Identity lifecycle automation
1,000+ employee company, internal IT
Boss Level
- Situation
- Group membership lived in the corporate directory, but the chat platform's user groups were maintained by hand. Every reorganization meant someone re-checking dozens of groups, and access that should have lapsed on a Friday often survived for weeks.
- What I built
- A scheduled sync between the directory and the chat platform's user groups, comparing desired state against actual and reconciling the difference. Critically, it runs dry-run first by default: every proposed add and remove is reported before anything is applied, so a bad directory change cannot cascade into mass access removal.
- Outcome
- Group membership became a consequence of the directory rather than a separate manual chore, and offboarding stopped depending on someone remembering.
- n8n
- Microsoft Entra ID
- Slack API
- Scheduled reconciliation