The problem in plain language
A person joins the business on Monday. HR has the employee record. The manager knows the role. IT knows which applications exist. Yet the employee still spends the first days requesting access one system at a time, waiting for managers to approve it, asking the service desk for updates and discovering new missing permissions only when real work begins.
This is often treated as an onboarding inconvenience. That framing is too shallow. It is an operating-system problem: the organisation has not converted a known business event—someone joining, changing role or leaving—into a reliable set of digital access actions.
What the buyer is actually trying to solve
The search language around this problem tends to be practical rather than architectural: “new employee access takes too long”, “automate employee provisioning”, “joiner mover leaver workflow”, “HR to IT onboarding automation”, or “how to give new starters the right system access”. Those searches are different descriptions of the same control gap.
The commercial signal is strong when onboarding repeatedly requires tickets, spreadsheets, email approvals or a person who knows which applications each role normally needs.
Evidence: modern identity platforms already model the lifecycle explicitly
Microsoft's current Entra documentation describes identity governance around a joiner-mover-leaver lifecycle. Its lifecycle workflow capabilities can add users to groups and teams, assign licences and access packages, update attributes, run custom tasks, disable accounts and remove access when a person leaves. Microsoft also documents HR-driven provisioning, where an authoritative HR source can trigger user provisioning and downstream changes.
The point is not that every organisation should buy a particular Microsoft feature. The useful evidence is architectural: mature identity operations treat employment state as a trigger, access as a governed entitlement, and downstream provisioning as a workflow that can be monitored and audited. If a business still relies on manual remembering, the process is operating below that standard.
Who owns the problem?
The immediate owner is usually IT, identity or service management. The budget owner may be the CIO or COO because the consequence is broader than security. HR is an essential data owner, managers are access decision-makers, application owners are technical evaluators, and the employee is the end user.
This split ownership is exactly why the problem survives. No single team can fix it by working only inside its own system.
Why it becomes urgent
Priority rises when headcount grows, the business opens new locations, a merger introduces more applications, onboarding delays become visible to executives, or an audit exposes inconsistent access removal. It also becomes urgent when role changes happen frequently: a company may automate new-hire accounts but still leave “movers” with a mixture of old and new permissions.
The economic consequence is wider than day-one productivity
- Lost productive time: paid employees wait for systems required to do the work they were hired to perform.
- Service-desk labour: IT spends time processing repetitive requests that follow predictable rules.
- Management overhead: managers repeatedly approve or chase access instead of making one role-based decision.
- Licence leakage: licences remain assigned after role changes or departures.
- Control risk: inconsistent joiner, mover and leaver handling makes it harder to prove that access is appropriate and removed on time.
Do not apply a generic percentage to these costs. Measure your own time-to-ready, number of onboarding access tickets, manual touches, licence removals and exceptions.
The likely root causes
The symptom “access takes too long” can have several causes. The most common architecture failures are an HR system that is not treated as the authoritative lifecycle source; no agreed mapping from role to baseline access; applications that are provisioned independently; approval rules that differ by department; incomplete integration capability; and no exception process for unusual roles.
Automation without those decisions merely moves confusion faster.
A practical intervention
- Define the authoritative event source for join, move and leave events.
- Map baseline access by role, department, location and employment type.
- Separate automatic baseline access from access that genuinely requires approval.
- Connect the identity layer to applications using supported provisioning mechanisms or controlled workflow integrations.
- Design exceptions explicitly: contractors, temporary elevation, cross-functional roles and failed provisioning.
- Record every automated and manual decision so the lifecycle can be audited.
- Measure time from authoritative lifecycle event to “ready to work”, not merely account creation.
Diagnostic questions
- Can HR create or change an employee record without anyone emailing IT?
- Can the business describe the minimum access package for each common role?
- Can IT see which downstream applications failed to provision?
- Does a role change remove obsolete access as reliably as it adds new access?
- Can a leaver workflow prove when critical access was disabled?
- Can licence recovery be triggered by the same lifecycle event?
What good looks like
A good identity lifecycle does not mean every access decision is automatic. It means predictable decisions are automated, sensitive decisions remain governed, exceptions are visible, and employment changes propagate through the digital estate without depending on memory. A new starter receives the baseline tools needed for the role; unusual access is requested deliberately; and departures remove access through a controlled, traceable process.
Where Mellorca fits
This problem usually requires more than configuring one identity product. Mellorca can map the joiner-mover-leaver operating model, identify authoritative systems and application dependencies, design role and approval logic, implement integrations, and establish monitoring for failures and exceptions. The goal is a working lifecycle across systems—not a prettier onboarding checklist.
Commercial path
A sensible path is: Discovery article → identity-lifecycle diagnostic → application/access dependency map → implementation roadmap → provisioning and workflow integration → managed monitoring.
Sources and further reading
- Microsoft Entra ID Governance: What are lifecycle workflows?.
- Microsoft Entra: Employee lifecycle automation deployment guide.
- Microsoft Entra: HR-driven provisioning.