You onboard an organisation, not a person
The unit of the relationship is a company: a contract, a set of entitlements, a start and an end date. The individuals inside it change constantly, and you are the last to hear about it.
Dealers, suppliers, distributors, franchisees, clinical partners, logistics providers. They need your systems, they are not in your directory, and the person who knows whether they still work there is not in your company either.
Workforce IAM assumes you employ the person. Customer IAM assumes the person acts for themselves. Here, someone else employs them and the contract acts for both of you.
The unit of the relationship is a company: a contract, a set of entitlements, a start and an end date. The individuals inside it change constantly, and you are the last to hear about it.
Your team cannot know that a dealership hired two people and lost three. Only the partner knows — which means administration has to be delegated, with limits, rather than centralised out of caution.
When a contract ends, access has to end for everybody it covered, across every system it touched, on the date it says. Doing that by hand is how dormant partner accounts survive for years.
The capabilities that separate a working programme from a spreadsheet of exceptions.
The partner administers their own people, within a boundary you define: which roles they can grant, how many, and never outside their own organisation.
Entitlements, branding, policy and lifecycle attached to the partner entity, so ending the relationship is one action rather than a search for accounts.
Large partners have their own identity provider and will not create accounts in yours. Accepting their assertion is cheaper and safer than holding credentials for their staff.
Access to the ordering portal is not access to the pricing engine. Partner entitlements need the same granularity as internal ones, and more discipline.
Browsing a catalogue and submitting a warranty claim are not the same risk, even from the same partner on the same day.
Who at which partner had access to what, over which period. This is the question that arrives with the contract dispute, not before it.
Each partner gets its own space, with its own identity providers, branding and local rules, while the parts that are genuinely shared stay shared instead of being copied and left to drift.
Monokee sits between their identity provider and your applications, translating protocols and applying your policy. Nobody has to move a directory for the relationship to work.
What a partner administrator can do is a flow with explicit branches and limits, reviewable by the people who own the contract rather than only by whoever configured it.
We'll show you which parts are contract, which are configuration, and which never needed to be either.
Talk to an expert