Overig · Overig
HR as the new source of truth for Identity & Access Management
More and more organizations are shifting from IT-driven to HR-driven identity management. No longer does the helpdesk decide who gets access, but the HR system that records the lifecycle of each employee. In this article, you will learn why HR is the new source of truth for IAM.

Marcel van Beek · Owner · 7 min read
In many organisations, the management of digital identities is still with IT. New employees are created manually, rights are granted via tickets, and departures are only discovered when someone no longer needs access. This leads to errors, delays, and risks.
However, there is a clear trend: the shift from IT-driven to HR-driven identity provisioning. More and more organisations recognise that the HR system is the most reliable source of information about who someone is, what role they hold, and when they join or leave the company.
1. The core of identity management: knowing who someone is
Identity & Access Management (IAM) revolves around one central question: who is allowed what within the organisation?
To answer that question effectively, you need reliable source data. HR systems contain exactly that data: name, employee number, function, department, start and end date, contract type, manager.
In contrast, IT systems often only know that someone has an account, not who that person actually is or why they have those rights. This leads to inconsistencies when roles change or employees leave.
2. HR systems contain the employee lifecycle
The HR system records the entire “joiner-mover-leaver” lifecycle.
Joiner → new employee, known with start date
Mover → role change or internal transfer
Leaver → departure date registered
By linking IAM directly to HR data, accounts and rights can be automatically created, adjusted, or revoked. The HR mutation triggers the change, not a separate IT ticket.
3. Fewer errors, more compliance
Manual provisioning is prone to errors. People forget to remove accounts or adjust rights.
An HR-driven approach ensures that access rights always align with the current HR status.
Benefits:
Immediate deactivation after leaving employment
Automatic allocation of correct rights on function or department change
Audit trails and traceability to source data
This is crucial for compliance with ISO 27001, NIS2, and GDPR.
4. HR as authoritative source in practice
In modern IAM architectures, the HR system acts as the authoritative source.
An example of this:
HR registers a new employee in AFAS, Visma or Nmbrs
Joinly reads the change and creates or updates the identity in Microsoft Entra ID
Role and department automatically determine roles, groups, and licenses
On departure, the account is deactivated on the exact leave date
Result: no more standalone IT processes, but one consistent data stream from HR.
5. The impact on the organisation
IT is relieved and focuses on governance and control instead of manual tasks
HR gains direct influence over digital access without technical knowledge
Security improves as each identity is traceable and timely adjusted
Audit and compliance are simplified because all access is traceable to HR data
6. The future: HR-driven governance
The next step is not only provisioning but also governance from an HR context.
For example:
Temporary access for project staff based on contract duration
Automatic approvals by managers in Joinly
Role and access suggestions via AI (role mining) based on function data
The HR database thus becomes not only the source of identity but also the basis for access policy.
Conclusion
The question of who may have access to systems begins and ends with HR.
By using HR systems as the primary source, a consistent, secure, and automated IAM chain is created.
With Joinly, organisations can easily realise this shift without complex IAM software or expensive licenses.
Explore more blogs

Segregation of Duties (SoD): wat het is en hoe je het afdwingt
Wat is segregation of duties (functiescheiding)? Uitleg, voorbeelden en waarom het vaak misgaat. Plus hoe je SoD-conflicten automatisch tegenhoudt.
Marcel van Beek · 4 min read

How do you apply AGDLP in a hybrid Entra/AD environment? (And why you shouldn't want to anymore)
Short answer: preferably not. AGDLP (Accounts → Global groups → Domain Local groups → Permissions) is a concept from the era of manual management. The entire nesting construction exists for one reason: to allow a human to assign permissions with as few mouse clicks as possible. As soon as an agent assigns group memberships directly based on HR data, this reason disappears and only the complexity remains. Moreover, in a hybrid environment, this complexity actively works against you, because Entra ID completely ignores nesting for licences and app assignment. In this article, you can read how AGDLP works and why it was once smart, where it breaks down in a hybrid environment, and what the modern alternative looks like: direct memberships, managed by automation.
Marcel van Beek · 5 min read

How do I set up role-based access control (RBAC) and least privilege for a municipality?
Start with the roles in your HR system and map them to roles, not to individual permissions per person. Group each role with precisely the access required for the job, adhering to the principle of least privilege. Manage these roles centrally and let an orchestration layer automatically assign and revoke them. This keeps access predictable, limited and demonstrable.
Mike Fraanje · 4 min read
See what Joinly can do for your organisation?
Start a free trial today or get in touch for advice on your HR and Microsoft environment.