Access Automation — Google Lifecycle is an OpenTechnologyApp project template for the joiner/mover/leaver problem every IT team has: a new hire needs an account, groups, and a welcome message on day one; a departure needs the same access removed, verified, and handed off — on a deadline, not eventually. Four queues, five playbooks, and automations that turn one field change into the work it actually implies.
What it tracks
Every hire or departure starts as one lifecycle case, and one field — Workflow State — drives everything downstream: Intake → Ready — Onboarding (or Ready — Offboarding) → In Progress → Complete. Moving a case to "Ready" is the trigger; everything after that is generated, not remembered.
Four queues, one lifecycle
| Queue | What lives there |
|---|---|
| Onboarding | One lifecycle case per new hire — employee and manager details, target org unit, target groups, effective date |
| Offboarding | One lifecycle case per departure — same shape, defaults to urgent priority |
| IT Tickets | The internal access work each lifecycle case generates, tracked and closed independently of the case that spawned it |
| New-Hire + Manager Communications | Welcome messages, day-one readiness checks, departure notices, and manager handoffs — as a tracked item, or as an actual email |
Automations that generate the work, not just remind you of it
Move a case's Workflow State to Ready — Onboarding and two things happen automatically: a Google onboarding task appears in the Onboarding queue, pre-filled with the target org unit and groups from the parent case, and an IT ticket appears in IT Tickets for the internal access work. Offboarding works the same way in reverse — urgent priority by default, since a departure on the clock is a different kind of urgent than a new hire who hasn't started yet.
A fifth automation — sending a manager-readiness email the moment a communication item is marked "Ready" — ships disabled by default, the same discipline as this template's device-audit sibling: verify the workflow with tracked items first, turn on the email once you trust it.
Five playbooks, one per work type
- Google onboarding — verify employee email, start date, org unit, and groups; create or verify the Google user; apply the target org unit and groups; record status and an evidence note
- Google offboarding — remove group memberships; suspend the user and rotate the password; clear recovery email and phone; move to the archived org unit; record the Drive-transfer decision; verify final state
- IT access ticket — confirm the lifecycle case and effective date; complete the requested access work; link the outcome and close
- Employee communication — verify recipient and template; send or complete the item-only handoff; record the delivery outcome
- Manager communication — verify the manager and lifecycle context; send or complete the handoff; record the outcome and any decisions made
What's tracked, not automated — on purpose
This is the honest part, and it matters more than any feature list: Google account changes are a checklist, not an API call. Every Google onboarding and offboarding task in this template is a manual playbook — the person doing the work opens the Google Admin console themselves and works the steps, then records what happened back on the item. There's no live connector creating or suspending Google users on your behalf yet.
That's a deliberate choice, not a missing feature waiting to be discovered. A tool that silently provisions or deletes accounts in your identity provider is exactly the kind of thing that shouldn't ship quietly — manual-until-verified is the same posture this template's automations take with email. If a live Google connector ships later, it's a separately authorized addition, not something this template does today.
One more scope note worth stating plainly: this template is Google Workspace-specific, not a generic multi-identity-provider system. If your org runs a different identity provider, the lifecycle-case and IT-ticket structure still applies — the Google-specific fields and playbooks would need their own equivalents built for your provider.
Get it
Import Access Automation — Google Lifecycle from the template picker in OpenTechnologyApp — it's built in, four queues and all.