A fast-growing accounting software company used BalkanID to automate joiners and leavers during its move to a new identity provider, then replaced standing admin privileges with just-in-time access granted for a stated purpose and removed automatically.
Systems
PeopleForce (HR), Okta, Google Workspace, secure enterprise browser, Slack, GitHub, Jira Service Management, AWS
Drivers
Minimize time spent on onboarding and offboarding; remove standing privileged access for developers and IT
Challenges before BalkanID
- The company was building identity operations in-house while migrating from Google to Okta, with a lean security team.
- Joiners and leavers depended on manual steps across the HR system, Google and Okta.
- Developers and IT held standing admin access across hundreds of groups. As the admin put it: "You've seen these hundreds of groups. This is completely unmanageable."
What they implemented
- Joiner: an HR webhook generates the corporate email, creates the user, and three days before the start date raises an access request that maps job title to Google and Okta groups, with approval in Slack.
- Leaver: daily termination check that suspends the user in Google and Okta.
- Group sync from Okta to the enterprise browser policy platform.
- JITPBAC for admin privileges: users start and stop a "purpose" in Slack, access is provisioned automatically, and it expires after at most 24 hours.
- The customer's own admins configure purposes and approval policies without BalkanID help.
Outcomes
- Joiner and leaver flows automated during the identity provider migration. The team was "very impressed with the offboarding flow."
- Standing admin access replaced by time-bound, purpose-based access for developers and IT, used regularly.
- Elevated access to deployment tooling provisioned in about one minute on request, and removed automatically.
- Renewed for a second year, expanding into access reviews and campaigns.