Skip to content

Scaling Power Platform Governance at Assurant with Automated Provisioning

  • by

Background

As adoption of Microsoft Power Platform expanded across Assurant, development teams needed a faster and more consistent way to establish secure environments.

The Fortune 500 risk management company wanted to standardize how teams requested and received Power Platform environments while strengthening data loss prevention (DLP) controls and supporting application lifecycle management. The broader goal was to give teams room to innovate without sacrificing the security and governance required at enterprise scale.

Assurant partnered with IntelliTect to design and implement an automated governance framework connecting ServiceNow, GitHub Actions, Power Platform, and Azure DevOps.

Challenges

Growing Power Platform adoption created a need for repeatable governance processes that could scale across teams.

Environment provisioning did not yet follow a standardized workflow. Each team needed properly configured development environments, security assignments, service connections, and deployment infrastructure before development could begin.

Connector access introduced another challenge. Teams needed different Power Platform connectors depending on their applications, but enabling those connectors had to remain consistent with both tenant-level and environment-level DLP policies.

Assurant also wanted to strengthen its broader governance practices around cost visibility, disaster recovery, logging, licensing, and database change management.

The challenge was to make Power Platform easier to adopt while ensuring that security and operational controls scaled with it.

Solutions

IntelliTect worked with Assurant stakeholders, developers, and the ServiceNow team to build an automated governance framework over approximately three months.

The solution included:

  1. Automated Power Platform environment provisioning
    IntelliTect created a GitHub Actions workflow triggered by a ServiceNow request. The workflow automatically provisions a set of development, model, and production environments for each team.
  2. Automated application lifecycle management setup
    Provisioning also creates the Azure DevOps pipelines, service connections, and variable groups required to move Power Platform solutions through the development lifecycle.
  3. Security group and service principal configuration
    The workflow automatically creates and assigns the required security groups and service principals. When Power Platform’s standard administrative roles did not match Assurant’s access requirements, IntelliTect developed an alternative role-assignment approach that provided necessary administrative access without granting environment deletion privileges.
  4. Automated DLP policy management
    A second ServiceNow-triggered GitHub Actions workflow allows teams to request Power Platform connectors. The automation updates both tenant-scoped and environment-scoped DLP policies so connector access can be enabled while preserving Assurant’s data protection requirements.
  5. Optional VNet integration
    Teams working with sensitive client data can provision environments with virtual network integration for additional network-level protection.
  6. Change management integration
    Both workflows use Assurant-specific PowerShell modules to create change records, incorporating provisioning and governance changes into established internal processes.
  7. Governance documentation and knowledge transfer
    IntelliTect documented the solution in Confluence and provided guidance for expanding governance practices around organizational logging, disaster recovery, licensing, cost visibility, and database change management.

Throughout the engagement, IntelliTect worked closely with Assurant’s ServiceNow developers to determine which provisioning options should follow organizational standards and which should remain configurable by individual teams.

Rather than introducing another standalone migration application, the solution made GitHub itself the interface for requesting and tracking migrations.

Outcome

Assurant now has a standardized, automated process for provisioning and governing Power Platform environments.

Teams can initiate requests through ServiceNow and receive environments configured with the infrastructure, security assignments, DLP controls, and deployment capabilities needed to begin development. Connector requests follow a similarly controlled workflow, allowing teams to access the functionality they need without bypassing established data protection policies.

Automation reduces the manual work required to onboard teams and helps ensure that environments begin with a consistent governance baseline.

Just as importantly, the framework gives Assurant a foundation it can continue building on as Power Platform adoption grows. Documentation and knowledge transfer enable internal teams to maintain the solution while extending governance practices into areas such as logging, disaster recovery, licensing, and cost management.

The result is a Power Platform environment that supports both development velocity and enterprise governance.