Free Shadow IT Report: Better SaaS management starts with discovering what apps are connected to your workspace.Scan Now

stitchflow
IconCase studies

High-Dollar Manual User Access Reviews: A Thing of the Past

Company size:1000+ employees
Industry:Cloud Infrastructure / Web Hosting
Compliance Framework:PCI DSS
Quote

Instead of chasing app owners and wrestling with spreadsheets each quarter, we now review access in minutes with Stitchflow. The process practically runs itself, and nothing falls through the cracks.

Matt Straka

Matt Straka

Director of IT, Vercel

The challenge: Quarterly reviews that drained time, budget, and trust

As a leading platform for front-end development and hosting, Vercel manages over 100 SaaS apps and is held to strict PCI DSS compliance standards. But their quarterly access reviews were anything but streamlined.

Each cycle pulled in 50+ stakeholders across Finance, IT, Security, and the line of business owners, yet the process was slow, manual, and high-risk:

  • Access reviews were tracked in Notion, with IT chasing follow-ups
  • CSVs were exported and compared manually against Okta data
  • Excel VLOOKUPs were used to find ex-employees and outdated access
  • Escalations were common, reporting was fragmented, and teams were frustrated

What should’ve been a repeatable, controlled process instead consumed weeks of senior team time, introduced audit risk, and relied on disconnected tools and outdated workflows.

The solution: Okta anchored identity. Stitchflow automated everything else.

Okta remained Vercel’s core identity platform, managing SSO and lifecycle for primary apps. But identity coverage stopped at the edge of what was SCIM- or SSO-enabled.

That left dozens of tools, especially CSV-based apps, shadow IT, and systems outside of automated provisioning, outside Okta’s perimeter, forcing IT to track access manually across spreadsheets and Notion.

Stitchflow filled this gap by continuously auditing 100+ apps (connected and disconnected), mapping them to Vercel’s access policies, and identifying risks that would’ve been missed:

What Stitchflow enabled:

  • Automated reminders to app owners, eliminating manual follow-ups
  • Live account status (deactivated in Okta, hidden, inactive > 90 days)
  • Shared review boards with full context; no spreadsheets, or Notion docs
  • Auditable logs and approval records, ready for PCI DSS audits at any time
Access reviews cut
from weeks to hours

across 100+ SaaS apps, dramatically reducing compliance overhead

Audit-ready at all times

with full approval trails, app context, and historical access logs

Zero spreadsheets or VLOOKUPs

with all reviews centralized in Stitchflow’s live dashboards

50+stakeholders unblocked

from manual reviews, follow-ups, and spreadsheet escalations

2 FTE of ITand Compliance time freed up

from quarterly audit prep, coordination, and reporting

The outcome

With Stitchflow, Vercel turned a painful, spreadsheet-driven audit process into a continuous, automated review system, one that spans both managed and disconnected apps.

No more scrambling at the end of the quarter. No more missed users. No more high-cost access reviews.

Stitchflow gave Vercel real access governance without manual effort.

More stories