Connect Resources

Solving IAM for the frontline workforce

Written by Brett Sedcole | Sep 4, 2026, 2:04:57 PM

Most organisations have solved IAM for 20% of their workforce. But what about the other 80%?

 

If you work in IT security or operations, there is a reasonable chance you have spent significant time and budget on identity and access management. You have got Entra ID in place, you are managing licences, you have got joiners, movers, leavers processes documented.

Here is the problem. That infrastructure almost certainly covers your desk-based workforce. It almost certainly does not cover the majority of your employees.

80% of the global workforce is frontline. The majority of IAM technology is built for the other 20%. That is the gap. And in most organisations, nobody is talking about it.

 

Who we are talking about

Frontline and deskless workers: hotel staff, warehouse operatives, healthcare workers, retail assistants, seasonal hires, contractors, volunteers. People who do not sit at a desk with a company laptop and a Microsoft 365 account. People whose working day is physical, mobile, shift-based.

There are 2.7 billion of them globally. In most large organisations they make up the majority of headcount. And in most large organisations, they are accessing work systems using shared credentials, personal email addresses, or not accessing them at all.

 

What this actually looks like in practice

Here is the scenario we see repeatedly. A new hire joins a hotel, a warehouse, a care home. They are told they need to access the rostering system, the learning platform, and the internal comms tool. Nobody has set up their accounts yet. IT raises tickets. Different teams own different systems. Three to ten days later, on average, they finally get access.

In the meantime, they are using someone else's credentials. Or WhatsApp. Or nothing.

Now multiply that across thousands of employees, across dozens of locations, across a workforce with high turnover. The problem snowballs to become both highly inefficient and alarming security risk.

  • Every shared credential is an unmanaged entry point into your systems.
  • Every manual provisioning process is a delay that leaves people working around the gap.
  • Every orphaned account (someone who has left the business but whose login still works) is exposure you probably do not know about.

69% of frontline workers are using personal messaging apps for work. That figure comes up in almost every conversation we have. It is not just because people are being careless, it’s because it is the only tool that works reliably.

 

The security argument

There is a tendency to frame frontline access as an employee experience issue. It is that too, but leading with experience tends to get it deprioritised. This is fundamentally a security and infrastructure issue.

Identity-related incidents account for 40% of all data breaches. Now consider that 80% of your workforce sits outside your identity management strategy. No managed credentials, no automated deprovisioning, no audit trail.

If 80% of your workforce sits outside your identity management perimeter, you have a significant and largely invisible attack surface. Regulators do not accept 'we think' as an answer. If you cannot show who has access to what, who approved it, and when it was revoked, you have compliance exposure.

 

A real example: Ennismore

Ennismore is the world's fastest-growing lifestyle hospitality company. Around 27,500 employees across 250-plus locations in 40-plus countries. Around 17,000 of those are frontline workers without corporate email accounts.

Before moving to Connect Frontline, provisioning was manual and fragmented across brands and regions, with no consistent day-one experience and no automated process for removing access when someone left. Accounts drifted. Nobody had a clear picture of who had access to what.

What we built with them was a single source of truth for all employee data, with automated provisioning into every platform they need access to. When HR adds a new starter with a start date, their accounts are ready before they walk through the front door. They activate by scanning a QR code in around 40 seconds. When someone leaves, access is removed automatically on their end date.

Since putting this in place, the entire workforce, including all 17,000 frontline workers, is now connected through one consistent, branded experience. And for the first time, the business has a full audit trail of who has access to what, across every location.

 

The cost of doing nothing

The investment case for fixing this is straightforward. IT teams in organisations of this size typically spend hundreds of hours a month on account-related tickets. New hires wait days before they can do their jobs. Platform licences go underutilised, with adoption commonly sitting at around 20-40% while the bill is paid at 100%. And the risk, both from security breaches and from regulatory non-compliance, continues to grow.

A 22% productivity drop from poor access. That is what Deloitte found when they measured the impact on frontline workers.

 

Three things to check today

If you want to understand whether this gap exists in your organisation, here is where to start.

  1. Map your identity coverage: What percentage of your workforce has a managed, individual digital identity? Anyone using shared credentials, or with no digital identity at all, is a gap.
  2. Trace a recent leaver through your systems: Pick someone who left the business in the last three months. How long were their accounts still active after they left? If you cannot answer that confidently, your JML process has a hole.
  3. Check your actual platform adoption rates: Not provisioned users, active users. If your frontline apps are sitting below 60% active, access friction is almost certainly the reason. Another comms campaign will not fix it.

The frontline workforce deserves the same security, the same reliability, and the same day-one readiness as everyone else. In most organisations right now, they do not have it. That is fixable.

If you’ve run any of these checks, we'd be curious to hear what you found.