Access removal for people who leave
When someone leaves, the user-access team used to hunt through sheets and pivots to find every account they held. Now the leaver notice is parsed and every access is one list, with what is already removed and what still needs a hand.
- Sector
- Housing finance, information security
- Period
- 2026
- The number
- Every access, one list
The leak
When an employee leaves, their access to every system has to be removed, promptly and completely, because a lingering account is both a security exposure and an audit finding. The user-access management team received the leaver's details from HR by email, then went looking: which systems did this person have accounts on, which were deprovisioned automatically, which need a manual removal, and has every one been done. The looking was done across multiple spreadsheets, with pivots and cross-matching by hand, for every leaver.
The leak was time, and the risk underneath the time: a missed account is exactly the kind of thing a manual process across spreadsheets produces.
The constraint
The source of truth was email and spreadsheets, not an identity system with an API, so the tool had to start from what existed. The team needed a view that was complete enough to be trusted for an audit and simple enough to work from every day. And it had to be clear about what it knew: which removals were confirmed by a system, which were asserted by a person, and which were still open.
The system
A dashboard that parses the HR leaver notifications as they arrive, resolves each person to their identities across the access records, and produces one list per leaver: every system they had access to, with each row marked as removed automatically, removed manually and by whom, or still pending. The team works from the pending rows, marks them as they go, and the record of the whole exit is kept for audit.
Across leavers, the dashboard shows what is outstanding, how long removals are taking, and which systems routinely need manual work, which is the list of integrations worth automating next.
The number
One list per leaver, every access on it, with the state of each. The cross-matching across spreadsheets is gone, and the audit trail is a by-product of the team doing its work.
What I would do differently
Wire the dashboard to the identity systems that do have APIs, so the "removed automatically" rows are confirmed by the system rather than inferred from a report. That integration was deferred to get the team off spreadsheets quickly, and it is the next step.