Cloud Sentry
People lifecycle

Joiners, movers, and leavers, handled as a service, not a checklist someone forgets.

Day-one access for a new hire. A clean re-scope when someone changes teams. Access revoked the day notice lands when someone leaves. Run by a named operator, not left on a list.

A joiner, a mover, and a leaver are not three separate problems. They are the same employee at three different moments, and each one needs the same thing: access that matches the role, changed the moment the role changes, and closed the day the person is gone. Provisioning software gets you partway there. Someone still has to own the rest.

The three moments

Every employee passes through the same three moments. Each one gets handled the same way, every time, by a named operator instead of whoever remembers.

Day one

Joiner

Access provisioned from the role and live on day one. A new hire starts working instead of waiting on a queue for the accounts the job needs.

Mid tenure

Mover

Access re-scoped for the new role, and the access the old role no longer needs comes off. A move is an addition and a removal, not just the first half.

Day of notice

Leaver

Access revoked the day notice lands, with equipment recovery tracked as part of the same task. Offboarding runs as tracked work with a named owner, not a mental note.

Software provisions accounts. We own the boundary.

A provisioning connector is good at one thing: pushing a standard account into a standard app the moment a request clears. That is real work, and it is not the whole job. Every connector has an edge where its automation stops.

We put a named operator at that edge. They resolve the exception a connector cannot judge, provision the app no connector reaches, track equipment recovery when someone leaves, and write down what happened so the record holds up later. The boundary is not a gap we hide. It is the line we staff.

What the connector handles

  • A standard account in a connected app
  • The request and the approval
  • A status update when the task is done

What the operator owns

  • The exception a rule cannot resolve
  • The app with no connector
  • Equipment recovery
  • The written record for your auditor

Offboarding is where the risk lives

Most access reviews turn up the same finding: a former employee with a live account somewhere. Nobody meant to leave it open. Offboarding touches more systems than one list can hold, and the last one is the one that gets missed. That is the classic identity failure: not the exotic attack, but the ordinary account nobody remembered to close.

We treat offboarding as access-lifecycle work with a written trail behind it, not a task someone gets to when there is time. See how the controls behind it map onto your compliance program, and how the same rails that grant access on the way in run the removal on the way out.

People lifecycle is one part of the managed IT we run day to day. See the full scope on the managed IT page.

Runs on the platform

One queue for every access change

Requests, approvals, and provisioning run on one set of rails in the platform, operated by named people, not left to whichever system remembers to check.

See how the lifecycle runs in your environment.

Read the published plan structure, or walk the full operated partnership, refusals included.

Published tiers, a written annual escalator cap, and an entry rung you can start today.

The scope, the visibility, and the work we do not take on, laid out section by section.