Skip to content
AuthMantraPraxis
authmantra.com ↗Start free trial

Provisioning track · 3 min

Joiner, mover, leaver: access that follows HR

Walk one person through a career and see what access should exist.

The idea

  1. 1Three moments

    People join, change roles and leave. Each moment should change access, not just a spreadsheet.

  2. 2Joiners get a baseline

    Access starts from the role: mail, chat and the tools the team uses, ready on day one.

  3. 3Movers are where privilege piles up

    Add what the new role needs and remove what the old one gave. Skip the second half and access only grows.

  4. 4Leavers lose everything at once

    When HR marks the person inactive, the change flows to every connected app.

Try it

Follow Asha

Step through her career. Then switch from HR-driven to ticket-driven access to see what gets forgotten.

This exercise needs JavaScript. Here is the answer key.

EventAccess that should existAccess with tickets
Joins SalesMail, CRMMail, CRM
Moves to FinanceMail, BillingMail, CRM, Billing
Takes a Support shiftMail, Billing, Support deskMail, CRM, Billing, Support desk
LeavesnothingCRM, Support desk

Check yourself

1 of 3 Why do movers collect extra access?

2 of 3 Where should the change start?

3 of 3 What should happen at leave time?

Answer key
  1. Why do movers collect extra access? Old access is rarely removed. Requests add; nobody files a ticket to remove.
  2. Where should the change start? The HR record. Access follows the HR record, not the other way round.
  3. What should happen at leave time? Every connected app removes access. Provisioning carries the change.