I am thinking of using JIRA to set up a User account management Add/Change/Delete workflow. It seems likely that someone else has already done this, and either could make it available or could sell the configurations. Has anyone seen this? I looked through the marketplace and didn't come across anything which seemed to include this functionality.
This is a workflow whereby a user, or the user's manager, or any other interested person - as the Reporter - would create an Issue requesting a user Add, Change or Delete action be taken, relating to some account with some privileges on some system.
For example, HR could create an Issue when a new person joins the company saying "(Reporter)HR, on behalf of (define Field here)Employee_Name, requests to Add an account, in the System "Google Apps" with (specific permissions and other characteristics in a Comment field)".
Or a project leader could create an Issue requesting that an existing employee from a resource pool be granted additional privileges on some system, to enable that employee to participate in a new project.
Or a manager could create an Issue advising of the imminent departure of an employee from the company, requesting the suspension of all of the accounts to which that employee has had access.
There would be a workflow which performs a lookup based on the system (Google Apps in this case) to identify the System Owner (a business person who would decide whether to grant the request) and JIRA would forward the created Issue to that System Owner. If the System Owner approves then JIRA would route the Issue onward to (another lookup, the Custodian of the implicated system).
At each stage, specific permissions would apply; for example, when the Issue is first created, it would be readable by only the System Owner contact(s) for the implicated System (and the reporter, and an Auditor role); only the System Owner contact(s) would have permission to change the state of the Issue to allow it to move on, etc.
The goals are an easy to use automated workflow, and security sufficient to creating an auditable trail of request/ approval/ implementation/ closure (or, at any stage, rejection -> closure).
Is this asking for something for which JIRA is well-suited? .. or am I trying to shoehorn this into a great tool that simply may not be the great tool for this specific purpose? I'm not sure, because really one more thing which such a system ought to do is maintain a database of who has what accounts (at a minimum). The workflow and permissions stuff I'm fairly sure JIRA can do, but having the side effect of maintaining a user/system matrix/database does not seem to be JIRA's thing?
And, if this isn't right for JIRA/ there is no prior art in JIRA, I'd appreciate suggestions of tools to do this, without crossing into the full (complicated, expensive, very time intensive to deploy) IAM space.
thanks,