Overig · Overig
IAM as the foundation for security governance: why IAM is the strategic pillar
Security governance revolves around control, predictability, and the structural protection of information. However, many governance efforts falter when access management is manual or fragmented. IAM forms the foundation of modern security because it determines who has access to data, applications, and systems. Joinly makes IAM simple, flexible, and fully automated. By synchronizing identities from HR and combining access rules through RBAC and ABAC, a reliable and scalable governance model is created that structurally reduces risks.

Mike Fraanje · 7 min read
Security governance is more than technology. It involves policy, responsibility, control, and maturity. Organisations invest in firewalls, monitoring, encryption, and awareness. However, all these measures fail when one element is missing: clear and consistent access management.
IAM determines who has access to which information, in what context, and for what period. It is the first line of defence and the foundation upon which all other security measures rest. Without strong IAM, governance quickly devolves into disparate measures that are difficult to manage.
Many organisations discover this during audits, incidents, or growth. Access appears fragmented. External parties remain active for too long. Roles shift without rights being adjusted. Cloud applications are added without central management. The result is that security governance exists only on paper, not in practice.
IAM changes this. And Joinly demonstrates how straightforward governance can be when IAM is no longer a technical project but a strategic pillar.
Why security governance doesn't work without IAM
Security governance requires consistent behaviour and predictable processes. Access is central to this. As long as access is granted manually, is dependent on individual tickets, or is spread across dozens of applications, a landscape emerges that no one can fully oversee.
Typical problems we often encounter:
employees build historical rights that are never cleaned up
external parties retain access after project completion
applications have their own user administrations without oversight
functions change, but rights do not change accordingly
audits require evidence that is difficult to supply
Security thus becomes reactive. Governance is primarily about searching for errors instead of preventing them.
IAM makes governance proactive. It ensures that access is automatically correct, even when teams, systems, or processes change.
IAM as the backbone of modern security
IAM is not a standalone toolset but the architectural layer that determines how securely an organisation can function. It forms the foundation beneath:
data minimisation
role separation
compliance (ISO 27001, NIS2, GDPR)
lifecycle management
monitoring and detection
third-party risk management
cloud security
When IAM is strong, every other security process becomes stronger. When IAM is weak, all other processes become vulnerable.
Joinly strengthens IAM in a way that aligns with modern organisations: flexible, understandable, and fully automated.
How Joinly changes IAM from complex to manageable
IAM is often known as complex. Many solutions require technical configurations, scripting, and complex policy structures. But that is not how IAM is meant to be. IAM should be simple, reliable, and logical for everyone within the organisation.
Joinly achieves this by combining three key principles.
1. HR provides identity data, IAM manages access
HR continues working as usual. Joinly automatically retrieves identity data and keeps it synchronised across all connected systems. IAM is not hindered by manual maintenance but remains current through continuous data flow.
2. Access follows policy via RBAC and ABAC
In Joinly, organisations don't have to choose between RBAC or ABAC. They simply use both, side by side or intermingled, exactly as their processes require.
Roles provide structure.
Attributes provide nuance.
Together they provide control and flexibility.
Joinly hides the technical complexity and makes the models applicable without deep IAM knowledge.
3. Provisioning and deprovisioning are automated
Access is adjusted as soon as something changes:
someone starts
someone changes role
someone moves to another department
an external contract ends
a project stops
All access is automatically adjusted across all connected systems. This ensures no gaps in governance.
IAM makes governance predictable
Successful security governance revolves around predictability: knowing that processes always follow the same path, regardless of who executes them or when. IAM makes this possible by automating access and basing it on policy.
With Joinly, governance becomes:
Consistent: access is always determined in the same way.
Traceable: every access decision can be explained and traced.
Scalable: changes in the organisation do not lead to chaos.
Audit-proof: auditors can immediately see that processes are reliable.
Risk-driven: excessive or broad access is automatically prevented.
No more ad-hoc actions. No exceptions upon exceptions. No dependence on individual employees.
The strategic value of IAM for organisations
IAM affects every layer of the organisation, even if teams are not aware of it. It supports:
digitisation
hybrid working
collaboration with external parties
cloud adoption
governance frameworks
risk management
business continuity
Organisations that implement IAM well become more flexible. They can onboard people faster, connect applications faster, respond to new risks faster, and comply with laws and regulations more easily.
IAM becomes a strategic advantage rather than a technological challenge.
Joinly as the IAM platform for modern governance
Joinly offers organisations a no-nonsense IAM solution that removes all complexity. The platform uses modern technology but doesn't feel technical. It automates access instead of managing it. It enables IAM to collaborate with HR, reducing the burden on HR.
With Joinly, organisations receive:
reliability through automated workflows
flexibility by combining RBAC and ABAC
simplicity because the complexity remains under the hood
safety through clear and consistent access rules
insight through full auditability
IAM thus becomes the foundation on which governance can be confidently built.
Explore more blogs

Segregation of Duties (SoD): wat het is en hoe je het afdwingt
Wat is segregation of duties (functiescheiding)? Uitleg, voorbeelden en waarom het vaak misgaat. Plus hoe je SoD-conflicten automatisch tegenhoudt.
Marcel van Beek · 4 min read

How do you apply AGDLP in a hybrid Entra/AD environment? (And why you shouldn't want to anymore)
Short answer: preferably not. AGDLP (Accounts → Global groups → Domain Local groups → Permissions) is a concept from the era of manual management. The entire nesting construction exists for one reason: to allow a human to assign permissions with as few mouse clicks as possible. As soon as an agent assigns group memberships directly based on HR data, this reason disappears and only the complexity remains. Moreover, in a hybrid environment, this complexity actively works against you, because Entra ID completely ignores nesting for licences and app assignment. In this article, you can read how AGDLP works and why it was once smart, where it breaks down in a hybrid environment, and what the modern alternative looks like: direct memberships, managed by automation.
Marcel van Beek · 5 min read

How do I set up role-based access control (RBAC) and least privilege for a municipality?
Start with the roles in your HR system and map them to roles, not to individual permissions per person. Group each role with precisely the access required for the job, adhering to the principle of least privilege. Manage these roles centrally and let an orchestration layer automatically assign and revoke them. This keeps access predictable, limited and demonstrable.
Mike Fraanje · 4 min read
See what Joinly can do for your organisation?
Start a free trial today or get in touch for advice on your HR and Microsoft environment.