Employee identity lifecycle, driven by your HR system of record

When someone is hired, promoted or terminated, that fact starts in exactly one place: the HR system. Everything downstream of it — a practice-management login, an ERP role, a phone extension, an Active Directory account, an M365 license — should follow from that HR event automatically, not from a checklist an IT admin works through by hand after someone remembers to tell them. TA LifeCycle Manager — one platform, deployed separately for each client because the work demanded it rather than sold off a price list — watches the HR system of record and provisions or removes access across every system a role change touches.

Three deployments, three HR sources

The same platform runs against three different HR systems, because that's what each client actually runs on payroll:

DeploymentHR sourceSystems provisioned
Multi-specialty dental support organizationUKG ProDenticon, Cloud9, RingCentral, AD/Entra, M365
Industrial manufacturer (oilfield)UKG ReadyNetSuite, Teams Phone, Meraki, AD/Entra, M365
Dental support organizationADP Workforce NowDentrix, Dolphin, Denticon, Peerlogic, AD/Entra, M365

Each row is its own fully isolated deployment, reading that client's HR system on that vendor's own terms. Nothing about one client's data or credentials is reachable from another's. Those terms differ more than a procurement checklist suggests: ADP Workforce Now holds an integrator to a materially stricter standard than either UKG product does, and meeting it is work you do once per vendor and never get to reuse. The dental support organization on ADP is where we did it (read the case study).

What happens when the target system has no write API

Denticon has no write API. Cloud9 deprecated the one it had. So provisioning or de-provisioning a step against either system can't just fire an API call and assume it worked, because there's no call to fire. Instead that step is handled through a verified manual path, with evidence attached, and confirmed automatically afterwards rather than assumed. Access is reconciled continuously against what every connected system actually grants, so drift surfaces as a routine report rather than as something an auditor finds first.

TA LifeCycle Manager Denticon Dentrix Enterprise Dolphin Cloud9 Ortho NetSuite RingCentral Teams Phone Meraki AD / Entra ID Microsoft 365 UKG Pro UKG Ready ADP Workforce Now
TA LifeCycle Manager at the center: UKG Pro, UKG Ready and ADP Workforce Now feed it, and it provisions access out to every downstream system it touches.

Offboarding, timed around how the paperwork actually moves

An HR termination packet goes to the employee's work email address, never their personal one. If the mailbox is disabled the instant the HR event fires, that packet has nowhere to go. So offboarding is sequenced rather than instantaneous: a departing employee's final paperwork still reaches them, and only then is access fully removed and the mailbox handed over to whoever inherits that work. Getting that order wrong is how a clean termination turns into an HR problem three weeks later.

If your HR system already knows, but nothing downstream does

Tell us which HR platform you run and which downstream systems still get updated by hand. Send us the details, or book a call to walk through what a deployment against your systems would look like. For the full list of systems we connect to, see systems integration.