SAAS MANAGEMENT / GOOGLE WORKSPACE & SLACK

SaaS systems. Organised around your people.

I design and automate Google Workspace, Slack and connected SaaS environments. Make accounts, groups, access and collaboration follow the employee lifecycle, with clear ownership and regular licence reviews.

Discuss your SaaS environment

UK-based. Working with UK and US businesses, and internationally.

BUSINESS NEED / ENGINEERING SCOPE

Make everyday administration follow clear rules.

A role change means several tickets. Groups drift, channels outlive their purpose and licences stay assigned after the need has passed. I connect your people data to the way each platform is organised, then build the automations and reviews that keep it useful.

01

Design Google Workspace

Build or reorganise organisational units (OUs), groups, service access and administrative roles. Agree which policies belong at OU or group level, how accounts move through the lifecycle and who owns shared resources.

02

Automate groups and access

Use Okta group rules and Group Push for supported integrations, or native dynamic groups where available. Base membership on agreed attributes such as department or location, with a clear source of truth and tests for joiners, movers and leavers.

03

Build Slack workflows

Design account provisioning, user groups, channel organisation and approved membership automations. Connect Slack Workflow Builder, Okta Workflows and supported APIs to requests, approvals and notifications, according to your subscription and permissions.

04

Review accounts and licences

Reconcile accounts with people and application owners. Review stale, duplicate, privileged and contractor access, then compare licence assignments with available usage reports. Recommend approved changes with retention needs and subscription terms accounted for.

ILLUSTRATIVE PROCESS

A role changes. The connected systems follow.

In this illustrative process, an approved role change updates the authoritative attributes. Rules adjust the agreed groups and app access, and supported automations update Workspace or Slack. Reconciliation checks the result and flags permissions or licences that need an owner's decision.

  1. Approve the role change

  2. Update attributes and rules

  3. Apply supported SaaS changes

  4. Review access and exceptions

DESIGN / BUILD / HANDOVER

A system you can understand and run.

Commission a design, a defined implementation or both. We agree the scope and acceptance criteria before delivery.

How design and delivery work
  • Workspace and Slack configuration design
  • OU, group, channel and access ownership map
  • Lifecycle automations with tested failure handling
  • Account and licence review findings
  • Approved change plan and operating documentation

EXPERIENCE BEHIND THE WORK

Relevant work you can inspect.

My prior in-house work joined identity, SaaS access and employee support. It includes contractor provisioning and controlled email allocation connecting Okta, Slack, a company-email table and the HR record.

From my prior in-house and contract delivery. These figures are not presented as Halation client totals.

See the business systems delivery record

SCOPING THE ENGAGEMENT

Start with the right questions.

Working with UK and US teams

I work remotely with teams in the United Kingdom, United States and internationally. We agree time-zone overlap, workshops, access arrangements and change windows before work starts. You work directly with the architect building your system.

Can Okta push groups and manage Google dynamic groups?

We choose a clear membership authority for each group. Okta group rules can populate groups used for supported Group Push integrations, with app assignment and push handled by separate groups. Google's native dynamic groups calculate membership from their own queries; they are not manually populated push targets. Available features depend on your subscriptions.

Can Slack channel membership follow identity changes?

Yes, where the workspace features and permissions support it. We scope user provisioning, user-group membership and channel actions individually, using supported native features or APIs. A group push does not by itself define every channel action; private channels, guests and removals need explicit rules and testing.

Can we start with a lifecycle, account or licence review?

Yes. We can scope a review around selected applications or the wider employee lifecycle. It identifies ownership gaps, access to reconsider and licences to assess before implementation. Reclaiming a licence and reducing a bill are separate questions governed by usage evidence, retention requirements and subscription terms.

CONNECT THE BUSINESS TO THE BUILD

What needs to work differently?

Tell me about your current systems, the outcome you need and the constraints. A short outline is enough to start.