← All Case Studies
WORKFORCE & ACCESS TRANSFORMATION

Moving 400+ Vendor Resources Into a New Access Model

Within four months, more than 400 vendor resources were migrated into six job-function groups in a work-from-home environment. The change was designed to bring role structure and access governance closer together without losing operational continuity.

400+ Vendor resources
6 Job-function groups
4 Months Migration timeline
CONTEXT

This was a people change, an access-control change and an operating-model change at the same time.

The program had a large vendor workforce working remotely, and access needed to be better aligned with the work people were actually doing.

I led the migration into six structured job-function groups and worked with Risk teams on the access-governance side of the change.

THE CHALLENGE

The migration had to be completed at scale without interrupting day-to-day work.

01

More than 400 people

A change affecting hundreds of resources creates coordination risk even before the technology or access questions begin.

02

Role-to-access alignment

The new grouping had to make sense operationally and support more appropriate access control.

03

Remote environment

Work-from-home operations increased the importance of getting access governance right.

04

Four-month window

The work needed clear sequencing and ownership to move a large population within a defined period.

MY ROLE

I led the migration and coordinated the people, operations and risk conversations around it.

My role covered migration planning and execution across 400+ vendor resources, while working with risk and operational stakeholders so the new job-function structure could be implemented in a controlled way.

Workforce Migration Access Governance Risk Alignment Vendor Operations Change Coordination Program Delivery
WHAT I DID

Treat the migration as an operating change, not a bulk access exercise.

01

Defined the target grouping

Organised the workforce into six job-function groups so the operating structure was clearer and access could be aligned more closely to role needs.

02

Planned the migration in manageable stages

Coordinated the movement of 400+ resources over a four-month period rather than treating it as one administrative event.

03

Worked with Risk on access requirements

Partnered with risk stakeholders to keep access management secure and compliant across vendor operations.

04

Moved the new model into business-as-usual

Supported the transition so the job-function structure could continue to work after the migration itself was complete.

RISKS & TRADE-OFFS

The important trade-off was pace versus control.

Area How I approached it
Access disruption

Migration planning had to account for operational continuity while role and access changes were being made.

Incorrect role mapping

The six-group model provided a clearer basis for aligning people to job functions.

Compliance exposure

Risk stakeholders were involved in the access-governance design and implementation.

Change fatigue

Breaking the work into a managed migration made a large population change easier to coordinate.

Inconsistent adoption

The new structure needed to become part of ongoing vendor operations, not end with the migration date.

WORKING WITH STAKEHOLDERS

No single team could complete the change on its own.

Program, vendor, workforce and risk stakeholders all had a different part of the answer. My role was to keep the migration moving while making sure those dependencies were dealt with before they became blockers.

Program Leadership Risk Teams Vendor Operations Workforce Stakeholders 400+ Resources
RESULTS

More than 400 resources moved into six structured groups within four months.

400+ Resources migrated
6 Job-function groups
4 Months Migration timeline
WFH Operating environment
Clearer Role Structure Access Governance Risk Alignment Controlled Migration Operational Continuity
WHAT I TOOK FROM IT
The practical lesson was that access governance works better when it starts with the job people are meant to do. Cleaning up permissions without fixing the role structure underneath usually means the same problem comes back.

Some operational detail and internal terminology have been generalised to respect organisational confidentiality.