Every workforce event starts in Workday. But without a direct governance layer, provisioning, access recalculation, and revocation still depend on manual IT follow-up, delayed, inconsistent, and impossible to verify at scale.
A new hire record created in Workday does not automatically provision an IdP account or application access. IT opens a ticket. The new employee waits. The delay is a productivity gap on day one and a governance gap every day after.
When an employee changes department or title in Workday, old entitlements are rarely removed. Access accumulates with every move. Privilege creep becomes the norm.
A termination in Workday closes the HR record. But access in your IdP, SaaS applications, and on-prem systems frequently remains active for days or weeks. Offboarding looks complete. The access is still there.
BalkanID connects to Workday via Workday and handles every Joiner, Mover, and Leaver event automatically, provisioning and deprovisioning across your IdP and every connected application.
Automated Joiner provisioning on day one
Peer-analysis birthright access, no guesswork
Atomic Mover updates, grant and revoke in one operation
Immediate Leaver deprovisioning and account suspension and verification of deprovisioning of access
Each JML event type is triggered by a Workday event delivered via Workday. Fully customisable to your organization's provisioning policies and approval workflows.
Connect Workday and IdP to BalkanID Playbooks via webhook or scheduled sync
Define provisioning policies, approval routing, and birthright access rules
Every JML event triggers the right playbook automatically, no manual steps
Full audit trail, approval records, and policy evidence, always ready

BalkanID gives your team a live, continuously governed identity lifecycle, not a monthly report that is stale before it lands.
Right access on day one. Removed the same day they leave.
Peer analysis ensures no over-provisioning. RBAC and ABAC policies enforced automatically.
Centralized, immutable audit logs. Compliance reviews become a report export, not a fire drill.
Three things that make BalkanID JML different from the ITSM tickets and spreadsheets you already rely on.
Every JML event triggers an automated playbook the moment it occurs in Workday, not when someone opens a ticket or remembers to act.
Birthright access is determined by analysing real colleagues with the same role, department, manager, and employment type, not from a static template someone built years ago.
Every execution, approval, grant, and revocation is logged in a centralized, immutable audit trail. RBAC, least privilege, alerts, and dashboards, included, not bolted on.
Connect Workday to BalkanID and have your first JML Playbook live in hours. Zero manual provisioning. Full audit trail from day one.