One new hire, one access grant, every subscribed app follows.
This is what changes when identity lives in one place instead of being provisioned separately per tool.
A new hire joins
An admin creates one account in Prime and assigns a role — Editor, say — scoped to the apps this person actually needs.
Every subscribed app appears automatically
If the organisation has Stack and Shield active, both show up for that person immediately — no separate provisioning step per tool.
Access follows the role, not manual grants
The 8-tier role hierarchy determines exactly what they can see and do — no one-off permission tweaks scattered across five admin panels.
Someone leaves — one revoke, not five
Deactivating the Prime account removes access everywhere at once — nobody has to remember to also revoke it in Stack, Shield, and everywhere else separately.
It's all logged
Every access decision — grant, deny, revoke — writes to an immutable audit trail. When someone asks who could see what and when, the answer already exists.