ICA • Manufacturing Sector
Plant floor and corporate IT are two different access worlds with two different sets of owners. ICA maps both in one structured discovery — before the implementation team writes a single policy.
Let's Talk Manufacturing IAM DiscoveryThe Uncomfortable Math
The Case
Manufacturing is the sector where identity governance meets physics. An access decision that is merely inconvenient in a bank can stop a production line, spoil a batch, or trip a safety system. That changes what the requirements phase has to establish, and it is why manufacturing discovery cannot be run from the same template as a financial services engagement.
The core difficulty is that a plant runs two estates that were never designed to share an identity model. Corporate IT has ERP, PLM and email, with named users and conventional joiner-mover-leaver processes. The plant floor has SCADA, HMI consoles, MES, historians and PLCs — often shared logins by design, because an operator cannot badge in mid-process, and some of that equipment predates modern authentication entirely. A twenty-year-old controller will not speak SAML no matter how good your IGA platform is.
Layer onto that a workforce that does not look like an office. Three shifts with handoffs. Seasonal and temporary labor. Contractors and OEM engineers who need remote access to specific machinery, sometimes urgently, sometimes from another continent. Multi-plant groups where every site grew its own naming conventions, and acquisitions that arrived with an identity estate nobody has fully mapped. Vendor remote access into operational technology is now one of the most scrutinized paths in the sector, and it is exactly the path least likely to be documented before discovery starts.
When that discovery takes 12 weeks, the cost is not only the consulting spend. It is a plant running on shared credentials for another quarter, an audit finding that was foreseeable, and an implementation scoped against an incomplete picture of who actually needs access to what. ICA structures the discovery in under 10 days, capturing IT and OT access requirements in one process rather than two disconnected workstreams — so the requirements document your integrator receives reflects the plant as it actually runs.
Regulatory Context
Every framework below touches identity and access governance in an industrial environment. These are the mandates ICA discovery maps against.
The governing security standard for industrial automation and control systems — the framework most OT identity requirements are ultimately justified against.
System security requirements. FR 1 (identification and authentication control) and FR 2 (use control) are where account, credential and authorization requirements are specified.
The PR.AA function — identity management, authentication and access control — is the common language most manufacturing security programs report against.
Guide to operational technology security. Sets the expectations for access control in environments where availability and safety outrank confidentiality.
Annex A controls for access control, identity management and access rights — the certification most multinational manufacturers are already carrying.
For the defense supply chain. Access control is the largest control family in 800-171, and evidence of it is what an assessment actually examines.
Use Cases
GSI Partners
GSIs running IAM programs across multi-plant manufacturing groups use ICA to compress discovery that would otherwise be repeated site by site — capturing plant-level variation once, in a structure the implementation team can act on.
Boutique Specialists
OT security specialists bridging the plant floor and corporate IT use ICA to run one discovery across both domains, so shared HMI accounts, vendor remote access and legacy controller constraints are documented as requirements rather than discovered during cutover.
End Client
Manufacturers evaluating IGA platforms under audit or customer-security pressure need a requirements baseline before vendor selection — one that accounts for equipment that cannot be changed and shifts that cannot be interrupted.
If you lead an identity practice serving manufacturers, industrial groups or operational technology environments, I would like 30 minutes to show you how ICA fits your delivery model.
Got it.
I will be in touch within 24 hours.
— Bill Leonard
API & Integrations
Pull results, retrieve answers, and push to ServiceNow — all via REST API.