. Activity timelines cover hundreds of monthly departures and replace manual exports.
  • Audit evidence on demand. Access certifications now carry usage data that supports FINRA and SOX reviews.
  • Application sprawl under governance. Unmonitored IdP-connected applications, dormant admin accounts, and empty groups are visible and owned.

Key takeaways

  • Pairing permissions with activity turns access reviews into decisions backed by evidence.
  • Automated leaver timelines cover the window between HR termination and directory cutoff.
  • Usage data retires manual scripting and returns engineering time to security work.

“If you ask any CISO, ‘How many files have you shared outside the company?'. . . most don't have answers — or they don’t have easy ways to answer those questions. In Oleria, I can answer those questions with a click.”

Mark Carter
CIO and CISO
Vimeo

“Having visibility and the ability to remove that share or that file access...is a real differentiator.”

Kevin Towey
Director, Security GRCP
Vimeo

“Oleria allows our business to focus on driving revenue, and less on checking compliance boxes.”

Kevin Towey
Director, Security GRCP
Vimeo