Product · Engineering and IT

IT Joiner-Mover-Leaver and Security Desk

Software for the IT team's people changes and security housekeeping. HR says someone starts, moves or leaves; the desk plans the account changes from your role matrix, makes them one approval at a time, and keeps the evidence an auditor asks for. Laptops out of compliance get a note to the person and their manager. Security findings become tickets with an owner. Unused seats and renewals get a note every Monday. Quarterly access reviews are packaged per system. No agent ever reads or resets a password, grants an admin role, or deletes an account.

For IT teams of 1 to 10 people looking after 50 to 1,000 staff, and for managed service providers running IT for several clients

7agents, each doing one small job
1coordinator you can chat with: Kit
1helpdesk chat for staff
2screens: the IT desk and the staff portal
IT Joiner-Mover-Leaver and Security Desk desk
The IT desk on a Monday morning: five live numbers, the access plan rows waiting for approval with the detail pane, Kit the coordinator, events in flight and tickets to send.
Who it is for

Is this desk for you?

The pack is built for the people who create and remove accounts, keep laptops compliant and answer the auditor. It fits three kinds of team.

An internal IT team at a growing company

One to ten people looking after identity, passwords, devices and the service desk for 50 to 1,000 staff. You get the desk, Kit, the staff portal and every agent. Your identity provider, device tool and service desk stay the record.

An IT or security operations team inside a large company

A regional IT team in an MNC with a rule that every account change is approved and evidenced. The desk gives them the plan, the approval trail and the access review packages; nothing is created or removed without a person.

A managed service provider

One workspace per client, each with its own role matrix, tools and reviewer. The planner and the chaser are the same for every client; the matrix differs.

Which departments use it inside a large company

IT Operations / Service DeskJoiners, movers and leavers planned and executed behind approval; tickets drafted; devices chased.
Security / ComplianceFindings ticketed with an owner; quarterly access reviews packaged and decisions recorded; evidence on every change.
People / HRRaises the event once in the HR system; sees the plan status without asking.
FinanceUnused seats reclaimed before renewals; the licence list with costs.
Not a fit if you want software that resets passwords, grants admin rights or removes accounts on its own. Every account change is a person's approval, and passwords, secrets and admin roles are off limits to every agent.

Where it fits in your day

1 · HR raises the eventA joiner, a mover or a leaver, with the dateFrom the HR system or the form on the desk.
2 · The software plansOne row per system from the role matrixWhat to create, change or remove, and what never to create.
3 · You approve and it runsOne click per row; every call held again by policyThe system's response is written as evidence.
4 · Nothing slipsEvery morning, every hour, every Monday, every quarterDevices at 07:30, findings hourly, licences on Monday, reviews each quarter.
The one rule

Everything the software produces is a plan, a draft or a package for a person. Every account creation, change or removal waits for approval, one call at a time, and the system's response is recorded. No agent reads, resets or asks for a password, secret or MFA. No agent grants an admin role. Nothing deletes an account, mailbox or device record; leavers are deactivated and kept for 90 days.

The desk · Screen 1 of 5

Today: approve, start, send

The first screen IT opens. Five live numbers. Every access plan row waiting for approval, with the event, the system, the action and the group. Kit beside them. Events in flight. Tickets to read and send.

Today: approve, start, send
The Today page. Joiners and leavers in flight, access to approve, devices out of compliance, critical and high findings; access plan rows with Approve / Done / Skip / Mine / Edit; Kit; events with Start / Done / Plan again; tickets with Sent / Closed / Draft again; Raise a people event.
Approve

You read the row (Priya Nair: identity account, groups eng-all and eng-backend) and approve it. The executor may now run it; the call is held once more by policy so you see the exact arguments.

Start

On the leaver's last day you click Start; the executor performs every Approved row in order and writes the evidence.

Draft again

Runs the ticket drafter once more after the requester wrote back.

The desk · Screen 1 of 5, lower half

Today: approvals and what Kit did

Scroll down for the exact calls the software wants to make, and Kit's recent work.

Today: approvals and what Kit did
Waiting on you: an identity account to create, a ticket to raise, a device note to send. What Kit did this week, including the MFA reset Kit was refused.
Waiting on you

The account to create with its groups, the ticket text, the note text. Approve or Deny in place.

What Kit did this week

Every run with its duration and tools, including the refusals.

The desk · Screen 2 of 5

People: events and the plan rows

Every event as a card by status, drag to move. Every access plan row with who approved it and when it was done. The directory.

People: events and the plan rows
The People page. Events by status; all access plan rows; the directory; all events.
Drag a card

Moving an event to Done records it; moving it to In progress starts the executor for a leaver.

All access plan rows

The evidence column is what the auditor reads: system, action, approved by, done at, the system's response.

The desk · Screen 3 of 5

Security: findings and devices

Findings from the scanner, medium and above, with the ticket draft. Devices out of compliance with the note drafted. Findings by severity and device issues at a glance.

Security: findings and devices
The Security page. Findings with Ticketed / Fixed / Accept risk / Edit; devices out of compliance with Fixed / Retired; findings by severity; device issues.
Accept risk

A finding you decide to live with. The playbook asks for the IT lead's name and a review date in the row.

Fixed

The person did the steps and the device tool confirms. The row leaves the list.

The desk · Screen 3 of 5, lower half

Security: every device

Every managed laptop and phone with its OS, encryption, last check-in and issue.

Security: every device
All devices.
The desk · Screen 4 of 5

Licences and reviews

Products with unused seats or a renewal coming, with the note and the money. Access reviews in progress with the reviewer. Every licence and every review.

Licences and reviews
The Licences and reviews page. Licences to act on with Actioned / Edit; reviews in progress with Decided / Applied; all licences; all reviews.
Actioned

You reduced the seats at renewal or renewed as advised. The row leaves the list.

Decided

The reviewer wrote their decisions on the row. Removals become plan rows and go through the executor behind approval.

The desk · Screen 5 of 5

Automations: switches, guard rails, history

Every automation with its switch. The pack's guard rails. The record of plans written, leavers executed, findings triaged and device checks.

Automations: switches, guard rails, history
The Automations page. Switches, Guard rails, and the run history per agent.
The desk · Screen 5 of 5, lower half

Automations: the record

Every plan, execution, triage and device check the desk ran, with duration and what it touched.

Automations: the record
Run history for the planner, the executor, the findings triager and the device chaser.
The staff portal

My IT: for everyone in the company

A page every employee can open with their own sign-in. Their details, the two rules IT never breaks, the IT helpdesk chat, a ticket form, and their own tickets, devices and access. The portal knows who is looking at it, so nobody sees anyone else's access.

My IT: for everyone in the company
The IT Staff Portal as Marcus Reid sees it: your details, the company card, Ask IT.
The staff portal, lower half

My IT: your tickets, devices and access

Below the chat: raise a ticket, and see your own tickets, your devices with their compliance state, and every access row that names you.

My IT: your tickets, devices and access
Raise a ticket, your tickets, your devices, your access.
The forms

Two short forms

Raise a people event when HR has not, or when a manager asks; the planner builds the plan within a minute. Raise a ticket from the portal; the drafter reads it and IT replies the same day.

Raise a people event, from the Today page.
Raise a ticket, from the staff portal.
The coordinator

Kit, IT Operations Coordinator

Kit is a software colleague you can chat with. Kit runs the morning list, knows which agent to use for what, reads the tables, and never touches an account without an approval, never asks for a password.

Kit, IT Operations Coordinator

Every morning: joiners starting within five working days with plans not done, leavers within two days, devices chasing for a week, critical or high findings with no ticket, tickets marked Needs a person. One short list, oldest first, with the owner. Tools: the HR system, the identity provider, device management, the security tool, the service desk, Turtle Notify.

Example. You type "What starts and ends this week?" Kit replies: "Priya Nair starts Monday; two of seven plan rows are approved, the identity account is waiting on you. Sofia Rossi leaves Friday; nothing approved yet, and Grace has not confirmed the forwarding address. Tomasz's contract ends the 30th. Omar's ThinkPad has been unencrypted for three days; the note is drafted."

What talking to Kit looks like

You typed a question. Kit turned it into a six-step task that reads the tables (events, plan rows, devices, findings) and is running it, step by step, in front of you. Reading needs no approval; anything that would change an account would stop and ask.

Kit's page after "What starts and ends this week?": the task running, step 1 of 6, with the steps listed on the right.
The 7 agents · 1 of 2

Joiners, movers, leavers and devices

An agent does one job. It starts when a row is logged, on a schedule, when you press a button, or when Kit asks it. It reads your tools and your playbook, writes its result into the record, and stops. No agent ever changes an account without an approval.

Access Planner

When a people event arrives it reads the person from the HR system, applies your role matrix, and writes one Access Plan row per system: what to create, change or remove, which group or role. For a mover it adds the new role now and removes the old after 14 days. For a leaver it writes the removal order at 17:00 on the last day. For a joiner it drafts the welcome note for the manager, with credentials via the vault, never by email. It never creates anything.

Example. "Priya Nair, Engineering, backend. Create: identity (eng-all, eng-backend), vault (Engineering), email, source control (team backend), CI, error tool, issue tracker, chat. Device: MacBook Pro from stock, enrolled, encrypted. Do not create: admin roles, production access (separate request after 30 days)."

Leaver Executor

When a leaver event is started it takes each Approved plan row in the playbook's order and performs it in the connected system: deactivate the identity account and revoke sessions, remove vault access, retire the device after backup, free the seat. Every call is held again by policy so you see the exact arguments. The system's response is written as evidence. It never deletes, and never touches a row that is not Approved.

Example. "29 Aug 17:02 identity deactivated (user 00u8k, sessions revoked, response 200). 17:03 vault access removed. 17:06 CRM seat reassigned to grace.mwangi. 30 Aug 09:10 device wiped after backup (action 8813). Approved by Daniel Okafor 29 Aug 16:40."

Device Compliance Chaser

Every morning it reads every managed device from the device tool, updates encryption, OS and last check-in, and for anything out of compliance drafts a note to the person with the exact steps and their manager copied. After seven days it raises a ticket. Sending waits for a person. It never locks or wipes a device.

Example. "Hi Omar, your ThinkPad reports that disk encryption is off. Please turn on BitLocker: Settings, Privacy and security, Device encryption, On. It runs in the background. Reply when done and IT will confirm. Daniel copied."
The 7 agents · 2 of 2

Findings, licences, reviews and tickets

The security and housekeeping work that gets skipped when the week is busy.

Findings Triager

Every hour it reads new findings from the security tool, keeps medium and above, closes duplicates against open tickets, picks the owner from the asset, and drafts the ticket: what was found and the control, what to do, the evidence needed. Creating the ticket waits for a person. A Critical finding alerts the IT lead at once.

Example. "Enforce MFA for 3 users without it (High). Users omar.haddad, chloe.martin, contractor-3. Control AC-7. Enable MFA enforcement for all-staff; they get the prompt at next sign-in. Evidence: screenshot of the policy and the three users' MFA status."

Licence Watcher

Every Monday it reads each product's assigned users and last sign-in from the identity provider, counts seats unused for 60 days (including leavers still assigned), and drafts the reclaim or renew note for the licence owner with the money involved. Never removes a seat.

Example. "CRM: 4 of 25 seats unused for 60 days (ben.okafor left, 3 never signed in). Reclaim before the 28 Oct renewal and renew at 21 seats: saves about 4,300 a year."

Access Review Packager

Each quarter, per system, it lists every user with last login and manager, recommends removal for leavers and 90-day-idle accounts, and emails the package to the reviewer. The reviewer records decisions; removals go through the executor behind approval.

Example. "Finance system, 6 users. Recommend removal: ben.okafor (left 29 Aug, still has a login), contractor-2 (last login 3 Jun, 100 days). Keep the rest."

IT Ticket Drafter

When a ticket arrives it sets the category and drafts the reply from your how-to articles. Access requests are checked against the role matrix; password and MFA resets, lost devices and security matters are marked Needs a person. Never resets, never grants, never sends.

Example. "NEEDS A PERSON: an access request. Role matrix says Finance analyst gets read-only; the reports module is a Finance lead entitlement. Omar's move is effective 1 Oct. Suggest: approve early with Daniel's sign-off, or wait for the mover plan."
The help desk

The IT Helpdesk, for staff

The IT Helpdesk sits on the staff portal. It answers how-to questions from your IT articles (VPN, MFA, encryption, software requests) and says where the viewer's own ticket or access request stands. It never resets anything, never grants access, and never says what another person has.

IT Helpdesk

A router sends the question to a how-to specialist (reads the articles) or a status specialist (reads the viewer's own tickets and events, nobody else's).

Example. "How do I turn on disk encryption?" Answer: "Mac: System Settings, Privacy and Security, FileVault, Turn on. Article: Disk encryption." "I lost my phone with the authenticator." Answer: "Call IT now. MFA is reset in person or on a video call with your badge; IT never resets it from a chat."
Your data

8 tables

Tables are where everything is stored. They look like spreadsheets and your team can open and edit them. Your HR system, identity provider, device tool, security tool and service desk stay the record; the desk holds the plans, the approvals and the evidence.

TableWhat is in itStages
PeopleEveryone IT looks after, mirrored from the HR system. The portal identifies viewers here.Starting → Active → Leaving → Left
People EventsEvery joiner, mover and leaver with the plan and the evidence.New → Planned → In progress → Done · Cancelled
Access PlanOne row per system per event: action, group, who approved, when done, the system's response.Planned → Approved → Done · Failed · Skipped
DevicesEvery managed device with its compliance state and the note drafted.OK · Chasing → Fixed · Retired
FindingsSecurity findings, medium and above, with owner and ticket.New → Ticketed → In progress → Fixed · Accepted risk · Duplicate
LicencesEvery paid product with seats, usage, renewal and cost.OK · Reclaim seats · Renewal due → Actioned
Access ReviewsOne row per system per quarter with the package and the decisions.Prepared → Sent → Decided → Applied
TicketsIT tickets with the drafted reply.New → Drafted / Needs a person → Sent → Closed
Your playbook and tools

The software knows nothing about your systems or your rules except what the tables and your playbook tell it.

IT Playbook and Role Matrix

Two documents: the role matrix and the IT rules (joiners, movers, leavers, devices, findings, licences, access reviews), and your IT how-to articles. Every agent and the helpdesk read them. Replace the starter text with your own.

Example. Add "Contractors: every account gets an end date and no vault access" and the planner applies it from the next contractor event.

Tools connected at setup

HR system (BambooHR, Personio, Gusto, Rippling, Deel, Workday, and more)Identity (Okta, JumpCloud, Auth0)Passwords (1Password, Bitwarden, LastPass)Devices (Intune, Jamf)Security findings (Drata, Lacework, SentinelOne)Service desk (Jira Service Management, Freshservice, ServiceNow, NinjaOne, and more)Turtle Notify

  • HR system (BambooHR, Personio, Gusto, Rippling, Deel, Workday, and more). The person's department, manager, role, start and end dates. Read only.
  • Identity (Okta, JumpCloud, Auth0). Groups and application assignments; deactivation and regrouping behind approval. Never deleted, never a password or MFA touched.
  • Passwords (1Password, Bitwarden, LastPass). Vault membership added or removed behind approval. No item is ever read.
  • Devices (Intune, Jamf). Compliance state, encryption, OS, last check-in. Retire behind approval; never lock or wipe from software.
  • Security findings (Drata, Lacework, SentinelOne). New findings with severity, asset and control. Read only.
  • Service desk (Jira Service Management, Freshservice, ServiceNow, NinjaOne, and more). Tickets read; drafts added as internal notes; tickets created behind approval.
  • Turtle Notify. Built in. Emails notes, alerts and review packages, behind approval where the rules say so.

The pack uses whichever AI model your company has already connected. Other vendors of the same kind swap in at install time without changing the desk; a team on JumpCloud, Bitwarden, Jamf and Freshservice gets the same desk.

When things run

The weekly timetable

Checks on arrival are on from day one. The schedules are off until you switch them on from the desk.

AutomationAgentWhenShips
Plan the accessAccess PlannerThe moment an event arrivesOn
Execute the leaver planLeaver ExecutorWhen an event is startedOn
Draft a replyIT Ticket DrafterThe moment a ticket arrivesOn
Check devicesDevice Compliance ChaserWeekdays 07:30Off until you switch it on
Triage findingsFindings TriagerEvery hourOff until you switch it on
Watch licencesLicence WatcherMonday 08:00Off until you switch it on
Package access reviewsAccess Review PackagerFirst Monday of the quarterOff until you switch it on

Buttons on the desk run agents too. "Plan again" rebuilds the plan after a role changes; "Draft again" reruns the ticket drafter.

How approvals work

A person is always between the software and the outside world

Three things always need a person. The software stops and waits at each one.

1 · Buttons on the desk

Approve, Done, Skip, Start, Sent, Ticketed, Fixed, Accept risk, Actioned, Decided. Only a person presses them. The software can plan an account; it cannot create it until the row is approved.

2 · Every call that touches an account, a device or a person

Even after the row is approved, the exact call (create this user with these groups, deactivate this user, send this note, create this ticket) is held. You read the arguments and click Approve or Deny. Passwords, secrets, MFA, admin roles and deletes are refused outright, from every agent.

3 · Plans

When you give Kit a task that changes anything, Kit shows what it will do first. Approve and run, change it, or cancel.

Approvals
The Approvals page for the IT workspace. Kit was asked to create Priya's identity account; it is held with the groups shown. The Findings Triager wants to raise the Critical S3 ticket; the Device Compliance Chaser wants to send Omar the encryption note.
Who approves. Owners and admins, by default. A waiting message expires unsent after 24 hours, and the admins are reminded after 4. An approver going on holiday can hand their queue to a colleague, and every decision made that way records both names. Every approval is written to the audit trail with the name, the time and the message as approved.
Rules the software must follow

Six rules the pack ships, and the built-in ones

A rule is checked before every single thing the software tries to do. The pack installs six rules of its own on top of the standard ones every workspace starts with.

Every account creation, change or removal needs a personNeeds a personCreate, update, deactivate, regroup, assign, retire, wipe: each call is held with its arguments.
No agent reads, resets or asks for a password, secret or MFANeverVault items, secrets, password and MFA resets are refused, from every agent and from Kit.
No agent grants an admin roleNeverAdmin, owner, superuser and privilege grants are refused outright.
Notes to staff and tickets are sent with approvalNeeds a personDevice notes, welcome notes and service desk tickets are drafted by agents and sent by a person.
Nothing deletes an account, mailbox, device record or ticketNeverLeavers are deactivated and kept for 90 days.
No bulk export of the directoryNeverThe directory, device list and findings stay in their tools.
Built-in rules on topNeeds a personThe standard rules every workspace starts with: sending, deleting, permissions and payments need approval; bulk export is recorded.
The list of rules for the IT workspace.
The overview: active rules, alarms, anything waiting for review, personal data masking.

Everything is recorded

For every run you can see which agent ran, why it ran, every step it took, and every rule that checked it. Passwords and card numbers are blanked out before anything is stored.

Audit trail
The audit trail for the IT workspace: a leaver's deactivation approved, an admin group grant refused, an MFA reset refused, an early deactivation denied by the reviewer, device notes approved.

Spending limits

A monthly budget with a warning level and a hard stop for the software's own usage.

Staff data

Names and emails are masked in what the software reads and writes. Every key is encrypted. Nothing exports the directory.

Every account change has a record

Who planned it, who approved the row, who approved the call, what the system answered, when. The audit trail and the Access Plan table say the same thing.

Who can see what

The desk is shared with IT. The staff portal shows each person only their own tickets, devices and access. Only owners and admins change the layout.

What it saves

Hours back for a three-person IT team

These estimates assume three IT people looking after 300 staff, with about 6 joiners, 2 movers and 4 leavers a month, 60 tickets a week, 300 managed devices, 10 new findings a week, 30 paid products and quarterly reviews of 8 systems. "Before" is the time by hand; "after" is the reading, approving and clicking that is left. Your numbers will differ. These are estimates, not measurements; after a month the audit trail gives you real figures.

JobAssumptionHours beforeHours afterWhat changes
Planning and provisioning a joiner3 h each, 6 a month4.21.2Plan from the matrix in a minute; you approve each row.
Offboarding a leaver with evidence4 h each, 4 a month3.71.0Executed in order, evidence written; you approve each call.
Chasing devices out of compliance3 h a week3.00.5Notes drafted every morning with the steps; you approve.
Turning findings into tickets30 min each, 10 a week5.01.2Deduped, owned and drafted; you approve.
Drafting ticket replies6 min each, 60 a week6.02.0Drafted from the articles; needs-a-person marked.
Licence housekeeping3 h a month0.70.2Every Monday, with the saving worked out.
Quarterly access reviews2 days a quarter1.20.3Packaged per system with recommendations.
Total per week23.86.4About 17 hours a week back across the team, and every account change has evidence the auditor accepts.

No orphaned accounts

The leaver whose CRM login lingered for months is deactivated at 17:00 on the last day, with the response recorded.

First-day access without the scramble

The plan is written the day HR raises the event; the accounts wait only for your approval.

An audit trail you did not have to build

Who approved what, when, and what the system said, for every change.

Estimates, not measurements. After a month the audit trail gives you real figures.

Getting started

Live in an afternoon

Installing takes one click. The real work is the role matrix.

1Install

Install the pack from the Solution Packs page. Connect your HR system, identity provider and service desk when asked; the password vault, device tool and security tool if you use them.

2Role matrix

Replace the starter text with your matrix and your leaver rules; paste in your IT how-to articles.

3People

Import the directory from the HR system so the portal and the plans can name everyone.

4First week

Run one joiner and one leaver through the desk end to end. Switch on the ticket drafter.

5Then

Switch on the device check, the findings triage and the licence watcher, and share the staff portal with everyone.

Pricing

Included on every plan

You pay for the platform, not per desk. The plan sets how many agents, employees and workspaces you can run; every desk is included, and runs are billed on your own model key at cost. 7 agents in this desk count against the plan's agent limit.

See plans
More desks