MercyCare is a Western Australian not-for-profit organisation delivering a wide range of services across aged care, health, disability, early learning and community support. With close to 2,000 staff working across 48 locations and delivering 29 services, MercyCare supports Western Australians from early childhood through to senior years.
Challenge
As MercyCare has grown, so too has the complexity of managing who has access to what across its systems.
The organisation operates in a sector where the stakes are high. Sensitive client and employee information must be protected. Regulatory obligations continue to expand. Meanwhile, the cybersecurity threat landscape facing healthcare and community service providers is evolving rapidly.
Existing identity and access management processes had not kept pace with these pressures. As a result, several interconnected issues were beginning to constrain operational efficiency and increase risk:
1. Manual joiner, mover and leaver processes
User provisioning and deprovisioning were largely manual. This created delays, added to administrative workload and introduced audit risk. Maintaining accurate identity data across multiple applications required significant ongoing intervention.
2. Inconsistent access controls and limited visibility
Access controls varied across systems, resulting in inconsistent levels of security and governance. Visibility of user permissions, entitlements and lifecycle events was limited, making effective oversight difficult.
3. Rising regulatory and compliance obligations
MercyCare’s obligations under the Privacy Act, Aged Care Act, Aged Care Quality Standards and the Essential Eight increased the need for demonstrable identity governance. Preparing for audits was resource intensive and difficult to scale as the organisation grew.
4. Escalating cyber threats targeting the sector
Healthcare and community service providers have become frequent targets for cyber attacks. Stronger identity security controls were needed to reduce exposure and protect the information MercyCare holds in trust.
Together, these issues resulted in operational inefficiencies, heightened compliance risk and limited MercyCare’s ability to consistently govern access across a growing application landscape.
MercyCare recognised the need to take action, and it presented a compelling business case for both business and technology leaders across the executive team.
Opportunity
Addressing these challenges required more than incremental improvement. MercyCare needed a modern identity governance platform that could automate identity lifecycle management, improve visibility of user access, enforce governance policies and provide auditable controls across the organisation.
The opportunity was to establish a trusted foundation for identity across MercyCare’s workforce and application landscape. Done well, this would enable:
- Consistent, automated provisioning of access based on role and responsibility
- Clear visibility of who has access to what, and why
- Faster onboarding and offboarding across employees, volunteers, contractors and vendors
- Stronger alignment with privacy, audit and cybersecurity obligations
- A scalable platform capable of supporting future growth in services and workforce
To deliver this, MercyCare partnered with NRI to implement SailPoint Identity Security Cloud as its enterprise Identity Governance and Administration (IGA) platform. NRI’s approach was structured across two phases, using its proven SailPoint implementation methodology to establish the identity foundation before enabling automation and governance at scale.
Solution
NRI worked closely with MercyCare to design and deliver a two-phase program. The first phase established a trusted identity foundation and improved visibility of access. The second layered on automation and governance controls. This sequencing was deliberate. It gave MercyCare confidence in the underlying identity data before enforcing changes to how access is managed day to day.
Phase 1: Identity foundation
Planning and discovery
NRI worked with MercyCare executives, business stakeholders, HR and IT teams to define the scope, objectives and success criteria for the program. Activities included:
- Identifying current identity and access management challenges and risks
- Documenting existing joiner, mover and leaver processes
- Capturing business and compliance requirements
- Assessing the application landscape and identity sources
- Developing the target state architecture, implementation roadmap and prioritised delivery plan
Establishing authoritative identity sources
A core objective of the foundation phase was to establish a single, authoritative source of identity information for the workforce.
This meant integrating MercyCare’s HR system as the authoritative source for employees and volunteers.
MercyCare’s directory system was also integrated as the source for contractors, vendors and other external identities.
Together, these integrations gave MercyCare a consolidated digital identity for every workforce member.
Discovery deployment across critical applications
SailPoint Identity Security Cloud was deployed in read-only discovery mode.
This allowed NRI and MercyCare to safely assess and analyse access across key applications before any changes were made. Key client identity, directory and enterprise systems were also onboarded during this phase.
Outcomes from Phase 1
By the end of the foundation phase, MercyCare had:
- A centralised 360-degree view of user access and entitlements
- Improved visibility of orphaned and uncorrelated accounts
- Enhanced reporting and audit capabilities
- A trusted identity data foundation to support automation in Phase 2
Phase 2: Lifecycle automation and governance
Planning and discovery
With the identity foundation in place, NRI configured SailPoint to automate identity lifecycle management and enforce consistent access governance.
Key capabilities delivered included:
- Automated joiner, mover and leaver processes, with provisioning and deprovisioning aligned to changes captured in the authoritative sources
- Role-Based Access Control (RBAC) aligned to MercyCare’s organisational structure, with access assignment based on identity type, directorate and service unit
- SailPoint Forms and Workflows to manage the lifecycle of external identities and automate the onboarding and offboarding of assets
- Integration with an internal asset management platform to coordinate asset assignment and recovery across the workforce lifecycle
- Periodic user access reviews to support ongoing governance and compliance
The result was a transition away from manual, fragmented access management to a scalable identity governance platform that improved operational efficiency, strengthened security and enhanced compliance readiness across MercyCare’s workforce and application ecosystem.
As noted by Manjusha Subhash, MercyCare’s IT Services Manager, “What once required significant manual effort across user onboarding, offboarding and asset management is now automated.”
Outcomes
The implementation of SailPoint Identity Security Cloud has strengthened how MercyCare governs identity and access across its workforce and applications. The improvements span security, compliance and day-to-day operations:
1. Automated identity lifecycle management
Joiner and mover processes are now automated. Accounts and access are provisioned based on role, organisational structure and employment status drawn from MercyCare’s HR system. This has reduced manual effort, accelerated the onboarding of new starters and ensured access is consistently aligned with business responsibilities from day one.
Result: 464 new starters onboarded in the last 12 months.
2. Automated account termination
Leaver processes are also automated. When an employee, contractor or volunteer leaves MercyCare, their access is revoked promptly across connected systems and offboarding notifications flow automatically to the relevant departments. The result is a reduction in administrative burden, freeing the Human Resources department to focus on higher-value work.
Result: 575 terminations processed in the last 12 months
Result: 5 weeks of HR work returned to the business every year.
3. Governance of non-employee identities
SailPoint Forms and Workflows manage the lifecycle of contractors, vendors and other non-employee identities. Requesting, approving, modifying and terminating access for external users is now a controlled and auditable process.
Result: No standing access for non-employees. Contractors, vendors and volunteers are granted access only for the period required
4. Streamlined asset onboarding and offboarding
Integrated SailPoint and internal asset management platform workflows now automate asset assignment and recovery across the workforce lifecycle.
Managers, employees and IT teams work from a shared process. Provisioning and recovery of assets is more timely, manual administration is reduced and an auditable record of approvals and handovers supports governance and compliance requirements.
“The easiest form I’ve ever used.”
— MercyCare HR manager, on the new asset onboarding form
5. Improved security and compliance
By centralising identity governance and automating access management, MercyCare has improved visibility of user access across critical systems. Compliance with internal governance requirements has strengthened; alignment with privacy, audit and cybersecurity obligations has been reinforced.
Result: Quarterly access review effort reduced from ~3 days to ~1 day.
— Financial Controls Internal Audit (June 2025) finding on residual access effectively closed.
6. Increased operational efficiency
With less manual work involved in provisioning, deprovisioning, access requests and identity administration, IT teams are freed to focus on higher-value initiatives. The drop in ticket volume has been substantial and the workforce now experiences faster, more consistent access to the systems they need.
Result: >90% drop in onboarding & offboarding tickets to the infrastructure team.
Result: >30% overall reduction in infrastructure team ticket volume.
MercyCare’s identity governance capability is now scalable, auditable and aligned with the regulatory and cyber obligations shaping the aged care and community services sectors. The foundation NRI helped establish positions MercyCare to grow its services and workforce with confidence.
Conclusion
“The SailPoint project has been one of the most impactful technology deliveries we have had at MercyCare. But beyond the technical outcome, what I valued most was the NRI team’s approach. From day one, they were always accessible, communicated clearly at every stage, and made what could have been a complex and disruptive implementation feel manageable and well-supported.”
— Manjusha Subhash, MercyCare, IT Services Manager
MercyCare’s identity governance capability is now scalable, auditable and aligned with the regulatory and cyber obligations shaping the aged care and community services sectors.
The foundation NRI helped establish positions MercyCare to grow its services and workforce with confidence.