Stepwork logoStepwork logo
ProcedureDeterministic AgentsMarketplaceSecurityClaude Co-Work Alternative
Book a Demo
ProcedureDeterministic AgentsMarketplaceSecurityClaude Co-Work Alternative
Book a Demo
  1. Home
  2. Marketplace
  3. Remove user from Identity Center in AWS

Remove user from Identity Center in AWS

Automatically remove a departing employee from IAM Identity Center from a Slack request with Stepwork. Remove their AWS account assignments and disable their access.

Shaun MacLellanFounder

Book a DemoSee the process
Use case
Employee offboardingIT
Best for
Cloud Administrator, IT Manager
Applications used
  • AWS
  • Slack
Business outcome
Risk reduction

On this page

  1. The problem
  2. The outcome
  3. The process
  4. Why Stepwork
  5. Similar use cases
  6. FAQ
IT
  • AWS

Remove user from Identity Center

One Slack request. Every AWS account closed to them.

Book a Demo

The problem

One person. A dozen AWS accounts.

Teams with many AWS accounts give people access through IAM Identity Center, one account assignment at a time. When someone leaves, each of those assignments has to go.

Done by hand, an admin works through the accounts one by one, or disables the user and leaves the assignments in place. Either way, there is no single record of when access ended across all of them.

The outcome

Access ends across every AWS account at once

Stepwork removes every account assignment for the user and disables their access in IAM Identity Center. The AWS access portal stops working for them, and the run records who asked and which accounts were cleared.

  • Every account assignment is removed.
  • The user’s access is disabled.
  • The Slack reply lists the accounts that were cleared.

The process

From Slack request to no AWS account access

A teammate posts the request in Slack. Stepwork clears the user’s assignments in the IAM Identity Center console, account by account, in the same order every time.

  1. Step 1

    Request it in Slack

    A teammate posts the departing employee’s work email in the offboarding channel. That message starts the flow, and Stepwork records who asked and when.

    Slack message in #offboarding asking to remove alex.chen@acme.com from AWS IAM Identity Center, with Stepwork confirming the flow started
  2. Step 2

    Find the user

    Stepwork signs in to the AWS console, opens IAM Identity Center, and finds the user with that exact email. If there is no match, or more than one, the run stops instead of guessing.

    IAM Identity Center search for alex.chen@acme.com showing Alex Chen still Active
  3. Step 3

    Remove account assignments

    Stepwork removes the user from every AWS account they are assigned to, along with the permission sets on each.

    IAM Identity Center user Alex Chen with every AWS account assignment and permission set removed
  4. Step 4

    Disable and reply in Slack

    Stepwork disables the user’s access, checks that no assignments are left, then posts the list of cleared accounts in Slack.

    Alex Chen disabled in IAM Identity Center with no account assignments, and a Slack reply that access is disabled
Slack message in #offboarding asking to remove alex.chen@acme.com from AWS IAM Identity Center, with Stepwork confirming the flow started
IAM Identity Center search for alex.chen@acme.com showing Alex Chen still Active
IAM Identity Center user Alex Chen with every AWS account assignment and permission set removed
Alex Chen disabled in IAM Identity Center with no account assignments, and a Slack reply that access is disabled

Why Stepwork

Every account, not just the ones you remember

Stepwork runs the path you recorded in IAM Identity Center. It works through every account assignment the user has, not a list someone wrote down, then disables their access.

Procedures
Book a Demo

Similar use cases

Similar use cases

  • Deactivate IAM user in AWSDisables console access and deactivates credentials for an IAM user in the AWS console.Learn more
  • Deactivate user account in OktaSigns into the Okta admin console, locates the user by email, deactivates the account, and confirms the status change ended all SSO sessions.Learn more
  • Disable user account in Microsoft Entra IDSigns into the Entra admin center, locates the user, and blocks sign-in, disabling the account across Microsoft services.Learn more

FAQ

Common questions

  • Post their work email in Slack. Stepwork removes their account assignments in IAM Identity Center, disables their access, and lists the cleared accounts.
  • No. IAM users are separate from Identity Center. Deactivating the IAM user is its own flow.
    Deactivate IAM user in AWS
  • No. Stepwork works in the AWS console, the same way an administrator would. Credentials are read from 1Password at run time, and Stepwork stores only the vault reference.
    Credentials

See it run on a process you already repeat

Bring one. We will show you what it looks like as a flow and what each run records.

Book a Demo
Stepwork

Deterministic agents for work that must run the same way every time.

ProcedureDeterministic AgentsMarketplaceSecurityClaude Co-Work AlternativeFAQ
Terms and ConditionsPrivacy PolicyData Processing AgreementSubprocessors

2261 Market Street #4481, San Francisco, CA 94114, USA

Loot Discount inc dba Stepwork

© 2026 Stepwork. All rights reserved.