SCNET · Enterprise IT · Ankara, Türkiye

Sanal Çekirdek

Who closes access when someone leaves?

Device management is judged on two days: the day someone starts and the day they leave. Sanal Çekirdek automates both flows and ties every change in between to the same chain.

A leaver's account still open is the quietest security gap there is. Nobody complains, because nobody notices.

The joining flow

When a new person arrives, the device should be ready, accounts open and the right applications installed. That happens when the HR record triggers the technical flow; every manually built step introduces delay.

  • The flow is triggered by the HR record
  • Role determines which applications are installed
  • Devices arrive ready to set up out of the box
  • The day-one checklist verifies itself

Role change and device replacement

The changes in between are what gets skipped most. When someone moves role and old permissions do not close, permissions accumulate; when a device is replaced and data does not follow, work stops.

  • A role change closes the old permissions as it opens new ones
  • Data and settings move with a device replacement
  • A loaner flow exists for faulty devices
  • Changes are tracked against one record

Leaving and reclaiming

The leaving flow matters more than the joining one. Access should close the same day, the device should come back and corporate data on it should be wiped — and none of those three should wait on the others.

  • Access closure is tied to the leaving date
  • Device return is tracked separately
  • Corporate data can be wiped remotely
  • Accounts that failed to close are reported weekly

Compliance and inventory accuracy

No control is trustworthy while the inventory misrepresents reality. Device records are reconciled with actual use, and a device absent from the record does not join the network.

  • Inventory is reconciled with devices actually connecting
  • An unregistered device receives no access
  • Encryption and patch state are visible per device
  • Unused licenses are reclaimed

How we work

  1. Map the joining and leaving flows
  2. Make the HR record the trigger
  3. Define role-based application and permission sets
  4. Reconcile inventory with actual use
  5. Report unclosed access on a cycle

How success is measured

  • A new joiner can work on day one
  • A leaver's access closes the same day
  • Inventory matches the devices on the network
  • The share of unused licenses is falling

Frequently asked questions

Can it integrate with our HR system?

With any system that offers an interface, and that is the preferred path. When the HR record is the trigger the flow starts by itself; waiting for a manual notification makes delay inevitable.

Can Mac, Windows and mobile be managed together?

Yes, though policy is never identical across platforms. Shared objectives are defined, implementation differs by platform, and the difference is documented.

Is this not the same as endpoint security?

This page covers a device's lifecycle and its access; the endpoint security page covers threat detection and response. Both operate on the same device but answer different questions.

Let's map your joining and leaving flows together and find which step creates the delay.

Map your joiner-leaver flow