Seasonal workers and identity automation. Pick one.

Posted by MudDifficult2015@reddit | sysadmin | View on Reddit | 15 comments

Every year, same problem. We hire \~300 seasonal warehouse staff between October and January. They leave. Some come back next season. Some don't. Some come back mid-season as rehires after quitting. HRIS treats rehires as new workers half the time, same worker the other half, depends on how HR entered them.

Result: duplicate accounts in AD. john.doe and john.doe2. Both with Okta profiles. Sometimes both active simultaneously. The old john.doe account still has group memberships from two seasons ago that never got cleaned up because the deprovisioning ran but didn't catch the app assignments that were added manually outside the normal workflow.

We've tried building automation around this. Every time we think we have it, HR changes how they enter rehires in the HRIS and the correlation logic breaks.

At this point the "automation" is one of my guys manually cross-checking a spreadsheet against AD before each season starts. That's not automation. That's just a different kind of manual.

Is anyone actually running a clean provisioning setup for high-churn seasonal workforces, or is this just the price of having humans involved in HR data entry?