Employee Exit & Role-Change Access Reconciler
Reconcile employee exits and role changes with IdP, SaaS, exception, and revocation evidence before an access closeout is accepted.
What problem does Employee Exit & Role-Change Access Reconciler solve?
A completed HR or identity-provider ticket can hide active SaaS accounts, old-role entitlements, expired exceptions, and revoked-access claims with no closeout evidence.
Use it to
- Audit a departure after the standard automation runs
- Check internal role changes for stale entitlements
- Track approved access exceptions to expiry
- Preserve revocation evidence for owner closeout
What it returns
- Event-to-access evidence ledger
- Orphaned and old-role access findings
- JSON owner-closeout gate
- IT and security review memo
A representative input and result
Access and approval boundaries
- Read access to one user-supplied local JSON evidence file.
- Write access only to the selected local output directory.
- No browser, network, credential, account, environment-variable, or external-action permission is required.
Known limitations
- The package reviews supplied exports and does not connect to or change an identity provider or SaaS account.
- It cannot prove that an export is complete, current, or authentic beyond the supplied evidence status.
- A ready result still requires the named IT or security owner to review the original systems and exceptions.
Questions
Does it connect to a live account?
No. Version 1 reviews documented normalized local evidence only.
Does it take the external action?
No. It never submits, revokes, publishes, contacts, pays, or changes an external system.
What files does it create?
A findings CSV, evidence ledger CSV, summary JSON, and owner-review memo.
How does malformed input behave?
Missing identifiers, duplicate identifiers, bad timestamps, and invalid numbers fail before a ready result is produced.
Does a ready gate prove compliance or legal sufficiency?
No. It means the supplied records have no automated finding and are ready for the named owner or qualified reviewer.
Can the output be audited?
Yes. Every finding includes a stable code, record identifier, message, and source dataset.
Employee Exit & Role-Change Access Reconciler keeps proof and approval boundaries visible.
The listing includes the tested package, realistic samples, declared permissions, and known limitations.
Get Employee Exit & Role-Change Access Reconciler on Agensi