Like most scaling businesses, Equals Group had grown up on a process built around tickets and manual approvals. A user would open a Jira ticket, select from an ever-expanding list of applications, and wait for approval (sometimes from two different reviewers) before someone in IT picked it up and granted access. In the best case, that meant adding the user to a group in Okta and letting SCIM (the standard for syncing user accounts to applications) push them into the app. In less ideal cases, it meant logging into the application's admin panel, sending an invite, waiting for the user to accept, then manually assigning a role.
It was a less than ideal User experience, with many new joiners spending their first day making sure they had the right access requirements. Off-boarding followed the same pattern in reverse, as Chris Yeo, who leads identity and access management at Equals Group, sums it up:
A common assumption is that putting everything behind single sign-on (SSO) and leaning on SCIM (the standard for syncing user accounts to apps) wherever possible is enough. The reality is messier. SSO handles authentication, but it doesn't manage the user lifecycle, meaning leavers can sit on active licences long after they've gone, and admin changes made directly inside an application stay invisible to the identity provider. SCIM helps, but as Chris puts it:
Many vendors lock it behind their highest licence tiers (the so-called "SSO Tax").
That's where Remitech came in. As Equals Group's trusted software partner, Remitech had spent time listening to the team, to the friction in their day-to-day, and to where the business was heading after the merger. The lifecycle gap and the audit pressure weren't theoretical; they were lived problems for Chris and his team. Once those problems were properly understood, the recommendation followed: C1. Chosen because it solved the specific gap that SSO alone couldn't, and because it fitted how the team already worked.
C1 also sits alongside the company's other SaaS products and helps fill the gaps. Through native connectors, it talks directly to applications and understands their permission structures, normalising everything into a clean model of resources, entitlements and grants.
For end users, access requests now flow through Slack or a clean web UI. Approvers are notified where they already work. Once approval lands, C1 provisions the access automatically, including in apps that historically required manual steps. Where a human genuinely needs to do something, C1 orchestrates the workflow, assigning tasks to the right people, holding until they're complete, then resuming.
The Equals Group's engineering team where able to see the art of the possible with the functionality. They built custom connectors into one of their internal backend APIs, allowing a user requesting access to a role bundle that now triggers automated provisioning across both a third-party SaaS app and Equals Group's own systems; one request, one approval, one unified flow. As Chris puts it: "The connectors are the superpower of C1. That's where it really shines."
The unifying effect matters most against the backdrop of the merger. Two businesses, two onboarding processes, two ways of granting access, collapsed into one. "It's like a unifying force," Chris says. "It's integral, especially when you're thinking about M&A."
Time-limited access is now standard for sensitive entitlements. Someone in accounts payable who needs to pull AWS billing reports once a month requests the specific role, gets it instantly, uses it, and C1 automatically takes it away again. As Chris describes it: "Zero touch for us. The user requests it, and because we know why they want it, we don't even bother approving it."
The processes were implemented successfully, but the real value came when they reviewed their progress. In a concentrated push of activity through the second half of 2025:
The stakes for a regulated fintech are real. "If they feel it's egregious enough, they might just fail you," Chris notes. "And then you're not ISO accredited, and then people won't do business with you." Reliable evidence trails aren't a nice-to-have, they protect the certifications that win and keep enterprise customers.
The success has been visible enough internally that it's reshaping how Equals Group buys software. The procurement bar has moved with it. Where the question used to be "does this tool support SSO?", it's now "does it have a good API? Does it support SCIM at a sensible tier? Does it work properly with C1?" Vendors who hide provisioning behind premium tiers no longer get a free pass.