Overig · Overheid
How do I set up role-based access control (RBAC) and least privilege for a municipality?
Start with the roles in your HR system and map them to roles, not to individual permissions per person. Group each role with precisely the access required for the job, adhering to the principle of least privilege. Manage these roles centrally and let an orchestration layer automatically assign and revoke them. This keeps access predictable, limited and demonstrable.

Mike Fraanje · Sales consultant IAM · 4 min read
What exactly do RBAC and least privilege mean?
Role-based access, or role-based access control (RBAC), means that you grant permissions to roles and link people to roles, rather than giving each individual separate permissions. A practitioner, a policy officer and a team leader each have their own profile with the access associated with that role. Least privilege is the accompanying principle: someone is granted no more access than is strictly necessary for their work.
Together, these principles ensure that access becomes explainable. For every employee, you can show why they have certain permissions, namely because the role requires it. This is exactly what the Baseline Information Security Government (BIO) requires.
How do you translate positions into roles at a municipality?
The practical starting point is a role overview that matches the positions as they appear in the HR-system. Map out which applications and data are needed per position and record this in an authorisation profile. Keep the number of roles manageable by looking at what positions have in common, and add department or organisational unit where this determines access. Avoid exceptions at an individual level, as these undermine the overview and are difficult to account for.
A municipality often has a large application landscape, from case management systems to office automation. By managing roles centrally rather than separately per department, you prevent fragmentation that leaves no one with a total overview.
How do you keep management central and provable?
RBAC only works if the assignment and revocation of roles is handled reliably. It is therefore wise to make the HR-system the source of truth and have an orchestration layer automatically apply the roles in the work environment. Joinly works as such a layer on top of Microsoft Entra ID or Google Workspace: upon entry, the employee receives the role associated with the position, a change of position automatically leads to the correct adjustment, and upon departure, the roles are revoked. Every change is logged.
This makes least privilege a continuous process rather than a one-off setup, and allows you to periodically demonstrate that actual access still matches the intended access. This applies to employees; citizen identities fall outside this setup.
FAQ
How many roles do I need? As many as necessary to meaningfully distinguish positions, but as few as possible to keep it manageable. Start with the largest position groups and refine where practice demands it.
What do I do with exceptions? Record exceptions as temporary, traceable assignments with an end date, rather than as permanent individual permissions. This keeps the overview intact.
Does RBAC align with the BIO? Yes. The Baseline Information Security Government (BIO) is based on role-based access and least privilege; RBAC is the direct implementation of this.
Explore more blogs

Segregation of Duties (SoD): wat het is en hoe je het afdwingt
Wat is segregation of duties (functiescheiding)? Uitleg, voorbeelden en waarom het vaak misgaat. Plus hoe je SoD-conflicten automatisch tegenhoudt.
Marcel van Beek · 4 min read

How do you apply AGDLP in a hybrid Entra/AD environment? (And why you shouldn't want to anymore)
Short answer: preferably not. AGDLP (Accounts → Global groups → Domain Local groups → Permissions) is a concept from the era of manual management. The entire nesting construction exists for one reason: to allow a human to assign permissions with as few mouse clicks as possible. As soon as an agent assigns group memberships directly based on HR data, this reason disappears and only the complexity remains. Moreover, in a hybrid environment, this complexity actively works against you, because Entra ID completely ignores nesting for licences and app assignment. In this article, you can read how AGDLP works and why it was once smart, where it breaks down in a hybrid environment, and what the modern alternative looks like: direct memberships, managed by automation.
Marcel van Beek · 5 min read

Wat betekent de Cyberbeveiligingswet (NIS2) voor het toegangsbeheer van gemeenten, provincies en waterschappen?
Gemeenten, provincies en waterschappen worden onder de Cyberbeveiligingswet automatisch aangewezen als essentiële entiteit, ongeacht hun omvang, en vallen daarmee onder proactief toezicht. Toegangsbeheer is een vast onderdeel van de zorgplicht: toegang moet beperkt, rolgebaseerd en aantoonbaar zijn. Geautomatiseerd accountbeheer met logging is de praktische manier om daaraan te voldoen.
Mike Fraanje · 4 min read
See what Joinly can do for your organisation?
Start a free trial today or get in touch for advice on your HR and Microsoft environment.