Skip to content
Kaamless
Book a demo

What I automate / Joining, moving and leaving

Joining, moving and leaving

A new joiner needs accounts in six or eight systems, the right access in each, a laptop, and a set of documents signed. It is done from a checklist that lives in someone's head or a document that is slightly out of date, and something is always missed — usually discovered by the new person on their second day.

Leaving is the same process in reverse and matters far more. Access that outlives the person is the most common serious security finding in small companies, and it happens for an ordinary reason: nobody owns the list.

The automation is not exotic. One request, a defined route, the accounts created or removed, and — the important part — a confirmation that each step actually happened rather than an assumption that it did.

You probably know this is you if

  • A new joiner's setup is assembled from memory and something is always missing
  • Nobody can produce a current list of who has access to what
  • Somebody who left months ago still has an active account somewhere
  • Signed policies and documents are chased by hand
  • Laptops and devices are tracked in somebody's memory

The jobs in this area

  • Setting up a new joiner across eight tools

    One request creates the accounts, access and equipment checklist, and tells each owner what to do.

  • Access that outlives the person

    Leaving triggers removal everywhere, with a confirmation that it actually happened.

  • Nobody knowing who has access to what

    A current access list generated on demand, plus a periodic review sent to whoever owns each system.

  • Chasing signed policies and documents

    Documents issued, reminders sent, and only the outstanding names left to chase.

  • Assets tracked in somebody's memory

    Laptops and devices logged against people, with a return checklist that runs at exit.

How a build like this goes

  1. 1

    Write down the actual list first, per role. Most companies have never had it on one page, and producing it is valuable before anything is automated.

  2. 2

    Automate creation where there is an API, and generate a clear task for a named owner where there is not. A checklist that arrives and is chased automatically is a large improvement over one that exists in principle.

  3. 3

    Make offboarding the priority, not onboarding. It is the one with real risk attached, and it is usually less work.

  4. 4

    Add a periodic access review that goes to whoever owns each system, so the list stays true without anyone maintaining it.

A worked example

Joiner and leaver across eight systems

Before
About three hours of HR and IT time per joiner, and an offboarding checklist that was completed most of the time.
After
One form, accounts created, owners notified for the rest, and a confirmed completion report. Offboarding runs the same way, in reverse.

At 24 joiners and leavers a year, three hours each is 72 hours. That is real but it is not the argument. The argument is the account that was still active four months after someone left — which costs nothing until the day it costs a great deal.

Those are illustrative figures, not a quote and not a promise. Your own numbers are the only ones that matter — the calculator does the same arithmetic on them.

What this normally costs

A job in this area is usually a connected module: ₹60,000 to ₹1,80,000, two to four weeks. The exact number comes from the audit, in writing, before anything is built.

The audit itself is ₹9,999 and comes off the first build in full. If it turns out this is not worth automating for you, that is what the report will say.

See the full price list

Questions about this kind of work

Some of our tools have no API.

Then those become generated tasks with named owners and automatic chasing, rather than silent gaps. Partial automation with complete visibility is much better than nothing, and it is honest about what it does.

Is this not what an HR system does?

Some do, well. If yours does, use it and I will say so. This work is usually needed because HR and IT use different systems and the join between them is a person.

Can it handle contractors and temporary access?

Yes, and that is often where the worst of the problem is — access granted for two weeks, three years ago, and never reviewed.

Tell me about your version of this

Anything on this list, or something that is not on it. Ask, and you will get a straight answer about whether it can be built.

What happens today, who does it, and how often. A few lines is plenty.

I reply within one working day. No mailing list, no follow-up you did not ask for.

Tell me the job you are tired of

One call, half an hour. You will get a straight answer about whether it is worth automating — including 'no' if that is the answer.