Join our Newsletter — 33% off our NHI Course

What breaks when HR and IT keep separate user directories?

Separate directories create duplicated identities, inconsistent employee records, and slow updates when someone joins, changes roles, or leaves. In practice, that can leave access lingering after termination or force IT to work from outdated HR data. The result is more manual cleanup, weaker visibility, and a higher chance that the wrong people keep the wrong access.

How Separate User Directories Break Joiner-Mover-Leaver Accuracy

When HR and IT maintain different user directories, the core failure is not just duplication. Each system starts to describe the same person in a different way, so status changes do not propagate cleanly. That creates a governance problem: the organisation no longer has one dependable view of who the user is, what role they hold, and whether access should still exist.

The problem gets worse during routine lifecycle events. A promotion, department transfer, leave of absence, contractor extension, or termination can be reflected in one directory but not the other, which makes identity updates slow and inconsistent. In practice, that means access reviews become harder to trust because the source records themselves disagree.

When the question is “what breaks,” the most important answer is the joiner-mover-leaver workflow. A separate HR directory may be accurate for employment status but not for IT entitlements, while IT may know which accounts exist but not whether the person is still active. That split can leave orphaned access, stale account attributes, and unresolved exceptions that keep accumulating over time.

Where Identity Drift Turns Into Access Risk

Separate directories usually create an identity-matching problem before they create a security incident. If the same employee has two records, each system may use a different identifier, manager, or department value, and those mismatches complicate provisioning, deprovisioning, and audit trails. The result is weaker traceability from employment event to account change.

That traceability matters because access decisions depend on timely, accurate upstream data. If IT receives late or incomplete updates, it may leave permissions in place after termination or fail to remove access when a role changes. If the organisation uses approval workflows, those workflows may also route against outdated ownership data, which slows remediation and makes exceptions more likely to be approved by mistake.

For a broader control perspective, the issue sits squarely in identity governance and access administration. Mature identity control depends on a reliable source of truth, consistent attribute mapping, and fast revocation when the employment relationship changes. Without that, the directory split becomes a persistent control gap rather than a one-time data quality issue.

What Organisations Need to Standardise Before the Split Spreads

The practical fix is not simply “sync the directories.” The organisation needs one authoritative ownership model for identity data, plus defined rules for which system governs each attribute. HR should usually own employment state and core worker attributes, while IT or IAM processes should own account state, entitlements, and technical lifecycle actions. If ownership is ambiguous, the split reappears in a different form.

A useful test is whether a change in HR can be turned into a dependable access action without manual interpretation. If a role change, termination, or rehire still requires someone to reconcile records by hand, the environment has not actually solved the problem. It has only added a second system that looks official but still depends on human cleanup.

Teams should also watch for the downstream effect on access reviews, audit evidence, and incident response. When directories disagree, reviewers spend more time validating identity records than evaluating privilege, and responders lose confidence in whether a disabled account should have been disabled elsewhere too.

Risk and Threat Considerations

Separate user directories raise the likelihood of stale access, delayed deprovisioning, and misassigned entitlements, especially when departures and role changes are processed manually. That creates a practical exposure window where the wrong account can remain active after the person’s business need has ended.

Failure mechanism: Identity drift between HR and IT causes lifecycle events to be recorded inconsistently, so account disablement, role updates, and access removals do not happen on the same timeline.

Impact: The organisation can end up with lingering access, weaker auditability, more false confidence in records, and a larger blast radius if a stale account is abused or forgotten.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 IA-5 — Authenticator Management Separate directories often leave stale accounts and credentials unmanaged across lifecycle changes.
AC-2 — Account Management The question is about lifecycle drift across user records and account state.
AC-6 — Least Privilege Directory mismatch can leave people with more access than their current role requires.
Recommendation — Enforce centralized credential lifecycle controls so account updates and removals happen consistently. Use centralized account management to keep provisioning and deprovisioning aligned with employment status. Revalidate entitlements at role change and remove excess access promptly.
NIST CSF 2.0 PR.AA-05 — Identity and Access Management The issue is fundamentally about reliable identity governance and access decisions across systems.
ID.AM-01 — Physical devices and systems are inventoried Dual directories create inventory ambiguity over which identity records and accounts exist.
Recommendation — Align identity sources so access decisions are based on one trustworthy lifecycle path. Maintain an authoritative inventory of user records and linked accounts.
ISO/IEC 27001:2022 A.5.16 — Identity management Separate HR and IT directories directly affect identity governance and record consistency.
A.5.18 — Access rights The central consequence is access lingering after role change or termination.
Recommendation — Define one identity management process with clear ownership and authoritative attributes. Review and revoke access rights promptly when employment status changes.
CIS Controls v8 CIS-5 — Account Management The question concerns duplicated identities and delayed lifecycle updates affecting user accounts.
Recommendation — Centralize account lifecycle management and remove stale accounts quickly.

Practitioner Guidance

What to verify: Confirm which system is the system of record for employment status, manager, department, and termination date, then verify that the technical account workflow consumes those fields without manual re-entry. If any critical attribute is retyped by hand, the control is already weakened.

Decision rule: If a directory mismatch can change whether someone keeps access, treat it as an access-control defect, not a data-cleanup task. Prioritise the joins that affect deprovisioning, role changes, and privileged access first, because those failures create the highest operational and security risk.

What good looks like: The organisation can show a single, timely path from HR event to account action, with clear ownership for exceptions and a short lag between employment change and access change. The less manual reconciliation required, the stronger the control.

Practitioner takeaway: Separate directories are dangerous when they force people to reconcile identity truth by judgment instead of process. The goal is not merely consistency of records, but reliable lifecycle enforcement that removes access when the business relationship changes.