IT Access Provisioning System

OPS/AP COORDINATOR · GOOGLE WORKSPACE · ROLE-BASED ACCESS · 3 FLOWS

Ops/IT Coord New Hire / Employee Approver Decision System (GWS) Security / Infra
Ops/IT Coordinator
Employee
Approval / security gate
Decision
System (Google Workspace)
Security / Infra
Complete
Google identity groups org-role-mts org-role-ops org-role-staff org-type-fte org-type-contractor
Constraints No public posting · Internal visibility only · Manager-gated
Flow 1 — New hire provisioning Google WorkspaceRole-based groups
Trigger
Identity setup
Group assignment
Tool provisioning
Verification
Ops / IT Coord
New Hire
Hiring Manager
GWS (system)
Security / Infra
Flow 2 — Role change / access modification Approval requiredLeast-privilege review
Request
Review
Approval
Execution
Confirm
Employee
Ops / IT Coord
Manager / Approver
GWS (system)
Security / Infra
Flow 3 — Offboarding / access revocation Time-criticalAudit evidence required
Trigger
Immediate actions
Full revocation
Asset return
Audit close
Ops / IT Coord
Departing Employee
Manager / HR
GWS (system)
Security / Infra

Exception paths & edge cases

E1 — Wrong group assigned on provisioning

New hire placed in incorrect org-role or org-type group, granting wrong tool access.

Re-entry: Ops removes from wrong group, adds to correct group, re-verifies access within 24h

E2 — 2SV not enabled within 24h

New hire fails to enable 2-step verification on Google account after provisioning.

Re-entry: Ops sends reminder, IT blocks non-2SV accounts after 48h grace period

E3 — Role change request without manager approval

Employee requests elevated access without documented manager sign-off.

Re-entry: Request held, Ops pings manager for approval, 2-day SLA before auto-decline

E4 — Contractor granted FTE-level access

org-type-contractor accidentally added to FTE-only groups or given persistent access.

Re-entry: Remove from FTE groups immediately, audit all contractor accounts quarterly

E5 — Offboarding triggered without notice

Immediate termination — no standard notice period. Access must be revoked same day.

Re-entry: Emergency revocation protocol — suspend GWS account within 1 hour of HR trigger

E6 — Device not returned at offboarding

Departing employee fails to return MacBook or other company hardware.

Re-entry: Remote wipe initiated, asset log updated, legal notified if not returned within 5 days

E7 — Shared account / alias not cleaned up

Departing employee owned a shared inbox or alias that others depend on.

Re-entry: Transfer alias ownership to Ops admin, notify dependents, update runbooks

E8 — Access creep — stale permissions post role-change

Employee changed roles but retained old group memberships and tool access.

Re-entry: Quarterly access audit, remove stale memberships, log changes in audit trail

E9 — New tool not in standard stack

Role requires access to a tool not covered by standard group assignment.

Re-entry: Ops creates access request ticket, security reviews, approver signs off, provision

E10 — GWS account creation fails

Technical error during account creation — email not delivered or account not activated.

Re-entry: Ops manually triggers account creation, verifies email delivery, re-runs provisioning