New hires work on day one. Leavers lose access in minutes.
One HR event triggers the whole chain: account, licence, mailbox, apps. The same chain runs in reverse the hour someone resigns. Built with Power Automate or n8n inside your Microsoft 365 or Google Workspace tenant, and every run writes the log your auditor asks to see.
Founder casework: identity-lifecycle automation built at a regulated Maltese operator (~100 staff), before ITSailor. Details in the field notes below.
New hires wait days. Leavers keep access for weeks.
Both failures have the same root: joiner and leaver handling lives in inboxes and one admin's memory. It scales with headcount, and it is the first process that snaps when you grow.
The day-one apology
The new hire shows up to "IT will sort you out by Thursday." Three days of borrowed logins, no email, no access to the systems they were hired to run. That is the first impression your company makes.
The leaver risk window
Accounts stay live for days after a departure. Sessions keep working, shared mailboxes stay readable, SaaS seats stay assigned. Ahead of an audit that is an access-termination finding. On a bad day it is an incident.
Licence and seat bleed
Nobody reclaims the Microsoft 365 seat, the Slack licence or the Figma editor when someone leaves. Finance keeps paying for ghosts, month after month, and the seat inventory stopped being true a year ago.
One HR event. The whole chain executes.
No ticket queue and no wiki checklist. The HR system fires a webhook, the workflow does the rest in seconds, and every step lands in a timestamped log. This is what a run looks like, joiner and leaver.
Illustrative run. The production version is built with Power Automate or n8n inside your tenant, tuned to your HR system and app stack, and logs every execution.
Why the log matters
“The auditor doesn't ask if you have a procedure in PDF. They ask if you can show the execution log. We showed them green checkmarks from Power Automate going back a full year.”
This exact automation passed a real regulator's audit.
Before ITSailor, the founder built this lifecycle at a regulated Maltese operator with roughly 100 staff. The numbers on this page come from that work, not from a brochure.
The starting point.HR offboarded staff by emailing IT. Departing employees kept active Exchange access, shared mailboxes included, for up to a week after exit. The regulator's audit was months away.
The build. A Power Automate workflow listening to HR status changes: it kills Entra ID sessions instantly, converts the mailbox to shared, reclaims the E3 or E5 licence and archives OneDrive. No human in the standard path.
The part that went wrong
The first production run archived the CEO's mailbox because of a typo in a department code in the HR system. 2 AM, sweating, restoring from backup. Since then every C-level account gets a manual Teams approval gate before the workflow touches it. That gate ships in every build.
Same operator, other end of the lifecycle. Onboarding a new employee was a 2-day manual click-and-install session through the helpdesk. After the rollout, accounts and access flowed automatically the moment the HR record existed: 30 minutes from sign-in to working, with the helpdesk out of the loop entirely.
Why we show the mess
Vendors love before-and-after numbers and hate telling you what broke on the way. The CEO-mailbox story is where the executive approval gate came from. Every safeguard in this offering exists because something like it went wrong once.
Six pieces of plumbing. All of it yours to keep.
Every flow, runbook and log lives in your tenant and your repository. The Exit Kit documents the whole build, so your next vendor could pick it up in 24 hours.
HR trigger integration
Personio, BambooHR, HiBob or a structured HR mailbox. If your HR system can fire a webhook or send a parseable email, it can drive the whole lifecycle. Power Automate or n8n, in your tenant.
Identity provisioning
Entra ID or Google Directory account creation with group-based entitlements. Department and role decide what opens. Nobody hand-picks permissions at 8 AM on a start date.
Licence assignment and reclamation
A right-sized licence assigned on day one and returned to the pool on exit. Routed through the Pax8 marketplace at vendor list price when you want everything on one EUR invoice.
SaaS seat provisioning
Slack, Jira, Notion, Figma and the rest granted through SCIM or documented API calls, and reclaimed the same way. The seat inventory stays true because the workflow maintains it.
The offboarding kill-switch
One trigger revokes sessions and refresh tokens, blocks sign-in, converts the mailbox to shared, archives OneDrive and strips every SaaS seat. Executive accounts get a manual approval gate first.
Evidence log and access reviews
Every run writes who, what and when to a log you own. Quarterly access-review exports come ready for an ISO 27001 A.5.18 check or a regulator-style access-termination test.
Start with the audit. Automate what it finds.
Fixed fee or retainer, agreed before work starts. No hourly billing at any tier.
Lifecycle Audit
One week. You learn how bad the leaver risk window really is.
- Current joiner / mover / leaver flow mapped step by step
- Offboarding risk assessment with an optional read-only Microsoft scan
- Licence and SaaS seat bleed quantified in euros
- Access-termination evidence gaps checked against ISO 27001 A.5.18
- Prioritised automation backlog + 45-minute walkthrough
Outcome
You know your leaver risk window in hours and your licence bleed in euros.
Lifecycle Automation Build
The joiner chain and the leaver kill-switch, wired and evidenced.
- HR trigger wired: Personio, BambooHR, HiBob or a structured mailbox
- Joiner chain: account, groups, licence, mailbox, SaaS seats via SCIM
- Leaver kill-switch: sessions, tokens, mailbox, OneDrive, seats, licence
- Manual approval gate for executive accounts
- Evidence logging + runbooks in your repository, Exit Kit included
Outcome
Onboarding and offboarding run themselves. You own every flow.
Managed Lifecycle
We operate the chains. You get the SLA and the evidence.
- Offboarding SLA: account disabled within 1 hour of HR notification
- Quarterly access reviews with a signed evidence pack
- Licence reclamation report: every freed seat credited
- New-app requests reviewed against your stack policy
- Flow maintenance as HR systems and tenant baselines drift
Outcome
A leaver process your auditor can verify from the log, quarter after quarter.
Built from four standing services.
The lifecycle offering assembles work ITSailor already runs as standalone engagements. Each one has its own page, scope and engagement model.
Microsoft 365 Management
Tenant operations, licence rationalisation and documented governance baselines.
View serviceWorkflow Engineering
The Power Automate and n8n build discipline behind every lifecycle flow.
View serviceCloud Licensing & Procurement
Pax8-routed licences at vendor list price, one EUR invoice, reclaimed seats credited.
View serviceGoogle Workspace Management
The same lifecycle on Google Directory, with a CIS-aligned Workspace baseline.
View serviceThe clauses the evidence log answers.
Provisioning and revocation are named controls in the frameworks EU operators are audited against. A timestamped run log answers them directly, without a documentation sprint before every review.
Access provisioned, reviewed and revoked on role change and exit. The run log is the record reviewers ask to see.
Human resources security and access control policies for essential and important entities. Leaver handling sits squarely inside it.
An ex-employee with live access to personal data is a security-of-processing failure. Revocation in minutes closes the window.
Measure it before you buy anything.
Both tools run free and self-serve. They produce the same numbers the Lifecycle Audit starts from, so nothing here asks you to take our word for it.
Offboarding Risk Assessment
Free · 10 questions · ~3 minutes
A 5-axis risk profile across access control, shadow IT, data continuity, compliance and post-departure monitoring. The optional read-only Microsoft scan shows live gaps in your own tenant.
Score your offboarding riskSaaS Auditor
Free scan · Microsoft 365 + Google Workspace
Finds the licences and SaaS seats you pay for and nobody uses, joiner-leaver bleed included. Runs against a live tenant and returns results in minutes.
Run the waste scanLicences that can sit under IT Onboarding & Offboarding.
ITSailor sells Microsoft and selected marketplace licences through Pax8 at vendor list price. Our margin is the Pax8 wholesale discount; service work is quoted or packaged separately.
Microsoft
Microsoft 365 Business Basic EEA (no Teams)
€5.60 / user / month
Monthly commit
Microsoft
Microsoft 365 Business Standard EEA (no Teams)
€11.21 / user / month
Monthly commit
Microsoft
Microsoft 365 Business Premium EEA (no Teams)
€19.54 / user / month
Monthly commit
Includes Defender for Business, Defender for Office 365 P1, Entra ID P1, Intune P1 - never double-sell these alongside BP.
View bundleMicrosoft
Microsoft 365 E3 EEA (no Teams)
€36.43 / user / month
Monthly commit
Microsoft
Microsoft 365 E5 EEA (no Teams)
€60.85 / user / month
Monthly commit
Microsoft
Microsoft Teams EEA
€8.89 / user / month
Monthly commit
EEA rule: every net-new EEA suite is '(no Teams)'; Teams ships as this standalone SKU.
View bundleMicrosoft
Exchange Online (Plan 1)
€4.20 / user / month
Monthly commit
Microsoft
Microsoft Entra ID P1
€7.32 / user / month
Monthly commit
Microsoft
Microsoft Intune Plan 1
€8.28 / user / month
Monthly commit
Microsoft
Microsoft 365 Copilot
€27.30 / user / month
1-Year commit, monthly billing
Annual commitment required by Microsoft. Self-serve copy must state the 1-year commitment explicitly. Requires eligible base (E3/E5/Business).
View bundleMicrosoft
Microsoft 365 Copilot Business
€21.84 / user / month
Monthly commit
SMB Copilot: requires Business Basic/Standard/Premium base, 300-seat cap.
View bundleNord Security
NordPass Business (password manager)
Usage-based, quoted
Monthly commit
Usage-billed on Pax8 (no fixed rate card via API - the /pricing endpoint 404s). Per-user password manager with admin console and policy. Pairs with NordLayer in the Secure Remote Workforce / Zero Trust Starter bundles (planned). Sold quoted/usage-based.
Honest answers to the questions buyers actually ask.
We are a 30-person company with no IT department. Is this for us?
+
This is built for exactly that situation. We wire the joiner and leaver chains into whatever HR flow you already have, then either run them under the managed tier or hand them over with runbooks. You get an SLA and a Slack channel instead of hiring a full-time admin.
Do you also supply the laptops?
+
Not today, and we would rather say so than improvise. This engagement covers identity, licences, apps and access. Device procurement and endpoint management are deliberately out of scope until we can run them at the same standard as the rest of this page.
Can you handle both Google Workspace and Microsoft 365?
+
Yes. The joiner and leaver chains work on either platform, or both at once for companies that split email and collaboration. Microsoft licensing routes through Pax8 today; Google resale stays quoted until the partner route is formally cleared.
What happens when someone leaves?
+
Under the managed tier: account disabled within 1 hour of HR notification, sessions and refresh tokens revoked immediately, mailbox converted to shared, OneDrive archived, SaaS seats stripped and the licence returned to the pool. Every step lands in the audit trail with a timestamp.
Which HR systems can trigger the flows?
+
Personio, BambooHR and HiBob are the common cases. Anything that can fire a webhook or send a structured email works, including a plain HR mailbox with a defined subject format. The trigger layer is deliberately boring so your HR team never has to change how they work.
Does the automation lock us into ITSailor?
+
No. The flows run inside your tenant, the runbooks live in your repository, and the Exit Kit documents the whole build so your next vendor picks it up in 24 hours. That is the Sovereign Mastery rule every ITSailor engagement closes with.
Who actually does the work?
+
One senior engineer, the same one you meet on the discovery call. No account managers, no offshore hand-off, no junior rotation. You get a single Slack channel and a direct line to the person who wrote the flows.
Make joiner, mover and leaver one procedure with an execution log.
The workshop maps the three paths onto the tooling you already pay for, and decides which steps have to leave a record an auditor can read.