Deactivate user account in Okta
Automatically deactivate a departing employee’s Okta account from a Slack request with Stepwork. Find the user, deactivate the account, and end every active sign-in session.
- Use case
- Employee offboardingIT
- Best for
- IT Administrator, Helpdesk Technician
- Applications used
Okta
Slack
- Business outcome
- Risk reduction
The problem
HR says goodbye. Okta finds out days later.
Offboarding starts with an HR notice and ends in the helpdesk queue. Someone opens the Okta admin console, searches for the person, and deactivates the account by hand. Often that is hours or days after their last day.
In that gap the person can still sign in through Okta to every application behind it: email, Slack, the CRM, the cloud console. Nobody writes down when access ended, so the audit question has no answer.
The outcome
Access ends when the request lands, not when someone gets to it
Stepwork deactivates the account in Okta and confirms the status change ended every active session. Applications behind Okta stop accepting the person at once. The run records who asked, when the account was deactivated, and whether every step completed.
- Every active Okta session is ended and confirmed.
- Every run names who requested it and when it ran.
- Every failure names the step and the reason.
The process
From Slack request to deactivated account
A helpdesk teammate posts the request in Slack. Stepwork runs the path recorded in the Okta admin console, in the same order every time.
- Step 1
Request it in Slack
A helpdesk teammate posts the departing employee's work email in the offboarding channel. That message starts the flow, and Stepwork records who asked and when.

- Step 2
Sign in to Okta
Stepwork opens the Okta admin console with a credential read from 1Password at run time. No Okta API token, only the access that admin account already has.

- Step 3
Find the user by email
Stepwork searches the Okta directory for the exact work email. If there is no match, or more than one, the run stops instead of guessing.

- Step 4
Deactivate the account
Stepwork deactivates the user, the same click an Okta admin makes. Sign-in through Okta ends for every application behind it.

- Step 5
Confirm every session has ended
Stepwork checks that the status reads Deactivated and every session has ended, then posts the result back to Slack with a timestamp.

Why Stepwork
Same path in Okta, every departure
Stepwork is a deterministic agent platform. It runs the Okta path you recorded, not a new plan each time, so the same request produces the same steps. Credentials stay in 1Password; Stepwork holds a vault reference, never the password. When the Okta admin console changes, AI vision recognizes the element and the run continues.
Similar use cases
The same offboarding step in other applications
Suspend user account in Google WorkspaceSigns in to the Google admin console and suspends the account, blocking sign-in while keeping the data.
Disable user account in Microsoft Entra IDSigns in to the Entra admin center and blocks sign-in, disabling the account across Microsoft services.
Deactivate member account in SlackSigns in to Slack admin and deactivates the member, removing their workspace access.
FAQ

