The context: a media group without a usable HRIS system
The client is a media group with more than 1,000 users, a hybrid IT infrastructure, and business users with very diverse profiles. On paper, the requirement is standard: to automate new hires, terminations (including immediate terminations), job changes, and contract renewals.
Two factors make this project less standard. The first: the client has an HRIS but does not want to connect it to the IAM platform. This means no real-time data feed on personnel changes and no automated “single source of truth” for HR. Any event in the lifecycle will have to be triggered by other means.
Second: the group requires very granular management of application rights. Each user must be granted specific access rights and roles, determined by their position and department. This is not a blanket assignment. It is tailored to each individual position.
The client is not looking to develop expertise in the IAM tool. Their request is clear: to delegate the entire configuration process to Youzer and focus on business operations.
The "Do It For You" Approach: Youzer sets it up, the customer takes the lead
The project begins with three deliverables provided by the client: a requirements specification, workflow scenarios, and an Active Directory attribute mapping.
The Youzer team analyzes the requirements document, identifies any ambiguities, and clarifies them with the client. Then the configuration process begins, without waiting for a perfect requirements document.
The “Do It For You” principle: Youzer configures, tests, and presents the results to the client. The client approves or makes adjustments. Technical discussions are limited to topics that require them: connecting to the group’s database, API integration with their ticketing tool.
This approach has a practical advantage: IAM expertise remains with Youzer. The client articulates a business requirement (“when an employee changes positions, their access rights must change accordingly”), and Youzer translates that requirement into configuration settings (workflows, matrices, differential calculations). The client doesn’t need to understand how it works for it to function properly.
Forms as a source of truth instead of the HRIS
Without an HRIS connector, another mechanism is needed to feed life-cycle events into the platform. The solution chosen: dedicated forms for each situation. A form for hiring, one for resignation, one for a job change, one for contract renewal, and one for immediate termination.
In practical terms, Youzer has become the group’s identity repository. The initial dataset was built through an initial import from the HRIS (historical data migration). Since then, every personnel change is processed through a form that automatically triggers the associated workflows: creating accounts, assigning permissions, requesting hardware, or—conversely—deactivating and revoking access.
To ensure the system's security, the group's employees access the forms via a single sign-on (SSO) connection. There is no need to create dedicated accounts on the platform: authentication is handled through the client's domain, with a guest role that limits access to the forms only.
This “HRMS-free” scenario is not all that rare. Some organizations are unable to connect their HRMS (due to technical limitations or the vendor’s refusal), while others simply choose not to. The important thing is that the absence of an HR connector does not prevent the automation of the lifecycle. It changes the point of data entry, not the ability to process the data.
Rights Management Using Cascading Matrices
This is the most fundamental part of the project. The group does not operate using simple rights packages. Each user is granted application access and roles that depend on the exact combination of their position and department.
The system is based on a chain of matrices. A main matrix first calculates the user’s profile based on two variables: their position and their department. This profile then feeds into secondary matrices that determine the assigned role for each application. The result: an employee in the marketing department with the role of project manager will not have the same access privileges as a project manager in the editorial department, even if the job title is identical.
This cascading system also allows for the smooth management of job changes. When an employee changes roles or departments, a differential calculation automatically compares the old profile with the new one. Outdated permissions are revoked, and new permissions are granted. There is no overlap, and no residual permissions are overlooked.
Integration goes beyond application access. Workflows also trigger API calls to the client’s ITSM system to automatically generate requests for physical resources: workstations, ID badges, and specialized equipment. The entire onboarding and offboarding process is covered, from the Active Directory account to the request to return an ID badge.
Results and Schedule
The project spanned six months from the receipt of the requirements specification to go-live. A functional first draft was delivered within two months. The following four months were devoted to making adjustments: refining the templates, handling special cases, and stabilizing API integrations.
This timeline reflects a common reality in complex IAM projects. The initial setup goes quickly. It’s the iterations that take time, because requirements become clearer as testing progresses, and certain scenarios only come to light once the system is in use.
Today, the group manages its day-to-day operations independently. Hires, departures, and job changes are processed through forms and handled automatically. Structural changes (such as creating a new position or changing department names) are still managed by Youzer as part of the managed service to ensure overall consistency.
This project illustrates an important point: incomplete requirements, a disconnected HRIS, or highly granular access rights management are not reasons to postpone an IAM project. These are practical constraints, and the managed service exists precisely to address them. The client provides business knowledge, while Youzer provides IAM expertise and configuration. The project moves forward in iterations, not based on exhaustive specifications.
If your organization has a similar need, the "Do It For You" model lets you get started without having to assemble an in-house IAM team.






