One ticket in, every system handled, one log out. Here is what happens between those points.
Offboarding
HR or the manager files the ticket
The help desk ticket names the employee and the last day. Nothing else changes about how your people request things.
Tenure reads it and resolves the person
The ticket is matched to one identity across Active Directory, the core, and every platform, including the ones that spell names differently or key on an employee number.
A dry run shows what will happen
Before anything changes, the run is previewed: every account, group, mailbox, extension, and seat that will be touched. Your admin approves it or corrects the ticket.
Every system is cleared in order
Sign-in is disabled first, then mail, MFA, phones, and each platform. Failures are retried. A system that cannot be reached is flagged instead of skipped.
The ticket and the log are updated
The help desk ticket gets the results. The run log records what was removed, from where, when, and by which service account, ready for an access review or an exam.
Onboarding
Onboarding runs the same sequence in reverse. The ticket names the position, and the position decides what the person gets: directory placement, groups, a mailbox, MFA enrollment, a phone extension, and seats on the platforms that role uses. A new teller and a new loan officer come out of the same process with different access, and the log shows why each item was granted.
What your team still does
- Files the ticket, exactly as today.
- Approves the dry run, which takes about a minute.
- Handles anything flagged for manual follow-up, with the reason stated in the log.
- Owns the service accounts and the server it runs on.
What it does not do
Tenure does not replace your help desk, your directory, or your MFA. It does not make access decisions on its own; position mappings are set by you during implementation and changed by you afterward. It does not call home.