Back to blog

Access Automation: The Google Workspace Joiner/Mover/Leaver Template

August 29, 20266 min
Workflow Management

Access Automation — Google Lifecycle is an OpenTechnologyApp project template for the joiner/mover/leaver problem every IT team has: a new hire needs an account, groups, and a welcome message on day one; a departure needs the same access removed, verified, and handed off — on a deadline, not eventually. Four queues, five playbooks, and automations that turn one field change into the work it actually implies.

What it tracks

Every hire or departure starts as one lifecycle case, and one field — Workflow State — drives everything downstream: Intake → Ready — Onboarding (or Ready — Offboarding) → In Progress → Complete. Moving a case to "Ready" is the trigger; everything after that is generated, not remembered.

Four queues, one lifecycle

QueueWhat lives there
OnboardingOne lifecycle case per new hire — employee and manager details, target org unit, target groups, effective date
OffboardingOne lifecycle case per departure — same shape, defaults to urgent priority
IT TicketsThe internal access work each lifecycle case generates, tracked and closed independently of the case that spawned it
New-Hire + Manager CommunicationsWelcome messages, day-one readiness checks, departure notices, and manager handoffs — as a tracked item, or as an actual email

Automations that generate the work, not just remind you of it

Move a case's Workflow State to Ready — Onboarding and two things happen automatically: a Google onboarding task appears in the Onboarding queue, pre-filled with the target org unit and groups from the parent case, and an IT ticket appears in IT Tickets for the internal access work. Offboarding works the same way in reverse — urgent priority by default, since a departure on the clock is a different kind of urgent than a new hire who hasn't started yet.

A fifth automation — sending a manager-readiness email the moment a communication item is marked "Ready" — ships disabled by default, the same discipline as this template's device-audit sibling: verify the workflow with tracked items first, turn on the email once you trust it.

Five playbooks, one per work type

  • Google onboarding — verify employee email, start date, org unit, and groups; create or verify the Google user; apply the target org unit and groups; record status and an evidence note
  • Google offboarding — remove group memberships; suspend the user and rotate the password; clear recovery email and phone; move to the archived org unit; record the Drive-transfer decision; verify final state
  • IT access ticket — confirm the lifecycle case and effective date; complete the requested access work; link the outcome and close
  • Employee communication — verify recipient and template; send or complete the item-only handoff; record the delivery outcome
  • Manager communication — verify the manager and lifecycle context; send or complete the handoff; record the outcome and any decisions made

What's tracked, not automated — on purpose

This is the honest part, and it matters more than any feature list: Google account changes are a checklist, not an API call. Every Google onboarding and offboarding task in this template is a manual playbook — the person doing the work opens the Google Admin console themselves and works the steps, then records what happened back on the item. There's no live connector creating or suspending Google users on your behalf yet.

That's a deliberate choice, not a missing feature waiting to be discovered. A tool that silently provisions or deletes accounts in your identity provider is exactly the kind of thing that shouldn't ship quietly — manual-until-verified is the same posture this template's automations take with email. If a live Google connector ships later, it's a separately authorized addition, not something this template does today.

One more scope note worth stating plainly: this template is Google Workspace-specific, not a generic multi-identity-provider system. If your org runs a different identity provider, the lifecycle-case and IT-ticket structure still applies — the Google-specific fields and playbooks would need their own equivalents built for your provider.

Get it

Import Access Automation — Google Lifecycle from the template picker in OpenTechnologyApp — it's built in, four queues and all.

Get in Touch

Interested in a topic? Drop a note and select a category. I'm also available for a free consultation meeting — reach out and we'll set something up.