Identity

Employee Account Termination

Provides a controlled, approval-driven path to deactivate user accounts and terminate active sessions immediately upon approval

Employee Account Termination
  • Triggered when an employee termination is initiated by authorized personnel
  • Routes the request through the appropriate approval flow
  • Deactivates the user account across all configured identity systems once approved
  • Automatically discovers the employee's identity integrations to ensure full coverage
  • Terminates all active sessions to immediately cut off access
  • Updates the ticket with the full outcome for audit and traceability

What Employee Account Termination does

Employee Account Termination is Harmony's automated workflow for immediately revoking a departing or terminated employee's access across all configured identity providers. An IT admin or manager initiates the request through the helpdesk chatbot, Harmony routes the request for manager approval, and upon approval deactivates the employee's accounts and terminates all active sessions - ensuring no unauthorized access remains. The entire sequence from request to deactivation is tracked in a high-priority ticket.

Who Employee Account Termination Is For

Persona

IT admins and managers who need to revoke an employee's access immediately following a termination or security incident.

Pain point

When an employee is terminated, IT needs to locate their account across every identity provider, revoke access in each system, and confirm active sessions are ended - while coordinating the approval paperwork. Harmony compresses this into a single request: the admin identifies the employee, gets manager approval via Slack or Teams, and Harmony handles the cross-IdP deactivation automatically.

How Employee Account Termination Works

Trigger

An IT admin or manager asks the helpdesk chatbot to terminate an employee's access. The chatbot is restricted to admin and agent roles - employees cannot self-terminate.

  1. Employee lookup

    The chatbot uses query_employees to find the target employee by name or email and confirms the correct person with the requester before proceeding.

  2. Confirmation

    The chatbot clearly explains the consequences (account deactivation across all IdPs, session termination, HIGH-priority ticket requiring approval) and waits for explicit confirmation. Ambiguous or vague responses are not accepted.

  3. Ticket creation

    A HIGH-priority termination request ticket is created, and an approval request is sent to the configured approvers (default: manager role, all-approver strategy, 48-hour timeout).

  4. Approval

    Approvers receive the request via Slack or Teams with the employee's details. If approval times out, the ticket is escalated to IT.

  5. Account deactivation & session termination

    On approval, Harmony deactivates the employee's accounts across all configured identity providers and terminates all active sessions.

Outcome

The ticket is resolved and completion is recorded.

Capabilities

  • Role-gated access - Only users with IT admin or agent roles can trigger termination. The chatbot blocks employee self-termination with a hard guard at both the prompt and tool level.
  • Employee lookup before acting - Always resolves the target employee via query_employees (including already-terminated employees) before proceeding, to prevent acting on the wrong person.
  • Distinguish permanent termination from temporary suspension - If the requester's intent is ambiguous (such as "disable", "remove access for now"), the chatbot asks a clarifying question and refuses to proceed on anything other than a confirmed permanent termination.
  • Mandatory explicit confirmation with stated consequences - Before creating the ticket, the chatbot describes exactly what will happen and requires unambiguous affirmation.
  • Approval routing with configurable approvers - Routes the termination request to the configured approval chain (default: manager; configurable approvers, strategy, and timeout).
  • Deactivate across multiple identity providers - Calls the IdP deactivation API for each configured identity provider (default: Okta; extensible to others).
  • Terminate all active sessions - After deactivation, immediately ends all active sessions in all configured identity providers to prevent continued access.
  • Escalate on approval timeout or error - If no approval response is received within the configured window, or if an error occurs, the ticket is unassigned and escalated to IT.

Main use cases

Immediate Access Revocation on an Employee's Last Day - An IT admin receives confirmation that an employee is leaving today and needs their access revoked before end of day. The admin asks the chatbot to terminate the employee's access, the chatbot looks up the employee, confirms consequences, creates the HIGH-priority ticket, and routes approval to the manager. Once approved, Harmony deactivates the accounts and terminates sessions automatically - no manual IdP work required.

Emergency Access Revocation Following a Security Incident - A suspected security breach involves a specific employee account. IT needs immediate termination. The admin initiates the termination request, the chatbot confirms the correct target employee and consequences, and the ticket is created and routed for emergency approval. Deactivation proceeds the moment approval lands.

Termination with Multiple Identity Providers - A company has both Okta and Microsoft Entra configured. An employee's last day requires revoking access in both. Harmony deactivates the employee across all configured identity providers in a single workflow run - no need for the IT admin to touch each system separately.

Integrations

IntegrationRole in the agent flow
OktaAccount deactivation and session termination (default IdP; configured per tenant)
Microsoft EntraAccount deactivation and session termination (configured per tenant)
Employee Directory (HRIS, internal)Target employee lookup via `query_employees` before initiating the request
Service Desk (internal)HIGH-priority ticket created and tracked throughout; resolved on successful termination or escalated
Approval / Notifications systemRoutes approval request to manager or configured approvers via Slack or Teams

FAQ

It's both. The IT admin or manager interacts with the AI Helpdesk chatbot to identify the target employee and confirm intent. Once the ticket is created, a deterministic workflow takes over: it routes for manager approval, deactivates accounts across all configured IdPs, terminates all active sessions, and resolves the ticket.

Meet more Agents