PEO & Multi-State Operations3 min readUpdated September 2026

A Cloud Access Runbook for a DevOps Consultancy's PEO Pick

A cloud and DevOps consultancy should run the same access runbook for every engineer, because neither Justworks nor Rippling can grant or revoke an IAM role inside a client's cloud account. New hires get standing access to a client's AWS, GCP, or Azure account, often with permission to change production, and the platforms only handle the pieces around it.

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

How should you prepare before the engineer's first day?

Draft the specific cloud access request before the person starts, not after: which client accounts, which IAM roles, and whether access is standing or requested per session. If the client requires a background check before granting console access, that check needs to clear before day one, not during their first week on the account. Rippling can start a background check from within its hiring workflow, while Justworks connects to third-party screening vendors, so confirm in a demo how much of the tracking each platform automates and who on your team still owns confirming a clear result before requesting the client-side access.

Step 2: Day-one provisioning for your own tools

Whatever the new hire needs inside your own company, laptop, internal Slack, your ticketing system, gets set up here. Rippling ties this to the same hire record that triggered the background check, so a laptop with disk encryption and your standard tooling can be configured and shipped automatically. Justworks handles payroll and benefits enrollment cleanly at this step but leaves device configuration to whatever separate process or MDM tool your consultancy already runs; for a two-person ops team, that's one more manual step to remember on a day already full of them.

Step 3: Requesting the actual client-side cloud access

This step happens outside either platform entirely. Someone submits the IAM role request through the client's own access process, whether that's a ticket to their platform team or a self-service request in their identity provider. The only thing your HR platform contributes here is a clean, current record of who's actively engaged with which client, so whoever's granting access on the client side isn't relying on a group chat message from three weeks ago to confirm someone's still on the account. Rippling's project or department fields can hold this if your team actually keeps them updated; Justworks has no equivalent, so this record lives in whatever separate system you use for client engagement tracking.

Step 4: Rotating engineers between client environments

DevOps consultants often carry active access to two or three client environments at once, and access should shrink, not just grow, as engagements wind down. Build a recurring review, monthly at minimum, that cross-checks who still has cloud access against who's still actively billing that client. Neither platform automates the client-side removal, but Rippling's more granular identity records make it easier to see, at a glance, which internal project assignments changed since the last review, which is the trigger that should prompt someone to go remove the matching cloud access. A consultancy running this review by memory instead of by a fixed date on the calendar tends to find it slips during exactly the busy weeks when staffing is changing the most, which is also when the risk of stale access is highest.

How should you handle offboarding, and what does a slow one cost?

The day someone leaves, your own systems should lock down immediately, and every client whose cloud environment they touched should get a same-day heads-up to revoke access on their end. A delayed offboarding is a bigger liability here than in most consulting categories, because the access in question can modify live infrastructure. Replacing a departing engineer isn't cheap either: the median cost per hire for a nonexecutive technical role runs close to $1,200 nationally by one estimate1, before counting the ramp time for a new hire to get comfortable inside a client's specific cloud setup.

Choosing the platform that fits this runbook

If your consultancy is small enough that one person tracks all of this by memory and a shared doc, Justworks' simpler model and lower administrative overhead may be enough, as long as that person is disciplined about the manual steps above. Once you're running this runbook across a growing roster with engineers touching several client environments at a time, Rippling's tighter integration between hiring events and your own internal access reduces the number of manual handoffs, even though the client-side cloud work stays manual either way. Payroll and platform costs together still typically land above a third of revenue for technical services firms this size2, so whichever platform you pick, the runbook discipline matters more to your risk than the fee difference between them.

Run this sequence for every engineer:

  1. Draft the specific cloud access request and clear any required background check before the engineer's first day.
  2. Provision your own tools on day one, including the laptop, internal Slack, and your ticketing system.
  3. Submit the IAM role request through the client's own access process, since it happens outside either platform.
  4. Review who still has cloud access against who is still actively billing each client, at least monthly.
  5. When someone leaves, lock down your own systems immediately and give every affected client a same-day heads-up to revoke access.
Executive Capability Standard

What Good Looks Like

A well-run cloud consultancy can list, for any active engineer, exactly which client cloud accounts and IAM roles they currently hold, and can confirm access was revoked on both the internal and client side within a day of an offboarding or rotation.

Building The Capability (5-Stage Skill Ladder)

1. Learn:Map out which access decisions happen inside your HR platform versus inside each client's own cloud environment, since the two are never the same system.
2. Do Manually:Keep a running spreadsheet of active client cloud access per engineer, reviewed monthly against current staffing.
3. Delegate:Assign one person to own the offboarding handoff to clients, so a same-day access-revocation request goes out every time.
4. Automate:Use your HR platform's project or department fields to track current client assignments, so access reviews start from accurate data.
5. Buy:Pair your HR platform with a client-side access review process that runs on a fixed schedule, not just when someone remembers to run it.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Frequently Asked Questions

Can Rippling or Justworks directly manage IAM roles inside a client's AWS account?

No. Both stop at your own company's systems and devices. Access inside a client's cloud environment is granted and revoked through that client's own process, and your HR platform's only real contribution is keeping an accurate, current record of who's actively engaged so that process runs on good information.

How fast should client-side cloud access be revoked after someone leaves?

Same day, ideally within hours. Standing access to production infrastructure is a different risk than access to a shared drive, and a delay of even a few days is enough time for unused credentials to become the thing a client's own security review flags.

Is a background check really necessary for a short-term cloud engagement?

Most clients granting console-level cloud access will require one regardless of engagement length, since the risk comes from the access level, not the duration. Confirm the specific requirement with each client rather than assuming a short project is exempt.

Sources

Where we quote a benchmark, we show its source. Other figures in this guide are estimates or general guidance, so check them against your own numbers.

  1. Median cost-per-hire (SHRM 2025 Recruiting Executives Benchmarking). SHRM 2025 Recruiting Executives Benchmarking data brief (PDF), 2025.
  2. Payroll as % of revenue by sector, US firms with <500 employees. US Census Bureau, Statistics of U.S. Businesses (SUSB) 2022, US NAICS sector by enterprise employment size, 2022.

Related Guides