One reliable picture of who exists
Identity data collected from the systems that hold it, reconciled, and kept aligned. Everything downstream is guesswork until this is true.
Contractors, seasonal staff, partner engineers, service accounts and now software agents all need access to the same systems — at different assurance levels, on different timelines, and mostly without ever appearing in the HR system.
Workforce IAM is usually designed around the first row and then extended, apologetically, to the other three. Read down the last column: that is where the programme actually is.
| Who | Where they come from | Who owns the lifecycle | Where it breaks |
|---|---|---|---|
| Employees | HR system | HR, with a defined process | Almost none at joining. The gap opens when they move team. |
| Contractors and consultants | Procurement, or an email to IT | The manager who hired them | No end date anybody enforces. Access outlives the engagement. |
| Partner and supplier staff | The partner organisation | Nobody inside your company | You are told when they arrive, never when they leave. |
| Service accounts and agents | Whoever needed one, whenever they needed it | Often the person who has since changed role | No lifecycle at all. Removal is assumed to be somebody else's risk. |
Nothing on this page is about employees. They are the case that already works.
Independently of who supplies it — this is the shape of the problem.
Identity data collected from the systems that hold it, reconciled, and kept aligned. Everything downstream is guesswork until this is true.
Joining, moving and leaving drive entitlements from an authoritative source, rather than from a ticket somebody remembers to raise.
The same person should not face the same authentication for a canteen booking and a payment run. Assurance belongs to what is being reached.
A session has a lifetime and a scope that can be shortened or ended from outside the application, without waiting for the next sign-in.
Entitlements expressed once, centrally, in terms the business recognises — not as a drifting copy inside each application.
Who had what, when, and on whose authority. If answering that takes a week of spreadsheets, it gets answered only under pressure.
Connectors bring identities and entitlements in from directories, HR sources and the applications themselves. Reconciliation keeps the picture aligned, instead of accurate once, at go-live.
Joiner, mover and leaver are flows on a canvas: the branches for the contractor, the transfer and the long absence are drawn rather than buried in a script one person understands.
Single sign-on with multifactor authentication in front of the applications, with step-up where the risk justifies it and session control that does not wait for the token to expire.
Usually it is the contractors, the service accounts, or the people who moved teams and kept everything. We'll map it with you.
Talk to an expert