CLAIMS_PROD_READ (approved by the data owner, expires in 90 days). I checked each one by reading it back from the target system. Welcome message with links sent to Priya and Tom R.Custom autonomous systems · Mock demo
Quartermaster: joiner and leaver access across every system
When HR records a new starter or a leaver, Quartermaster works out exactly which access goes with the role, provisions the routine parts, asks the right owner about the sensitive parts, and keeps a record of all of it. On the way out, it finds the accounts nobody remembers, including the ones outside single sign-on.
The metric at the centre: access gaps. Every account that doesn't match what the person's role should have, missing or left behind. Quartermaster acts until it reads zero.
Mock demo · fictional company and data
Press Restart, then Next (or →). The run stops when it needs your approval: you play the human.
Access plan for Priya N.: 11 routine items, 1 needs approval
✓Routine, provisioned on Monday 08:00 automatically11 items▸
!Read access to production claims data needs the data owner's approvalApproval▸
Found 14 accounts and credentials for Daniel K., 2 of them outside single sign-on
✓Disable SSO, revoke sessions and tokens, transfer ownership12 items▸
!Legacy IAM user dkowal-deploy has an access key still in use by a build serverDecide▸
- Run the routine plan at 17:00 as scheduled.
- Move the Jenkins job to an IAM role (draft: PR #431), then deactivate the key on Monday. Until then, alert on any use outside jenkins-legacy-01.
AKIA…7QX is under watch until PR #431 merges. The access review record is ready.🧾Access record: Daniel K. offboarding audit log · access-reviews/2026/leavers/daniel-k.json
Timeline
Open items
- IAM key AKIA…7QX: deactivate after PR #431 (owner: platform team, due Monday).
- On-call gap next week (owner: Sara L.).
Each joiner, change and leaver gets a record like this, with who approved what and when. Your access reviews start from evidence, not spreadsheets.
AKIA…7QX and confirmed nothing has tried to use it since. Daniel K.'s offboarding is closed; the record is updated.Why it matters
This is a mock scenario. The figures are design targets, not measured results.
What it solves
- Slow, ticket-driven onboarding. A new engineer waits days for access that a role template could grant on the first morning.
- Access nobody remembers granting. Leavers keep tokens, keys and accounts outside single sign-on long after they've gone.
- Offboarding that breaks things. Deleting a credential a system still depends on causes an outage. Quartermaster checks usage first.
- Access reviews built from spreadsheets. Every grant, approval and revocation is already on record.
Key features
- Triggered by HR events from Workday, BambooHR, Personio or your HR system
- Role templates that learn from what peers on the same team actually hold
- Connects to identity, collaboration, code and cloud: Okta or Entra ID, Google Workspace or Microsoft 365, Slack or Teams, GitHub, AWS
- Policy-driven approvals: sensitive access goes to the data or system owner, with time limits
- Discovery of accounts and credentials outside SSO, with usage checks before removal
- Every step verified by reading the target system back
- Audit records for every joiner, mover and leaver
How it stays safe
Quartermaster only runs routine steps on its own: the ones defined by a role template your team approved, which can be checked afterwards and undone. Anything sensitive, unusual or destructive waits for the owner. It works with the least privilege each connected system allows, and every action is logged with the evidence behind it. The same verifiable, reversible, contained rule decides what runs unattended.
Want a Quartermaster for your organisation?
We build it around your HR system, identity provider and the tools your teams actually use. Tell us how long onboarding takes today.
More demos
Beamreach