The enterprise extends past the company
Design partners, contract manufacturers, maintenance crews, logistics providers. A meaningful share of the people using your systems are employed by somebody else, under a contract with an end date.
Both industries run an extended enterprise — tiers of suppliers, dealers, contractors — and a workforce that mostly does not sit at a desk. Identity programmes designed for the office reach the factory gate and stop.
Enough that the same platform serves both, and enough differences that the same configuration never does.
Design partners, contract manufacturers, maintenance crews, logistics providers. A meaningful share of the people using your systems are employed by somebody else, under a contract with an end date.
Line operators, technicians, drivers, field service. They authenticate in gloves, in noise, in a hurry, often on a device that is not theirs and sometimes on one bolted to a wall.
Controllers, robots, test rigs, telematics units, integration accounts. Each needs credentials, almost none has a lifecycle, and the ones installed a decade ago were configured by somebody who has since retired.
The relationship is not between two parties. Your engineering data, your parts catalogue and your warranty systems descend through tiers you contract with, and tiers you do not.
A service network of hundreds of independent businesses hires and loses staff constantly. Nobody notifies the manufacturer, so accounts survive the people who held them unless the partner administers their own.
Design files shared with a tier-one partner for a programme that ended two years ago are the most valuable thing on the network, and the least likely to have had its access reviewed.
Connected cars, telematics units and service tools all authenticate to back-end services. They have long lifecycles, no user, and a credential rotation story that has to work over the air.
Every one of these is true in the office, which is why office-designed identity reaches the factory gate and stops. Read the right column: that is the actual requirement.
None of this argues for weaker authentication in production. It argues for authentication designed against the constraints that actually exist there.
The same identity, reaching the same system, can face a badge tap at a shared terminal and a passkey from a laptop. What is asked is a branch on the canvas, not a global policy.
Each organisation gets its own domain and its own administrator, inside limits you define — because you cannot maintain a list of who works at four hundred independent businesses.
Service accounts, controllers and integration credentials are collected, owned and reviewed like everything else, rather than living outside governance because they always have.
The shared one, with the badge reader that half works. It is usually the most honest test of an identity design.
Talk to an expert