Skip to content
ITSM Identity Operations

Identity tickets that open, route, and close themselves

Aquera ITSM Identity Operations connects your systems of record, HCM, recruiting, and non-employee SORs, to your ITSM and identity providers. SOR change events become tickets automatically, approved catalog requests become real access, and every action is logged in Unified Logging Analytics, no manual service desk work required.

Trusted by 1,500+ Organizations Worldwide

Wingstop_logo Warby_Parker_logo Lucid_Motors_logo JD_Sports_logo Silicon_Valley_Bank_logo_(2018) Allbirds_logo Allergan_logo backblaze_92n7 Forbes_logo Aptiv_logo Casper_Sleep_logo.svg Opendoorlogo.svg squarespace-logo-horizontal-black IonQ_corp_logo.svg Lindt-Logo images FIGS_Inc_Logo E.l.f.-Logo everlane-logo-vector images (1) 656661c5e4f9dbb18f4bd724_Matterport Myfitnesspal-Logo-Vector.svg- StoneX_Group_Inc_official_2023_logo.svg kisspng-keller-williams-realty-lake-charles-clarks-summit-5b08ba53863a91.8378231615272986435498 Bupa_logo.svg wwf_logo_large_rgb_72dpi_1_1_1_1_783732 b5586b9a-1c73-46ad-bccf-09ab444e2def-1
What It Delivers

Tickets, access, and lifecycle, without the manual work

Auto tickets
Joiner, Mover, Leaver (JML) tickets generated from SOR events, even before day one
Approved → done
catalog approvals fulfilled in the IDP, no swivel-chair provisioning
End-date enforced
contractor access monitored and offboarded on time, every time
The Gap

Removing the manual service desk tax

Every identity event in your ITSM carries a hidden manual cost: tickets typed by hand after someone notices an HR change, approvals waiting on swivel-chair provisioning, contractor end dates living in spreadsheets, and reference data drifting from HR reality.

Without identity operations
Tickets typed by hand. Onboarding runs late and offboarding gets missed when someone has to notice the HR event first.
Swivel-chair fulfillment. Approved access requests still wait for an admin to add users to groups and applications manually.
Contractor access lingers. End dates live in spreadsheets and inboxes, access quietly outlives the engagement.
With ITSM Identity Operations
Tickets generated automatically. JML tickets created from SOR change events using your own ticket templates, even before day one.
Approval becomes access. Approved catalog items are fulfilled in the IDP, groups, entitlements, and applications assigned automatically.
End dates enforced. Extension tickets are raised as dates near, and offboarding happens on time if not extended.
Go Deeper

ITSM Identity Operations Solution Brief

Ticket generation, access fulfillment, contractor lifecycle, org sync, and the full comparison, learn more now.

Download the datasheet
How It Works

From SOR event to ticket, to access, to audit log

Aquera turns every system-of-record change into the right ITSM action, tickets generated, catalog requests fulfilled, contractors offboarded on time, and logs every step in Unified Logging Analytics.

1 GENERATE

Turn SOR events into ITSM tickets

HCM and recruiting change events create onboarding, offboarding, and role-change tickets using your own ticket templates, even before day one.

  • Event-to-ticket. Joiner, mover, and leaver tickets from SOR change events.
  • Your templates. Each event type maps to your ITSM template and field map.
  • Early onboarding. Pre-day-one tickets from candidate recruiting events.
2 FULFILL

Turn catalog approvals into IDP access

When a service catalog request is approved, Aquera adds the user to the right groups, entitlements, and applications in Okta, Entra ID, or Active Directory, automatically.

  • Approval-to-access. No admin provisioning step after approval.
  • Group, entitlement, app. All three fulfillment types supported.
  • Contractor lifecycle. Catalog-driven onboarding with persisted end dates.
3 LOG

Audit every action in one place

Unified Logging Analytics consolidates SOR change events, Aquera, ITSM, and IDP logs, with Log Insights dashboards and report-only mode to preview changes before they apply.

  • Unified logging. SOR, ITSM, and IDP logs in one dashboard.
  • Log Insights. Analyze integration results end to end.
  • Report-only mode. Preview changes before implementation.
What Makes It Different

The same service desk, without the manual work between event and action

Event-Driven Tickets

JML tickets are generated directly from SOR change events using your own ticket templates, no one has to notice the HR event and type a ticket.

Approval-to-Access

Approved service catalog items are fulfilled in the IDP automatically, groups, entitlements, and applications assigned without a provisioning queue.

End-Date Enforcement

Contractor end dates are monitored continuously; extension tickets are raised as dates near and offboarding happens on time if not extended, no spreadsheets.

Let's Talk

See ITSM Identity Operations in Action

A 30-minute working session mapped to your ITSM and identity stack, scoped to the systems you actually run.

Request a Demo
The Shift

From manual service desk to automated identity operations

Manual ITSM identity process
Aquera ITSM Identity Operations
JML tickets created by hand after someone notices the HR event, late and inconsistent
JML Tickets. Generated automatically from SOR change events, even before day one
Approved requests queued for an admin to provision manually
Access Fulfillment. Approved catalog items fulfilled in the IDP, groups, entitlements, applications
Contractor end dates tracked in spreadsheets; access outlives the engagement
Contractor End Dates. Monitored continuously, extension tickets raised, offboarding on time
Org reference data updated ad hoc; departments and cost centers drift from HR
Org Reference Data. Departments, locations, cost centers, and hierarchy synced on schedule
ITSM user accounts created by hand, often only when onboarding stalls
On-Behalf-Of Users. Created automatically when onboarding requires them
Audit evidence scattered across systems, exports, and inboxes
Audit Trail. Unified Logging Analytics across SOR, Aquera, ITSM, and IDP logs

Frequently asked questions

What is Aquera ITSM Identity Operations? +

Aquera ITSM Identity Operations connects an organization's systems of record, HCM, candidate recruiting, and non-employee SORs covering contingent workers and B2B partners, to its ITSM application and to identity providers such as Okta, Microsoft Entra ID, and Active Directory. SOR change events become ITSM tickets, and approved service catalog requests become real access, automatically.

Can Aquera create onboarding tickets before an employee's first day? +

Yes. Early onboarding ticket generation creates tickets from candidate recruiting system events, so IT work can start before day one.

What problem does it solve? +

It removes the manual service desk work behind identity events: JML tickets typed by hand, swivel-chair fulfillment, contractor end dates tracked in spreadsheets while access outlives the engagement, and ITSM org reference data drifting from HR reality.

What are the core capabilities? +

Four: JML ticket generation from SOR change events; access request fulfillment that turns approved service catalog items into IDP group, entitlement, and application assignments; contractor onboarding lifecycle management with end-date enforcement; and organizational reference data sync.

How does it work? +

It sits between the systems of record and the service desk: the systems of record decide who; Aquera runs the ITSM identity automations and unified logging; and the ITSM platform and identity providers receive the tickets, fulfilled catalog items, and access.

What is the manual service desk tax? +

The recurring manual work behind every identity event in an ITSM: JML tickets typed by hand, swivel-chair fulfillment, contractor end dates living in spreadsheets, and stale reference data drifting from HR reality. Aquera eliminates each of these by automating from the systems of record.

Which systems of record can drive it? +

HCM systems, candidate recruiting / applicant tracking systems, and non-employee systems of record covering contingent workers and B2B partners. Change events from these SORs trigger ticket generation and data sync.

Which ITSM platforms does it support? +

ServiceNow and other leading ITSM platforms. Aquera integrates with the ITSM application's tickets, service catalog items, organizational reference data, and user accounts; additional platforms are supported on request.

Which identity providers does it work with? +

Okta, Microsoft Entra ID, and Active Directory, among others. Aquera fulfills group, entitlement, and application access in the IDP and onboards or offboards contractor accounts there.

What is JML ticket generation? +

Automatic creation of onboarding, offboarding, and role-change tickets in the ITSM from HCM and candidate recruiting change events, using the customer's own ITSM ticket templates. Tickets can be generated early, before day one.

What is access request fulfillment? +

When a service catalog request for group or application access is approved in the ITSM, Aquera identifies the approved request and adds the user to the identified IDP group or application, no manual provisioning step.

How does it stop contractor access from lingering? +

With end-date enforcement: Aquera monitors contractor end dates continuously, raises extension tickets as dates near, and offboards contractors on time if the engagement is not extended. Left to spreadsheets, contractor accounts stay active an average of 47 days after termination (CISA).

Does it require coding? +

No. Configuration is point-and-click: per integration, you enable ticket management, organizational data sync, user lifecycle management, and access fulfillment, then complete attribute maps and schedules, no scripts.

What is Aquera Unified Logging Analytics? +

A single analytics layer that collects SOR change events, Aquera logs, ITSM logs, and IDP logs, with Log Insights dashboards, one place to audit every identity action across the integration.