People and the IT function: the loops that serve the employee, not the business process
- Джимшер Челидзе
- 11 hours ago
- 35 min read
This article is also available in Russian: Russian version.
The five loops in this article do not make a product and do not bring in revenue directly. What they have in common is something else: for all five, the user is an employee of the company, not a customer and not a machine. The HR loop puts the person on the books. Learning gives them knowledge. IT support fixes whatever is stopping them from working. Security protects what they were given access to. The workplace is the environment they spend their day in.
Hence their shared misfortune: they get squeezed, because their effect is only visible when they are missing. Nobody counts what a day costs when half the office has no email. Or what a month costs while a new hire is still looking for someone to ask. Or what one departing employee costs when their access was never revoked. None of these costs land in a report, so in the budget they lose to any visible project.
The second shared trait — they are the first to show what state the company is actually in. A knowledge base nobody writes into is not a system problem. Tickets that IT closes fast while the problem keeps coming back are not a service-desk problem. An engagement survey with no consequences kills trust in the next survey. Technology fixes nothing here; it makes the sharpness visible.
Below: what each of the five loops does, who needs it, and what has to be in place first. At the end — how they connect, the vendors you will actually meet, and a shared selection checklist.
What is in this article
People: HRM, recruiting, HR e-signature and WFM — the HR core and the add-ons you attach to a specific pain
Knowledge and learning: LMS and knowledge bases — why coverage beats perfection
IT as a service: ITSM and ITAM — tickets, service catalogue, asset records
Information security: DLP, IDM/IAM, SIEM — layers of defence and the order you build them in
The digital workplace: mail, office, messaging and video — the hygiene layer and how you replace it
How these five loops connect — the common entry point and the common order
The role of AI in employee-facing loops — where the return is highest and why the money does not go there
Vendors you will actually meet — common solutions by subclass
Typical mistakes and a selection checklist — the shared debrief and what to check before you buy
People: HRM, recruiting, HR e-signature and WFM
Core HR administration is simple: it is mandatory from the first employee, and the only question is whether you run it in a dedicated system or in spreadsheets with a compliance risk attached. After that comes the fork: hiring, learning, shifts, engagement — each piece is covered by a separate class, and buying them as a bundle off the back of a "unified HR platform" pitch is a reliable way to pay for things you will never use. Let us go through what exists here, what you actually need, and what gets attached as the pain arrives.
What the loop does — and what it does not
The HR loop covers everything to do with people as a company resource: records and payroll, hiring, onboarding paperwork, work schedules, learning, retention.
What it does not do: it does not build people management. The system will show you attrition, but it will not explain why one department loses people twice as fast — that is a manager's job, not a report's. And it does not replace culture: pulse surveys take the temperature, the treatment stays with management.
Subclasses: what the loop is made of
HR core: personnel records and payroll. Hires, transfers, leave, timesheets, payroll calculation, statutory reporting.
Effect: the mandatory part is closed correctly, without manual reconciliation and without exposure to penalties; people data sits in one place.
Drawback: the core is conservative and tied to employment law — updates are mandatory and their timing is not always convenient.
ATS — recruiting. Candidate funnel, vacancies, integration with job boards, communication history.
Effect: candidates do not get lost between recruiters, you can see where the funnel leaks, and what closing a role actually costs.
Drawback: it earns its keep from roughly a few dozen hires a year; for one-off hiring it is an extra layer.
HR e-signature — electronic HR documents. Applications, orders, acknowledgements, signatures — no paper and no travelling to another city to sign something.
Effect: paperwork shrinks from days to hours, especially in distributed teams.
Drawback: it requires careful handling of signatures and retention: these are legally significant documents, not a convenient chat with HR. And not everything converts to digital — depending on the jurisdiction, some categories of employment documents stay outside the scope of electronic signature frameworks such as eIDAS in the EU or the ESIGN Act in the US, and stay on paper. Check the list for every country you employ people in before you promise a paperless HR function.
WFM — workforce management. Shift rosters, overtime tracking, staffing norms, demand forecasting.
Effect: shifts are covered without firefighting and without overtime premiums; the roster stops being a manager's personal art project.
Drawback: the class is for places with shift work and hourly staff; for an office company it is redundant.
Engagement and development. Pulse surveys, performance reviews, employee goals, career tracks. Learning is the neighbouring class — covered below under Knowledge and learning: LMS and knowledge bases.
Effect: problems in teams become visible earlier than in resignation letters.
Drawback: surveys with no follow-up work against you: people answer honestly once, and then they stop.
Who needs the loop, who is too early — and what has to come first
The HR core is needed immediately and by everyone — that is a legal requirement, not a maturity question. After that, the add-ons attach to a specific pain. ATS — when you are hiring at a scale of tens of roles a year and you have more than one recruiter. HR e-signature — when staff are distributed and paper travels by courier. WFM — when you have shift staff and overtime. Engagement — when attrition has become expensive.
Too early or not needed: a "unified HR platform with everything included" for a small company means paying for functions it will grow into in years, if ever.
What it connects to and when to implement. The core goes in first and lives on its own; the add-ons go in on triggers, not as a package. Upwards, the loop feeds payroll cost and headcount data into the accounting and analytics loop; sideways, into learning. A simple rule: personnel records are mandatory by law, everything else attaches to pain, and the order here is dictated not by architecture but by what hurts most.
What the loop gives the business — and its typical drawbacks
Effect. Risk removed: HR records and documents in order means no penalties and calm inspections. Speed: hiring and onboarding stop being the bottleneck on growth. And visibility: attrition, cost per hire, overtime become numbers you can work with rather than impressions.
Drawbacks people talk about less. People data is the most sensitive data in the company: a leak hits you both legally and in terms of trust. The loop turns into bureaucracy easily: every add-on adds forms and approvals for the employee, and at some point the HR system starts getting in the way of work. And measurement without action: an engagement dashboard nobody responds to destroys trust faster than having no dashboard at all.
2026: the context
HR tech is one of the fastest-moving segments. Electronic HR documents have gone mainstream in most markets where the law allows them, and talent scarcity has forced companies to take the cost of hiring and retention seriously. Two things now shape the choice more than features. The first is where employee data physically lives and who processes it — GDPR in the EU and comparable regimes in the UAE and Singapore make data residency and processor arrangements a procurement question, not an IT one. The second is automated decisions about people: the EU AI Act puts employment-related use of AI in a category where you have to be able to explain what the system did and why, which changes what you should accept from a vendor's screening and scoring features.
Cost drivers. Almost everything in this loop is priced per employee or per seat. HR e-signature is a per-employee-per-year class: cheap per head, but its effect depends entirely on coverage — half the workforce on paper means you still run a paper process. ATS is priced per recruiter seat, so it scales with the recruiting team, not with the company. Rollout runs from a couple of weeks in a small company to several months in a distributed one. The larger line is usually not licensing but the legal work behind electronic HR documents and issuing signing credentials to every employee. Note the general shape: per-seat classes scale linearly with headcount and give you no economy of scale — doubling the workforce doubles the bill.
Knowledge and learning: LMS and knowledge bases
Knowledge in a company usually lives in three places: in an experienced employee's head, in somebody's folder on a drive, and in a chat where it was already explained once. The first leaves with the person, the second cannot be found, the third sinks. The class we are about to discuss moves knowledge from personal to corporate — and in 2026 that acquired a second meaning: a tidy knowledge base became fuel for corporate AI.
What the class does — and what it does not
An LMS is responsible for learning: courses, tests, learning paths, mandatory training and the reporting on it. A KMS is responsible for knowledge: policies, instructions, solutions to recurring problems, project experience.
What the class does not do: it does not create knowledge and it does not replace mentoring. The system stores and distributes whatever somebody took the trouble to write down; if the people who hold the knowledge write nothing, you get a beautiful empty portal. And it does not guarantee learning: a completed course and the ability to do the thing are different, and practice lies between them.
Subclasses: what the class is made of
LMS — training and mandatory instruction. Courses, tests, assignments, deadlines, reporting for health-and-safety and other mandatory training.
Effect: mandatory training is closed with evidence, rather than "we briefed everyone verbally"; a new hire's onboarding follows a route rather than somebody's mood.
Drawback: it slides into box-ticking easily — courses get clicked through in ten minutes, the reporting is green, the knowledge is not there.
Authoring tools and content production. Course builders, video, simulators.
Effect: an internal expert can package knowledge themselves, without an external contractor.
Drawback: content production is a separate job that somebody has to be paid for in time; without that, the library freezes at five courses.
KMS — the knowledge base. Policies, instructions, solutions to recurring cases, and search across all of it.
Effect: the answer is found in a minute instead of a walk to a colleague; a departing employee's knowledge stays in the company.
Drawback: a base with no owner goes stale and becomes dangerous — an employee follows the instruction and breaks something that has since been working differently.
Onboarding and mentoring. New-hire routes, first-week checklists, an assigned mentor.
Effect: the new hire reaches productivity faster and distracts the team less.
Drawback: a formal route with no live mentor produces a feeling of abandonment — here the system is an aid, not a substitute for a person.
Knowledge and competency assessment. Tests, competency matrices, development plans.
Effect: you can see where the gaps in the team are, and training gets assigned against the gap rather than against intuition.
Drawback: a competency matrix is a living document; if you do not update it, in a year it describes a company that no longer exists.
Who needs the class, who is too early — and what has to come first
Needed from roughly fifty people, or wherever hiring is continuous — the point at which you find yourself explaining the same thing over and over. A knowledge base separately is needed wherever a person leaving takes something important with them: engineering decisions, the subtleties of working with particular clients, project history.
Too early or not needed: a small team gets by on a shared drive and conversation; an LMS for the sake of three courses is an extra entity.
What it connects to and when to implement. As a rule the class comes after the HR core: training is assigned to employees, and employees live in the HR loop described above. Upwards it feeds competency data into HR and learning analytics. And there is a connection that in 2026 matters more than the older ones: the knowledge base is the input for corporate AI. A RAG assistant is built on top of it, not instead of it: the quality of its answers equals the quality of your documents. Companies that spent years tidying up their policies got an advantage they had no idea they were building.
What the class gives the business — and its typical drawbacks
Effect. Speed of onboarding: a new hire gets to work faster and the team spends less time repeating explanations. Knowledge retained: a departure stops being the loss of a chunk of expertise. Obligations closed: safety and policy training is documented. And — the new effect — a ready base for an AI assistant.
Drawbacks people talk about less. The class rests on the people who write: if an expert has neither time nor motivation to package knowledge, no system will do it for them. Content ages invisibly — an outdated instruction is worse than a missing one. And measurement is deceptive: course completion percentage can be driven to a hundred without anything about the work changing.
Optimum instead of maximum: why coverage beats perfection
The temptation of this class is to do it perfectly: a polished course, an immaculate base, a single house style. In Dzhimsher Chelidze's book "Artificial Intelligence. A Practical Guide to Implementation" there is a pattern about exactly this. It is stated as briefly as it can be — optimum instead of maximum; in the book the rule is called the 70/30 rule. The meaning: a system running at 70% accuracy with full adoption delivers more than a system at 95% accuracy that ten percent of people use. Look for the optimum, not the maximum.
For a knowledge base this translates literally. A living base that the teams maintain themselves — uneven in places, hasty in others — but that people open every day is more useful than a flawless portal they visit once a quarter after a reminder. Start with whatever gets asked most often, and work on getting people to go there; the tidying up can come later.
2026: the context
The class changed meaning. Before AI went mainstream, the knowledge base counted as internal hygiene; now it is the asset that determines whether your corporate assistant works at all. Mandatory training requirements have not gone anywhere in the meantime — the LMS is still the tool that closes them with evidence. One thing worth adding for anyone certifying against SOC 2 or ISO/IEC 27001: security-awareness training and its records sit in this class, which means the LMS quietly becomes part of your audit evidence rather than just an HR tool.
Cost drivers. Cloud LMS and knowledge bases are priced per user per month — another class that scales linearly with headcount, so the total is set by how many people you licence, not by how much you use it. Rolling out learning takes about a month; a knowledge base starts on the day you sign up. The expensive part here is not the software. It is producing courses and filling the base: that is people's working time, and it usually exceeds the licence cost. Budget the content owner's hours explicitly, or the licence buys you an empty shell.
IT as a service: ITSM and ITAM
Tickets reach IT in three ways: a direct message to the admin, an email to a shared mailbox, and a shout down the corridor. Some things get done straight away, some are forgotten forever, and the question "why is our IT so slow" has no answer — because there is no data. ITSM is about IT no longer being a black box: tickets in one stream, timings that can be measured, assets that are counted. It is also, usually, the company's first school of process management. Let us go through the class, its subclasses and the role of AI.
What the class does — and what it does not
ITSM turns IT support into a managed service: a single point of contact, priorities, response and resolution targets, history on every incident, a catalogue of what IT is actually obliged to provide.
What the class does not do: it does not fix a shortage of hands and it does not replace architecture. If you have a lot of incidents because the infrastructure is old, ITSM will count them neatly — and that is all; the cure sits in the infrastructure budget, not in the ticket system.
Subclasses: what the class is made of
Service desk and incident management. A single intake window, routing, priorities, service level agreements.
Effect: a ticket does not get lost, it has a deadline and an owner; for the first time you can see the real load on IT.
Drawback: without sensible priorities the system turns into an "everything is urgent" conveyor — the SLA is met on paper and the dissatisfaction stays.
Change and release management. Who changes what in production and when, how it is approved, how it is rolled back.
Effect: fewer outages inflicted by your own hands on a Friday evening.
Drawback: overdo it and you get bureaucracy where any change takes a week to approve — and workarounds that route around the process entirely.
ITAM and CMDB — IT asset records. What we have: hardware, licences, services, and the dependencies between them.
Effect: licences are neither over-bought nor suddenly exhausted; during an incident you can see what depends on what.
Drawback: a CMDB goes stale faster than any other reference book — without automated discovery it is lying to you within a quarter.
Monitoring and observability. System health: availability, load, errors, request traces.
Effect: IT finds out about an outage, rather than the business finding out from a customer's phone call.
Drawback: alert thresholds set once become noise over time — and people stop reacting to noise.
Knowledge base and self-service portal. Instructions, standard fixes, password reset without a human involved.
Effect: routine requests — passwords, access, instructions — get closed without first-line involvement, and first line does the work that genuinely needs a person.
Drawback: a knowledge base with no owner goes stale and starts doing harm — an employee follows the instruction and breaks something that was working.
Who needs the class, who is too early — and what has to come first
Needed once the IT function is around five people, or where you have external SLA commitments — to your own customers or to a contractor. Symptoms that it is time: tickets living in messaging apps; nobody knows how many there are or how quickly they close; licences and hardware counted in a spreadsheet once a year; half a day spent during an outage working out what actually broke.
Too early or not needed: for a company with one system administrator, ITSM is overkill — a shared mailbox and discipline will do. But asset records in a simple form are useful even there.
What it connects to and when to implement. The class grows as IT grows; it has no fixed place in the queue. One dependency does matter: the inventory of IT assets from ITAM/CMDB is a precondition for information security, covered in the next section — you cannot protect what you have not inventoried. And a practical detail: ITSM usually disciplines IT before IT starts disciplining the business, which is why the class often becomes the whole company's training ground for process management.
What the class gives the business — and its typical drawbacks
Effect. Manageability: IT stops being a black box, the service acquires timings and metrics, and the manager acquires a basis for a conversation about budget. Money: counted licences and assets usually produce quick savings. Resilience: fewer outages from uncontrolled changes, and faster recovery when they happen.
Drawbacks people talk about less. The class turns into imitation easily: SLAs met, metrics green, users unhappy — because you measured ticket closure speed rather than whether the problem was solved. Implementation consumes the IT function's own time, and it is already short of hands. And the classic sizing mistake: a heavyweight process framework stretched over a team of five eats more than it gives.
2026: the context
Two shifts matter. The first is that service management platforms have absorbed IT asset management, and asset data is now expected to be discovered automatically rather than typed in — which changes what "good" looks like when you evaluate one. The second is regulatory: rising expectations for infrastructure protection have turned IT asset records from internal IT hygiene into a precondition for meeting security requirements. NIS2 in the EU expects entities in scope to know what they run and to manage the risk in their supply chain; SOC 2 and ISO/IEC 27001 audits both ask for an asset inventory before they ask about anything clever. That makes ITAM a compliance artefact and not only an operations one.
Cost drivers. A cloud service desk for a small IT team is a per-agent subscription and stands up in weeks. A corporate programme with a service catalogue, service level agreements, a configuration database and integrations is a different animal: the cost is driven by the number of integrations, the number of configuration item types you decide to track, and the implementation work — and it runs six to twelve months. These are two different stories and you must not confuse their timelines. In a corporate budget, put licences on a separate line from services: in heavyweight systems, the licences alone are a visible share of the total.
Information security: DLP, IDM/IAM, SIEM
In information security a company usually lives at one of two extremes. Either "we have antivirus, that is enough". Or buying expensive systems off a slide — half of which then blink alerts into the void. Both extremes cost money: the first when an incident happens, the second every month. Order matters more than budget here: you cannot protect what you have not inventoried. A SIEM — the system that collects and analyses security events — bought before order in IT assets turns into an expensive noise generator. Let us go through what each class does, who needs it, and what order it is sensible to build them in.
What the loop does — and what it does not
The security loop protects three things: data (against leakage and loss), access (who can get in where) and infrastructure (against attacks and failures). Different classes cover different layers — from an employee's password to an attack monitoring centre.
What the loop does not do: it does not cancel the human factor and it does not replace processes. Most incidents start not with a breach of the perimeter but with a phishing email, a weak password, and access rights left with someone who has left the company. Systems reinforce discipline — they do not create it.
Subclasses: what the loop is made of
IDM/IAM and PAM — accounts and access. Who has access to what, granting and revoking rights, privileged accounts under special control.
Effect: a leaver loses all access on their last day, rather than "when someone remembers"; rights are granted by role, not by friendship.
Drawback: implementation runs into the job of getting roles in order — and that is work on the org structure, not on software.
DLP — data loss prevention. Control of channels: email, messaging, USB drives, printing; the system sees a confidential file heading out.
Effect: leaks are caught before the customer database is published, not after.
Drawback: DLP without data classification is blind — until you have defined what is confidential there is nothing to control; plus a delicate balance with employee privacy. In the EU that balance is not a matter of taste: monitoring of employees touches GDPR and, in many countries, works-council and co-determination rules, which means the works council is a stakeholder in the rollout, not an afterthought.
SIEM and SOAR — monitoring and response. SIEM collects events from all systems and looks for signs of attack; SOAR automates the response.
Effect: an attack is visible while it develops, rather than after the damage.
Drawback: SIEM is not a box, it is a process: without analysts working through the alerts it becomes an expensive noise generator.
EDR/XDR — endpoint protection. The successor to antivirus: it sees suspicious behaviour on computers and servers and isolates what is infected.
Effect: ransomware stops on the first machine rather than after it has walked the whole network.
Drawback: it needs agents across the entire estate and hands to work through the detections.
NGFW and network protection. Next-generation firewalls, VPN, network segmentation.
Effect: an attack that gets into one segment does not roam the whole network.
Drawback: rules age — a firewall with three-year-old rules is protecting the network you had the day before yesterday.
Backup. The last line: when everything else has failed, backups are what save the business.
Effect: ransomware is an unpleasantness rather than a catastrophe.
Drawback: a backup that has never been restored is a hypothesis, not a defence; restoration has to be practised.
Who needs the loop, who is too early — and what has to come first
The base loop is needed by everyone, immediately: access under control, EDR on the machines, a firewall, backups with restoration tested, people trained on phishing. This is hygiene, like accounting. SIEM and a SOC are for mid-size and up: when there are so many systems and events that watching with your eyes no longer works. Symptoms that it is time for DLP: work with customer databases and trade secrets, turnover in departments that have access to data.
Too early or not needed: a full security operations centre is beyond a small business both in money and in purpose — a service model is more sensible (managed detection and response, monitoring as a service). Buying a SIEM without people to triage the alerts is too early for everyone.
What it connects to and when to implement. The security loop rests on order in IT, and order in IT assets is created by ITSM and ITAM, covered in the previous section: you cannot protect what you have not inventoried. So a SIEM as a rule goes in after IT asset records are in order, and IAM rests on an up-to-date org structure and role model. The loop's input is events from every system in the landscape; its output goes into monitoring and into regulatory reporting. And the more critical the company's systems are considered to be — up to and including entities in scope of NIS2 in the EU — the harder the requirements on this loop become.
What the loop gives the business — and its typical drawbacks
Effect. A lower price per incident: an attack caught on the first machine costs orders of magnitude less than a business stoppage. Regulatory cover — under GDPR, penalties for mishandling personal data are tied to a share of global annual turnover, which means the question "why do we need DLP" is now answered in percentages of revenue rather than in opinions. And trust: for B2B customers, the security maturity of a supplier is increasingly a condition of the contract, evidenced through SOC 2 or ISO/IEC 27001 rather than assurances.
Drawbacks people talk about less. Security is pure cost with no visible effect while everything is fine, and its budget is cut first — until the first incident. The loop is easy to over-tighten: blanket prohibitions push employees into workarounds, and actual security drops. And the talent shortage: buying tools is easier than finding the people who will make them work.
2026: the context
Regulatory pressure is rising from three directions. Data protection: GDPR in the EU and comparable regimes elsewhere have made personal-data handling a board-level exposure rather than an IT topic, and the same logic now applies to AI systems that process employee data under the EU AI Act. Sector and infrastructure rules: NIS2 extends security and incident-reporting duties to a wider set of entities and pulls supplier risk in with them; in payments, PCI DSS does the same for cardholder data. And assurance as such: SOC 2 and ISO/IEC 27001 have become the default way a customer checks you, with ISO/IEC 42001 emerging as the equivalent question for AI management systems. A separate note on DLP: monitoring employees requires legal groundwork — a documented monitoring policy, notification of staff, a defined confidentiality regime, and in much of the EU consultation with the works council. Without that paperwork, DLP creates legal risk instead of protection.
Cost drivers. The base loop for a small company is a handful of per-endpoint and per-seat subscriptions; for mid-size the count of endpoints, seats, log volume and retention period drives most of it, with the firewall, endpoint protection and access control each a separate line. The base loop stands up in months, not years. DLP is priced per seat, and at a hundred seats it becomes comparable with the rest of the loop put together — another class with no economy of scale. Then the two dominant drivers, which are not licences at all. The first is 24/7 coverage: continuous monitoring means either three shifts of analysts or a managed service, and an in-house operations centre costs an order of magnitude more than an external one. The second is retention: log and evidence retention requirements set your storage bill, and the longer the retention obligation, the more the SIEM costs to keep rather than to buy. If your systems fall under critical-infrastructure or sector rules, add certified tooling and mandated reporting connections — these are separate budget lines and they can exceed the entire base loop.
The digital workplace: mail, office, messaging and video
The only class in this cycle that every employee uses every day — and the only one almost never treated as a project. It gets "implemented" like this: on Friday an email goes out saying that from Monday email is moving. On Monday work stops. Let us go through what the digital workplace consists of, why it is an environment rather than a project, in what order it makes sense to replace the familiar services, and where these transitions break most often.
What it is — and what it does not do
The digital workplace is the set of tools an employee's day happens in: mail and calendar, documents, messaging, video, files. Individually none of them manages a process; together they form the environment every other system runs inside.
In the map of implementation order — the summary map published in the hub article of this cycle — this set stands apart and is called the hygiene layer: everyone needs it, immediately, it has no "time is right" threshold and no predecessors. From the same source: mail, office and messaging are an environment, not a project.
What this environment does not do: it does not manage processes. An approval in email stays email, it does not become document management — that is what ECM and document systems are for. It does not store knowledge: a chat where everything was once explained does not become knowledge — that is the knowledge base's job. And it does not replace a system of record: a spreadsheet four people maintain is not a system, it is a deferred problem.
Subclasses: what the environment is made of
Mail and calendar. Corporate email, shared calendars, meeting rooms, distribution lists.
Effect: the basic communication infrastructure and the only genuinely universal channel for talking to the outside world.
Drawback: email pulls everything onto itself — approvals, tasks, file storage — and turns into a personal archive nobody but the owner can retrieve anything from.
Office suite and co-authoring. Documents, spreadsheets, presentations, several people working at once.
Effect: versions called "report_final_2_edits_FINAL" disappear.
Drawback: format compatibility with the outside world is the eternal pain of any migration: inside everything works, and the document you sent to a counterparty opens differently at their end.
Corporate messaging. Day-to-day communication, team channels, integrations with systems.
Effect: short questions stop living in email, and a discussion stays in the context of the task.
Drawback: messaging has no memory in the managerial sense — a decision taken in a chat and never carried into a system does not exist a month later.
Video conferencing. Meetings, webinars, recording and transcription.
Effect: a distributed team works without losing the quality of the discussion.
Drawback: the ease of calling a meeting is the most underestimated consumer of working time in the company.
Files and the corporate portal. Shared storage with access rights, an intranet, news, policies, an employee directory.
Effect: documents live in one place with comprehensible permissions, rather than in email and on USB sticks.
Drawback: without naming conventions and section owners, storage turns into a dump within a year — a place where putting a copy is faster than finding the original.
Who needs it, who is too early — and in what order to replace it
Everyone needs it — the question is not whether you have a digital workplace but whether you manage it or it assembled itself. The second variant is easy to recognise: work conversations in personal messaging apps, documents in personal cloud accounts, a departed employee's access to the shared folder that nobody revoked.
Requests for access, equipment and accounts are no longer this environment — they belong to ITSM, covered above, where they turn into a measurable flow with timings.
It becomes a separate project when you face a migration — consolidating two suites after an acquisition, moving to a different provider, or bringing hosting into a specific jurisdiction — or when the company outgrows free tiers: more than a hundred employees, harder requirements on where data is stored, and access rights that stopped being manageable.
The order of replacement. This layer has no predecessors, and there is no rigid canon inside it either. But there is a logic I would hold to: go by the cost of stoppage. That is, start with whatever brings work to a halt first. Mail and calendar first — without them all external communication stops. Then files and storage — that is where the things you cannot lose are kept. Then the office suite — the most painful part for people, because it touches daily habits. Messaging and video last: they are easier to replace and easier to roll back. Pilot on one business unit with real external counterparties, not on the IT department, which will adapt to anything.
What the environment gives the business — and its typical drawbacks
Effect. Manageable access: an employee leaves and access closes the same day, rather than being discovered a year later in an audit. Company data stays inside the company's perimeter rather than in personal cloud accounts. And speed: co-authoring a document saves not minutes but approval cycles.
Drawbacks people talk about less. This is the class most visible to people: any roughness is visible to everyone immediately, and the complaints go not to the IT function but to the chief executive. The cost is built from a licence per head — it grows linearly with headcount and gives no economy of scale. And compatibility with the outside world stays your problem forever: a counterparty is under no obligation to adapt to your choice.
There is one more layer above this environment that essentially nobody automates: the executive's own loop — goals, decisions, and the commitments made to themselves and to the team. The corporate workplace covers the day's traffic; it does not cover the weekly review of goals or the record of why a decision was made the way it was. That layer is a tool for one person, it is not part of the company's digital workplace, and it does not require an implementation programme — which is precisely why it stays invisible in every IT budget.
Why these transitions break on people, not on technology
Technically, any contractor can move a mailbox. What breaks is something else. In Dzhimsher Chelidze's book "Artificial Intelligence. A Practical Guide to Implementation", the fifth of the seven sins of digitalisation is underestimating change management and resistance: communication is minimal or formal, and in return the company gets sabotage, active or passive. With AI projects it is fear of losing the job; with the workplace environment it is the feeling that someone took away a tool the person had mastered over twenty years and handed them one where they are a beginner again.
It shows up not as open refusal but more quietly: people keep messaging in personal apps, documents move to personal drives, and the "official" system gets used only when a manager is looking. Formally the transition is complete; in fact the company lives in two environments at once — and that is the worst of all states, because the data drifts apart across both.
What to do about it. Explain the reason for the move before it starts, and honestly — including the part where it will be inconvenient. Provide training not as an email with a link to an instruction, but live, on your own actual documents. Leave a transition period with both systems working, but with a declared switch-off date for the old one — an open-ended transition period equals no transition. And start with the managers: as long as the chief executive approves documents in the old tool, everybody else will do the same.
2026: the context
Migrating between workplace suites has stopped being a question of principle and become a question of operations: the products are mature enough that daily work does not suffer. The main difficulty has shifted from functionality to two other things. Compatibility of complex documents with the outside world — and people's habits. Two further pressures have grown. Data residency and sovereignty requirements now decide the shortlist for a growing set of organisations — regulated sectors in the EU, government-adjacent work in the UAE and Singapore — and that is a procurement constraint, not a feature comparison. And AI features have moved into the workplace suite itself: meeting transcription, drafting, semantic search across mail and files. That changes the security question, because the assistant sees whatever the user's permissions let it see, and it changes the legal one, because recording and transcribing people at work is regulated in the same places employee monitoring is.
Cost drivers. The workplace is the purest per-user-per-year class there is: the bill is headcount multiplied by tier, with no economy of scale whatsoever, and the AI add-ons are typically a further per-user line on top. Migration timing: a small company moves over a weekend, an organisation of several hundred people over a quarter; at thousands of employees it goes in waves and stretches across a year. What usually costs more than the licences is something else: retraining people, sorting through years of accumulated files, and rebuilding complex spreadsheets, templates and mail integrations with adjacent systems.
How these five loops connect
These five loops rarely end up in the same project and almost always end up in the same budget argument. What connects them is not integration but one and the same object of record: the person and their access.
The common entry point — the employee and their role. The HR core is the single source of truth about who works at the company, in what position, from what date. All four of the others depend on it: who to grant access to, who to enrol in training, whose tickets to accept, whose rights to revoke on departure. If the HR loop is not connected to access management, the company gets the classic finding of any audit — active accounts belonging to people who left.
The common order — hygiene before add-ons. One rule works in all five loops: the base layer is closed before the expensive systems. In security it is especially vivid: an event management system while leavers' access is still live is monitoring an open house. But the same holds for the rest. A knowledge-base assistant on top of an empty base, a learning platform with no answer to "who makes the courses", an HR platform "with everything included" — in every case the top floor has been bought while the ground floor is still open.
Where they exchange data. IT asset records from the service loop should flow into the security loop rather than living separately: you can protect what you know about. HR events feed access management and learning. Employee tickets to IT support are the best map of holes in the knowledge base: whatever gets asked about most is exactly what the documents do not cover. And the workplace environment — mail, messaging, files — is what everything else runs on top of, and the first thing to break during a migration.
The special case — the digital workplace. It is not a project, it is an environment. It has no separate effect you can present to a CFO, and that is precisely why its transitions break more often than anything else: not on the technology, but on people and habits. Treating it as a hygiene layer is more accurate than treating it as an initiative with a payback calculation.
How this connects to the rest of the landscape. HR documents flow into the data and documents loop, personnel costs into the accounting and analytics loop, and the knowledge base becomes the foundation for a corporate assistant — which is already the territory of the article on routine automation and AI. Underneath all five sits the physical and platform layer covered in IT infrastructure.
The role of AI in employee-facing loops
There is a paradox here worth naming straight away: these are the loops with the highest return from AI and the most modest budget for it.
What AI already solves.
In HR. Parsing and first-pass screening of CVs: out of the flow of applications the recruiter sees the relevant ones first. Draft job ads and candidate emails. An employee assistant for HR questions — leave, a certificate, a policy — instead of a queue at the HR desk. Attrition forecasting from historical data.
In knowledge. An assistant that answers with a link to the document instead of a search through folders. Draft courses and tests built from existing policies. Analysis of employees' questions: whatever gets asked most is the map of holes in the base.
In IT support. Classification and routing of requests without a dispatcher. Suggested fixes from the history of similar incidents. A first-line assistant. Anomaly detection in monitoring before a threshold fires.
In security. Behavioural analytics: the model notices that the accountant's account is exporting the customer database at three in the morning, even where the access is formally permitted. Alert prioritisation — out of a thousand events the analyst sees the ten worth attention. Phishing analysis before the employee clicks.
In the workplace. Meeting transcription with the commitments extracted. Help writing emails. Search across correspondence and files by meaning.
What is coming (a forecast, not a fact). Agents that run a candidate from offer through to first day. Agents that execute routine IT requests end to end — from an access reset to granting rights per policy, under human control. Analyst agents in the monitoring centre that hand a human a drafted version of the incident. An assistant that prepares a person for the working day: what to read, what to decide, what to delegate.
Where the money actually goes. Everything listed above is classic back office. And here the observation this article is worth remembering for applies. Dzhimsher Chelidze's book "Artificial Intelligence. A Practical Guide to Implementation" describes investment bias — trap No. 2 of six: the lion's share of AI budgets goes into visible front-office projects, although back-office scenarios pay back several times better. On the cases in the book, that is around 70% of budgets at a two- to three-times return, while the back office delivers several times more. The five loops in this article are exactly the back office that is habitually underinvested. Before launching an AI storefront for customers, I would count what the queue at IT support costs and what a month of new-hire onboarding costs.
Conditions without which it will not fly. Data: a clean history of HR events and hires, a ticket history with correct categories, events from all security systems, order in the file storage. And separately — documents that do not contradict each other. This is the key condition for three loops at once: given two conflicting policies, an assistant will confidently pick one and never mention that there was a second. Processes: documented HR procedures, standard ticket scenarios with an explicit definition of done, an established alert triage routine — otherwise a smart system will simply speed up the delivery of signals into the same void. People and security: an owner for every section of the base and an update rule; personal data requires de-identification before it goes to cloud models; the assistant's rights are never broader than the rights of the employee it stands in for.
Three boundaries worth knowing before the pilot.
The first: this is where AI comes closest to decisions about people. Among the unacceptable events named in the book, one is about exactly this case — an AI system making discriminating or unlawful decisions in production. From the same source, the mandatory check before launch: a bias crash test. The typical failure looks mundane: CV screening is trained on the history of your own hiring, and that history reflects the past preferences of hiring managers — so the model faithfully reproduces them, including the ones the company would not say out loud. This is also where regulation has caught up: the EU AI Act treats employment-related uses as a category where you must be able to explain the system's role and keep a human in the decision. The working rule: AI ranks and prepares, a human takes the decision about a person — and can explain it without referring to the system.
The second: an assistant inherits every mistake in your access rights. It sees everything it has access to. If the finance folder is open to "all employees", smart search does not create a new problem — it makes the old one instantly available. Getting access rights in order is not preparation for AI; it is the condition for switching it on safely. The same goes for meeting transcripts: the rule for who may start a recording and who will see the transcript is set before the feature is enabled, not after the first scandal — and in the EU that rule is a works-council conversation, not an IT setting.
The third: AI itself becomes a target. Deepfaked executive voices and prompt injection into corporate assistants have left the exotic category, and the old protection rules do not catch them. The information security loop has to cover the company's own AI systems too — that is part of the perimeter, not a separate topic for conferences. If you are already certifying against ISO/IEC 27001, ISO/IEC 42001 is the frame that asks the same governance questions about AI systems specifically.
The honest boundary. AI does not fix organisational problems here, it makes them visible. An assistant does not fill the knowledge base and does not solve "nobody writes anything". It does not shorten the support queue if the queue is caused by a shortage of people or by rotten infrastructure. And it replaces neither a threat model nor response processes. A company that bought an assistant instead of getting its documents in order gets confident answers based on outdated policies — and within a quarter employees stop believing it. Rebuilding that trust costs more than getting things in order would have in the first place.
Vendors you will actually meet
The table lists solutions you will repeatedly run into on projects in these classes. It is not a ranking and not a shortlist: check data residency, certification scope and regional availability for every jurisdiction you employ people in before you decide anything.
HR core and payroll — Workday · SAP SuccessFactors · Oracle HCM · Dayforce · BambooHR · Personio · HiBob
Recruiting (ATS) — Greenhouse · Lever · SmartRecruiters · Ashby
HR e-signature — DocuSign · Adobe Acrobat Sign
Workforce management (WFM) — UKG · Quinyx · Deputy
Learning (LMS) — Cornerstone · Docebo · 360Learning · TalentLMS · Litmos · LinkedIn Learning
Knowledge base (KMS) — Confluence · Notion · Guru · Glean
ITSM and service desk — ServiceNow · Jira Service Management · Freshservice · Ivanti · Zendesk
IT asset management (ITAM) — Lansweeper · Snipe-IT · Device42
Identity and privileged access — Microsoft Entra ID · Okta · CyberArk · Delinea
Data protection and DLP — Microsoft Purview · Forcepoint · Netskope
Endpoint protection (EDR/XDR) — CrowdStrike · SentinelOne · Microsoft Defender
Network protection (NGFW) — Palo Alto Networks · Fortinet
SIEM — Splunk · Microsoft Sentinel · Elastic
Backup — Veeam · Rubrik · Commvault
Digital workplace — Microsoft 365 · Google Workspace · Slack · Zoom · Atlassian
The choice in each loop starts from its own question. The HR core is usually predetermined by your payroll and finance stack and by the countries you employ people in — multi-country payroll is where most platforms actually differ. The add-ons are bought pointwise, for the process that hurts. In learning it is rarely functionality that decides but content production: ask yourself who is going to make the courses, and start from that answer. In service management, look at the size of your IT function: a heavyweight enterprise platform gets in a small team's way more than it helps. In security, do not start from a product — start from the answer to what you are protecting and from whom. And in the workplace environment, two things decide, and neither of them appears in any deck: what your counterparties use, and how complex your documents are. A spreadsheet with heavy formulas and macros is the definitive migration test.
Typical mistakes and a selection checklist
The mistakes repeat across all five loops, so I have gathered them into one list.
Buying a platform "with everything included". You pay for what the company will not grow into for a long time. Add-ons are bought against a specific pain, with a named trigger.
Starting with expensive systems and skipping hygiene. A security event management system while leavers' access is still live is monitoring an open house.
Buying a system without people. A SIEM with no analysts is a noise generator at the price of a car a year. A learning platform with no course author is an empty shell.
Measuring the process instead of the result. The ticket was closed in an hour, the problem came back the next day. A hundred percent course completion means neither knowledge nor changed work. An engagement survey with no consequences kills trust in the next one.
Leaving the knowledge base without owners. An outdated instruction is more dangerous than a missing one: people act on it.
Chasing perfect content. A living base that people use is more useful than a flawless one nobody opens.
Not allocating time for packaging knowledge. An expert will not write a course in the gaps between other work — it is a job, and it has to be paid for in time.
Building IT asset records by hand. Without automated discovery the register is lying within a quarter.
Stretching a heavyweight framework over a small team. And the reverse: a lightweight tool will not hold a corporate process. The process has to be sized to the team.
Taking weeks to approve changes. People will start changing things around the process, and you will lose even the visibility you had.
Over-tightening with prohibitions. Employees move to personal email and messaging — and the data leaks where there is no control at all.
Not practising restoration. A backup is verified by restoring it on a schedule, not by faith.
Rolling out HR e-signature without legal groundwork. HR documents are legally significant, the categories that can be signed electronically differ by country, and the mistakes surface during an inspection or a dispute.
Handing CV screening to AI without a bias audit. The model will reproduce historical skew and present it as objectivity.
Treating a move to a new workplace environment as a technical task. A contractor will move the mail; habits will not move. And separately: not starting with the managers, and testing on the IT department, which will adapt to anything.
Leaving an open-ended transition period. Two working environments with no switch-off date is not a transition, it is a data split.
Forgetting the company's own AI systems. Corporate assistants and models are a new attack surface; protecting them is part of the loop, not an exotic extra.
A checklist before you choose a system
Hygiene is closed: access is revoked on departure, endpoint protection is deployed, backups are verified by restoration, people are trained. Before the large purchases, not in parallel with them.
There is a threat model: what we are protecting, from whom, what happens if it is lost. I would answer this before any purchase in the security loop.
The HR core is chosen from the finance and payroll stack and the countries you operate in: compatibility with payroll and statutory reporting matters more than the interface. Add-ons come against a specific pain, with a named trigger.
A service catalogue is documented: what IT promises the business. Before the system is chosen.
Owners are named for every section of the knowledge base, along with an update rule — before it is filled, not after. And it is written down who produces content, and in what working hours.
Key policies have been checked for contradictions. This is a mandatory step before any AI assistant, in three loops at once.
The pilot runs against a result metric, not a process metric: time to fill a role, time for a new hire to reach independent work, share of tickets resolved first time, time to detect an incident, and the false-positive rate.
People and process are budgeted alongside the system: who triages alerts, within what time, what they do during an incident. Who supports it, who cleans it, who trains people.
Personal data handling is settled: where it is stored, who has access, what goes out to cloud models. This is the most sensitive category in the company — both legally and in terms of people's trust.
A bias audit has been carried out for any AI scenario touching people — before launch, not after a complaint.
For the workplace environment: a migration test on your most complex documents, an external compatibility check with three counterparties, a pilot in a unit with real external communication, and the switch-off date for the old environment announced together with the launch date for the new one.
What next
The overall map of classes is in Enterprise IT systems: the map. Other analyses in this cycle: Production, assets and warehouse · Customers and sales · Money, planning and analytics · Data and documents · Routine automation and AI · IT infrastructure.
To go deeper, see Dzhimsher Chelidze's books "Digital Transformation for Directors and Owners", "Artificial Intelligence. A Practical Guide to Implementation" and "Artificial Intelligence. Freefall" — available to download free.
If you still have questions, you are welcome to come to us for training or consulting.


