Deprovisioning is the point
Single sign-on is usually sold on convenience — one password, fewer resets, happier users. That is true and it is not the main reason to do it. The main reason is that a significant share of departed employees keep working logins after their last day, not through malice but because IT deprovisioning was never triggered by HR accepting a resignation.
When identity is connected to the HRMS, that trigger exists. Access revocation becomes an assigned, escalating task inside offboarding clearance rather than something that happens when somebody notices. Given that the Code on Wages now requires wage components to be settled within two working days of the last working day, clearance has to be tight anyway.
The same logic runs forward. A new hire configured during onboarding can have access provisioned before day one, and a transfer between sites or departments can change what they see, because the employee record already knows.
Joining, moving, leaving
Joining
Access provisioned from the role and site configured during onboarding, so day one does not start with a request queue.
Moving
A transfer or promotion changes reporting line and site in the employee record — and access can follow, rather than accumulating permissions from every previous role.
Leaving
Revocation is a tracked clearance task with an owner and an escalation, not an assumption that IT saw the same email.
And in between
Role-based access inside Bhivo follows your real hierarchy, so a regional head sees their region without being made an administrator.
