HR Grease | Issue #004 | For HRIS practitioners who keep the machine running

———————————————————————————

In this issue:

  1. The access control mistake almost every HRIS implementation ships with

  2. Hot Take: access reviews are an HRIS problem, not a security team problem

  3. Quick Win: the access audit you can run this week, no ticket required

———————————————————————————

01 — The Grease

The RBAC mistake that doesn't surface until it's already a problem

Most RBAC design happens once during implementation and then gets treated as finished. That's the mistake.

When a system goes live, access setup usually follows one of two shortcuts: mirror the org chart, or copy whatever the legacy system had. Both feel efficient. Both quietly encode the same flaw they describe who reports to whom, not who should be able to see what.

The org chart tells you nothing about data sensitivity. A manager who needs visibility into their team's schedules doesn't automatically need visibility into comp history or disciplinary records but role templates built off reporting lines tend to bundle all of it together, because splitting it out takes implementation hours nobody budgeted for.

Here's why it doesn't surface immediately:

  1. Nobody checks access when nothing goes wrong. RBAC is invisible infrastructure. It doesn't throw errors. It just quietly grants more than it should.

  2. Reorgs inherit the original template. Every promotion or new manager gets slotted into the same role group, so over-provisioning compounds instead of resetting.

  3. The audit that would catch it usually isn't scheduled. Security teams audit systems they own. HRIS access often falls into the gap between HR and IT.

  4. The first sign is usually a person, not a report. Someone notices they can see a coworker's salary. Or a former employee's account still has live access three weeks after termination.

  5. By then, it's not a config fix it's a disclosure conversation.

The problem isn't that access gets granted wrong once. It's that nobody owns checking whether it's still right.

The practical fix isn't a bigger RBAC redesign project. It's assigning one name separate from whoever owns the org chart to a recurring access review. If that name doesn't exist at your org right now, that's the actual gap.

———————————————————————————

02 — HOT TAKE

Access reviews are an HRIS problem. Stop routing them to security.

Most orgs treat RBAC review as a security or compliance function checked once a year during an audit, by someone who has never opened the role configuration screen.

That's backwards. Security teams can confirm access controls exist. They can't tell you whether a "Regional HR Manager" role should include comp data for a region that manager doesn't cover that requires knowing the system's role architecture, which is an HRIS admin's job.

I've seen orgs pass a clean security audit on RBAC and still have people looking at data they had no business seeing, because the audit tested that roles existed and were named consistently not that the grants matched the job.

The real question isn't whether your org has an access control policy. It's whether the person maintaining your HRIS role architecture is the same person reviewing whether it's still accurate.

———————————————————————————

03 — Quick Win

For any HRIS platform: run this access spot-check this week

You don't need a full audit to catch the most common problem. Do this instead:

  1. Pull the role assigned to your highest-headcount manager tier — not an executive, a frontline or mid-level role, since that's where over-provisioning hides.

  2. List every data field and report that role can access — the actual grant list, not just the role name.

  3. Ask one question per field: does this role need this to do the job, or did it inherit it from a template?

  4. Flag anything you can't justify in one sentence. That's your starting list.

Under 20 minutes, and it's the fastest way to find out if your implementation-era assumptions still hold up.

———————————————————————————

📊 Quick Poll

Have you ever found someone with access they shouldn't have had?

Options:

- Yes — I found it myself

- Yes — an audit caught it

- No — but I'm not fully confident

———————————————————————————

If someone forwarded this to you - welcome. 270+ HRIS practitioners are already in the loop; subscribe free at hr-grease.com to get the next one directly.

Who owns access reviews at your org - HRIS, security, or nobody? Reply and tell me, I'm curious how split that really is.

Next issue: vendor consolidation, and what happens to your integration stack when your point-solution vendor gets acquired - the part nobody plans for until the acquisition notice hits their inbox.

— JR Cecil, Lead HRIS Sysadmin & UKG Pro Specialist
linkedin.com/in/jr-cecil/

Recommended for you

View all
caret-right