Every leaver checked against employee records, group memberships, devices and app access. Back as names and systems: this person left in June and still appears in three groups.
Offboarding fails at the edges. Payroll is stopped, the laptop is collected, the main accounts are disabled, and then there is the analytics tool one team bought on a card and a contractor account in a system nobody remembers buying. Six weeks later an audit finds them.
A companion reads employees, groups, devices and app access, and gets to the end of the list. A person doing this stops in the boring middle, and the interesting rows are always near the end of the alphabet.
01
What does an access audit actually produce?
A list with names and systems on it.
A companion reads the employee records, group memberships and app access it can see, then compares that against your leavers and your intended access model.
What comes back is specific: this person left in June and appears in three groups. And it finishes, which is the part that does not happen by hand.
02
Can it drive onboarding?
A companion takes the human half.
Which new starter has no buddy assigned, whose equipment order has not shipped, which manager has not completed the first-week checklist.
It reads the state and drafts the nudges, grouped by person so nobody gets four. Rippling’s own workflows keep granting the access the moment somebody starts.
03
Devices, people and access: three lists that disagree
A companion reports the laptops assigned to people who have left, the people with no device at all, and the devices that appear twice.
Every correction waits for confirmation, which for access changes is not a formality. Revoking the wrong person’s access on a Tuesday morning makes you extremely findable. IT patterns: ai for it admins.
04
Bulk access changes go one batch at a time
Proposed before anything happens, reviewed one batch at a time, because revocation at scale is where a confident mistake is most expensive. Payroll runs stay inside Rippling under its own approvals.
Available actions follow the Rippling action list and the vendor’s public API, and the tenant’s permission model applies to the connection. A group the connected account cannot see stays invisible.
Yes, within what the connected account can see. A companion reads employees, groups and app access and reports who still has what, by name and system.
Payroll, benefits and filings stay inside Rippling under its own approvals. This connection reads records and stages changes to them for you.
Ask for everything still attached to each leaver: groups, app access, assigned devices. The edges are where offboarding fails, and a list that runs to the end catches them.
Yes. Connect the account and a companion reads employees, groups, devices and app access, and produces the offboarding list nobody finished. Its actions follow Rippling’s public API, and payroll, benefits and filings stay inside Rippling.
Changes arrive as a reviewed proposal, in batches, and wait for your confirmation. Revoking the wrong person’s access is worth one extra click to avoid.
Put a companion on the human half: who has no buddy, whose equipment has not shipped, which manager has not done the first-week check, drafted as one nudge per person. Rippling’s workflows keep doing the provisioning. See automate customer onboarding checklists.