EnterpriseScenario 4 of 7

Nobody at head office could say who was able to post as the company.

Eleven market teams, eleven sets of tools, and a shared-password spreadsheet that had outlived three of the people on it.

Vantry Group·Composite: global logistics operator, 4,200 staff across 11 marketsIllustrative scenario

Snapshot

4 min read4 of 7
Segment
EnterpriseGlobal logistics
Team size
31Across 11 markets + central brand team
Channels
44LinkedIn, YouTube, X, Facebook, local Instagram
Time to value
12 weeksSecurity review, pilot, full rollout
Placeholder

Role-based access across 11 market workspaces

Permissions, approval stages and audit trailArt pending — 1600×1000

01 — The situation

Before

This was not a company that lacked process. It was a company whose process stopped at the border of each market.

Eleven markets each ran their own social presence, which was the right call — a post about a new terminal in one country is not interesting in another, and the local teams knew their audiences. Each market picked its own scheduling tool, or used none. Each market held its own logins.

The central brand team in head office set guidelines, distributed a quarterly asset pack, and then found out what had been published by looking at the channels like any other member of the public. When a regional post needed correcting, the correction went out by email to a distribution list and was applied at whatever speed the market applied it.

The credentials were the part that made the security team uncomfortable. Access to a corporate channel was a username and a password in a spreadsheet on a shared drive, distributed to whoever needed it that quarter. Six such spreadsheets existed across the group. When someone left the company, their laptop was reclaimed and their email was disabled, and the password they knew stayed exactly as valid as it had been the week before.

02 — The friction

What it was costing

The exposure was not hypothetical, and the reporting was six weeks stale by design.

An internal access audit was attempted and could not be completed. Three channels were found with no identifiable current owner — accounts created for a campaign years earlier, still live, still carrying the company's name, still reachable by anyone who had ever been handed the sheet. The audit could not establish how many people held working credentials, because the sheet recorded who had been given access, never who had lost it.

Governance had the same shape. Two of the eleven markets operate under regulatory constraints on how service claims are worded. Compliance review of social content happened by email, before publication, in principle. There was no record afterwards of what had been reviewed by whom, so demonstrating that it had happened relied on someone finding the right mail thread.

The global performance picture was assembled quarterly by two analysts over about three weeks: eleven exports, inconsistent date ranges, metrics that were not defined the same way in every tool. By the time the board saw the number it described a quarter that had ended six weeks earlier, and no one could drill into it without commissioning the work again.

What this was costing

  • Shared-credential spreadsheets6
  • Channels with no identifiable owner3
  • Analyst time per quarterly report≈3 weeks
  • Auditable record of compliance reviewNone

03 — What changed

The reworked workflow

Access stopped being something a person knows and became something a role has.

  1. Multi-brand workspaces + advanced permissions

    One workspace, eleven market spaces, permissions by role

    Each market keeps its own space, its own queue and its own asset library. Access is granted to a role in the workspace rather than by handing over a channel password, so removing someone's access is one action with an immediate and verifiable effect. Head office holds visibility across all eleven without holding the ability to publish into them.

  2. Approval workflows

    Compliance is a stage in the path, and it leaves a record

    For the two regulated markets, a compliance stage sits between draft and scheduled. Nothing routes around it. Crucially, the approval is recorded against the post — so the question 'was this reviewed, by whom, when' is answered by opening the post rather than by searching an inbox.

  3. Cross-platform analytics

    The quarterly report became a standing view

    Reach, engagement and channel growth across all eleven markets in one place with one set of definitions. The analysts stopped assembling the number and started interrogating it. Head office now looks at market performance in the week it happens rather than six weeks later.

  4. API + webhooks

    Publishing events flow into the systems that already exist

    Webhooks push publication and approval events into the group's internal tooling, so the social record lives alongside every other operational record rather than in a silo that has to be exported. Campaign content from the central asset system is pushed in programmatically instead of being emailed as a quarterly zip.

The eleven markets kept their autonomy over what to say. Head office gained a defensible answer to who can say it.

04 — Results

What moved, and by when

  • Markets on a single governed workspace

    0 of 1111 of 11

    12 weeks

  • Shared-credential spreadsheets in use

    60

    by week 10

  • Regulated-market posts with recorded review

    No record100%

    from week 6

  • Analyst time per quarterly report

    ≈3 weeks≈2 days

    first full quarter

Honest note on what drove this

Twelve weeks is the honest number and most of it was not implementation. Security review, data-handling sign-off and market-by-market change management took roughly eight of those weeks; the pilot market was live in eleven days. Any organisation with a procurement process should plan for the review, not the rollout. The three orphaned channels were reclaimed through each platform's own recovery process — a workspace cannot recover an account it never had access to.

The honest answer to 'who can post as us' was a spreadsheet, and the spreadsheet was a list of everyone we had ever asked.

Group communications director — composite of multi-market enterprisesIllustrative scenario

05 — What to take from this

Transferable lessons

Useful whether or not you ever open NOWScale — these are the parts that generalise.

  • Shared credentials are an offboarding failure waiting to happen

    Any access model where revoking a person's access requires changing a password that other people also use will not be revoked promptly. Access should be attached to identity, so removal is a single reliable action.

  • An audit you cannot complete is itself the finding

    If you cannot enumerate who holds access to your corporate channels, you do not have a partial answer — you have an unmanaged surface. Treat the inability to produce the list as the risk.

  • Compliance review needs a record, not just a step

    A review that happened but cannot be evidenced provides no protection when it is questioned months later. Attach the approval to the artifact.

  • Central visibility and local publishing rights are separable

    Head office usually wants to see everything, not to control everything. Splitting those two permissions lets regional teams keep the autonomy that makes their content work.