
Company Profile
Manufacturing / construction (partner integration)Manufacturer / integrated with 20 partner companies
Challenge Summary
Sharing information with partner companies required extracting only the parts that were safe to show, which was so cumbersome that many things ended up not being shared. Audits also required records of "who viewed what."
Key Outcomes
- 4 typesRoles
- 89 peopleActive users
- 100%Audit log retention
Before
Extracting only the shareable parts is so cumbersome that things end up not being shared at all.
After
Control view and edit scope by role. Safely open access to partner companies as well.
Situation before deployment
In two departments running manufacturing and construction businesses, information was regularly shared with 20 partner companies. Drawings, specifications, and process information needed to be shared, but opening internal systems directly would expose confidential information.
In practice, staff continued to extract only the needed parts into Excel or PDF and send them individually by email. The extraction work was time-consuming, and granularity varied from person to person, so operational efficiency did not improve.
Audits also began to require an audit trail of "who viewed and operated on what," and the existing information sharing method could no longer support this. The business units sent dozens of individual requests per month to the IT team asking to "share this information with company X," and the response effort was increasing.
Background and selection reasons
Three options were considered: a major vendor's IAM product, a generic external sharing SaaS, and building on NocodilySuite. The IAM product was feature-rich but required additional development to control show/hide at the field level for business data. The generic SaaS had coarse audit log granularity, raising concerns about meeting audit requirements.
We chose NocodilySuite because the business platform—authentication, database, APIs—was provided out of the box, giving us confidence we could build role-based view/edit permissions, field-level control, and audit logging in a short time. We also valued the flexibility to build a dedicated UI for partner companies on top of the platform.
The PoC period was one month. We first limited scope to one partner company and verified view scope control and audit logging. After the business unit, IT team, and audit team all confirmed usability and audit coverage, we moved to full-scale deployment.
Deployment process
The overall project ran for three months. Month one was PoC and role taxonomy design, month two was building access control, field-level control, and audit log features, and month three was communications to partners and phased rollout to 20 companies.
Roles were organized into four types: administrator, site leader, member, and partner. Each role's view, create, edit, delete, and publish permissions could be set as a combination. Show/hide could also be controlled at the data field level.
Since partner companies sometimes did not have their own domain, we issued dedicated login IDs. Audit logs were designed to record all views and changes so that "who saw what and when" could be traced for audits.
Changes after deployment
Individual adjustment requests about "what to share with which partner company" were reduced by 90%. Just assigning a role controls the visible scope, and business units can handle this without going through the IT team.
The practice of sending files as email attachments is gone, and partner companies can always reference the latest information. Issues from misaddressed emails or referencing outdated versions have been resolved.
All audit logs are now retained, and audit trails are readily available. Audit effort has been significantly reduced, lightening the load on both the audit team and the IT team.
Impact (metrics)
Voices from the Team
We no longer agonize over what to share with partner companies. Just assigning a role opens up only the scope that's safe to share.— IT Manager
Permission requests to the IT team have decreased, and work no longer stalls. Audit logs are also readily available for audit response.— Business Unit Representative
Future Plans
In the next phase we plan to integrate with SSO and automate account provisioning. By systemizing the lifecycle management of partner accounts, we aim to automatically revoke permissions when someone leaves or a contract ends.
System CompositionAccess control + role settings + field-level control + audit logs


