A Cloud Access Runbook for a DevOps Consultancy's PEO Pick
A cloud and DevOps consultancy should run the same access runbook for every engineer, because neither Justworks nor Rippling can grant or revoke an IAM role inside a client's cloud account. New hires get standing access to a client's AWS, GCP, or Azure account, often with permission to change production, and the platforms only handle the pieces around it.
Vendors Covered in this Article
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
How should you prepare before the engineer's first day?
Draft the specific cloud access request before the person starts, not after: which client accounts, which IAM roles, and whether access is standing or requested per session. If the client requires a background check before granting console access, that check needs to clear before day one, not during their first week on the account. Rippling can start a background check from within its hiring workflow, while Justworks connects to third-party screening vendors, so confirm in a demo how much of the tracking each platform automates and who on your team still owns confirming a clear result before requesting the client-side access.
Step 2: Day-one provisioning for your own tools
Whatever the new hire needs inside your own company, laptop, internal Slack, your ticketing system, gets set up here. Rippling ties this to the same hire record that triggered the background check, so a laptop with disk encryption and your standard tooling can be configured and shipped automatically. Justworks handles payroll and benefits enrollment cleanly at this step but leaves device configuration to whatever separate process or MDM tool your consultancy already runs; for a two-person ops team, that's one more manual step to remember on a day already full of them.
Step 3: Requesting the actual client-side cloud access
This step happens outside either platform entirely. Someone submits the IAM role request through the client's own access process, whether that's a ticket to their platform team or a self-service request in their identity provider. The only thing your HR platform contributes here is a clean, current record of who's actively engaged with which client, so whoever's granting access on the client side isn't relying on a group chat message from three weeks ago to confirm someone's still on the account. Rippling's project or department fields can hold this if your team actually keeps them updated; Justworks has no equivalent, so this record lives in whatever separate system you use for client engagement tracking.
Step 4: Rotating engineers between client environments
DevOps consultants often carry active access to two or three client environments at once, and access should shrink, not just grow, as engagements wind down. Build a recurring review, monthly at minimum, that cross-checks who still has cloud access against who's still actively billing that client. Neither platform automates the client-side removal, but Rippling's more granular identity records make it easier to see, at a glance, which internal project assignments changed since the last review, which is the trigger that should prompt someone to go remove the matching cloud access. A consultancy running this review by memory instead of by a fixed date on the calendar tends to find it slips during exactly the busy weeks when staffing is changing the most, which is also when the risk of stale access is highest.
How should you handle offboarding, and what does a slow one cost?
The day someone leaves, your own systems should lock down immediately, and every client whose cloud environment they touched should get a same-day heads-up to revoke access on their end. A delayed offboarding is a bigger liability here than in most consulting categories, because the access in question can modify live infrastructure. Replacing a departing engineer isn't cheap either: the median cost per hire for a nonexecutive technical role runs close to $1,200 nationally by one estimate1, before counting the ramp time for a new hire to get comfortable inside a client's specific cloud setup.
Choosing the platform that fits this runbook
If your consultancy is small enough that one person tracks all of this by memory and a shared doc, Justworks' simpler model and lower administrative overhead may be enough, as long as that person is disciplined about the manual steps above. Once you're running this runbook across a growing roster with engineers touching several client environments at a time, Rippling's tighter integration between hiring events and your own internal access reduces the number of manual handoffs, even though the client-side cloud work stays manual either way. Payroll and platform costs together still typically land above a third of revenue for technical services firms this size2, so whichever platform you pick, the runbook discipline matters more to your risk than the fee difference between them.
Run this sequence for every engineer:
- Draft the specific cloud access request and clear any required background check before the engineer's first day.
- Provision your own tools on day one, including the laptop, internal Slack, and your ticketing system.
- Submit the IAM role request through the client's own access process, since it happens outside either platform.
- Review who still has cloud access against who is still actively billing each client, at least monthly.
- When someone leaves, lock down your own systems immediately and give every affected client a same-day heads-up to revoke access.
What Good Looks Like
A well-run cloud consultancy can list, for any active engineer, exactly which client cloud accounts and IAM roles they currently hold, and can confirm access was revoked on both the internal and client side within a day of an offboarding or rotation.
Building The Capability (5-Stage Skill Ladder)
How to Get Started
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
Justworks fits a small consultancy where one disciplined operator can track client access manually and mainly needs payroll and benefits handled well.
Rippling fits a growing consultancy that wants its internal hiring and access records tied together as engineers rotate across several client cloud environments.
Frequently Asked Questions
Can Rippling or Justworks directly manage IAM roles inside a client's AWS account?
No. Both stop at your own company's systems and devices. Access inside a client's cloud environment is granted and revoked through that client's own process, and your HR platform's only real contribution is keeping an accurate, current record of who's actively engaged so that process runs on good information.
How fast should client-side cloud access be revoked after someone leaves?
Same day, ideally within hours. Standing access to production infrastructure is a different risk than access to a shared drive, and a delay of even a few days is enough time for unused credentials to become the thing a client's own security review flags.
Is a background check really necessary for a short-term cloud engagement?
Most clients granting console-level cloud access will require one regardless of engagement length, since the risk comes from the access level, not the duration. Confirm the specific requirement with each client rather than assuming a short project is exempt.
Sources
Where we quote a benchmark, we show its source. Other figures in this guide are estimates or general guidance, so check them against your own numbers.
- Median cost-per-hire (SHRM 2025 Recruiting Executives Benchmarking). SHRM 2025 Recruiting Executives Benchmarking data brief (PDF), 2025.
- Payroll as % of revenue by sector, US firms with <500 employees. US Census Bureau, Statistics of U.S. Businesses (SUSB) 2022, US NAICS sector by enterprise employment size, 2022.
Related Guides
Rippling vs Firstbase for a Five-Person DevOps Consultancy
For small cloud and DevOps consultancies: when a client contract finally justifies company-owned hardware, and how to keep overhead proportional.
Kandji vs Rippling IT for Cloud and DevOps Consultancies
Cloud and DevOps consultants need real admin rights to do their job. Here's how Kandji and Rippling handle that without giving up baseline security.
Rippling vs Gusto When One Person Runs Benefits for a Dozen Engineers
A small cloud and DevOps consultancy with a handful of highly paid engineers has different needs than a larger team. Here's the Rippling vs Gusto tradeoff.
Deel vs Remote for Cloud and DevOps Consultancies
A checklist and common pitfalls for cloud and DevOps consultancies deciding between Deel and Remote to hire SREs and infrastructure engineers abroad.
Make vs Zapier for Solo IT and Cloud Consultants
A practical comparison of Make and Zapier for a one-person or small technical consultancy handling scheduling, invoicing and basic support without a full team.
Notion vs Slite for Cloud & DevOps Consultants
How a cloud or DevOps consultancy should choose between Notion and Slite for infrastructure runbooks, architecture decisions, and on-call docs.