A category of platform — Rippling is a prominent example — promises to unify what have traditionally been separate worlds: HR provisioning (hiring, role changes, offboarding) and IT provisioning (accounts, access, devices). The appeal is obvious and real: when someone joins, moves or leaves, the HR event and the IT access change are the same event, and running them as one process rather than two disconnected ones closes gaps that cause both friction and security risk. But merging IT and HR provisioning also concentrates two sensitive domains in one platform, and doing it safely means capturing the security upside without creating a new concentration of risk. It is a genuine improvement done well, and a new exposure done carelessly.
Why unifying provisioning is attractive
The disconnect between HR and IT provisioning is a familiar source of both inefficiency and risk. Someone joins and their accounts and access are set up manually, late, or incompletely. Someone changes role and their access is added but not removed, so entitlements accumulate. Someone leaves and their access lingers because the offboarding did not reliably reach IT — the dormant account that becomes a security hole. Unifying provisioning solves these at the root: the HR event drives the IT change automatically, so joiners are provisioned correctly, movers have access adjusted properly, and leavers are deprovisioned reliably and promptly. That last point is a genuine security win, because lingering access after departure is one of the most common and dangerous access-governance failures, and unified provisioning largely eliminates it.
The safety considerations
- Concentration of sensitive domains. Merging IT and HR provisioning puts two sensitive systems — access control and employee data — in one platform, which is efficient and also a concentration; a compromise or failure touches both, and that dependency deserves conscious weighing.
- Access governance must stay rigorous. Automating provisioning is powerful only if the underlying access model is right; automating the granting of excessive or wrong access just makes the mistake faster. Least privilege has to be built in, not assumed.
- The leaver process must be reliable. The biggest security prize is reliable deprovisioning; confirm that the platform genuinely removes access promptly and completely when someone leaves, because that is where the value concentrates.
- Data protection across the merge. Employee data and access data together raise the data-protection stakes; how the platform handles and secures that combined sensitive data matters.
Doing it safely
- Capture the deprovisioning win deliberately. Ensure the unified process reliably and promptly removes access on departure and role change, because that is the security upside that justifies the approach.
- Get the access model right first. Automate provisioning on top of a least-privilege access model, so the automation grants correct access quickly rather than wrong access efficiently.
- Weigh the concentration consciously. Accept the concentration of IT and HR in one platform as a deliberate trade for the integration benefit, with awareness of the dependency it creates.
- Protect the combined sensitive data. Apply the data-protection and security rigour that access data and employee data together warrant.
Merging IT and HR provisioning is a genuine improvement when done safely, because unifying the joiner-mover-leaver process closes exactly the access-governance gaps — especially lingering access after departure — that cause real security risk. The firms that get it right capture that deprovisioning win deliberately, build the automation on a sound least-privilege access model, and accept the concentration of two sensitive domains consciously rather than by accident. Done that way, unified provisioning turns a fragmented, gap-prone process into a reliable, secure one; done without attention to the access model and the concentration, it just automates whatever was already wrong, faster.
Free · 4 minutes
Would you survive contact with a determined attacker — or an auditor?
Fourteen questions on access, patching, detection, and recovery — the basics that prevent most real incidents, and the ones most often assumed rather than verified. Banded finding on screen, full sheet by email.
Who this is for
This reading is for:
- CTOs and CISOs weighing platforms that unify IT and HR provisioning
- IT and HR leaders tired of disconnected joiner-mover-leaver processes
- Firms considering tools like Rippling that span HR and IT
- Boards interested in the security upside of unified provisioning
Sixteen Pillars helps firms capture the deprovisioning win deliberately, build provisioning on a sound least-privilege model, and accept the IT/HR concentration consciously. Pricing is published at /pricing/. If this is live for your organisation and you would like an independent reading, the place to start is a conversation.
Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.
Free interactive tool
Website compliance checklist
What your site has to do, based on what it actually does
Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.
Everything that applies
Ordered by what to do first: legal requirements you can close quickly, then larger pieces of work, then what is expected rather than required. Not exhaustive, and not a legal audit.
Dated PDF, yours to keep or circulate.
Free interactive tool
Interactive deadline calculator
Check which regulations apply to you and when
Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.
Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.
Most technology problems are not technology problems. They are control problems.
The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.
Full Governance by Sixteen Pillars
Govern your business. Prove your compliance.
A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.
See what's coming