140-Entity Tenant Collapse Post Go-Live
HCM / Security / Business Process Architecture
- Security groups structured around implementation team convenience, not data access requirements. 140 entities sharing 4 parent security groups, producing cascading over-permission events.
- Business Process routing logic bypassed via hardcoded condition rules to meet go-live date, leaving 23 BPs in non-standard states invisible to standard admin review.
- No documentation of tenant configuration decisions. Zero change register provided at go-live handoff.
- Integration Suite ISUs granted System Admin-equivalent permissions — a SOX control exposure that had not yet surfaced to the client's audit team.
- Full security group redesign across 140 entities — Principle of Least Privilege applied by domain, sub-domain, and reporting line. Entity-level data segregation enforced in HCM and Financials.
- All 23 Business Processes reconstructed from ground zero against the client's actual approval authority matrix. Condition rules replaced with proper branching logic.
- Complete Change Register delivered. Tenant Configuration Baseline document produced for future audit reference.
- ISU permissions scoped to minimum required functional domains. SOX exposure remediated and documented for external audit team.
within 90 days
to standard
recovery timeline
pre-audit