Work

05People and IT operations

Complete the employee request, not another ticket.

One request coordinates People, IT and Security. The employee sees a clear plan. Managers approve access once.

See the employee workspace

Example targets
Confirm in the pilot

6 hoursservice target
One planacross teams
Timedprivileged access

01 The change

Less chasing. One clear place to work.

Today

  1. 01Employees choose between several portals and teams.
  2. 02The same identity and manager details are requested more than once.
  3. 03Access is granted without a clear expiry or owner.

New way of working

  1. 01One request becomes a clear plan across People and IT.
  2. 02Standard access and exceptions are shown separately.
  3. 03Approved changes run on the effective date and remain visible.

02 How it works

The system prepares the work. People keep the decision.

01
Confirm

Check the employee change

Role, manager, location and effective date are read from Workday.

Workday event WD-88103
02
Compare

Build the access plan

Current access is compared with the standard Revenue Systems role.

Okta · role model
03
Separate

Show the exception

Production admin is kept outside the standard package with a 30-day expiry.

Access policy IAM-07
04
Approve

Managers decide once

The manager approves standard access. The system owner approves the exception.

Two named owners
Connected systems
WorkdayOktaJira Service ManagementGoogle Workspace1Password

03 What the employee sees

A work screen, not another chatbot.

The employee sees the open work, the evidence behind the recommendation and the decisions that need their judgment.

Transfer readinessHiring manager
Recommended next stepESR-5518

Approve the standard role and a 30-day production-admin grant.

The role package is standard. The exceptional grant has an owner, training requirement and automatic expiry.

Manager and effective date confirmedTraining scheduled firstException expires after 30 days
EmployeeOne plan, one owner and a clear completion date.
ManagerStandard access separated from exceptions.
Service ownerReadiness, overdue work and expiring access.

04 Systems and control

Connected to the tools you already use.

Access is limited by workflow. The system can read and prepare work; sensitive or final actions remain with a named person.

WorkdayRole and effective date
OktaGroups and applications
Jira Service ManagementRequest and service history
Google WorkspaceGroups and shared access
1PasswordVault access and expiry
ActionSystemPerson
Read worker contextPurpose-limitedTeam scope
Prepare access planAllowedManager reviews
Grant standard accessAfter approvalManager approves
Grant privileged accessAfter two approvalsManager and owner
Final accountability stays with the role that owns the work.

05 How to begin

Start with one live queue.

Use real work in a controlled pilot. Compare the recommendation with the team’s decision before adding write access.

Weeks 1–201

Map service rights

Define requests, data limits and approval owners.

Weeks 3–602

Show one service plan

Join People and IT context without taking action.

Weeks 7–1003

Pilot transfers

Enable approved standard access and timed grants.

Have a workflow in mind?

Bring the queue that absorbs your team’s attention.

Discuss the workflow