Skip to main content
Joinly by KoppelHet

Public sector

Access that follows the job, in an organisation that accounts for itself

A public sector agency with employees across the country lets access follow from role and department. Permissions belong to a job, not to a person.

Two employees in conversation at a table in an open-plan office
employees
more than 600employees
changes a month, handled automatically
around 55changes a month, handled automatically
of changes logged
100%of changes logged

Access had grown per person, and after years nobody knew why

A public sector agency with more than six hundred employees spread across the country has many people who have been there a long time. That is a strength. For access management it is a problem, because access arranged per person grows with the years of service. Someone who has held four jobs in fifteen years had the permissions of all four.

For an organisation that accounts for its work, that is hard to explain. It is also hard to clean up, as long as nobody knows exactly which access was granted for what. Every clean-up started with an inventory and ended before the inventory was finished.

What they wanted: permissions that belong to a job, not to a person

The organisation wanted to turn the question around. Instead of asking what this person has collected over the years, the question should be what this job needs. Whoever holds the job gets that; whoever leaves it loses it. And the gap between what someone should have and what someone actually has should be visible, so cleaning up no longer takes an inventory.

Permissions that grow with years of service are not a reward. They are a risk nobody chose.

What was built: roles per job, and the gap in view

In Joinly it is set down per job and department what access belongs with them. Onboarding, role changes and offboarding run from HR, and a change of role replaces the permissions instead of adding to them. That stops the pile-up for everyone who changes job from now on.

For what was already there, the access review was brought in: it puts intended access next to actual access and shows where someone has more than the job prescribes. What was left over from a previous job comes into view and is removed, with the change in the audit log.

De toegangsevaluatie in Joinly: feitelijke naast bedoelde toegang

Today: explainable access, and accounting without searching

For every grant there is a reason that follows from the job. That makes access explainable, to an auditor and to the organisation itself. Around fifty-five changes a month run from HR, and permissions no longer grow with years of service.

The substantiation comes from the system. Who got which access when, and on what basis, is on record for more than six hundred people, without an inventory being needed first.

What you can count on

  • No vendor lock-inYour identities and your configuration stay yours.
  • Your data out whenever you wantYou can export your data at any time.
  • Standard SLAOur standard SLA is available on request.
  • Support during implementationOur specialists set it up together with you.
  • ISO 27001 certifiedInformation security to an internationally recognised standard.

Want to see what this means for your organisation?

Book a 30-minute demo. We walk through your own situation: which HR system you use, which systems need to follow and what can be automated first.

Book a demo