HRIS, IGA, ITSM, ITAM: who really manages the employee lifecycle?

Diagram showing HRIS, IGA, ITSM and ITAM connected around the employee lifecycle.

An employee’s arrival, internal move, or departure may seem like a simple event: information changes in the HRIS, then the relevant teams take the necessary actions.

In reality, the same change often needs to be reflected across multiple systems:

– the HRIS;
– directories and IAM or IGA solutions;
– ITSM;
– ITAM;
– ERP and business applications;
– document management tools;
– approval workflows;
– tools used by managers, HR, IT, and security teams.

Each tool performs its own function effectively. Yet accounts, access rights, equipment, responsibilities, documents, and approvals do not always keep pace with one another.

The problem, therefore, does not necessarily lie with the tools. It comes from the lack of a shared organizational context capable of connecting them.

The employee lifecycle is not limited to the HRIS

The HRIS naturally serves as the reference point for HR data. It generally contains information about the employee, their position, manager, location, contract, and status.

However, a change in the HRIS is not always enough to trigger all the operational consequences of that change.

When an employee joins, for example, it is necessary to:

– prepare their accounts;
– assign them the appropriate access rights;
– order or allocate their equipment;
– provide the necessary documents;
– inform their manager;
– request certain approvals;
– integrate them into the appropriate processes and applications.

During an internal move, new access rights must be added, but those that are no longer justified must also be identified.

When an employee leaves, access rights must be revoked, accounts closed or transferred, equipment recovered, responsibilities reassigned, and evidence of each action retained.

The HRIS knows about the HR event. It does not necessarily manage all the operations that result from it.

HRIS, IGA, ITSM, and ITAM: four tools, four scopes

The HRIS knows the HR situation

The HRIS records information about the employee:

– their identity;
– their position;
– their manager;
– their location;
– their contract;
– their arrival, internal move, or departure.

It is essential, but does not always manage application accounts, equipment, physical access, or external populations.

IGA governs identities and access rights

An IGA solution helps answer essential questions:

– who has access to what?
– why was this access granted?
– is it still justified?
– who requested and approved it?
– when should it be reviewed or revoked?

Identity Governance and Administration (IGA) therefore plays a key role in the creation, modification, review, and removal of access rights.

However, it does not necessarily manage the entire onboarding process, equipment, documents, business tasks, or manager notifications.

ITSM handles requests and tickets

ITSM organizes the processing of requests submitted to IT:

– account creation;
– access assignment;
– software installation;
– equipment preparation;
– incident resolution.

It structures operations, but often comes into play after a ticket has been created. It does not always have the full context explaining why a person changes roles, scope, or responsibilities.

ITAM tracks equipment and assets

ITAM makes it possible to identify the equipment assigned to a person:

– computer;
– phone;
– monitor;
– license;
– specific equipment;
– other digital or physical assets.

It knows which asset is assigned, but not always which HR or organizational change should trigger its assignment, modification, or return.

These four categories are therefore complementary. None of them necessarily has, on its own, all the context required to manage the journey from end to end. The ROK Lifecycle page specifically presents this distribution between HRIS, IGA, ITSM, and ITAM.

Infographic showing how HRIS, IGA, ITSM and ITAM connect to the real organization to manage the employee lifecycle.

Why do gaps persist between tools?

Each application has its own representation of the organization

A position may be defined differently in the HRIS, directory, ERP, IAM tool, and business applications.

Job titles, groups, profiles, and access rules multiply. When a person changes roles, each team must interpret the change and then translate it into its own system.

Access rights are still too often assigned directly to individuals

An access right may be perfectly justified on the day it is granted.

However, it can become excessive when the person:

– changes position;
– leaves a project;
– joins another entity;
– becomes a manager;
– completes a temporary assignment.

If the access right remains associated with the person rather than with the actual role they perform, access rights gradually accumulate.

Actions are not performed at the same time

The HRIS may be updated immediately while:

– the equipment is prepared several days later;
– the account is created after the employee’s arrival;
– old access rights remain active;
– documentation is not provided;
– the new manager is not informed;
– evidence is reconstructed after the fact.

The change is a single event, but its consequences are spread over time and across multiple teams.

External contractors often fall outside the standard process

Contractors, freelancers, interns, apprentices, and partners are not always managed in the same way as employees.

They may not be recorded in the HRIS or may appear there with limited information. Their access rights are then created based on an email or a ticket, without a clearly defined role or an automatically usable end date.

Evidence remains scattered

In the event of an audit, it is necessary to retrieve:

– the initial request;
– the manager’s approval;
– the justification for the access right;
– the creation date;
– any modifications;
– proof of revocation.

This information often exists, but across multiple tools. The audit then becomes a process of reconstruction.

The missing link: organizational context

To connect tools effectively, a common source capable of describing the real organization is required.

This source should not only indicate the employee’s name and manager. It should make it possible to understand:

– their position;
– their role;
– their entity;
– their location;
– their responsibilities;
– their hierarchical and functional reporting lines;
– their scope of responsibility;
– the potential duration of their assignment.

This is the role of the living organizational chart.

Unlike a static organizational chart, it is not used solely to represent the structure. It becomes an operational source capable of connecting people, roles, processes, access rights, and approvals.

When organizational data changes, that change can become a triggering event for the relevant tools.

ROK is based on this principle: the living organizational chart, synchronized with the HRIS and directories, becomes the common foundation for processes, access rights, and compliance.

From an “application-first” approach to an “organization-first” approach

In a traditional approach, each application defines:

1. its own users;
2. its own roles;
3. its own rules;
4. its own access rights;
5. its own approval workflows.

The organization must then maintain consistency between these different representations.

In an organization-centric approach, the order is reversed:

1. the real organization is modeled;
2. each person is assigned to a position and a role;
3. processes identify the right stakeholders from this source;
4. access rights derive from actual responsibilities;
5. changes remain traceable.

The objective is not to create a new isolated database. It is to provide existing tools with the same organizational context.

Why bring BOAT and IGA together?

Automation technologies have long been divided into several categories: BPM, workflow, RPA, low-code, integration, and document management.

Gartner now groups some of these capabilities under the BOAT category, for Business Orchestration and Automation Technologies. These platforms aim to unify process orchestration, connectivity, automation, and new AI-related capabilities.

But automating an action is not enough.

It is also necessary to know:

– who can perform it;
– who must approve it;
– what data can be accessed;
– what access rights are required;
– what segregation of duties rules must apply.

This is where IGA comes in.

The two approaches therefore answer complementary questions:

– BOAT: what needs to happen?
– IGA: who can do what?

ROK connects these two approaches to the same organizational foundation. Workflows and access rights are no longer configured separately: they can derive from the same position, the same role, and the same real-world change.

What does a truly orchestrated lifecycle look like?

Change
Organizational change
Actions that can be triggered
Arrival
Employee creation and assignment to a position
Accounts, access rights, equipment, documents, tasks, approvals
Internal move
New position, role, location, or manager
Removal of previous access rights, assignment of new ones, update of responsibilities
Departure
Position deactivation or end of contract
Access revocation, equipment recovery, task transfer, evidence archiving
Contractor
Defined assignment, sponsor, scope, and duration
Temporary access, approvals, expiration date, controls, and automatic revocation

Orchestration is not just about executing these actions faster.

It must also ensure that:

– the right rule was applied;
– the right person approved;
– the right access was granted;
– the previous access right was removed;
– every decision remains explainable and verifiable.

Should the HRIS, IAM, or ITSM be replaced?

No.

An orchestration strategy should not require a complete overhaul of the information system.

The HRIS can remain the system of record for HR data. IGA continues to govern access rights. ITSM handles requests. ITAM tracks equipment. ERP, document management systems, and business applications retain their respective functions.

ROK acts as an organizational orchestration foundation that connects these systems to the company’s real organizational structure.

An arrival, internal move, or departure thus becomes a shared event rather than a succession of isolated requests.

ROK is designed to integrate with the existing information system, including HRIS, ERP, SAP, CRM, document management systems, ITSM, directories, and business applications, without requiring their replacement.

What benefits can be expected?

Fewer tickets and less manual data entry

Actions can be generated from the initial change, without requiring each team to manually recreate the context.

Access rights better aligned with actual roles

Access rights are linked to the position and responsibilities rather than solely to the individual.

Better management of internal moves

An internal move is no longer limited to adding new access rights. It also makes it possible to identify previous access rights that are no longer justified.

Inclusion of external populations

Contractors can be linked to an assignment, a sponsor, a scope, and a duration.

Continuous traceability

Requests, approvals, changes, and revocations are recorded as they occur.

Better coordination between HR, IT, and security

The three departments work from the same organizational event, while retaining their own tools and responsibilities.

Novares: 11 employee lifecycle workflows in production

At Novares, the living organizational chart has become an operational foundation deployed internationally.

The solution notably covers:

– onboarding;
– internal moves;
– departures;
– exports to the HRIS;
– temporary contract management.

Novares currently uses 11 employee lifecycle workflows across 21 countries. The case presented by ROK concerns an organization of 6,000 employees, with HR approvals completed within 24 hours.

The value therefore does not lie in automating an isolated task.

It lies in the ability to maintain a consistent organizational model across roles, workflows, access rights, and responsibilities, despite changes within the company.

How to assess your own employee lifecycle?

To assess the maturity of your employee lifecycle, start with a real case and ask five questions.

1. What event triggers the change?

Is it a change in the HRIS, an email, a form, a ticket, or a manual action?

2. Which tools need to be updated?

List the directories, applications, equipment, documents, accounts, and workflows involved.

3. Who needs to take action or approve?

Identify HR, the manager, IT, security, application owners, and control functions.

4. Which actions remain manual?

Identify tickets, files, emails, manual data entry, and checks performed outside the system.

5. What evidence do you need to retain?

Determine how to retrieve the request, justification, approval, assignment, and revocation.

This analysis makes it possible to distinguish three types of problems:

– a data problem;
– a coordination problem between tools;
– a governance and responsibility problem.

Towards a truly managed employee lifecycle

The employee lifecycle should not become an additional tool.

It should become a shared flow between HR, IT, security, managers, and existing applications.

The HRIS knows the change.

IGA governs access rights.

ITSM organizes requests.

ITAM tracks equipment.

The living organizational chart provides the context that connects everything together.

When a person joins, changes roles, or leaves the company, the right actions can then be triggered for the right person, in the right tools, and with the right evidence.

Do you have a fragmented onboarding process, an internal move that takes several weeks, or a departure that is difficult to secure?

Bring us a real scenario. In 30 minutes, we identify the gaps, the tools involved, and the possible automations, without disrupting your existing information system.

Frequently Asked Questions

Can an HRIS manage the employee lifecycle on its own?

The HRIS remains the system of record for HR data, but it does not always manage accounts, access rights, equipment, documents, and external populations. Additional orchestration may be necessary.

What is the difference between IAM and IGA?

IAM primarily concerns the operational management of identities and access. IGA adds a governance dimension: access justification, access reviews, roles, segregation of duties, approval, and traceability.

Why is ITSM not enough?

ITSM effectively handles tickets and requests, but it often comes into play after a request has been submitted. It does not necessarily have the organizational context required to automatically trigger all the actions associated with a change of position.

What is a living organizational chart?

A living organizational chart is a dynamic model of the organization, synchronized with systems of record and connected to positions, roles, responsibilities, processes, and access rights.

Do existing tools need to be replaced to automate the employee lifecycle?

No. The objective is to connect the HRIS, IGA, ITSM, ITAM, ERP, document management systems, and business applications to a shared organizational context.

How can orphaned accounts be avoided after a departure?

Revocation should be triggered by the actual end of the position, contract, or assignment, rather than relying solely on a manual ticket. Each account and access right should also retain a justification and an owner.

Subscribe To Our Newsletter

Share this post

More to explore

Go ahead and get started right now!