All articles
·9 min

Automated onboarding and offboarding: grant access in 2 hours, revoke it in 2 minutes

Day 1 without an email account, day 400 with access to everything

Two problems that look like opposites share the same root cause: nobody owns the process by which a person gains and loses access to company systems. A new hire waits days for an ERP account. A former employee stays in Slack and the CRM for months after their last day.

The numbers we consistently see at companies with 50-250 employees:

  • 8-14 systems where a new person needs an account: email, ERP, CRM, VPN, ticketing, project tool, cloud storage, time tracking, building access, plus 2-3 department-specific apps
  • 4-9 hours of administrative work per new hire, split between HR, IT and the direct manager — email requests, approvals, account creation, ordering a laptop
  • 2-5 working days until the person has everything they need; until then they look over a colleague's shoulder or work from a borrowed login
  • On departure, 20-40% of accounts stay active 30 days after the last working day
  • 15-25% of monthly paid licenses belong to people who no longer work there. On a typical stack at 35-45 EUR/user/month with 120 employees, that's 700-1,300 EUR/month spent on nobody

The uncomfortable part: nobody is doing a bad job. The process simply doesn't exist as a process — it exists as a set of habits, a spreadsheet checklist, and three people who each remember something different.

What automated provisioning actually looks like

The core idea is simple: one source of truth for "who works here and in what role", usually the HR system. From there, four events trigger everything else automatically:

1. Hire — the identity is created in the central directory (Entra ID or Google Workspace), role-based groups are applied, accounts propagate into connected applications, and tasks open for laptop, phone and building access

2. Role or department change — new access is granted and, more importantly, old access is removed; the step almost everyone skips

3. Temporary suspension (long medical leave, secondment) — accounts are disabled without losing data

4. Departure — sessions and tokens invalidated, accounts disabled, mailbox delegated to the manager, cloud files transferred, licenses released back to the pool

Technically it works in two layers: HR to the central directory (API or a dedicated connector), then the directory to applications via SCIM where it exists, via API where it doesn't, and via an auto-filled ticket for legacy systems that have neither. Not everything can be automated — but everything can be triggered, tracked and evidenced.

Why the spreadsheet checklist doesn't hold

Almost every company already has an onboarding checklist. Here's why it fails:

  • It depends on one person's memory. When they're on holiday, steps get skipped.
  • It ignores role changes. Someone who has moved through three departments in five years holds access from all three. It's called privilege creep, and it's the single most common finding in any serious audit.
  • It leaves no trail. In an ISO 27001 audit or a NIS2 assessment, "we took care of it" is not evidence. A log showing who requested, who approved and when it executed is.
  • Nothing is ever reconciled. Nobody compares the HR roster against the list of active accounts. The first time you measure that gap, it's usually wider than anyone expected.

Case study: technical services firm, 140 employees

A company we worked with at NEXVA SYSTEM had 11 systems with user accounts and 60-70 joiners and leavers per year, including seasonal field staff. Onboarding took an average of 3.5 days to full access, and the last internal audit found 34 active accounts belonging to people who had left — the oldest 14 months old.

What we built:

  • The HR system became the single source of truth; every hire, role change or departure emits an event into an orchestrator
  • A role-based access matrix: 9 roles defined together with department heads, each with an exact list of groups and applications. Anything outside the matrix requires explicit approval and expires automatically after 90 days
  • Automatic propagation into Entra ID and, via SCIM or API, into 6 of the 11 applications; for the remaining 5 (two legacy apps, building access, vehicle fleet, supplier portal) the system opens pre-filled tickets with deadlines and escalation
  • A daily reconciliation job comparing HR, the central directory and every application, flagging any account that shouldn't exist
  • A dashboard for IT and HR: time to full access, blocked steps, orphaned accounts, free licenses in the pool

Results after 6 months:

  • Time to full access: from 3.5 days to under 4 hours for standard roles
  • Administrative work per new hire: from ~7 hours to under 45 minutes, almost all of it approvals
  • Orphaned accounts at audit: from 34 to zero, with disablement averaging 6 minutes from the departure being recorded in HR
  • 9,400 EUR/year in reclaimed licenses, purely from seats released correctly and reused from the pool
  • The ISO 27001 audit passed with no findings on access control — for the first time

What deliberately stays with humans

Automation doesn't remove decisions. These stay with people, explicitly:

  • Approving privileged access — administrators, financial data, customer personal data
  • Exceptions to the matrix — approved by name, with a written reason and an expiry date
  • Systems without an API — a human executes, but the ticket arrives pre-filled with every detail and escalates if it stalls
  • The day-1 conversation — a good system frees up the manager's time for exactly this

Costs and ROI

For a company with 50-250 employees and 8-12 systems:

| Component | Cost |

|-----------|------|

| Process analysis + role-based access matrix | 2,000-4,000 EUR |

| HR + central directory integration (Entra/Google) | 3,000-6,000 EUR |

| Application connectors (SCIM/API), 5-10 systems | 4,000-9,000 EUR |

| Daily reconciliation, dashboard, audit reports | 2,500-4,500 EUR |

| Monthly maintenance | 150-400 EUR/month |

The business case closes from three directions, not one: reclaimed licenses (5,000-12,000 EUR/year at 100-200 employees), saved administrative hours (5-8 hours per new hire, which at 50 hires/year is over 250 hours), and recovered productive days — someone who genuinely starts working two days earlier, at a loaded cost of 120-180 EUR/day, is worth 12,000-18,000 EUR/year across 50 hires. The avoided security risk isn't in the math, but it's usually what convinces the board.

Common mistakes

  • Starting with the tool instead of the matrix. Without a clear definition of what "sales rep access" means, any tool just becomes a more expensive way to create the same mess.
  • Big bang across all 12 systems. The first two should be email and the central directory, then two more per month. One connector that works beats five that half-work.
  • Deleting instead of disabling. On departure, disable the account and retain it for 30-90 days. Immediate deletion leads to data loss and unpleasant meetings.
  • Only joiners and leavers. Role changes are half the access problem and are almost always ignored.
  • No reconciliation. Every provisioning system drifts over time. The daily comparison job is what turns automation into an actual control.

How to start

1. Count honestly: how many systems hold user accounts, how many accounts are active, and how many people are on the HR roster. The gap is your starting point.

2. Write the access matrix for the first 5-8 roles, together with department heads.

3. Automate offboarding first — it's simpler, it pays back immediately in cost and risk, and it blocks nobody if it needs tuning.

4. Then onboarding, starting with the roles you hire for most often.

5. Add daily reconciliation before expanding to the remaining applications.

System access is one of the few processes where automation pays off simultaneously in money, time and compliance. It's also the easiest to prove: one list of orphaned accounts usually ends the debate.

Want to see how many active accounts you have with nobody behind them, and what that costs you every month? Book a free consultation.

Want to discuss automating your processes?

Book a consultation