Trending Topics

What ASDA can teach your business about unmanaged identities
High staff turnover, seasonal workers and sprawling supply chains can leave forgotten accounts behind. ASDA shows how businesses can stop them becoming a security risk
Retailers are used to people coming and going, but their system access doesn’t always leave with them.
That creates a problem that is easy to underestimate. A former employee, Christmas temp, or contractor whose account remains active isn’t simply a messy entry in an IT system. If those credentials fall into the wrong hands, they can provide an attacker with legitimate access to the business.
“Active accounts belonging to former staff present an open door to your network,” says Dray Agha, Senior Manager of Security Operations at Huntress. “Attackers actively scan for these dormant identities to bypass perimeter defences completely.”
The challenge is particularly acute in retail. Seasonal hiring can mean bringing large numbers of people into the business quickly, while high staff turnover creates an equally pressing need to remove access at the other end. Add employees changing roles, contractors, suppliers and other third parties, and keeping track of who should have access to what becomes considerably harder.
ASDA offers a useful example of how retailers can tackle the problem – and why fixing it involves more than periodically hunting for old accounts.
When the employee leaves but the account doesn’t
The problem often starts with how many systems an employee touches.
“Large companies often use dozens of disconnected systems that do not speak directly to HR databases,” Agha says. “When an employee leaves a company, their core network access might be revoked immediately while individual cloud application accounts are forgotten.”
The danger is that nobody needs to notice the account is still there until someone else starts using it. Credentials can be stolen through phishing or infostealer malware, or turn up in data leaked elsewhere. And if the account belongs to someone who left months ago, there may be nobody around to spot that something looks wrong.
Attackers prize these dormant identities precisely because activity involving a legitimate user account may be harder to distinguish from normal behaviour.
The obvious answer is to keep a close record of every account. In practice, doing that manually becomes increasingly difficult as an organisation grows.
“Spreadsheets become outdated the moment they are saved,” Agha says. “This creates a compliance risk during audits and guarantees that some accounts will remain active long after the employee departs.”
The experience of other large retailers illustrates the scale of that problem. Currys, for example, previously used Excel files and manual account creation as part of its identity processes. Identity governance specialists SailPoint say that provisioning a user could take a day or more, while creating new accounts by copying existing ones had resulted in employees accumulating more access than they needed.
ASDA had a chance to start again
For ASDA, the catalyst for rethinking identity came when the supermarket separated from former parent Walmart.
The retailer needed to establish its own identity architecture for a workforce of 138,000 people, including short-term employees to handle seasonal peaks. ASDA used the separation as an opportunity to rethink how it created and managed identities.
“As a CISO, what I care most about is any security risks to the business,” says Simon Langley, Chief Information Security Officer at ASDA. “Cyber incidents and data breaches are a big concern, but so is identity. There are some areas of our business where we have a really high turnover of staff, for instance, over Christmas we take on thousands of short-term workers.”
He adds that it could previously take “up to a week to give them an identity on our systems… So, we need to efficiently onboard people to make sure people quickly have the correct access rights.”
Langley turned to a third party for help. “We looked at SailPoint Identity Security Cloud as a potential tool and realised that it fit perfectly with ASDA’s new infrastructure,” he says.
New starters need access quickly enough to do the job they were hired for, but that access also needs to disappear when they leave. Between those two points, permissions should change as people move around the business.
This is the principle behind a joiner, mover and leaver, or JML, process. Done properly, somebody joining the company receives access appropriate to their role; somebody moving jobs has their permissions adjusted rather than simply collecting new ones; and somebody leaving has access withdrawn.
For ASDA, SailPoint became the identity security layer underpinning that process. Its central architecture now manages access for those 138,000 employees, including seasonal workers.
The wider lesson isn’t simply to automate account creation. It’s to establish a reliable source of identity data and connect changes in somebody’s employment status to changes in their access.
“A secure JML process hinges on a single source of truth for identity data,” Agha says. “Access rights must be granted based on specific job roles and revoked automatically the moment an employment status changes.”
Retail identity in the AI era
Retailers face unique identity challenges, from seasonal hiring and high staff turnover to third-party access and complex technology environments. Retail Identity in the AI Era explores how retailers can automate identity management, right-size access, govern external identities, and simplify compliance across the business.
Download the white paper to strengthen identity security and turn it into a competitive advantage.
Don’t forget the people who aren’t employees
Even a well-designed JML process can develop a sizeable blind spot: people who never appear in the HR system in the first place.
Retailers depend on contractors, suppliers, logistics companies and other outside organisations whose staff may need access to internal applications and data. Yet the usual trigger for removing access – an employee leaving the company – may never arrive.
“IT teams rarely receive automated alerts when a contractor finishes their project,” Agha says. “This creates a blind spot where supply chain partners retain access to sensitive systems indefinitely.”
ASDA faced exactly this issue. Alongside its employee population, the retailer has around 6,000 contractors who require access but sit outside its standard HR processes. It brought those users into a governed identity process using SailPoint’s Non-Employee Risk Management product. “Today, all of these people are now logged into Workday, integrated with SailPoint, and SailPoint ServiceNow for request management and more,” says Langley.
The distinction between employees and contractors is important. Companies need to know not only which accounts exist, but who is responsible for them. Contractor access should have an owner, a reason for existing and, where appropriate, an end date. Otherwise today’s legitimate supplier account can quietly become tomorrow’s ghost identity.
Automation helps, but it needs good data
Once you’re dealing with thousands of staff, keeping on top of all those changes by hand gets messy fast. Automation takes some of that work away, updating access as people join the business, change jobs or leave. Access reviews provide another check, helping pick up outdated permissions.
There are tangible benefits beyond security. SailPoint says Specsavers recovered 2,000 Microsoft 365 licences associated with duplicate accounts and people who had left after cleaning up its identity data.
But automation isn’t a substitute for getting the underlying process right.
“Overly aggressive automation can cause costly business disruptions,” Agha warns. “An incorrect entry in an HR database might automatically lock a legitimate user out of critical systems.”
For organisations wondering where to begin, that makes existing ghost accounts a useful starting point. Agha recommends comparing active accounts with current employment records, investigating discrepancies and putting processes in place that tie future access to employment or contract status.
The goal isn’t simply to delete old accounts faster. It’s to stop them becoming forgotten in the first place.

