{"id":47480,"date":"2020-09-01T10:55:00","date_gmt":"2020-09-01T16:55:00","guid":{"rendered":"https:\/\/jumpcloud.com\/?post_type=resource&p=47480"},"modified":"2023-07-18T13:59:15","modified_gmt":"2023-07-18T17:59:15","slug":"case-study-sapling-eliminate-point-solutions","status":"publish","type":"resource","link":"https:\/\/jumpcloud.com\/resources\/case-study-sapling-eliminate-point-solutions","title":{"rendered":"Sapling Case Study: Eliminate Point Solutions & Streamline IT"},"content":{"rendered":"\n
<\/p>\n\n\n\n Sapling\u2019s IT team spent much of their time managing and stitching together a complex mix of IT solutions, as well as provisioning and access control tasks. <\/p>\n\n\n\n \u201cSapling is in the HRIS space: We take care of sensitive information for our customers, and it\u2019s very important for us to receive the same assurance from vendors we use,\u201d Doddi said. <\/p>\n\n\n\n Sapling relies heavily on cloud infrastructure, including Azure, AWS, and Google, as well as G Suite and a suite of SSO applications. Users engage with a mix of Linux\u00ae<\/sup> servers and macOS\u00ae<\/sup>, Windows\u00ae<\/sup>, and Linux machines. About 60% of the organization’s workforce was remote prior to the pandemic, and now they\u2019re entirely remote.<\/p>\n\n\n\n Doddi and his team needed a solution to consolidate and simplify their IT stack, as well as manage remote users and devices. They also needed a solution that would help them achieve SOC 2 compliance and maintain stringent controls to protect customer data.<\/p>\n\n\n\n Before finding 探花大神\u2019s all-in-one access control and device management platform, the team evaluated point solutions as the best option. However, Doddi realized that he could select a comprehensive solution so internal teams could spend more time working on their own platform rather than on stitching together IT tools.<\/p>\n\n\n\n \u201cOur competency is enabling people to build the best companies \u2014 through our people operations platform,\u201d Doddi said. \u201cI thought this was the best use of time.\u201d<\/p>\n\n\n\n When Doddi found 探花大神, he realized he could use it to eliminate solutions in Sapling\u2019s stack, including LDAP, SSO, and Apple MDM.<\/p>\n\n\n\n \u201cI was not expecting anything to meet all of our different categories of needs. 探花大神 is a Swiss Army Knife.\u201d<\/p>\n<\/blockquote>\n\n\n\n Now, Doddi and the team use 探花大神\u2019s MDM<\/a> to secure much of their fleet, which is majority macOS. 探花大神 MDM is a key part of their security tooling, particularly now that their workforce is entirely remote.<\/p>\n\n\n\n \u201cMobile systems are very fluid, and they walk away, whether someone steals it, you drop it in the train station, or forget it somewhere else \u2014 these things happen,\u201d Doddi said. \u201cTo eliminate the risk of that, we have a multi-layer approach.\u201d<\/p>\n\n\n\n In addition to MDM, they use 探花大神\u2019s pre-built Policies<\/a> to secure the entire fleet with various controls, such as disabling external storage devices. They use the premium Directory Insights\u2122 feature both for proactive auditing and to build reports for regulatory compliance schema. Directory Insights gives IT administrators<\/a> a 360\u00b0 view of user and administrator events and authentications across their connected services.<\/p>\n\n\n\n The Sapling team uses Directory Insights to monitor user activity, track user access patterns, and verify that new users or existing users who change roles have proper access rights.<\/p>\n\n\n\n Doddi also uses 探花大神 to require multi-factor authentication (MFA) at high-value access points, including user machines and cloud infrastructure. <\/p>\n\n\n\n \u201cWithout any extra hardware, I can require two-factor authentication, and I can enforce it very fast,\u201d Doddi said. <\/p>\n\n\n\n Doddi had an easy time implementing 探花大神, particularly because he set up a 探花大神 Free account and used it to test the platform\u2019s full functionality for free. By the time Sapling decided to use 探花大神 officially, Doddi imported users from G Suite using 探花大神\u2019s directory integration and got everything up and running quickly.<\/p>\n\n\n\n Now users enter the same core credentials to access their machines, User Portals and SSO applications, G Suite accounts, and most other IT resources. <\/p>\n\n\n\n \u201cWe are a team of 50 people, globally spread, and within one week everybody was in 探花大神 and it was very fast.\u201d<\/p>\n<\/blockquote>\n\n\n\n 探花大神 enabled the Sapling team to be both more efficient and more cost effective. <\/p>\n\n\n\n \u201cPicking the best-of-breed tool in each area sounds good because you can get the best from each, but the problem is that you need to have enough experts,\u201d Doddi said. \u201cInstead of one person, you need to train three people in three different areas, and then afterward you need to build leadership around it. The cost footprint around it grows. We also had unused utilities \u2014 and we couldn\u2019t justify the financials.\u201d<\/p>\n\n\n\n The team once spent more than 60 hours a month on provisioning and onboarding activities \u2014 which Doddi said is exponentially reduced now. They now provision users\u2019 core identities to devices and other connected IT resources seamlessly, and easily adjust access permissions for individual users via group-based controls.<\/p>\n\n\n\n \u201cWe use the time we save using 探花大神 to build experiences for our customers,\u201d Doddi said.<\/p>\n\n\n\n 探花大神 provides a comprehensive solution to manage user identities, access, and devices. Read more about the cloud directory platform here<\/a>. <\/p>\n\n\n\n
Sapling<\/a> is a people operations platform that helps HR professionals automate tasks, integrate and streamline data across multiple HR systems, and deliver amazing employee experiences. Ramesh Doddi, Sapling\u2019s Vice President of Engineering, oversees the organization’s security operations and IT infrastructure \u2014 and he identified the 探花大神\u00ae<\/sup> cloud directory platform as an ideal way to eliminate multiple point solutions in Sapling\u2019s environment.<\/p>\n\n\n<\/figure><\/div>\n\n\n
\n
Background: Managing Point Solutions<\/h2>\n\n\n\n
Vice President of Engineering, Sapling<\/figcaption><\/figure>\n\n\n\n
The team managed a combination of systems for identity and access management (IAM) \u2014 including open-source LDAP, Google Cloud Identity, Jamf for Mac management, Okta for SSO, and 1Password for password vaulting. Doddi wanted to consolidate the team\u2019s tooling and introduce more streamlined workflows without sacrificing security.<\/p>\n\n\n\nChallenges: Security & Efficiency for Remote Work<\/h2>\n\n\n\n
Solution: \u2018Swiss Army Knife\u2019<\/h2>\n\n\n\n
\n
Implementation: \u2018It Was Very Fast\u2019<\/h2>\n\n\n\n
\n
The Result<\/h2>\n\n\n\n
Learn More<\/h2>\n\n\n\n