EP139 – The MSP Joiner-Leaver Problem Nobody Talks About with Cristian Bogdan from CooperBox

Cristian discusses how his MSP experience provisioning thousands of pandemic-era laptops exposed frequent mis-provisioned user accounts, often caused by clients submitting incomplete joiner requests (missing departments, licenses, and permissions). He highlights the larger risk on off-boarding, citing studies in the UK and USA where 50% of businesses reported former employees not being fully off-boarded, leaving residual access and ongoing licensing costs. Cristian describes a self-serve joiner/leaver platform designed to replace fragile ticket-based workflows with guided forms, integrations with HR platforms via APIs, a governance engine that validates requests against policies, an approval queue for final review, and tracking of what was provisioned to ensure consistent deprovisioning, including manual notes for non-SSO legacy apps. He explains MSP commercialisation options (embedded, add-on, hybrid), benefits for compliance evidence (e.g., ISO 2701), applicability to internal IT/co-managed environments, and notes the product was largely built using OpenAI Codex.

 

00:00 Welcome and Setup

00:24 MSP Origin Story

01:26 Joiner Provisioning Pain

02:36 Leavers and Residual Access

04:45 Automation and HR Integrations

08:03 Self-Serve Governance Workflow

09:41 Compliance Value and ROI

10:54 Pricing and Target Users

16:34 Governance Engine vs Scripts

18:18 AI Future and Readiness

20:19 Building with Codex

22:08 Wrap Up and Contact

 

Listen on Spotify or Apple Podcasts

 

Connect with Cristian Bogdan on LinkedIn by clicking here –https://www.linkedin.com/in/c-bogdan/

Connect with Daniel Welling on LinkedIn by clicking here – https://www.linkedin.com/in/danielwelling/

Connect with Adam Morris on LinkedIn by clicking here – https://www.linkedin.com/in/adamcmorris/

Visit The MSP Finance Team website, simply click here –https://www.mspfinanceteam.com/  

MSP Glossary: MSP Finance Glossary Explained | MSP Finance Team

We look forward to catching up with you on the next one. Stay tuned!

Transcript:

Dan: Cristian, welcome to the podcast

Cristian: Thank you. Thank you for having me

Dan: you’re very welcome. And, a- as is customary, we, we probably should’ve hit record about 10 minutes ago, for our green room conversation. But, Adam and I feel, like we’ve definitely had an education around, around the topic that you’re grappling with, today, and really looking forward to sharing that with our audience.

So, your MSP experience started on the ground, trying to provision laptops with user accounts that hadn’t been properly provisioned. is that right?

Cristian: Yes, it is. I’ve joined the company just before, pandemic hit, and I was building, especially during the pandemic time, thousands of laptops for them. Everybody was working from home. And that’s how my experience started with,bad provisioned accounts, to call them that way. And yes, i-it was a problem for me at the time, [00:01:00] even though I was not directly involved in provisioning the accounts.

I was provisioning the laptops. every time I had an, improperly provisioned account, I had to go back and sort it out myself, as that was far, quicker than just go back to the service desk and ask him to complete that ticket. human mistakes happen everywhere, so I’m not here to blame anyone.

It’s just the nature of the business. the bigger the numbers, the more, mistakes happens

Dan: and, t- talk me through what some of the issues were like. what was mis- mis-provisioned? And was this the client or the MSP who, or both?

Cristian: sometimes it’s both, but most of the incidents they were coming from the client side because they were not, they were not creating the request properly based on what they needed. just imagine somebody new, join as an manager for a department and, he has new employees. He doesn’t know how to fill in those form correctly first time.

Even though he has been kind of inducted, he’s just not experienced with that. [00:02:00] And from there everything just is snowball

Dan: and so this would be things like, the permissions weren’t granted in the right way or,

Cristian: Certain permissions in SharePoint, certain licenses haven’t been provisioned for third-party application or you name it, anything in the spectrum. most of the time they just send an username and the date which we have to chase back and ask, “Okay, what do you want for these users? Which department is gonna work?

What licenses do you want?” So on and so forth. So i-it is a back-and-forth ticket, most of the time for the joiners

Dan: and, of course, j-joiners is one thing. they won’t last forever though, so then they leave at some point, don’t they? So then there’s another problem

Cristian: Yes. when we started to, investigate, if the product we want to create is gonna be, sellable on the market, we discovered that, there are studies made in UK and USA, where the businesses that they [00:03:00] participate in the study, 50% of them, they have reported that they have not fully off-boarded their former employees.

They have retained residual access long time after they left the business. And I think that is not just a statistic because I have witnesses myself within the MSPs that people forget to tell us that, employees left. they submitted a form for off-boarding the client without mentioning third-party applications or anything that is not standardized to M365 or domain controllers as we had most of the time.

very easy to forget things and left behind

Dan: that puts,the client obviously at risk, of, bre- breach of data, but also additional costs if they’re still paying for licensing associated to some of these, some of these platforms

Cristian: Of course, licensing is one that is easy to spot and has a high impact because you [00:04:00] keep paying for licenses when you don’t have active users. but there are also other parties which, as you mentioned, is a high risk for the business as a user has left the business. compliance-wise, there is no 99% compliance, is you are compliant or you’re not.

and the risk for the security, it’s big. It depends, for example, many people think of the external attacks on the business, but they kind of forget about the internal attack inside the business. And we had a number of businesses that they had problems with their employees, and they, mainly because of internal issues, and they started from, having access that they shouldn’t have

Adam: that all makes sense, Cristian. Can you explain to me, though, how your tool deals with the problem is that the end user, either forgets they have a lever or they know they’ve got the lever, but [00:05:00] they don’t think about all aspects of that lever’s footprint? So in the traditional process, the MSP can only do what they do and stuff is left or missed.

How does your tool kind of handle that, that, that process?

Cristian: first of all, it’s important for the client to report that there is a leaver. that is the starting point. on top of that, we have integration with HR platforms. am I okay to say a name of a platform of… Yeah, okay. So I

Dan: as long as they don’t sue us, yeah.

Cristian: you can cut it off. It’s not a problem. So w-we started OpenAPI for the integration because we were aware that this is gonna be a problem, and we have integrated with HR platform via third-party platform.

Currently, I have, made some workflow myself via n8n to have flexibility to integrate with pretty much anything that is a third-party application to us. But we can integrate with anything else, ’cause we handle the APIs, so we can open them [00:06:00] for whoever needs them. And when they made a request in HR platform for that user to, become a leaver, that automation process goes into our platform.

Into our platform goes through a governance engine. The governance engine is gonna look at it and say, “Yes, we can execute,” and, “No, we cannot execute this.” And if it’s a yes, then it’s gonna land into an approval queue where a person is gonna look. It’s gonna be a final review before the actual execution

Dan: and that assumes, of course, that it’s looking back at how the user was provisioned initially

Cristian: Yes. So we have a full track. So when they onboard the user, everything that has been provisioned, it stick with that account. So at the moment when you’re gonna remove that user, even if it’s a third-party application that we cannot control, we have a special section for notes where people say in that notes when they provision the user, we have applied, I don’t know, Adobe license, for [00:07:00] example.

Yeah. When they remove that user, they will not be able to remove that user unless they confirm that they have removed the license from that, third-party application

Adam: So, so, so that will make sense now, but it still relies on the individual telling the application that they’ve added that specific license originally

Cristian: Y-yes, because we cannot control beyond single sign-on. So if it’s a legacy application or if it’s not single sign-on or single sign-on is not configured, then it’s beyond our control. So the only means we have at that time is to have manual input

Adam: Sure. but I get how the, these extra steps now are helping to reduce,non-compliances or mistakes. That, that does make sense

Cristian: I mean, mistakes, they’re gonna be no matter how much automation we can make. It’s only that much we can automate, but we gonna definitely reduce the incidents by [00:08:00] a very large number

Dan: And we were talking about how the sort of traditional joiner-leaver communication happens with a, with an MSP and some of the fragility of,of that. so e-effectively what we’re talking about here though is that clients can self-serve,user provisioning and deprovisioning without it having to go through, a service desk ticket as it would traditionally.

Cristian: Yes, that is our, kind of by design factoring in. We understood that the ticketing system is not, appropriate for this kind of action. A joiner and the leaver is a business event, it’s not an incident. That’s why we try to eliminate this problem and this friction that comes in, kind of Chinese gossip between, clients and MSP through ticketing system.

And we have managed to empower the client to [00:09:00] execute everything themselves, even though they are not technical. So we simplify the process so much that for the person who’s making a request for a user to join the business, it is so simple that they don’t need any training. They… All they need is to know how to use a computer

Dan: Which of course, s- some end users still don’t know that. but if they can book a ticket, they can use this platform basically.

Cristian: Yes. So we tried, that was our main goal when we designed the user experience to simplify it as much as possible. So now they have a very simple form that they fill in four steps, and all the steps, they are guided, one step leads to another until they are ready to submit, that one for approval

Dan: Very good. And i-in, in the green room, we were talking about, well, what’s the end client’s response gonna be to this? they’re gonna, they’re gonna say: Well, this is less work for you now, so we pay you less?

Cristian: yes, that is one of the challenges MSPs they’re gonna face. however, in [00:10:00] my view, the fact that the client can provision faster and fix their problems in real-time rather than waiting for a ticket is a massive bonus for them. On top of that is the compliance. So if the client that is aiming for certain, frameworks for compliance like ISO 2701, for example, they can use this platform to, provide evidence on their processes, how they follow, and everything else that they do.

They can extract a report from the platform, and they can provide that one to an assessor. I think that is a massive,benefit for them, especially in terms of, being standardized and following a process that is aligned with the compliances. We’re gonna sit on top of the compliances always with the platform because we want to empower the MSP to resell this as a governance tool

Dan: And, I, I guess, well, that, that leads me to one of my questions in terms of how the MSP would [00:11:00] commercialize this. You see this as being something additional that they sell, or would you see it as being a tool that they integrate into their stack and amend their overall price with the,the feature advantage and benefits of, of the compliance,achievement?

Cristian: It is indeed. There are multiple,models for selling this product. the client that we’re working with, they want to embed this one within the package they offer for their clients as an up-packaging service. but I do believe there will be MSPs that they would like to sell it separately or in a hybrid model.

I don’t know, for their main,client base, they’re gonna sell it as add-on into the packages they sell. And if they have like, I don’t know, clients that they come and go or they are,occasional clients, they might resell it as, a feature

Dan: And is this an issue specifically to MSPs or is this a wider, [00:12:00] like an internal IT function in a larger business? would they, could they be a user of this platform?

Cristian: Absolutely, yeah. So as long as there is somebody technical who understand how to, configure the platform for the end user, that’s workable. it doesn’t matter if it’s an MSP or if it is an internal IT platform. the only thing that really matters is the number of clients so they can become profitable.

the rest of them is just technicalities that can be solved

Dan: Yeah. and I’m thinking,the obvious,best fit client for this would probably be those that do have a particular interest in, in governance and compliance and,and are perhaps re-regulated or working towards,a particular framework. but also I can see this being really useful in a co-managed environment, where there’s perhaps plenty of opportunity for the MSP and the internal IT function to, to drop a ball and not [00:13:00] know who’s doing what.

Cristian: Absolutely, yeah. Absolutely. It’s very important, especially when there are multiple IT teams that they don’t have a clear line of,separation between them, then yes, it’s trackable. one thing that we did focus quite a lot once we start to develop this platform is to coagulate all the, reports into a single place.

Even though we have a number of integration with other tools, our tool is still coagulating the reports in a single place because this fraction between different tools as it is in use today, for example, like an MSP is trying to use an RMM to control the clients. It’s trying to use a ticketing system that’s from a different vendor.

It’s trying to use a licensing system, different vendor. All this fractioning, it’s creating a lack of control. It’s very difficult to track who did what, did when did, [00:14:00] and we coagulate all these reports into a single platform, so we know at all time what happened and why it happened.

Adam: just around the model again. could an MSP choose to provision the user administration for the client as they do today using your tool? and if they did, would it end up eating up more of their time or about the same?

Cristian: I would not recommend an MSP to also be the requester and the approver for the client. there are three entities. It’s ourselves as a business, is the MSP, and is the client, and that’s how the platform has been structured. The client has two entities. One is a requester, somebody who’s requesting that one.

It can be an automated process coming from an HR platform, but it has to be a request coming from somewhere, and it has an approver, somebody who’s gonna oversee what’s happening before doing that. So it’s not gonna be [00:15:00] practical for an MSP to, kick the corner and score with the head in the same time

Adam: I get that. So I guess I’m trying to understand what the MSP’s response to the question from the end user is when they say, we’ve– you’ve taken care of that for us before. Now it feels like we’ve got more work to do.”

Cristian: Isn’t

Adam: answer to that particular objection?

Cristian: It’s not more work at all. It’s literally if it’s not the same, it’s less. Because now the structure that they have to fill in, it’s starting from the same basis as creating a username, the access that you want, licenses that you want to assign to that user. But it’s kind of a simplified. I’ve seen in my, my, experience at an MSP, the ticketing system they have in their Excel spreadsheets, they have Word forms, they have all sorts of forms that they submit within the ticket because that’s how they operate, and the MSP kind of accepted that is non-standardization.

“Okay, [00:16:00] this is how you operate. When you go on board, you’re gonna follow your…” Now it’s gonna push a bit back into the client also to be more standardized rather than everybody having all the tools all over the place, and that’s gonna create less friction between the MSP and the client, and also it’s gonna make the life of the client a lot easier.

Because once they have a problem, it’s gonna be very easy for them to go back into the platform and fix it rather than request for the MSP to add additional access that they kind of forgot to add into the request

Dan: And think, thinking of, MSPs then that might be the appropriate starting point for this platform. It’s gonna be those that already have implemented some level of control, some guidelines to, to, to help the end client be,helpful, to themselves in providing information in a structured, standard way that, that there, there is some level of, control around the joiners and leavers [00:17:00] process.

Cristian: Yes, we’ve seen that they try to do starting from… we try to do ourselves basic scripting in PowerShell, so just the service desk use a certain PowerShell script to kind of fast provision accounts. the biggest problem with those tools, is that it’s very difficult to maintain scripts. you have to be, you have to have somebody who’s responsible for maintaining, controlling what’s happening with that script at all times.

if you go a level up, we can speak about Rust or NA8 where people they try to kind of, automate the process from the ticketing system going towards RMM, so on and so forth. The biggest missing part is the governance engine that we have implemented into our tool. So for us, if an, a request comes, that request is not an execution command.

It’s just a snapshot of that user. We’re gonna run that one through the governance engine, and if the governance engine say, “Yes, we can execute this,” there are a number of policies that they have to [00:18:00] match exactly. If one fails, it’s gonna be a fail, so we’ll not execute anything. If that one is possible to be executed, then it lands into the queue of the approver.

If the approver says, “Yes, I’m happy with that to be executed,” then that is the moment when the execution starts in our end.

Dan: And we,we’re in the age of AI now, so we have to ask you the question: Is AI gonna do all of this for us, in a year’s time anyway?

Cristian: depends. It depends. It might help AI. at the minute we have not implemented AI at all into the platform. but I think there are places where AI might help. it depends how people they will learn to operate with AI. It’s not the technology. The technology is here. It’s just a matter of how people tend to interact with the AI.

‘Cause we can track, for example, if the businesses they’re gonna reach a level where their employees are [00:19:00] actually, orchestrators and they use AI as that level, then we can integrate our platform to do a deterministic work for the request that’s coming from an AI. So yes, AI is gonna be here. it’s not gonna go, and we are thinking of ways we can integrate AI into the platform.

But at the minute we have not touched it at all because we believe the market is not ready for this kind of automation. When the market is gonna be ready, we have all the tools already prepared because the tool we have created is so modular and it’s very much easy for us to just plug in and plug out whatever we need to do

Dan: Very good. So actual intelligence, rather than artificial for, for at least the next couple of quarters then?

Cristian: Yes, it’s gonna be, it’s gonna be for a while. We are waiting for the market. We are ready today to adopt AI if they are ready, but at the minute we don’t see that happening too much into the market. And we are very efficient into kind of adopting [00:20:00] AI for ourselves. being a very small business, at the minute it’s just myself in the business, I have to rely heavily into AI, for pretty much anything that I’m doing.

So I’m, pro-efficient in the AI. I’m waiting for the others to be the same pro-efficient so I can deliver, the same level of,of tooling for them

Adam: Well, there’s an interesting question there. So to, to what extent has AI helped you develop this product? I mean, has it been a large component of it in terms of churning out the code, or have you pushed that? Yeah. Okay

Cristian: yes. So, it has been massively coded with Codex. the application itself has over 100,000 lines of code, which they have been written in a period of two and a half, three months. without Codex, it wouldn’t have been possible for me to do all that. it’s literally impossible. and I spend most of my time, not writing the code but actually verifying the code

Adam: Yeah, sure. And sorry, what did you say it was written in?

Cristian: CodeX

Adam: and what’s, what [00:21:00] AI platform did you use to help you write that?

Cristian: it’s, Codex is part of OpenAI and is available on VS Code. so that’s how I’m using it. I’m coding in VS Code and I’m helping myself with Codex

Adam: And so what, what would you, what score would you give out of 10 for your AI helper in terms of the quality of the code and the consistency and the errors that are made and all the rest? What– if compared to a human, what would you give it?

Cristian: I will not compare it to human because it’s a bit different, but I will give it a score of seven. I think that is gonna be a fair score for, the times that has hallucinated, gone sideways, and I have to go back and rectify things. for the fact that, I had to build tools around it to make sure it stays within the parameters, it doesn’t go off-rail.

I think a seven, seven is a fair score for, Codex

Dan: and of course, with the AI, I agree with you on [00:22:00] that, but we’ll,we’ll not get into that,that black hole. and I’m sure it’s not listening to this conversation, and if it is,it’s a positive seven, not a negative seven. really interesting talking to you. pr- probably, probably mu- much more, than Adam and I thought there was to joiners and leavers and, and the governance, a- around it. And,it’s this time in the podcast where we, we offer our guest a, a shameless plug. So, how, if anyone wants to talk to you, how best to get in touch?

Cristian: LinkedIn is probably the best, for me. even if people are using the phone number that I have on my website, many times I’m not available, so it’s gonna end up into a message box. So LinkedIn is probably the best. Send me a message, I will reply to you as soon as I, I can. but I’m gonna see it anyway.

So that’s my mainstream platform for communication at the minute

Dan: Very good. And, any final thoughts, Adam?

Adam: Well, I, yeah, I guess I hadn’t considered that this was a problem that needed [00:23:00] solving,or hadn’t even thought up, thought that it was a problem that need, needed fixing. So it’s been quite interesting actually, and I really do, wish you the best of luck, Cristian, on this project.

well, once you started talking about the integration of with the HR platform, that started to kick in a bit more for me, I think. that kind of actual, actually tying it into the HR responsibility and tying it into the, additional, the existing workflows and processes that are already in place.

I think,back to what Dan said, if, if we, if you’re targeting the security, the high security posture clients,who, who are interested in, in, in that, that, there’s mo- more mature end user clients, then I think then this definitely has a place. yeah, really quite interesting and definitely the AI side of it in terms of how that will integrate with it again to move it on further, is obviously gonna be part of the journey, isn’t it, as things go forward?

Cristian: Yeah. Well, if any MVP, that has become a product has changed the shape quite dramatically. So this is a starting point for us. I don’t know where it’s gonna end yet, but I think it’s gonna be, very different [00:24:00] than what it is today

Dan: A br- a brave new future awaits us, I’m sure. And,Cristian, it’s been a pleasure talking to you, so thank you very much for joining us on the show

Cristian: Thank you very much

Want to chat?