How FreeAgent Built Complete Access Visibility And Mature Least Privilege Governance

FreeAgent is a cloud based accounting software company serving over 200,000 small businesses, freelancers, and accountants. As a regulated fintech business and part of NatWest Group, strict security and compliance standards are fundamental.

With Cakewalk, FreeAgent enhanced and automated their access visibility, moved access governance into Slack, increased user engagement, and strengthened least privilege across the business while maintaining usability.

"Cakewalk works with users where they already are. It makes access governance part of everyday work instead of something happening in the background."
Steven Williamson
Head of Information Security @ FreeAgent
Introduction

FreeAgent is a cloud based accounting software provider headquartered in Edinburgh, Scotland. The company serves more than 200,000 small businesses and has been part of NatWest Group since 2018. As a fintech business operating in a regulated environment, security, compliance, and risk reduction are core priorities.

Access management is not limited to central IT. Multiple stakeholders across the business manage access at different levels for different services. As the organization matured, it became clear that access governance needed to provide complete visibility, enforce least privilege, and engage users directly in the process.

Managing access in Google spreadsheets did not scale and did not provide the control or auditability required for a regulated environment.

The Challenge

Achieving complete access visibility

FreeAgent needed a clear, current view of who has access to which services across the business. Spreadsheets did not provide reliable oversight and did not scale with organizational complexity.

Implementing mature least privilege governance

Many organizations talk about least privilege, but implementing it well is difficult. For FreeAgent, reducing access was fundamental to reducing risk from malware, insider abuse, and phishing. Lower access reduces the impact of any successful attack.

Least privilege had to be enforced consistently and with maturity, not just documented as policy.

Engaging users in the governance process

Access governance is a shared responsibility across teams. Previous tools worked for security or corporate IT, but they lacked user engagement. Adding friction or managing access entirely in the background created awkward conversations and reduced transparency.

FreeAgent wanted a solution that worked with users where they already operate and made them active participants in the process.

The Solution

FreeAgent implemented Cakewalk to centralize access visibility, support mature least privilege governance, and integrate access workflows directly into Slack.

Slack first access workflows

Access requests and approvals happen directly in Slack. For employees, interacting with Cakewalk feels similar to messaging corporate IT. This usability was key.

The Slack interface makes access governance visible and approachable instead of hidden or intimidating.

User prompted access awareness

Cakewalk prompts users directly about the services they can access. Instead of silently managing permissions in the background, employees are made aware of their access and encouraged to participate in reviews.

This helps build a culture of security across the business rather than treating security as a separate function.

Central visibility and scalable governance

Cakewalk provides a centralized view of access across services, replacing spreadsheets with a structured and scalable system. Security teams gain clearer oversight while multiple stakeholders across the business remain involved in decision making.

Least privilege is not only documented but actively implemented and maintained.

The Results
Cakewalk helped FreeAgent move from spreadsheet based tracking to structured, user engaged access governance aligned with regulated fintech standards.
Operational maturity and scale
  • Spreadsheet based access tracking replaced with a scalable system
  • Improved visibility into who has access to which services
  • Structured governance across multiple stakeholder teams
User engagement and security culture
  • Employees interact with access governance directly in Slack
  • Users are prompted about their access instead of being managed silently
  • Access governance becomes part of everyday work
Risk reduction and compliance
  • Least privilege implemented more consistently across the business
  • Reduced potential impact of malware, insider abuse, and phishing
  • Improved ability to demonstrate access control maturity in a regulated environment
Agentic Access Management For Fast-Moving Companies.
Founded:
Industry:
Employees:
51 to 200 employees
Key Stat:
  • Spreadsheet based access tracking replaced with a scalable system
  • Employees interact with access governance directly in Slack
  • Reduced potential impact of malware, insider abuse, and phishing

In the news

High Performer
"Absolutely game changing for JML management"
Easiest Setup
“Cakewalk helps us to run employees access from one simple place”
Easiest to do business with
"Easy. Super reliable. Love it."
Fastest Implementation
"Effortless UX, super valuable!"
Best support
"Best product for fast-moving tech companies"

Get going with Cakewalk - it’s a piece of cake.

Consolidate all accesses, apps and AI agents
Fully automate workflows with Agent Cake
Get guidance based on insights, reducing your attack surface
RBAC, auto provisioning, automated audits and more
Superpower your existing IdP
Get going in minutes