Joiner, mover and leaver access
Grants, adjusts and removes application access from one approved people record, so nothing survives a leaver.
Tools
Microsoft Entra ID, Okta, CyberArk, Jira Service Management
Outcomes
Starters working on day one • Leaver accounts closed on the last day • No orphaned app access after a role change
Documentation
Instruction-ready detail below
Access is granted by whoever remembers the request and removed whenever someone remembers to ask. New hires wait a week for the tools they need, leavers keep a mailbox and an admin group for weeks, and people who change role quietly keep the old role's permissions on top of the new ones.
The workflow takes one approved people record as the source of truth. For a starter, it maps the role to a named access template, raises anything the template does not cover as a question for the manager, and schedules the grants for the first morning. For a mover, it lists what the old role had, what the new role needs, and the difference, so the extra is removed on purpose rather than by luck. For a leaver, it revokes the sign-in, the group memberships, the app grants and the shared mailboxes, then confirms each one closed rather than assuming it did.
A human approves the template, the exceptions, and any access that has to wait until day two.