Provisioning track · 3 min
A leaver, end to end
From the HR record to every connected app, and the log.
The idea
1HR marks the person inactive
Your HR system stays the list of who still works here. One change there is the only thing anyone types.
2SCIM carries the change
SCIM 2.0 sends active=false to AuthMantra. No ticket, no email to IT.
3Apps follow
Outbound SCIM updates each connected app that supports it. An admin can also suspend the account, which signs the person out everywhere.
4The log remembers
Each step is written to the audit log. Export it, watch the live feed, or stream it to your SIEM.
Try it
Run the leaver steps
Pick a command or type it. Every output is simulated.
$ curl -X PATCH $TENANT/scim/v2/Users/8f2a -H "Authorization: Bearer $SCIM_TOKEN" -d @deactivate.json HTTP/1.1 200 OK {"id":"8f2a","userName":"asha@example.com","active":false} ✓ user inactive $ curl $TENANT/scim/v2/Users/8f2a -H "Authorization: Bearer $SCIM_TOKEN" HTTP/1.1 200 OK {"id":"8f2a","displayName":"Asha Rao","active":false,"meta":{"resourceType":"User"}} ✓ confirmed: active is false $ # admin console: Audit log, filter on Asha 18:02:11 hr-sync user.deactivate asha@example.com success 18:02:12 system app.provision mail success 18:02:12 system app.provision billing success ✓ every step has an actor, a target and a status
Check yourself
1 of 3 Which action signs a person out everywhere?
2 of 3 What does SCIM send for a leaver?
3 of 3 Where does the record of each step live?
Answer key
- Which action signs a person out everywhere? Suspending the account. An admin can suspend an account, and the person is signed out everywhere.
- What does SCIM send for a leaver? active set to false. It is a standard attribute update.
- Where does the record of each step live? The audit log. It can be exported, watched live or streamed to a SIEM.
Go deeper
Field notes
Joiner, mover, leaver: the offboarding checklistAccess that outlives employment is a common audit finding. Start every change from the HR record, remove old access when roles change, and use one checklist for leavers.SCIM 2.0 in plain EnglishSCIM is a standard REST API for keeping users and groups in step across systems. HR changes flow to AuthMantra, and outbound provisioning carries them on to apps.
Runbooks
Offboarding checklist: joiner, mover, leaverRunbookBlueprints
Joiner–Mover–LeaverBlueprintLexicon