Case Studies | Healthcare & Life Sciences

Automating new hire access on AWS

New Hire Provisioning Agent

About

A Healthcare & Life Sciences business working with Cloud Combinator on AWS. The client is anonymised at their request.

Challenge

The challenge had four focus areas, all centred on making onboarding fast, correct and accountable.

Manual, repetitive onboarding

Setting up a new hire meant granting access by hand, tool by tool, for every joiner. It was slow, easy to make inconsistent, and pulled time away from the team for work that follows a predictable pattern.

Role-based least privilege

Access needed to follow the person's role exactly, granting what the role defines and nothing more. Getting this wrong in either direction, too little or too much, creates friction for the joiner or unnecessary risk for the business.

A single, trustworthy source of truth

The intended access in the matrix, the record of work in Jira, and the access actually granted all had to stay in step, so the picture never drifts away from reality.

Keeping people in control of exceptions

Standard, role-based hires should run without anyone approving them, but anything beyond a role must still pass through a human decision before it is applied.

Solution

The access matrix, a spreadsheet a third-party provider maintains, is uploaded to a versioned Amazon S3 bucket. That upload triggers a loader that parses it into Amazon DynamoDB, the live source of truth for what each role should have and what each person currently has. When an operator labels a Jira ticket, Jira calls a secured Amazon API Gateway endpoint, which starts the agent on Amazon Bedrock AgentCore.

1 label

Starts a full provisioning run on AWS

0

Manual approvals for standard role-based hires

100%

Of runs leave an audit trail in Jira

By the numbers:

  • 1 label - Starts a full provisioning run on AWS
  • 0 - Manual approvals for standard role-based hires
  • 100% - Of runs leave an audit trail in Jira
Changes

The proof of concept met its acceptance criteria. A labelled Jira ticket now sets up a standard new hire from their role end to end, the matrix reflects exactly what was granted, Slack reports the result, and Jira holds a complete record of every step.

  • Automatic runsLabelling a Jira ticket triggers a run on AWS on its own, with no manual approval step for standard, role-based joiners.
  • Role-based least privilegeThe agent grants only what the role's matrix entry defines. Access beyond the role is never granted automatically, and is flagged for review.
  • A self-updating source of truthEvery change is written back to Jira and to the access matrix, and a current-state spreadsheet is regenerated, so the record always reflects reality.
  • Governed exceptionsBeyond-role requests can be raised in plain language through Slack, but are only applied after they are approved in Jira.
  • HandoverCloud Combinator delivered the working agent, the deployment repository and setup notes, leaving a third-party provider able to run and extend it.

With Atlassian proven end to end, the same pattern extends naturally to the other tools already captured in the matrix, giving a third-party provider a foundation for fuller, role-driven onboarding as the team continues to grow.

AWS Stack

Amazon Bedrock AgentCore

For hosting and running the provisioning agent, including a governed gateway for admin-level actions.

AWS Lambda

For the serverless compute that loads the matrix and handles incoming triggers.

Amazon API Gateway

For a secured entry point that lets only Jira start a run.

Amazon DynamoDB

For the live source of truth on roles and people.

Amazon S3

For versioned storage of the access matrix, with a full history for audit and rollback.

AWS Secrets Manager

For keeping the Slack and Jira credentials safe.

YOU MIGHT LIKE

Related success stories

View all case studies

Case Studies | Insights

Utilising Language Recognition, Speed, and Enhanced Security to Make Social Media a Force for Good

  • Here, we take a detailed look at how the Cloud Combinator team collaborated with another cutting-edge AI service provider that provides intelligent systems to “make social media more social” for brands and users alike.
  • Arwen AI is a UK-based startup specialising in AI solutions to manage and enhance brands’ social media interactions. Founded in 2020 by Matt McGrory, Dr. David Cole, and Joel Bailey, Arwen. AI focuses on using AI to automatically detect and remove spam, toxic comments, and other unwanted content from social media platforms.
  • The team at Arwen have three core products. ‘Moderate’ is focused on identifying and removing toxic content from social media channels. ‘Engage’ helps brands identify and engage with meaningful conversations on social media, and ‘Customize’ allows brands to apply bespoke algorithms to their channels - creating an even more effective moderation and engagement.
Read more
CONTACT US

Ready to turn AI into impact?

We'll help you spot the highest-value opportunities, reduce risk around your first AI initiative, and define a clear path to results from day one.

Why talk to us:

Outcome-driven recommendations

AWS-recognised delivery expertise

Risk-aware AI adoption

Clear next step, not a sales pitch

Start with a focused 20-minute conversation about your goals — no pressure, no commitment.

This website uses cookies to enhance user experience and to analyze performance and traffic on our website.

See our Privacy Policy for details.