A global streaming company unifies 320,000+ identities and 12,000+ SaaS apps in one access graph
12,000+ SaaS applications. Three kinds of identity. No correlation between them. Oleria linked every employee, contractor, and production partner account to one verified person, assigned owners to 75%+ of unowned accounts, and replaced standing admin access with just-in-time access.

Watch video
320,000+
Identities correlated
Workforce and partner accounts linked to verified people in one access graph
12,000+
SaaS apps mapped
OAuth grants and scopes categorized by data sensitivity and risk
75%+
Owner attribution
Previously unowned service accounts, test accounts, and groups now have an accountable owner
Industry
Media and entertainment
Use Cases
Multi-domain identity correlation
OAuth and SaaS governance
NHI ownership
Just-in-time privileged access
Size
~21,000 employees and contractors
300,000+ external partner identities
About the organization
The company produces and distributes original series, films, and documentaries to a global subscriber base. Its cloud-first, decentralized engineering culture built much of its identity infrastructure in house. Its productions depend on hundreds of thousands of external creative partners, agencies, and studio contractors.
The challenge
Identity lived in three populations with separate rules for provisioning, sponsorship, and offboarding: employees, contingent workers, and several hundred thousand production partners. A decade of in-house innovation added a custom identity store, an internal policy engine that makes 50 million access decisions a day, and home-grown partner onboarding, all running alongside commercial identity providers.
- Disconnected identity records. One person often held several unlinked accounts across Okta, Google Workspace, the custom IdP, and legacy production systems. Basic hygiene and blast-radius questions took weeks of cross-team data stitching.
- SaaS and OAuth sprawl. Between 12,000 and 15,000 SaaS applications were active. Users authorized third-party OAuth apps with corporate credentials, granting vendors access to company data outside the security team's view.
- Standing privileged access. Persistent admin accounts and custom admin roles were difficult to monitor, measure, and audit.
- Unowned non-human identities. Service accounts, test accounts, and Google Workspace groups accumulated over years of growth without a verified human owner.
"Oleria unified our employees, contractors, and global partner ecosystem into a single, correlated identity view. Mapping real activity to resource-level access across thousands of SaaS apps closed our shadow IT blind spots and brought accountability to our entire identity footprint."
Director of Identity and Access Engineering, global streaming company
“People are really, really good at sharing things — but not so good at revoking those privileges once they’re no longer needed.”

The solution
Oleria built one Access Knowledge Graph that correlates every human and non-human identity across commercial identity providers, internal systems, and partner databases.
- Multi-domain identity correlation links every account held by an employee, contractor, or studio partner to one verified person.
- SaaS and OAuth scope mapping ingests permissions and grants across 12,000+ applications and categorizes third-party scopes by data sensitivity and risk.
- Non-human identity owner mapping discovers service accounts, test accounts, and groups, then assigns an accountable human owner.
- Just-in-time privileged access through Oleria Access Requests replaces persistent admin access with time-bound authorization across core cloud infrastructure and SaaS applications.
- Activity normalization compares assigned entitlements with real use to surface dormant accounts and privileged exceptions as they appear.
Business outcomes
The company now sees every person, every account, and every app grant in one governed view.
- One person, one identity. 21,000 workforce identities and 300,000+ partner accounts sit in a single access graph, so hygiene and blast-radius questions are answered from one source.
- Accountability for non-human identities. 75%+ of previously unowned service accounts, test accounts, and Google Workspace groups have a named owner.
- OAuth risk under control. High-risk third-party grants across 12,000+ SaaS apps are visible and governable.
- Lower privileged risk. Standing admin access is replaced by just-in-time, time-bound access.
- Policy decisions grounded in activity. Oleria's activity intelligence informs how the team tunes the rules in its internal policy engine.
Key takeaways
- Correlating identities to one person is the foundation for every other governance control at partner-ecosystem scale.
- OAuth grants are access, and they need the same governance as directory entitlements.
- Owner attribution and just-in-time access shrink the standing risk that non-human and admin accounts carry.
“If you ask any CISO, ‘How many files have you shared outside the company?'. . . most don't have answers — or they don’t have easy ways to answer those questions. In Oleria, I can answer those questions with a click.”
.avif)
Vimeo
“Having visibility and the ability to remove that share or that file access...is a real differentiator.”
.avif)
Vimeo
“Oleria allows our business to focus on driving revenue, and less on checking compliance boxes.”
.avif)
Vimeo