Lean IT team. Sponsor-grade evidence.
A prebuilt runbook pack for sponsor-backed service businesses of 20 to 250 people with a small IT team or an MSP: offboarding, access changes, license reclaim, and endpoint containment behind one approval gate in the Teams or Slack you already use, each decision written to a tamper-evident chain that answers a lender's or auditor's control questions.
Offboarding lags on a three-person team
A departure touches identity, mailbox, licenses, Intune devices, and the ticket queue, and a lean team gets to it when the queue allows. The offboarding runbook runs those steps as one approval-gated flow with each step recorded, so a departure is closed the day it happens, not the week after.
Access sprawl shows up in diligence
Stale guests, dormant accounts, and group memberships nobody remembers granting surface in cyber-insurance questionnaires and in the sponsor's diligence. Dormant account review, guest cleanup, and group membership runbooks turn each cleanup into a named decision on the chain instead of a spreadsheet exercise.
The MSP acts on a ticket, and there is no trail
When an outside team holds admin rights, the operator rarely has a record of what changed and who agreed to it. Every runbook the MSP runs through AscendCore carries a human approve or deny decision and lands on an append-only SHA-256 chain the operator can export and re-verify without trusting anyone.
The sponsor asks who approved that
After an incident, the first question from the board or the lender is who approved the change and when. The oversight evidence pack compiles a window of live chain events into one document: what was proposed, what a named human decided, what executed, and the SOC 2 controls it is evidence for, without standing up a new system of record. A ServiceNow ticket can open the request, and the decision is written back to it.
What's in the pack
13 runbooksEmployee Offboarding
Automate end-to-end employee offboarding across Okta, Microsoft 365, Jira, and Intune. Suspend accounts, revoke OAuth tokens, transfer files, revoke licenses, archive mailbox.
Access Role Change
Multi-system orchestrated role transitions for promotions, transfers, and contractor-to-FTE conversions. Five seed roles ship out of the box (support tiers, sales SDR/AE, engineering contractor/FTE/intern, HR generalist/manager); each transition produces a single approval card showing the full access diff and executes sequentially across Okta + Entra + Jira + M365 with per-step audit outcomes.
Group Membership Management
Automate Microsoft Entra security group, M365 group, and distribution list membership changes from Slack and Teams. Name-resolved, approval-gated, idempotent.
SSO App Assignment
Assign a SaaS application directly to a user in Okta from Slack or Teams, approval-gated, idempotent, and audited.
Dormant Account Review
Find Okta accounts inactive beyond a configurable threshold and propose suspending them in one approval-gated review, fully audited.
Conditional Access Policy Review
Review current conditional-access posture, flag common gaps, and record the reviewed findings on the tamper-evident audit chain with approval; policy changes remain manual.
Guest Account Cleanup
Remove a stale external guest account from Slack or Teams in one approval-gated pass. A safety gate refuses member accounts, and removal is restorable for 30 days.
Unused License Reclamation
Find licensed Microsoft 365 accounts that are disabled or inactive beyond your threshold and reclaim the reviewed seats in one approval, fully audited.
Endpoint Containment
Lock a suspected-compromised user's Intune-managed devices and contain their account (sign-in disabled, sessions revoked) with one approval and a security-namespaced audit row.
Compromised Account Response
Contain a suspected account compromise in one approval: revoke every active session, invalidate the password, and force MFA re-enrollment, fully audited.
MFA Re-enrollment
Automate Okta and Microsoft Entra ID MFA factor reset and re-enrollment from Slack and Teams, with approval-gated execution and audit-friendly logging.
Password Reset
Automate password resets in Okta or Microsoft Entra ID directly from Slack and Microsoft Teams. Approval-required by default, with full audit trail.
Account Unlock
Automate Microsoft Entra ID and Okta account unlocks from Slack and Teams. Identity verification, approval-gated unlock, failed-login counter reset.
Evidence your auditors can re-verify
Every approval decision lands on an append-only SHA-256 chain. Export it as CSV and re-verify it offline, without trusting AscendCore.
Evidence for: SOC 2 CC6.1 (logical access). Every access change in this pack carries a named human approve or deny decision before anything executes, and the approving surface identity is bound into the record's hash.
Evidence for: SOC 2 CC6.2 and CC6.3 (access provisioning, review, and removal). Offboarding, dormant account review, guest cleanup, and group changes are recorded append-only with actor, target, and timestamp, so who held access and who removed it is answerable from the export.
Evidence for: SOC 2 CC7.2 and CC7.3 (monitoring and change detection). Endpoint containment and compromised account response record the request, the human decision, and the execution outcome as chained events that re-verify offline.
Evidence for: SOC 2 CC8.1 (change management). Each governed change carries a request, an explicit human decision, and an execution outcome as separate chained events, compiled on demand into the oversight evidence pack as CSV or a print-exact PDF.
Evidence for: cyber-insurance questionnaire controls on privileged access, offboarding timeliness, and MFA. The exported chain shows each password reset, MFA re-enrollment, access removal, and containment action with its approver and timestamp, so the answer is a filtered export, not a recollection.
A runbook pack is not a compliance program, and AscendCore's own SOC 2 Type I is planned, not certified. These mappings show which controls the approval gates and audit chain produce evidence toward, for your auditor, your lender, and your insurance renewal. Your compliance owner makes the determination.
Start with a 30-day sandbox pilot, no card required, or have the MSP you already pay deploy it through the AscendCore partner program. Every runbook here is one of the 31 live in production today, and the approval gate and the audit chain stay yours either way.
See the flow before you talk to anyone
The demo dashboard runs the same approval queue, audit chain, and governance surface your team would use. No signup wall.
