Skip to content

003. Centralizing Group Membership Management in AccessIT

Date: 03-13-2025

State: Proposed/Accepted/Deprecated/Superseded

Status: Accepted

Context

Historically, the osdu-platform-team group and other application-centric AD groups have been managed manually or through various distributed processes. This creates challenges with auditing, consistency, and visibility into who has access. Additionally, the organization's AccessIT system was introduced as a single point of reference for application access requests and approval workflows.

To strengthen IT security and compliance, the company aims to:

  • Maintain a single authoritative source for user access requests and approvals.
  • Ensure traceability and auditability of all membership changes (who approved them, when they were added, etc.).
  • Reduce administrative overhead by automating user access synchronizations between AccessIT and Active Directory (AD).

To be Access Model Architecture

architectural_diagram

Decision

We have agreed to move the onboarding and membership lifecycle management of the osdu-platform-team and osdu-admins (and other relevant groups) to AccessIT. Users will request membership via AccessIT, and upon approval, the system will automatically synchronize membership changes to AD groups.

In short:

  1. No direct manual additions to osdu-platform-team or osdu-admins in AD.
  2. AccessIT becomes the required route for access requests and approvals.
  3. Automatic synchronization ensures AD reflects the current state of approved membership.

Consequences

  1. Stronger Security & Compliance

  2. A single system (AccessIT) governs all access requests, enabling robust approval workflows and audit logging.

  3. Reduces the risk of unauthorized AD group additions or orphaned accounts.

  4. Improved Traceability

  5. One audit log in AccessIT shows exactly who approved which request and when, simplifying investigations and compliance checks.

  6. Potential Onboarding Adjustments

  7. Teams will need to be trained on using AccessIT for all future access requests.


Last update: 2026-09-14