Employee identity lifecycle, driven by your HR system of record
When someone is hired, promoted or terminated, that fact starts in exactly one place: the HR system. Everything downstream of it — a practice-management login, an ERP role, a phone extension, an Active Directory account, an M365 license — should follow from that HR event automatically, not from a checklist an IT admin works through by hand after someone remembers to tell them. TA LifeCycle Manager — one platform, deployed separately for each client because the work demanded it rather than sold off a price list — watches the HR system of record and provisions or removes access across every system a role change touches.
Three deployments, three HR sources
The same platform runs against three different HR systems, because that's what each client actually runs on payroll:
| Deployment | HR source | Systems provisioned |
|---|---|---|
| Multi-specialty dental support organization | UKG Pro | Denticon, Cloud9, RingCentral, AD/Entra, M365 |
| Industrial manufacturer (oilfield) | UKG Ready | NetSuite, Teams Phone, Meraki, AD/Entra, M365 |
| Dental support organization | ADP Workforce Now | Dentrix, Dolphin, Denticon, Peerlogic, AD/Entra, M365 |
Each row is its own fully isolated deployment, reading that client's HR system on that vendor's own terms. Nothing about one client's data or credentials is reachable from another's. Those terms differ more than a procurement checklist suggests: ADP Workforce Now holds an integrator to a materially stricter standard than either UKG product does, and meeting it is work you do once per vendor and never get to reuse. The dental support organization on ADP is where we did it (read the case study).
What happens when the target system has no write API
Denticon has no write API. Cloud9 deprecated the one it had. So provisioning or de-provisioning a step against either system can't just fire an API call and assume it worked, because there's no call to fire. Instead that step is handled through a verified manual path, with evidence attached, and confirmed automatically afterwards rather than assumed. Access is reconciled continuously against what every connected system actually grants, so drift surfaces as a routine report rather than as something an auditor finds first.
Offboarding, timed around how the paperwork actually moves
An HR termination packet goes to the employee's work email address, never their personal one. If the mailbox is disabled the instant the HR event fires, that packet has nowhere to go. So offboarding is sequenced rather than instantaneous: a departing employee's final paperwork still reaches them, and only then is access fully removed and the mailbox handed over to whoever inherits that work. Getting that order wrong is how a clean termination turns into an HR problem three weeks later.
If your HR system already knows, but nothing downstream does
Tell us which HR platform you run and which downstream systems still get updated by hand. Send us the details, or book a call to walk through what a deployment against your systems would look like. For the full list of systems we connect to, see systems integration.