Skip to content

New hires work on day one. Leavers lose access in minutes.

One HR event triggers the whole chain: account, licence, mailbox, apps. The same chain runs in reverse the hour someone resigns. Built with Power Automate or n8n inside your Microsoft 365 or Google Workspace tenant, and every run writes the log your auditor asks to see.

2 days → 30 min
New-hire setup, before vs after
0 min
Manual IT work per offboarding
100%
Access-termination audit score
€1,500/mo
Dead-licence spend reclaimed

Founder casework: identity-lifecycle automation built at a regulated Maltese operator (~100 staff), before ITSailor. Details in the field notes below.

The problem

New hires wait days. Leavers keep access for weeks.

Both failures have the same root: joiner and leaver handling lives in inboxes and one admin's memory. It scales with headcount, and it is the first process that snaps when you grow.

The day-one apology

The new hire shows up to "IT will sort you out by Thursday." Three days of borrowed logins, no email, no access to the systems they were hired to run. That is the first impression your company makes.

The leaver risk window

Accounts stay live for days after a departure. Sessions keep working, shared mailboxes stay readable, SaaS seats stay assigned. Ahead of an audit that is an access-termination finding. On a bad day it is an incident.

Licence and seat bleed

Nobody reclaims the Microsoft 365 seat, the Slack licence or the Figma editor when someone leaves. Finance keeps paying for ghosts, month after month, and the seat inventory stopped being true a year ago.

The mechanism

One HR event. The whole chain executes.

No ticket queue and no wiki checklist. The HR system fires a webhook, the workflow does the rest in seconds, and every step lands in a timestamped log. This is what a run looks like, joiner and leaver.

Loading the interactive console

Illustrative run. The production version is built with Power Automate or n8n inside your tenant, tuned to your HR system and app stack, and logs every execution.

Why the log matters

The auditor doesn't ask if you have a procedure in PDF. They ask if you can show the execution log. We showed them green checkmarks from Power Automate going back a full year.
- Michal Jatczak, founder · ITSailor
Field notes

This exact automation passed a real regulator's audit.

Before ITSailor, the founder built this lifecycle at a regulated Maltese operator with roughly 100 staff. The numbers on this page come from that work, not from a brochure.

Case: the offboarding kill-switch

The starting point.HR offboarded staff by emailing IT. Departing employees kept active Exchange access, shared mailboxes included, for up to a week after exit. The regulator's audit was months away.

The build. A Power Automate workflow listening to HR status changes: it kills Entra ID sessions instantly, converts the mailbox to shared, reclaims the E3 or E5 licence and archives OneDrive. No human in the standard path.

0 min
Manual offboarding work
100%
Access-termination audit score
€1,500/mo
Dead licences reclaimed

The part that went wrong

The first production run archived the CEO's mailbox because of a typo in a department code in the HR system. 2 AM, sweating, restoring from backup. Since then every C-level account gets a manual Teams approval gate before the workflow touches it. That gate ships in every build.

Case: the joiner side

Same operator, other end of the lifecycle. Onboarding a new employee was a 2-day manual click-and-install session through the helpdesk. After the rollout, accounts and access flowed automatically the moment the HR record existed: 30 minutes from sign-in to working, with the helpdesk out of the loop entirely.

Why we show the mess

Vendors love before-and-after numbers and hate telling you what broke on the way. The CEO-mailbox story is where the executive approval gate came from. Every safeguard in this offering exists because something like it went wrong once.

What gets built

Six pieces of plumbing. All of it yours to keep.

Every flow, runbook and log lives in your tenant and your repository. The Exit Kit documents the whole build, so your next vendor could pick it up in 24 hours.

HR trigger integration

Personio, BambooHR, HiBob or a structured HR mailbox. If your HR system can fire a webhook or send a parseable email, it can drive the whole lifecycle. Power Automate or n8n, in your tenant.

Identity provisioning

Entra ID or Google Directory account creation with group-based entitlements. Department and role decide what opens. Nobody hand-picks permissions at 8 AM on a start date.

Licence assignment and reclamation

A right-sized licence assigned on day one and returned to the pool on exit. Routed through the Pax8 marketplace at vendor list price when you want everything on one EUR invoice.

SaaS seat provisioning

Slack, Jira, Notion, Figma and the rest granted through SCIM or documented API calls, and reclaimed the same way. The seat inventory stays true because the workflow maintains it.

The offboarding kill-switch

One trigger revokes sessions and refresh tokens, blocks sign-in, converts the mailbox to shared, archives OneDrive and strips every SaaS seat. Executive accounts get a manual approval gate first.

Evidence log and access reviews

Every run writes who, what and when to a log you own. Quarterly access-review exports come ready for an ISO 27001 A.5.18 check or a regulator-style access-termination test.

Productized engagements

Start with the audit. Automate what it finds.

Fixed fee or retainer, agreed before work starts. No hourly billing at any tier.

Lifecycle Audit

One week. You learn how bad the leaver risk window really is.

Scoped to youFixed fee · 1 week
  • Current joiner / mover / leaver flow mapped step by step
  • Offboarding risk assessment with an optional read-only Microsoft scan
  • Licence and SaaS seat bleed quantified in euros
  • Access-termination evidence gaps checked against ISO 27001 A.5.18
  • Prioritised automation backlog + 45-minute walkthrough

Outcome

You know your leaver risk window in hours and your licence bleed in euros.

Scope the audit
Most popular

Lifecycle Automation Build

The joiner chain and the leaver kill-switch, wired and evidenced.

Scoped to youFixed scope · 2-4 weeks
  • HR trigger wired: Personio, BambooHR, HiBob or a structured mailbox
  • Joiner chain: account, groups, licence, mailbox, SaaS seats via SCIM
  • Leaver kill-switch: sessions, tokens, mailbox, OneDrive, seats, licence
  • Manual approval gate for executive accounts
  • Evidence logging + runbooks in your repository, Exit Kit included

Outcome

Onboarding and offboarding run themselves. You own every flow.

Scope the build

Managed Lifecycle

We operate the chains. You get the SLA and the evidence.

Scoped to youMonthly retainer · 6 months min.
  • Offboarding SLA: account disabled within 1 hour of HR notification
  • Quarterly access reviews with a signed evidence pack
  • Licence reclamation report: every freed seat credited
  • New-app requests reviewed against your stack policy
  • Flow maintenance as HR systems and tenant baselines drift

Outcome

A leaver process your auditor can verify from the log, quarter after quarter.

Talk about managed
Why auditors ask about this

The clauses the evidence log answers.

Provisioning and revocation are named controls in the frameworks EU operators are audited against. A timestamped run log answers them directly, without a documentation sprint before every review.

ISO 27001:2022A.5.18 · Access rights

Access provisioned, reviewed and revoked on role change and exit. The run log is the record reviewers ask to see.

NIS2Art. 21(2)(i)

Human resources security and access control policies for essential and important entities. Leaver handling sits squarely inside it.

GDPRArt. 32

An ex-employee with live access to personal data is a security-of-processing failure. Revocation in minutes closes the window.

Free diagnostics

Measure it before you buy anything.

Both tools run free and self-serve. They produce the same numbers the Lifecycle Audit starts from, so nothing here asks you to take our word for it.

Offboarding Risk Assessment

Free · 10 questions · ~3 minutes

A 5-axis risk profile across access control, shadow IT, data continuity, compliance and post-departure monitoring. The optional read-only Microsoft scan shows live gaps in your own tenant.

Score your offboarding risk

SaaS Auditor

Free scan · Microsoft 365 + Google Workspace

Finds the licences and SaaS seats you pay for and nobody uses, joiner-leaver bleed included. Runs against a live tenant and returns results in minutes.

Run the waste scan
Provisioned stack

Licences that can sit under IT Onboarding & Offboarding.

ITSailor sells Microsoft and selected marketplace licences through Pax8 at vendor list price. Our margin is the Pax8 wholesale discount; service work is quoted or packaged separately.

Microsoft

Microsoft 365 Business Basic EEA (no Teams)

€5.60 / user / month

Monthly commit

Microsoft

Microsoft 365 Business Standard EEA (no Teams)

€11.21 / user / month

Monthly commit

View bundle

Microsoft

Microsoft 365 Business Premium EEA (no Teams)

€19.54 / user / month

Monthly commit

Includes Defender for Business, Defender for Office 365 P1, Entra ID P1, Intune P1 - never double-sell these alongside BP.

View bundle

Microsoft

Microsoft 365 E3 EEA (no Teams)

€36.43 / user / month

Monthly commit

Microsoft

Microsoft 365 E5 EEA (no Teams)

€60.85 / user / month

Monthly commit

Microsoft

Microsoft Teams EEA

€8.89 / user / month

Monthly commit

EEA rule: every net-new EEA suite is '(no Teams)'; Teams ships as this standalone SKU.

View bundle

Microsoft

Exchange Online (Plan 1)

€4.20 / user / month

Monthly commit

Microsoft

Microsoft Entra ID P1

€7.32 / user / month

Monthly commit

Microsoft

Microsoft Intune Plan 1

€8.28 / user / month

Monthly commit

Microsoft

Microsoft 365 Copilot

€27.30 / user / month

1-Year commit, monthly billing

Annual commitment required by Microsoft. Self-serve copy must state the 1-year commitment explicitly. Requires eligible base (E3/E5/Business).

View bundle

Microsoft

Microsoft 365 Copilot Business

€21.84 / user / month

Monthly commit

SMB Copilot: requires Business Basic/Standard/Premium base, 300-seat cap.

View bundle

Nord Security

NordPass Business (password manager)

Usage-based, quoted

Monthly commit

Usage-billed on Pax8 (no fixed rate card via API - the /pricing endpoint 404s). Per-user password manager with admin console and policy. Pairs with NordLayer in the Secure Remote Workforce / Zero Trust Starter bundles (planned). Sold quoted/usage-based.

FAQ

Honest answers to the questions buyers actually ask.

We are a 30-person company with no IT department. Is this for us?

+

This is built for exactly that situation. We wire the joiner and leaver chains into whatever HR flow you already have, then either run them under the managed tier or hand them over with runbooks. You get an SLA and a Slack channel instead of hiring a full-time admin.

Do you also supply the laptops?

+

Not today, and we would rather say so than improvise. This engagement covers identity, licences, apps and access. Device procurement and endpoint management are deliberately out of scope until we can run them at the same standard as the rest of this page.

Can you handle both Google Workspace and Microsoft 365?

+

Yes. The joiner and leaver chains work on either platform, or both at once for companies that split email and collaboration. Microsoft licensing routes through Pax8 today; Google resale stays quoted until the partner route is formally cleared.

What happens when someone leaves?

+

Under the managed tier: account disabled within 1 hour of HR notification, sessions and refresh tokens revoked immediately, mailbox converted to shared, OneDrive archived, SaaS seats stripped and the licence returned to the pool. Every step lands in the audit trail with a timestamp.

Which HR systems can trigger the flows?

+

Personio, BambooHR and HiBob are the common cases. Anything that can fire a webhook or send a structured email works, including a plain HR mailbox with a defined subject format. The trigger layer is deliberately boring so your HR team never has to change how they work.

Does the automation lock us into ITSailor?

+

No. The flows run inside your tenant, the runbooks live in your repository, and the Exit Kit documents the whole build so your next vendor picks it up in 24 hours. That is the Sovereign Mastery rule every ITSailor engagement closes with.

Who actually does the work?

+

One senior engineer, the same one you meet on the discovery call. No account managers, no offshore hand-off, no junior rotation. You get a single Slack channel and a direct line to the person who wrote the flows.

Make joiner, mover and leaver one procedure with an execution log.

The workshop maps the three paths onto the tooling you already pay for, and decides which steps have to leave a record an auditor can read.