Global Identity & Employee Lifecycle
Designed and implemented a centralized employee-lifecycle model connecting identity, devices and applications — replacing manual operations with automated, auditable flows.
Context
An international company ran several disconnected systems for identity, users, devices, applications, onboarding, offboarding and internal administration. Each had its own version of the truth.
Challenge
- Manual lifecycle operations across multiple platforms.
- Duplicated data with no clear source of truth.
- Inconsistent audit outputs.
- Tight dependencies between several SaaS platforms.
My role
Architect and technical implementer — from process mapping to integration and ongoing operational improvement.
Responsibilities
- Architecture & process mapping
- Integration planning
- Workflow design
- Technical implementation
- System coordination
- Operational improvement
Architecture
- A centralized lifecycle model as the source of truth for joiners, movers and leavers.
- The internal platform connected to identity systems and device management.
- Standardized data shared consistently across connected systems.
- Audit exports and automated notifications built into the flow.
- RequestJoiner / mover / leaver
- ApprovalRight approvals
- IdentityOkta
- AccountsProvisioned
- DeviceJamf-enrolled
- ApplicationsBy role
- AuditConsistent record
Project lifecycle
- 01
Request
A lifecycle event is raised.
- 02
Approval
Routed for the right approvals.
- 03
Identity
Identity created or updated in Okta.
- 04
Accounts
Application accounts provisioned.
- 05
Device
Device enrolled and bound to identity.
- 06
Applications
Access granted by role.
- 07
Audit
Consistent audit record produced.
Implementation
- Okta integrated as the identity backbone with SSO and lifecycle events.
- Google Workspace and Jamf connected so accounts and devices follow the same lifecycle.
- Automation (Make.com, PowerShell, APIs) removing repeated manual steps.
- Manual dependencies reduced and audit outputs made consistent.
Documentation & handover
Operational and project documentation were prepared as part of delivery, with handover and acceptance support included where in scope — so the environment can be operated, audited and improved after go-live.
Client names and selected implementation details are intentionally anonymized.
Outcome
A connected identity and lifecycle model with reduced manual work, a clearer source of truth and consistent, audit-ready outputs.
Related projects
Internal platform · Data
OngoingInternal Operations Platform
Architected a central internal platform with a single data model and role-based workflows to replace forms, spreadsheets and manual approvals — prepared for automation and AI.
PAM360 · Public-sector delivery
DeliveredPrivileged Access Management Implementation for Liberecká IS, a.s.
Coordinated the complete technical delivery of a ManageEngine PAM360 privileged-access solution under public-procurement requirements — from vendor communication to deployment, documentation and handover.