Access Enforcement
Onboarding Access
When IT is notified that a new hire is onboarding we create a profile in Sassafras for them and link it to the employee's NetID. We then add requested services to the users profile utilizing the tags section.

We track the following major families of security groups or services:
| Tag | Details |
|---|---|
| AD | Documents access to an Active Directory Security Group (Storage, Management/Admin access, etc) |
| SM | Documents access to use a Shared Mailbox |
| RM | Documents access to use a Resource Mailbox (Room Calendars, Vehicles, etc) |
| EG | Documents access to an Entra Group |
| DG | Documents access to a Shared Google Drive |
| SW | Documents access to specific Software packages (Adobe, Parallels, 1Password, etc) |
| Mailbox | Documents users who have a Personal Mailbox (claimed into PVFA) |
| Laserfiche | Documents users who have access to PVFA's Laserfiche |
| Qualtrics | Documents users who have access to PVFA's Qualtrics |
| 2NetID | Documents users who have a secondary NetID for elevated privileges |
Each of these are prefixes and must have the specific group or mailbox specified after, you connect them with an underscore. These would be just the group alias itself and not the full group path or email address (aka do not include any variation of @tamu.edu in the tag, it is understood that everything is @tamu.edu). These are all case sensitive and should match what is currently used in the source.
Offboarding Access
When IT is notified that an employee is leaving the College or University we will look up the users profile and remove access to the services or groups they had documented in their profile tags and proceed with offboarding steps.