Public sector
Access that follows the job, in an organisation that accounts for itself
A public sector agency with employees across the country lets access follow from role and department. Permissions belong to a job, not to a person.

- employees
- more than 600employees
- changes a month, handled automatically
- around 55changes a month, handled automatically
- of changes logged
- 100%of changes logged
Access had grown per person, and after years nobody knew why
A public sector agency with more than six hundred employees spread across the country has many people who have been there a long time. That is a strength. For access management it is a problem, because access arranged per person grows with the years of service. Someone who has held four jobs in fifteen years had the permissions of all four.
For an organisation that accounts for its work, that is hard to explain. It is also hard to clean up, as long as nobody knows exactly which access was granted for what. Every clean-up started with an inventory and ended before the inventory was finished.
What they wanted: permissions that belong to a job, not to a person
The organisation wanted to turn the question around. Instead of asking what this person has collected over the years, the question should be what this job needs. Whoever holds the job gets that; whoever leaves it loses it. And the gap between what someone should have and what someone actually has should be visible, so cleaning up no longer takes an inventory.
Permissions that grow with years of service are not a reward. They are a risk nobody chose.
What was built: roles per job, and the gap in view
In Joinly it is set down per job and department what access belongs with them. Onboarding, role changes and offboarding run from HR, and a change of role replaces the permissions instead of adding to them. That stops the pile-up for everyone who changes job from now on.
For what was already there, the access review was brought in: it puts intended access next to actual access and shows where someone has more than the job prescribes. What was left over from a previous job comes into view and is removed, with the change in the audit log.

Today: explainable access, and accounting without searching
For every grant there is a reason that follows from the job. That makes access explainable, to an auditor and to the organisation itself. Around fifty-five changes a month run from HR, and permissions no longer grow with years of service.
The substantiation comes from the system. Who got which access when, and on what basis, is on record for more than six hundred people, without an inventory being needed first.
What you can count on
- No vendor lock-inYour identities and your configuration stay yours.
- Your data out whenever you wantYou can export your data at any time.
- Standard SLAOur standard SLA is available on request.
- Support during implementationOur specialists set it up together with you.
- ISO 27001 certifiedInformation security to an internationally recognised standard.
Customer stories
More customer stories
Organisations with a similar question, in a different sector.
Want to see what this means for your organisation?
Book a 30-minute demo. We walk through your own situation: which HR system you use, which systems need to follow and what can be automated first.
Book a demo

