JustHandled Labs
// Security & Compliance

Employee Exit & Role-Change Access Reconciler

Reconcile employee exits and role changes with IdP, SaaS, exception, and revocation evidence before an access closeout is accepted.

What problem does Employee Exit & Role-Change Access Reconciler solve?

A completed HR or identity-provider ticket can hide active SaaS accounts, old-role entitlements, expired exceptions, and revoked-access claims with no closeout evidence.

Use it to

What it returns

A representative input and result

fixture-backed sample
input One terminated employee still has an active non-SSO CRM account, while a revoked payroll account has no verified revocation receipt and an exception expired yesterday.
result Gate: BLOCK. Active access after exit, missing revocation evidence, non-SSO review, and an expired exception require owner closeout.

Access and approval boundaries

Known limitations

Questions

Does it connect to a live account?

No. Version 1 reviews documented normalized local evidence only.

Does it take the external action?

No. It never submits, revokes, publishes, contacts, pays, or changes an external system.

What files does it create?

A findings CSV, evidence ledger CSV, summary JSON, and owner-review memo.

How does malformed input behave?

Missing identifiers, duplicate identifiers, bad timestamps, and invalid numbers fail before a ready result is produced.

Does a ready gate prove compliance or legal sufficiency?

No. It means the supplied records have no automated finding and are ready for the named owner or qualified reviewer.

Can the output be audited?

Yes. Every finding includes a stable code, record identifier, message, and source dataset.

Employee Exit & Role-Change Access Reconciler keeps proof and approval boundaries visible.

The listing includes the tested package, realistic samples, declared permissions, and known limitations.

Get Employee Exit & Role-Change Access Reconciler on Agensi