IT OPS

Offboarding Orphaned Access Sweep Agent

An agent that investigates a named departed employee across your systems, finds every lingering access grant and shared resource.

CategoryIT Ops
Enginepaperclip
Difficultyadvanced
Triggerchat
Steps5
Setup~25 min

How it runs

The automated pipeline, trigger to output.

  • TriggerChat request names the departed employee
  • ActionQuery GitHub for lingering access and tokensGitHubGitHub
  • ActionFind owned and externally shared Drive filesGoogle DriveGoogle Drive
  • LogicReason over findings and rank by riskOpenAI
  • OutputDeliver prioritized remediation planSlack

What it does

Runs an investigative sweep for a single departed person whose offboarding may have been incomplete. The agent reasons across multiple systems to find access that survived the official offboarding: stale tokens, lingering group memberships, shared documents, and service accounts they still own, then writes a ranked remediation plan.

When to use it

Use this during a security review, after a rushed departure, or when an audit flags a former employee. It is for the messy real-world cases where a simple checklist isn't enough and you need judgment about what's risky.

How it works

  1. 1A chat request kicks off the sweep with the departed employee's name and email.
  2. 2The agent queries GitHub for lingering org membership, owned repos, and active personal tokens.
  3. 3It searches Google Drive for files the user still owns or has shared externally.
  4. 4It checks Slack for active sessions and channel memberships tied to the account.
  5. 5It reasons over the findings, ranks each by risk, and drafts a remediation plan.
  6. 6It delivers the prioritized plan and risk notes to the security review channel for sign-off.

Set it up

What you configure once, before turning it on.

  1. 1
    Connect GitHubRepos, issues, pull requests, actions.
  2. 2
    Connect Google DriveDocs, sheets, slides, files.
  3. 3
    Connect SlackChannels, DMs, threads, mentions.
  4. 4
    Connect OpenAIModels, embeddings, files.
  5. 5
    Set each agent's modelWe leave models unset so you pick the tier — fast + cheap, or top-quality.
  6. 6
    Tune it to your dataEdit the prompts, filters, and field mappings so it matches how your team works.
  7. 7
    Test, then turn it onRun once against a sample, confirm the output, then enable the trigger.

Run this workflow in your colony.

14-day trial. No DevOps. No Sales call. Provisioned in under a minute.