Task 1 · typically 30 min, every day
Grant and remove access to apps, repos and shared drives
Let people request access themselves with approval built in
Access request tools let users ask for an app or group from Slack or a portal, route it to the owner for approval, and grant it automatically, with a full audit trail for reviews.
- 1Pick the tool: Entra ID access packages, Okta Identity Governance, or ConductorOne, Lumos or Opal.
- 2Name an owner for each app or group who approves requests.
- 3Allow requests from Slack or Teams and set access to expire where sensible.
- 4Use the same tool to send quarterly access reviews to owners.
Tools: Microsoft Entra ID Governance · Okta Identity Governance · ConductorOne · Lumos · Opal
One more way to fix itHide the other fixes
Drive joiners, movers and leavers from the HR system automatically
When HR adds, changes or ends someone in the HR system, Okta Workflows or Entra ID lifecycle workflows create accounts, assign groups and remove access without a ticket.
- 1Connect your HR system (Workday, BambooHR, HiBob, Rippling) to Okta or Entra ID as the source of truth.
- 2Map departments and job titles to groups that grant the right apps.
- 3Build joiner, mover and leaver workflows (Okta Workflows or Entra ID Governance lifecycle workflows).
- 4Use SCIM provisioning for apps that support it so accounts are created and removed automatically.
- 5Test with a fake employee before switching on.
Tools: Okta Workflows · Microsoft Entra ID Governance · Google Workspace · Rippling IT