One of the world's largest industrial manufacturers ran Delinea for privileged access across more than 2,000 privileged accounts, 800 servers, and administrators on every continent. The manufacturer's estate ran on Google Cloud, and Delinea could not manage GCP workspaces or IAM service accounts on its own, so every cloud integration was a custom script, and every script broke when Delinea released an update. Venice manages GCP workspaces and IAM service accounts out of the box, so the manufacturer replaced Delinea in three weeks and moved every administrator to Just-in-Time access.
The problem: An incomplete PAM solution held together by custom code
Delinea had no out-of-the-box support for managing GCP workspaces or IAM service accounts. Every cloud workflow ran on a custom API script.
“Every integration was custom API work, and every custom module was a single point of failure,” the company's VP of Identity and Access Management said. “Our cloud accounts needed scripts the platform couldn't provide out of the box, and each script was one product update away from breaking.”
When an update broke a script, the IAM team was the one who found out. On top of the scripts sat an agent on every managed endpoint that the team had to patch, monitor, and troubleshoot.
“We weren't operating a PAM program anymore. We were maintaining one,” the VP said. “It felt like we were duct-taping it together.”
We weren't operating a PAM program anymore. We were maintaining one. It felt like we were duct-taping it together.
VP of Identity and Access Management
The scripts, the agents, and the update breakages all traced back to the same cause: Delinea had no support for the platform the company runs on. The team decided to replace it rather than keep patching around it.
Migration: three weeks, nothing to install
Migrating off Delinea and onto Venice took three weeks. All 2,000 privileged accounts and over 800 servers moved to Just-in-Time access brokered through Venice.
There were two factors that made the timeline possible. Venice is agentless, so there was nothing to deploy on servers or endpoints. And discovery is automated: during rollout, Venice mapped more than 48,000 servers and 425,000 identities across the environment, giving the team a complete inventory of its privileged access surface for the first time.
“We moved 2,000 privileged accounts and 800 servers off our legacy PAM in three weeks,” the company's CISO said. “I've been through a lot of enterprise security migrations. None of them moved as fast as Venice did.”
I've been through a lot of enterprise security migrations. None of them moved as fast as Venice did.
CISO
The results: Zero standing privilege without slowing anyone down
GCP workspaces, IAM service accounts, and all 800 servers are now governed by Venice. Standing privilege is gone: no administrator holds a password to anything. Access is requested, granted for a fixed window, logged, and revoked when the window closes. For auditors, the answer to “who has standing access to this server” is now: no one.
“Honestly, I expected pushback from admins, but it never came,” the VP said. “We run a thousand Just-in-Time requests a day across four continents, and nobody is telling me we slowed the business down.”
More than 1,300 users across every region the company operates in now go through Just-in-Time requests, and no team has reported that access got slower. The company also spends significantly less than it paid for Delinea, with no custom integration work to maintain.
“Admins stopped noticing the control is there,” the VP said. “That's what good security looks like.”