Workflow Automation

IT access provisioning and offboarding revoke for Singapore SMEs: who cuts the keys when someone leaves Friday

IT access provisioning and offboarding revoke for Singapore SMEs: who cuts the keys when someone leaves Friday

IT access provisioning and offboarding revoke for Singapore SMEs: who cuts the keys when someone leaves Friday

Friday 16:47. The owner’s cousin — the unofficial IT person who also runs payroll on Mondays — gets a Telegram: “pls disable Jason, last day today.” Jason still has Google Workspace, the Xero invite, three vendor portals that never went through SSO, a shared Drive folder with supplier contracts, and a company WhatsApp on his personal phone. Nobody has a list. The cousin opens Admin Console, guesses which groups matter, and hopes the weekend does not invent a login.

That is the IT access problem for a Singapore SME. Not a missing identity product. Not a cyber “threat landscape” slide. A design gap: hire and exit happen in chat; the keys live in a dozen places; and the person who cuts them is still a named human who needs a register, a last-day checklist, and a chase list for anything that does not die when you hit Disable.

This guide is the operator runbook for IT access provisioning and offboarding revoke in a 10–80 person Singapore firm. Name who grants. Name who revokes. Name the access register. Name the last-day sequence. Name the non-SSO leftovers. Automation files the register, flags the exit, and chases the humans who still hold the switch — it does not invent consent to wipe every account because a Sheet cell turned red. Soft peers if you already run the people side: leave cover, employee onboarding paperwork, expense claims. Wider frame: workflow automation services. This is not a second hire-pack paperwork article, not resume screening, not an MSSP pitch, and not grant or PSG theatre.

What this guide covers

  • What IT access provisioning / offboarding revoke means for an SME operator — not an IdP vendor page
  • What “automation” means here: register, flags, chase — named human still gates grant and revoke
  • Why Singapore SME context (cousin-as-IT, chat-triggered exits, SaaS sprawl) matters without a news dump
  • A print-and-mark-up runbook: hire/exit trigger → access register → grant path → last-day IdP disable + session revoke + non-SSO chase → audit timestamps → leave-cover for the IT/admin owner
  • Who signs grant vs revoke, and where judgement stays human
  • Sheets / Drive / Telegram DIY that stops before auto-revoke everything
  • Failure modes and a this-week checklist
  • Soft next step — consult → build → train, lightly

What automation means here

Search “IT offboarding” or “access provisioning SME” and you will mostly get enterprise IAM whitepapers, MSSP package pages, or a product tour that assumes you already have Okta, a full HRIS, and a security team. Useful as a sketch. Thin as an operating manual for a trading, logistics, construction, recruitment, or professional-services firm where “IT” is one trusted person with Admin Console access, and Friday exits arrive as a Telegram ping.

For an SME operator, the job is simpler to name:

A named human still decides grant and revoke. Automation keeps the access register honest, flags hire and exit triggers, and chases incomplete last-day work — with timestamps you can show if someone asks “was Jason still in Xero on Monday?”

Three purchases get confused under the same phrase:

  • Software — Google Workspace / Microsoft 365 admin, an identity add-on, a password manager, a SaaS that promises “lifecycle.” Fine when your roles are already written and someone still owns the exception list.
  • A service — someone maps *your* systems into a living register, wires hire/exit triggers into that register, builds the smallest chase pings for last-day and non-SSO leftovers, trains the cousin-as-IT and the backup, and is still reachable when a new vendor portal appears next quarter.
  • A chat habit — “pls disable” into a group with no register, no last-day sequence, and no audit row. It works until the cousin is on MC the same Friday someone leaves.

Buy software if the identity layer is clean and volume is high. Leave it careful and manual if you have eight people and three tools. Hire a service when the same Friday scramble repeats, access spans IdP + finance + ops SaaS + personal devices, and a missed revoke is mailbox, data, or invoice risk — not a checkbox for a grant form.

Core thesis, said once: named human gates the keys; automation files the register and chases the gaps. Auto-revoke-everything because a date passed is not maturity. It is hope with a cron job.

Why Singapore SME access + offboarding matter (without a theatre roundup)

You do not design this runbook because a compliance blog told you to. You design it because people leave on Fridays, the unofficial IT person has a day job, and half your tools never joined SSO.

Cousin-as-IT is normal. In a 15–40 person firm, Admin Console, domain DNS, and “who has the Xero invite” often sit with one trusted person who also does something else. When they are on AL, leave cover for *that* owner matters as much as leave cover for invoice approve — see the leave-cover design.

Exits arrive in chat. HR paperwork may live in a folder; the revoke trigger still shows up as WhatsApp or Telegram. If the process starts only when someone remembers to message IT, you will miss silent leavers, contractors who “finished last week,” and people who kept a vendor login after the contract ended.

SaaS sprawl beats the IdP story. Google or Microsoft disable is necessary and not sufficient. Vendor portals, logistics tools, marketing seats, shared mailboxes, and “we bought one licence on the founder’s card” accounts do not die when you click Suspend. Those need a chase list with owners and done-by timestamps.

PDPA, lightly — not a legal brief. Email mailboxes, Drive folders, and personal devices that held company WhatsApp or files are personal-data and access surfaces. Offboarding is not only “kill the login.” It is also who owns the mailbox forward or hold, what leaves the personal phone, and who records that the chase happened. Treat this as operator hygiene aligned with care for personal data — not as a substitute for counsel or a DPO memo.

Labour and tooling pressure is permission to stay practical. You do not need a platform migration sold as cyber readiness. One living access register, one last-day sequence, and one backup for the IT/admin owner beats a slide deck about zero trust that nobody can run on a quiet Tuesday.

The named runbook (print this)

Print this. Write real names and real systems. If a blank stays empty on last day, you do not have offboarding yet — you have a hope that Telegram arrives early enough.

1. Hire / exit trigger

  • Who opens a hire row (ops / HR / founder): _______________________
  • Who opens an exit row (same, plus manager): _______________________
  • Where the trigger lives: ________ (Sheet tab / shared mailbox label / form → Sheet)
  • SLA from “last day confirmed” to “IT notified”: ________ (example: same business day, Asia/Singapore)

Exit trigger is separate from onboarding paperwork. Paperwork proves the hire; this runbook cuts and returns the keys. Do not merge them into one overloaded checklist that nobody finishes.

2. Access register (living list, not a wiki nobody opens)

Minimum columns:

| Field | Why it exists |

| --- | --- |

| Person / contractor | Who holds the keys |

| Role / team | Default bundle hint |

| System | Workspace, M365, Xero, vendor portal, VPN, etc. |

| Account ID / email | What to disable or delete |

| Access level | User / admin / shared mailbox / API |

| SSO? | Yes / No — No means chase on exit |

| Owner of that system | Who can actually revoke |

| Granted date / by | Audit |

| Revoke due (last day) | Clock |

| Revoke done timestamp / by | Proof |

| Notes (mailbox, device, shared folder) | Exceptions |

One row per person–system. Not “Jason — all the usual stuff.” Shared mailboxes and shared Drive folders get their own rows when more than one human can open them.

3. Grant path (provisioning without theatre)

1. Hire trigger lands → register rows created from a role bundle (template tabs: Sales, Ops, Finance, Contractor-light).

2. Named granter reviews the bundle — adds or removes systems for *this* person.

3. Grant happens in the real admin UI (or invite email).

4. Granter stamps Granted date / by on each row.

5. Day-3 or day-5 ping: any “invite pending” or “still using founder login” rows get chased.

Judgement stays human on admin rights, finance systems, and anything that can move money or export a full customer list. Automation may pre-fill the bundle; it does not auto-admin someone because the job title matched a string.

4. Last-day sequence (the Friday spine)

Order matters. Write clock language.

1. Confirm last day and time (Asia/Singapore) on the exit row — not vibes.

2. IdP / primary directory disable (Google Workspace Suspend / Microsoft block sign-in) at the agreed time — usually end of last day or immediately after handover meeting.

3. Session revoke / sign-out everywhere where the admin panel offers it.

4. Mailbox path — named decision: hold / delegate / auto-reply / transfer ownership of Drive. Record who owns the mailbox now.

5. Password manager / shared vault — remove from groups; rotate any shared secrets that person could see.

6. Non-SSO SaaS chase list — every register row where SSO = No: owner pinged with link to the row, due timestamp, and “reply done when revoked.”

7. Devices — company laptop return checklist; personal phone: remove company WhatsApp / MDM / mail profile as applicable. Note what you could not verify.

8. Audit stamp — each row gets Revoke done timestamp / by. Incomplete rows stay red into next week — not “we’ll finish Monday” with no owner.

5. Leave-cover for the IT / admin owner

The cousin gets MC too. Name:

  • Primary IT/admin for access: _______________________
  • Backup who can open Admin Console and the register: _______________________
  • Where credentials / break-glass live (company vault, not a personal phone note): _______________________
  • What the backup may not do alone (example: create new Super Admin; delete domain): _______________________

Wire this to your leave-cover design. Access revoke that dies when IT is on AL is the same class of failure as invoice approve that dies when Mei is on AL.

Who signs (grant, revoke, exceptions)

| Decision | Named role (example) | Automation may… | Automation must not… |

| --- | --- | --- | --- |

| Approve role bundle for new hire | Manager + IT/admin | Pre-fill template rows | Grant admin because title matched |

| Grant finance / payroll / bank-file tools | Finance owner + IT | Flag “finance tier” | Silent invite to Xero admin |

| Revoke on last day (IdP) | IT/admin (or backup) | Remind at T−1 / T−0 | Disable early without human confirm |

| Non-SSO vendor revoke | System owner listed on row | Chase ping + escalate | Assume “done” from silence |

| Mailbox / Drive ownership | Ops or manager + IT | Offer default path options | Auto-delete mailbox day-of |

| Exception: keep access past last day | Founder / director written yes | Flag overdue revoke | Extend because chat said “asap” |

If “who signs” is “the group chat,” you do not have a control. You have a scrollback.

Sheets vs “an IT tool”

A company Google Sheet (or Excel in SharePoint) plus Admin Console plus Telegram is enough to start if:

  • You have under ~80 people and a countable system list
  • Someone will actually update Revoke done timestamps
  • Non-SSO owners are named humans, not “vendor team”

Move toward a tighter tool when:

  • Contractor churn is weekly and the Sheet lies
  • You already pay for an HRIS that can emit hire/exit events worth trusting
  • Multiple admins need forced checklist UX and you are tired of arguing about columns

Do not buy a platform to avoid writing the register. The register is the product until the process is true on a quiet Tuesday.

Steal-this-build DIY (stops before auto-revoke everything)

Build only this. Stop where judgement starts.

1. Sheet: Access_Register with the columns above; separate tab Role_Bundles (Sales / Ops / Finance / Contractor-light).

2. Sheet: Hire_Exit_Log — date, person, type (hire/exit), last day, trigger by, IT notified timestamp, status.

3. Drive folder (company Shared Drive): `/People/Access/` — only IT primary + backup + one ops owner.

4. Telegram or WhatsApp dedicated thread or bot ping: messages only contain link to the exit row + due time — not passwords, not screenshots of Admin Console.

5. T−1 reminder (Apps Script or manual morning habit): list exits with last day = tomorrow and any row still missing Revoke due.

6. T−0 checklist printed or a second tab: IdP → sessions → mailbox path → vault → non-SSO chase → device notes → stamps.

7. T+2 chase: any red revoke rows escalate to system owner’s manager once — then founder if still open.

Hard stop: do not auto-Suspend Workspace because a date cell passed. Do not auto-delete mailboxes. Do not scrape passwords into the Sheet. Do not put break-glass admin passwords in Telegram. The DIY files and chases; the named human still cuts the keys.

Failure modes (name them so you can spot them)

  • Telegram-as-register — “pls disable” with no rows, no stamps, no non-SSO list.
  • IdP-only offboarding — Workspace off, Xero and three vendor portals still live on Monday.
  • Founder-card SaaS — licences and admins nobody listed because the bill never hit company finance.
  • Shared password folklore — one Notion or vendor login everyone knows; leaver still “knows.” Rotate or kill on exit.
  • Mailbox limbo — account suspended, nobody owns the inbox, customers mail a ghost.
  • Personal phone company chat — WhatsApp left on personal device; no recorded ask to leave groups / remove account.
  • IT single point of failure — cousin on MC, Friday exit, backup cannot open Admin Console.
  • Merged onboarding mega-checklist — paperwork + laptop + access in one 90-line Sheet nobody finishes; access revoke loses to “HR will handle.”
  • Silent auto-revoke fantasy — a script disables accounts from calendar without human confirm and without mailbox path. Fast, confident, and how you lock out the wrong contractor or destroy evidence you needed.

This week checklist

  • [ ] Name primary and backup IT/admin for access; confirm backup can open Admin Console without the primary’s phone
  • [ ] Create Access_Register with SSO? and Revoke done columns; list every system that can hold company data or money
  • [ ] Write four role bundles (even rough) so hire grant is not invented from memory each time
  • [ ] Define last-day clock (e.g. disable at 18:00 SGT on last day unless founder exception is written)
  • [ ] Pick mailbox default path (delegate vs auto-reply vs hold) and write it once
  • [ ] Run one tabletop on a fictional Friday leaver: walk IdP → sessions → mailbox → vault → non-SSO → devices → stamps
  • [ ] Schedule T+2 review of any red rows from the last real exit
  • [ ] Link this runbook beside leave-cover and onboarding paperwork so hire and exit do not fight over the same chat thread

Soft next step

If your Friday Telegram already looks like the opening scene, you do not need a cyber roadshow. You need a living register, a last-day sequence, and a backup for the human who still cuts the keys.

Lynqra’s usual path is consult → build → train: map *your* systems and owners, put the smallest Sheet + chase that makes last day true, train primary and backup to run it without heroics, and stay reachable when a new non-SSO seat appears. Pair it with leave cover so access revoke does not die on IT’s MC week, and keep onboarding paperwork as the hire-paper track — not a second copy of this article. Money-side peers stay one click away when the same firm is cleaning expense claims and the wider workflow automation picture.

Named human. Living register. Last-day stamps. Everything else is decoration until those three are true.