New hire placed in incorrect org-role or org-type group, granting wrong tool access.
Re-entry: Ops removes from wrong group, adds to correct group, re-verifies access within 24h
New hire fails to enable 2-step verification on Google account after provisioning.
Re-entry: Ops sends reminder, IT blocks non-2SV accounts after 48h grace period
Employee requests elevated access without documented manager sign-off.
Re-entry: Request held, Ops pings manager for approval, 2-day SLA before auto-decline
org-type-contractor accidentally added to FTE-only groups or given persistent access.
Re-entry: Remove from FTE groups immediately, audit all contractor accounts quarterly
Immediate termination — no standard notice period. Access must be revoked same day.
Re-entry: Emergency revocation protocol — suspend GWS account within 1 hour of HR trigger
Departing employee fails to return MacBook or other company hardware.
Re-entry: Remote wipe initiated, asset log updated, legal notified if not returned within 5 days
Departing employee owned a shared inbox or alias that others depend on.
Re-entry: Transfer alias ownership to Ops admin, notify dependents, update runbooks
Employee changed roles but retained old group memberships and tool access.
Re-entry: Quarterly access audit, remove stale memberships, log changes in audit trail
Role requires access to a tool not covered by standard group assignment.
Re-entry: Ops creates access request ticket, security reviews, approver signs off, provision
Technical error during account creation — email not delivered or account not activated.
Re-entry: Ops manually triggers account creation, verifies email delivery, re-runs provisioning