Cutting IAM offboarding time by 85% with ticket-driven automation
How the IAM Operations team used three years of ServiceNow ticket history to prioritize, automate, and scale identity lifecycle management, with zero missed access removals since rollout.
At A Glance
Background
Manual identity work doesn’t scale with ticket volume
IAM Operations was managing onboarding, offboarding, and access changes through largely manual processes. As ticket volume grew, this created delays in provisioning, error-prone manual checks across roughly 25 downstream applications, SLA-driven escalations, and a heavy reliance on individual effort rather than repeatable process.
Rather than automate reactively, the team started with evidence: three years of ServiceNow ticket history, analyzed to find which processes carried the greatest volume and risk, and therefore the greatest return on automation.
Solution Approach
Four phases, each validated before the next
The program was rolled out incrementally, proving value in production before expanding scope and building organizational confidence at every step.
Data-Driven Prioritization
3 years of ticket data analyzed to rank automation candidates.
Onboarding Automation
ServiceNow → Adaxes webhook provisions AD access automatically.
Offboarding Automation
8 hrs → 1–1.5 hrs, zero missed removals across 25 apps.
Snowflake & CyberArk
Access provisioning and credential integration in final testing.
Phase 1: Data-Driven Prioritization
3 YEARS OF SERVICENOW TICKET DATA
The team analyzed three years of ServiceNow ticket data across every IAM request type to find the highest-volume, highest-impact candidates for automation. The analysis surfaced onboarding, offboarding, and Snowflake access as the top three priorities, turning the roadmap that follows into an evidence-based decision rather than a guess.
Phase 2: Onboarding Automation
SERVICENOW → ADAXES WEBHOOK
When the client’s ServiceNow team declined to support a legacy integration approach, the team built a webhook-style endpoint instead: a custom PowerShell command hosted in Adaxes, triggered automatically by ServiceNow business rules, script includes, and an outbound REST message.
New-hire onboarding tickets now provision AD access with no manual intervention. A planned HR system migration, which would streamline this further, is currently on hold, so ServiceNow remains the system of record in the meantime.
Phase 3: Offboarding Automation
25 APPS · 3×/WEEK · ~50 USERS/CYCLE
The largest pain point: manually verifying access across roughly 25 applications per departing employee. The team automated AD account disablement and group membership removal, built policy-aware manager reassignment logic (removed for contractors, retained for full-time employees), and shipped an interim VLOOKUP-based HTML tool to cover applications with no user-management API. Engineers upload a user list and instantly see exactly who has access to what.
Offboarding cycles that once took ~8 hours of manual cross-checking now close same-day in roughly 1–1.5 hours, with zero missed access removals.
Phase 4: Snowflake, Service Accounts & CyberArk
FINAL TESTING BEFORE PRODUCTION
The same ServiceNow-driven model is now being extended to Snowflake access provisioning, automated service account creation, and CyberArk integration for credential management. All three are in final testing ahead of production rollout, following the same validate-in-production pattern that carried Phases 1–3.
Results
Before vs. after automation
| Metric | Before | After |
|---|---|---|
| Time per offboarding cycle | ~8 hours | ~1–1.5 hours |
| Turnaround | Multi-day | Same-day closure |
| Access-removal accuracy | Manual, error-prone | Zero missed removals |
| Onboarding provisioning | Manual AD setup | Fully automated (ServiceNow → Adaxes) |
| Application coverage | 25 apps, checked manually | API-automated + tool-assisted |
Why this matters
Faster deprovisioning shrinks the security window for departed users to retain access.
Freed-up analyst time gets redirected to higher-value IAM work instead of repetitive checks.
Consistent, repeatable execution reduces audit and compliance risk.
A proven, incremental delivery model ready to extend to more applications and processes.
Roadmap
What’s next
In Progress
- Snowflake access automation via ServiceNow
- Automated service account creation and CyberArk credential integration, currently in testing
Next Opportunities
- Extend API-based automation to remaining non-API apps in the 25-app scope
- Resume HR system migration to feed onboarding data directly
- Formalize audit logging and reporting for all automated IAM actions
- Expand ticket-driven prioritization to the next tier of IAM processes
Summary
From manual and escalation-prone to data-driven and automated
In a short span, IAM Operations moved from a fully manual, escalation-prone process to a largely automated, data-driven platform, cutting offboarding time by roughly 85% while improving accuracy to zero missed access removals.
The phased, evidence-based approach has proven repeatable and is now extending to Snowflake, service accounts, and privileged credential management.
