Moving 400+ Vendor Resources Into a New Access Model
Within four months, more than 400 vendor resources were migrated into six job-function groups in a work-from-home environment. The change was designed to bring role structure and access governance closer together without losing operational continuity.
This was a people change, an access-control change and an operating-model change at the same time.
The program had a large vendor workforce working remotely, and access needed to be better aligned with the work people were actually doing.
I led the migration into six structured job-function groups and worked with Risk teams on the access-governance side of the change.
The migration had to be completed at scale without interrupting day-to-day work.
More than 400 people
A change affecting hundreds of resources creates coordination risk even before the technology or access questions begin.
Role-to-access alignment
The new grouping had to make sense operationally and support more appropriate access control.
Remote environment
Work-from-home operations increased the importance of getting access governance right.
Four-month window
The work needed clear sequencing and ownership to move a large population within a defined period.
I led the migration and coordinated the people, operations and risk conversations around it.
My role covered migration planning and execution across 400+ vendor resources, while working with risk and operational stakeholders so the new job-function structure could be implemented in a controlled way.
Treat the migration as an operating change, not a bulk access exercise.
Defined the target grouping
Organised the workforce into six job-function groups so the operating structure was clearer and access could be aligned more closely to role needs.
Planned the migration in manageable stages
Coordinated the movement of 400+ resources over a four-month period rather than treating it as one administrative event.
Worked with Risk on access requirements
Partnered with risk stakeholders to keep access management secure and compliant across vendor operations.
Moved the new model into business-as-usual
Supported the transition so the job-function structure could continue to work after the migration itself was complete.
The important trade-off was pace versus control.
Migration planning had to account for operational continuity while role and access changes were being made.
The six-group model provided a clearer basis for aligning people to job functions.
Risk stakeholders were involved in the access-governance design and implementation.
Breaking the work into a managed migration made a large population change easier to coordinate.
The new structure needed to become part of ongoing vendor operations, not end with the migration date.
No single team could complete the change on its own.
Program, vendor, workforce and risk stakeholders all had a different part of the answer. My role was to keep the migration moving while making sure those dependencies were dealt with before they became blockers.
More than 400 resources moved into six structured groups within four months.
The practical lesson was that access governance works better when it starts with the job people are meant to do. Cleaning up permissions without fixing the role structure underneath usually means the same problem comes back.
Some operational detail and internal terminology have been generalised to respect organisational confidentiality.