Sector solution · Municipalities & local government
IAM in government
Within government, you process sensitive citizen data daily, spread across many departments, chain partners, and external hires. Joinly links your HR system to Microsoft Entra ID or Google Workspace, ensuring employee accounts and access are managed automatically, securely, and verifiably. Ready for the Baseline Information Security Government (BIO) and the Cybersecurity Act.
Take the IAM quick scan

Who is this for?
Joinly works for any government organisation that wants to manage employee account management centrally and securely, while maintaining autonomy per department or business unit.

Municipalities
Municipal organisations with many departments, a large application landscape and continuous inflow and outflow of permanent and hired employees, who are annually accountable via ENSIA and fall under the Baseline Information Security Government (BIO).

Provinces and water boards
Decentralised governments that, like municipalities, fall under the Baseline Information Security Government (BIO) and are automatically designated as an essential entity by the Cybersecurity Act.

Joint arrangements
Collaborative partnerships such as environmental services, safety regions, and public health services (GGDs), featuring mixed teams from multiple parent organisations and therefore extra challenges regarding access management.

Executive organisations and sheltered workshops
Connected parties and municipal executive bodies, with many rotating employees and their own applications that still connect to the central working environment.
What is IAM in government?
More and more government organisations are facing the same challenge: you must work digitally secure and be able to demonstrate this, but no one knows exactly whether it is good enough.
Identity and Access Management (IAM) is the set of processes that governs who has access to which systems, and why. Within government, this is difficult because employees work across many departments and chain partners, because there is high reliance on external hires, and because the inflow and outflow of staff is continuous.
Properly managed IAM means that the creation, modification, and removal of accounts is handled automatically and verifiably.
Why IAM is essential for government
The government runs on trust and diligence with citizen data. IAM is central to this.

Critical sectors
Organisations active in vital sectors such as energy, healthcare, transport, water, government, and industry.

Cloud & IT service providers
Companies providing IT services such as: SaaS platforms, Managed Service Providers, Cloud hosting, and Integration platforms

Essential business processes
Organisations that manage systems crucial for: Business continuity, Operational processes, and Production environments

Medium & large organisations
NIS2 is primarily focused on organisations with: - 50+ employees - Or significant revenue - Or important societal impact
Prepare your organisation for the new European cybersecurity standard
IAM is an integral part of government frameworks
Digital security is not optional for the government. Access management is a standard component within the sector's frameworks, and well-organised IAM is exactly what is needed.

Baseline Information Security Government (BIO)
The Baseline Information Security Government (BIO) is the mandatory standards framework for the central government, municipalities, provinces, and water authorities. Its successor, BIO2, aligns with international information security standards (NEN-EN-ISO/IEC 27001:2023 and 27002:2022) and is risk-based. For municipalities, BIO 1.04 formally remains in force as mandatory self-regulation until the Cybersecurity Act takes effect. Access management, featuring role-based access, least privilege, and logging, is a core component of this baseline.

Cloud & IT service providers
Companies providing IT services such as: SaaS platforms, Managed Service Providers, Cloud hosting, and Integration platforms
NIS2 applies to many more organisations than before. You are likely subject to the legislation if you are active in one of these categories:
How Joinly helps you become NIS2 compliant
Joinly serves as the control and automation layer on top of Microsoft Entra ID for Identity & Access Management:
HR-gestuurde provisioning
Wij koppelen je personeelssysteem aan de werkomgeving, zodat:
- accounts automatisch ontstaan bij indiensttreding
- toegang direct wordt geblokkeerd bij vertrek
- een functiewijziging automatisch leidt tot de juiste toegang
Rol- en toegangsgovernance
Rollen gekoppeld aan functie en aan afdeling of organisatieonderdeel:
- behandelaar, beleidsmedewerker, baliemedewerker en teamleider elk het juiste profiel
- transparante vertaling van rol naar rechten
Logging & Compliance reporting
wij verzamelen en structureren logboeken van provisioning, audittrails en uitzonderingsrapporten
- toegang en wijzigingen zijn inzichtelijk voor audits en incidentrespons
- compliance met het normenkader is aantoonbaar
SCIM & applicatie integraties
Gebruikers automatisch gekoppeld aan applicaties voor dienstverlening en bedrijfsvoering:
- geen silo's buiten de centrale werkomgeving
- volledige controle over toegang
Where governments often get stuck
manual provisioning and offboarding
no central RBAC / role structure
limited logging capabilities
no integration with HR or authorisation processes

What you achieve with NIS2-compliant IAM
Prepare your government organisation for secure access, reduced administrative burden, and smooth audits.
Faster NIS2 audit preparation
Your IAM structure is pre-configured to meet compliance requirements, reducing audit time and the need for corrective work.
Less manual management work
Automated compliance without additional operational pressure on IT teams.
Automatic lifecycle governance
Onboarding, role changes, and offboarding are automatically processed in Entra and connected applications. No manual actions required.
Security maturity
Your IAM grows with Zero Trust and modern security standards, without added complexity.
IAM scan for government
Do you want to know:✅ how compliant your IAM landscape currently is✅ where the biggest risks are✅ concrete next steps to become NIS2-proof
Schedule a FREE NIS2 IAM Scan with our experts
Ask away
Frequently Asked Questions
If you're having trouble with the frequently asked questions, feel free to send us a message.
Frequently Asked Questions
Joinly is an Identity & Access Management (IAM) platform that automatically manages who has access to what within your organization. We integrate your HR system with Microsoft Entra and other applications so accounts and rights are automatically created, adjusted, and removed. No separate scripts. No manual lists. Just control.
Joinly integrates with the standard HR systems used by government agencies and translates that data to the work environment. Ask for the current list of integrations.
Microsoft Entra provisioning is powerful, but encounters limits once processes become more complex. Think of multiple HR systems, advanced rights matrices, approval flows, or temporary access. Joinly adds a governance layer on top of Entra. The platform determines who gets which roles, manages workflows, and monitors the user lifecycle. This makes Entra operational, while Joinly takes charge.
Joinly can integrate with almost any HR system that has an API or a reliable export option. In practice, organisations often work with systems such as AFAS, Visma YouServe, Nmbrs, or Dayforce. The core is that HR becomes the source for identity data. Once that foundation is in place, Joinly automatically translates changes to the rest of the IT landscape.
No. Microsoft Entra is often the starting point, but Joinly can also manage on-premises Active Directory and provision SaaS applications via API or SCIM. Even systems without modern APIs can be integrated through smart integrations into the workflow. Joinly is not limited to one platform but serves as a central layer between HR and all target applications.
IAM can be complex, especially as organisations grow and processes become fragmented. Joinly makes that complexity manageable by reducing everything to clear roles, resources, and lifecycle events. A hiring, role change, or termination is automatically translated into access management. The technology behind it is powerful, yet it remains comprehensible and predictable for the organisation.
When a new employee is created in the HR system, Joinly automatically detects this change. Based on function, department, or other characteristics, the appropriate roles are determined. Accounts are then created and rights assigned in the integrated systems. Any approvals are automatically handled. This way, an employee has the right access from their first working day.
Upon an offboarding, Joinly ensures that access is revoked timely and in a controlled manner. Accounts are deactivated, group memberships are removed, and access rights are rescinded. The entire process is documented in the audit log, making it demonstrable what has happened. This prevents security risks and forgotten accounts.
Yes. Joinly supports temporary access, for example, for projects or external employees. Access can be granted with a fixed end date, after which it is automatically revoked. If desired, an approval flow can be set up in advance. This keeps temporary access manageable and controllable.
Start with the IAM quick-scan or schedule a demo to see where the greatest benefits are.
Knowledge Articles

Hoe richt ik rolgebaseerde toegang (RBAC) en least privilege in bij een gemeente?
Begin bij de functies in je personeelssysteem en vertaal die naar rollen, niet naar losse rechten per persoon. Koppel aan elke rol precies de toegang die de functie nodig heeft, het principe van least privilege. Beheer die rollen centraal en laat een orchestratielaag ze automatisch toekennen en intrekken. Zo blijft toegang voorspelbaar, beperkt en aantoonbaar.
Mike Fraanje · 4 min leestijd

Wat betekent de Cyberbeveiligingswet (NIS2) voor het toegangsbeheer van gemeenten, provincies en waterschappen?
Gemeenten, provincies en waterschappen worden onder de Cyberbeveiligingswet automatisch aangewezen als essentiële entiteit, ongeacht hun omvang, en vallen daarmee onder proactief toezicht. Toegangsbeheer is een vast onderdeel van de zorgplicht: toegang moet beperkt, rolgebaseerd en aantoonbaar zijn. Geautomatiseerd accountbeheer met logging is de praktische manier om daaraan te voldoen.
Mike Fraanje · 4 min leestijd

Hoe trek ik bij uitdiensttreding automatisch alle toegang van een medewerker in?
Koppel het personeelssysteem aan een orchestratielaag boven Microsoft Entra ID of Google Workspace. Zodra de uitdienstdatum in het personeelssysteem staat, trekt die laag op dat moment automatisch het account en alle gekoppelde rechten in, of schort ze op. Zo voorkom je actieve accounts van vertrokken medewerkers en leg je elke wijziging vast in een logboek.
Marcel van Beek · 4 min leestijd

Wat vraagt de Baseline Informatiebeveiliging Overheid op het gebied van toegangsbeheer voor medewerkers?
De Baseline Informatiebeveiliging Overheid vraagt dat toegang voor medewerkers gecontroleerd wordt verleend, beperkt blijft tot wat nodig is voor de functie, periodiek wordt beoordeeld en bij vertrek direct wordt ingetrokken. Kort gezegd: rolgebaseerde toegang, least privilege, logging en een sluitende levenscyclus van accounts. Door het personeelssysteem te koppelen aan de werkomgeving automatiseer je precies die eisen.
Marcel van Beek · 3 min leestijd


