Practitioner's guide to the future of identity — new maturity model
Access the guide

A global streaming company unifies 320,000+ identities and 12,000+ SaaS apps in one access graph

12,000+ SaaS applications. Three kinds of identity. No correlation between them. Oleria linked every employee, contractor, and production partner account to one verified person, assigned owners to 75%+ of unowned accounts, and replaced standing admin access with just-in-time access.

Watch video

320,000+

Identities correlated

Workforce and partner accounts linked to verified people in one access graph

12,000+

SaaS apps mapped

OAuth grants and scopes categorized by data sensitivity and risk

75%+

Owner attribution

Previously unowned service accounts, test accounts, and groups now have an accountable owner

Industry

Media and entertainment

Use Cases

Multi-domain identity correlation

OAuth and SaaS governance

NHI ownership

Just-in-time privileged access

Size

~21,000 employees and contractors

300,000+ external partner identities

About the organization

The company produces and distributes original series, films, and documentaries to a global subscriber base. Its cloud-first, decentralized engineering culture built much of its identity infrastructure in house. Its productions depend on hundreds of thousands of external creative partners, agencies, and studio contractors.

The challenge

Identity lived in three populations with separate rules for provisioning, sponsorship, and offboarding: employees, contingent workers, and several hundred thousand production partners. A decade of in-house innovation added a custom identity store, an internal policy engine that makes 50 million access decisions a day, and home-grown partner onboarding, all running alongside commercial identity providers.

  • Disconnected identity records. One person often held several unlinked accounts across Okta, Google Workspace, the custom IdP, and legacy production systems. Basic hygiene and blast-radius questions took weeks of cross-team data stitching.
  • SaaS and OAuth sprawl. Between 12,000 and 15,000 SaaS applications were active. Users authorized third-party OAuth apps with corporate credentials, granting vendors access to company data outside the security team's view.
  • Standing privileged access. Persistent admin accounts and custom admin roles were difficult to monitor, measure, and audit.
  • Unowned non-human identities. Service accounts, test accounts, and Google Workspace groups accumulated over years of growth without a verified human owner.

"Oleria unified our employees, contractors, and global partner ecosystem into a single, correlated identity view. Mapping real activity to resource-level access across thousands of SaaS apps closed our shadow IT blind spots and brought accountability to our entire identity footprint."

Director of Identity and Access Engineering, global streaming company

“People are really, really good at sharing things — but not so good at revoking those privileges once they’re no longer needed.”

Peter Clay
CISO, Aireon

The solution

Oleria built one Access Knowledge Graph that correlates every human and non-human identity across commercial identity providers, internal systems, and partner databases.

  • Multi-domain identity correlation links every account held by an employee, contractor, or studio partner to one verified person.
  • SaaS and OAuth scope mapping ingests permissions and grants across 12,000+ applications and categorizes third-party scopes by data sensitivity and risk.
  • Non-human identity owner mapping discovers service accounts, test accounts, and groups, then assigns an accountable human owner.
  • Just-in-time privileged access through Oleria Access Requests replaces persistent admin access with time-bound authorization across core cloud infrastructure and SaaS applications.
  • Activity normalization compares assigned entitlements with real use to surface dormant accounts and privileged exceptions as they appear.

Business outcomes

The company now sees every person, every account, and every app grant in one governed view.

  • One person, one identity. 21,000 workforce identities and 300,000+ partner accounts sit in a single access graph, so hygiene and blast-radius questions are answered from one source.
  • Accountability for non-human identities. 75%+ of previously unowned service accounts, test accounts, and Google Workspace groups have a named owner.
  • OAuth risk under control. High-risk third-party grants across 12,000+ SaaS apps are visible and governable.
  • Lower privileged risk. Standing admin access is replaced by just-in-time, time-bound access.
  • Policy decisions grounded in activity. Oleria's activity intelligence informs how the team tunes the rules in its internal policy engine.

Key takeaways

  • Correlating identities to one person is the foundation for every other governance control at partner-ecosystem scale.
  • OAuth grants are access, and they need the same governance as directory entitlements.
  • Owner attribution and just-in-time access shrink the standing risk that non-human and admin accounts carry.

“If you ask any CISO, ‘How many files have you shared outside the company?'. . . most don't have answers — or they don’t have easy ways to answer those questions. In Oleria, I can answer those questions with a click.”

Mark Carter
CIO and CISO
Vimeo

“Having visibility and the ability to remove that share or that file access...is a real differentiator.”

Kevin Towey
Director, Security GRCP
Vimeo

“Oleria allows our business to focus on driving revenue, and less on checking compliance boxes.”

Kevin Towey
Director, Security GRCP
Vimeo