Please use this identifier to cite or link to this item: https://hdl.handle.net/10419/342433 
Year of Publication: 
2026
Series/Report no.: 
IUCF Working Paper No. 7/2026
Publisher: 
ZBW - Leibniz Information Centre for Economics, Kiel, Hamburg
Abstract: 
Identity Access Management has become a strategic capability for growing medium-sized companies. As organizations expand, collaborate with external partners and operate across multiple digital systems, access rights must be managed in a transparent, secure and scalable manner. This paper outlines how a role-based authorization model can reduce complexity and improve governance across Microsoft 365, HR tools, and project controlling, CRM and finance applications. The proposed model is based on Role-Based Access Control and combines baseline roles, functional roles and temporary project roles. This modular structure supports least-privilege access, improves auditability and enables automated Joiner-Mover-Leaver processes. The paper further discusses stakeholder involvement, governance responsibilities, compliance requirements and the economic value of standardized access management. The findings show that a business-oriented role model is not merely a technical instrument but a strategic enabler for secure growth, operational efficiency and sustainable digital governance.
Abstract (Translated): 
Identity Access Management gewinnt für mittelständische Unternehmen zunehmend strategische Bedeutung. Mit wachsender Organisation, internationaler Zusammenarbeit, projektbasierten Arbeitsformen und einer heterogenen Systemlandschaft steigt die Komplexität der Zugriffssteuerung erheblich. Zugänge zu Microsoft 365, HR-Tools sowie Projektcontrolling-, CRM- und Finanzbuchhaltungs-Anwendungen müssen nicht nur effizient vergeben, sondern auch nachvollziehbar dokumentiert, regelmäßig überprüft und bei Rollenwechseln oder Austritten zuverlässig entzogen werden. Im Fokus steht ein rollenbasiertes Berechtigungsmodell auf Basis von Role-Based Access Control (RBAC), das Transparenz, Sicherheit und Skalierbarkeit im Identity Access Management mittelständischer Unternehmen unterstützt. Das Modell folgt einer dreistufigen Rollenarchitektur aus Basisrollen, Funktionsrollen und Zusatz- beziehungsweise Projektrollen. Es ermöglicht, Berechtigungen aus der tatsächlichen Funktion einer Person abzuleiten, statt sie individuell und historisch gewachsen zu vergeben. Neben Governance-Prinzipien wie Least Privilege und Segregation of Duties werden ein methodisches Vorgehen zur Rollenentwicklung, die Einbindung relevanter Stakeholder, Automatisierungspotenziale im Joiner-Mover-Leaver-Prozess sowie Compliance- und Audit-Aspekte dargestellt. Abschließend werden wirtschaftliche Nutzenpotenziale und typische Einführungsrisiken eingeordnet.
Subjects: 
Identity Access Management
Rollenmodellierung
Role-Based Access Control
Governance
Risikomanagement
Kapitalkosten
JEL: 
G0
G30
Document Type: 
Working Paper

Files in This Item:
File
Size





Items in EconStor are protected by copyright, with all rights reserved, unless otherwise indicated.