Equals Group is a fast-scaling fintech spanning money management, payments and embedded payments for businesses.The company operates in a space defined by scale, speed, and regulatory pressure. When Railsr and Equals Money merged, they saw an opportunity: not just to unify systems, but to rethink access management entirely.

Equals Group is a fast-scaling fintech spanning money management, payments and embedded payments for businesses.The company operates in a space defined by scale, speed, and regulatory pressure. When Railsr and Equals Money merged, they saw an opportunity: not just to unify systems, but to rethink access management entirely.

Equals Group is a fast-scaling fintech spanning money management, payments and embedded payments for businesses.The company operates in a space defined by scale, speed, and regulatory pressure. When Railsr and Equals Money merged, they saw an opportunity: not just to unify systems, but to rethink access management entirely.

Working with Remitech, Equals Group rolled out C1, an identity governance and access automation platform, to take user lifecycle management from a manual, ticket-driven process to a connected, auditable system that scales with the business.

Working with Remitech, Equals Group rolled out C1, an identity governance and access automation platform, to take user lifecycle management from a manual, ticket-driven process to a connected, auditable system that scales with the business.

Working with Remitech, Equals Group rolled out C1, an identity governance and access automation platform, to take user lifecycle management from a manual, ticket-driven process to a connected, auditable system that scales with the business.

The Old Way: A Familiar Industry Pattern

The Old Way: A Familiar Industry Pattern

The Old Way: A Familiar Industry Pattern

Like most scaling businesses, Equals Group had grown up on a process built around tickets and manual approvals. A user would open a Jira ticket, select from an ever-expanding list of applications, and wait for approval (sometimes from two different reviewers) before someone in IT picked it up and granted access. In the best case, that meant adding the user to a group in Okta and letting SCIM (the standard for syncing user accounts to applications) push them into the app. In less ideal cases, it meant logging into the application's admin panel, sending an invite, waiting for the user to accept, then manually assigning a role.

It was a less than ideal User experience, with many new joiners spending their first day making sure they had the right access requirements. Off-boarding followed the same pattern in reverse, as Chris Yeo, who leads identity and access management at Equals Group, sums it up: 

"Manual, manual, manual is where we were… If it's manual going in, it's manual coming out." 
"Manual, manual, manual is where we were… If it's manual going in, it's manual coming out." 
"Manual, manual, manual is where we were… If it's manual going in, it's manual coming out." 

Why SSO alone wasn't enough

Why SSO alone wasn't enough

Why SSO alone wasn't enough

A common assumption is that putting everything behind single sign-on (SSO) and leaning on SCIM (the standard for syncing user accounts to apps) wherever possible is enough. The reality is messier. SSO handles authentication, but it doesn't manage the user lifecycle, meaning leavers can sit on active licences long after they've gone, and admin changes made directly inside an application stay invisible to the identity provider. SCIM helps, but as Chris puts it:

"SCIM is a standard, so everybody does it differently, and you have to pay for it."
"SCIM is a standard, so everybody does it differently, and you have to pay for it."
"SCIM is a standard, so everybody does it differently, and you have to pay for it."

Many vendors lock it behind their highest licence tiers (the so-called "SSO Tax").

That's where Remitech came in. As Equals Group's trusted software partner, Remitech had spent time listening to the team, to the friction in their day-to-day, and to where the business was heading after the merger. The lifecycle gap and the audit pressure weren't theoretical; they were lived problems for Chris and his team. Once those problems were properly understood, the recommendation followed: C1. Chosen because it solved the specific gap that SSO alone couldn't, and because it fitted how the team already worked.

What Changed with C1

What Changed with C1

What Changed with C1

C1 also sits alongside the company's other SaaS products and helps fill the gaps. Through native connectors, it talks directly to applications and understands their permission structures,  normalising everything into a clean model of resources, entitlements and grants.

For end users, access requests now flow through Slack or a clean web UI. Approvers are notified where they already work. Once approval lands, C1 provisions the access automatically, including in apps that historically required manual steps. Where a human genuinely needs to do something, C1 orchestrates the workflow,  assigning tasks to the right people, holding until they're complete, then resuming.

The Equals Group's engineering team where able to see the art of the possible with the functionality. They built custom connectors into one of their internal backend APIs, allowing a user requesting access to a role bundle that now triggers automated provisioning across both a third-party SaaS app and Equals Group's own systems; one request, one approval, one unified flow. As Chris puts it: "The connectors are the superpower of C1. That's where it really shines."

The unifying effect matters most against the backdrop of the merger. Two businesses, two onboarding processes, two ways of granting access, collapsed into one. "It's like a unifying force," Chris says. "It's integral, especially when you're thinking about M&A."

Time-limited access is now standard for sensitive entitlements. Someone in accounts payable who needs to pull AWS billing reports once a month requests the specific role, gets it instantly, uses it, and C1 automatically takes it away again. As Chris describes it: "Zero touch for us. The user requests it, and because we know why they want it, we don't even bother approving it."

The Business Impact

The Business Impact

The Business Impact

The processes were implemented successfully, but the real value came when they reviewed their progress. In a concentrated push of activity through the second half of 2025:

1

1

1

Just under 2,000 access requests granted
Just under 2,000 access requests granted

2

2

2

231 auto-approved, nearly all auto-provisioned
231 auto-approved, nearly all auto-provisioned
231 auto-approved, nearly all auto-provisioned

3

3

3

Over 1,000 access revocations, all auto-approved and auto-provisioned (driven by HR system feeds for leavers)
Over 1,000 access revocations, all auto-approved and auto-provisioned (driven by HR system feeds for leavers)
Over 1,000 access revocations, all auto-approved and auto-provisioned (driven by HR system feeds for leavers)

4

4

4

1,115 hours saved through automation — the equivalent of 28 full working weeks
1,115 hours saved through automation — the equivalent of 28 full working weeks
1,115 hours saved through automation — the equivalent of 28 full working weeks

Hours saved are the headline, but the deeper shift is a gained confidence in audit posture. With the new automated system every grant and every revocation creates a task, every task is logged. So when an auditor walks in and asks the question they always ask, the answer exists. In the old world of manual actions and heightened potential of human error, that was a moment of genuine risk. In the new world, it's a search.

Hours saved are the headline, but the deeper shift is a gained confidence in audit posture. With the new automated system every grant and every revocation creates a task, every task is logged. So when an auditor walks in and asks the question they always ask, the answer exists. In the old world of manual actions and heightened potential of human error, that was a moment of genuine risk. In the new world, it's a search.

The stakes for a regulated fintech are real. "If they feel it's egregious enough, they might just fail you," Chris notes. "And then you're not ISO accredited, and then people won't do business with you." Reliable evidence trails aren't a nice-to-have, they protect the certifications that win and keep enterprise customers.

The success has been visible enough internally that it's reshaping how Equals Group buys software. The procurement bar has moved with it. Where the question used to be "does this tool support SSO?", it's now "does it have a good API? Does it support SCIM at a sensible tier? Does it work properly with C1?" Vendors who hide provisioning behind premium tiers no longer get a free pass.

The Ongoing Development

The Ongoing Development

The Ongoing Development

C1 is now positioned as the central nervous system for identity at Equals Group. The team is rolling out time-limited access for IT itself, exploring C1's new Actions feature (which lets users trigger system changes through approved automations rather than carrying standing admin rights), and extending custom connectors into more internal systems.

C1 is now positioned as the central nervous system for identity at Equals Group. The team is rolling out time-limited access for IT itself, exploring C1's new Actions feature (which lets users trigger system changes through approved automations rather than carrying standing admin rights), and extending custom connectors into more internal systems.

The direction of travel is clear: less standing access, more zero-touch automation, and a single, auditable place where access happens.

The direction of travel is clear: less standing access, more zero-touch automation, and a single, auditable place where access happens.

Ready to Reclaim Hours Lost to Manual Access Management?

Ready to Reclaim Hours Lost to Manual Access Management?

Ready to Reclaim Hours Lost to Manual Access Management?