19 ms·
Figure out who's leaving the company: dump, diff, repeat
- l0b0 3y agoNow to figure out how the frig to implement this at $work.
- enasterosophes 3y agoSince we're a puppet shop, the user account definitions are largely (albeit not exclusively) kept in hiera (i.e. yaml), tracked in Git. We haven't used this for the purpose of writing epitaphs, but we could. In fact, since such changes need to go through code review, someone could theoretically author their own removal and add an epitaph of their choice in the commit message; after they leave, the change can be approved and merged in their absence.
- bigiain 3y agoHeh. Now I want to sneak in a CI automation or a pre commit hook or something - to post _my_ version of my obituary when I've left.
- jacquesm 3y ago'Reflections on trusting trust' :)
- bigiain 3y agoAhhh thanks! Of _course_ the right place to do this is hidden in the compiler. ;-)
- jacquesm 3y agoI wonder how long it would take them to figure it out. Bonus point if it is a two stage, where the compiler contains the real logic but some innocent tool looks like it is the culprit. And of course per the original you modify the compiler in such a way that an attempt to recompile it will reinstall the gimmick. And maybe redirect the distribution downloader to the point that it uses a locally cached devtools copy that ... you get the idea...
- RajT88 3y agoI do this for various reasons at my work. To function in day to day tasks you need to be able to read stuff in AD. I have solved interesting problems this way like: How do I get access to X thing when the security groups are not documented? Find someone with access and recurse their MemberOf and diff your own. I also have used it to find people leaving.
- al_borland 3y agoWe used to use Sametime and I’d periodically search for “Deleted - “, which would show me everyone who was deleted over the past few months, before they fell out of the system.
- alpb 3y agoThe “epitaph” app that was mentioned is an internal Google web site. I always found it to be fascinating.
- mickeyp 3y agoLDAP's full of secrets. It's a great way to keep tabs on what's going on in a company. And to think that you can get nearly all of it with anonymous access. Team or department mergers before they were announced? Yep, I've caught those. Secret mailing lists for internal projects? Check who's a member and you can ferret out what's going on. Bonus if the list mail address gives some of it away. `ldapsearch' is good if you know your way around LDAP. Apache LDAP Studio is a great UI tool if you just want to explore. Everyone should know enough about LDAP to build a login service that binds against it for internal apps. You can exploit the groups the sys admins maintain to control permissions in your app. It's very powerful and an easy way to get up an running in no time.
- throwawaaarrgh 3y agoI'm still flabbergasted when a company lets me index their entire AD tree as a random (or, holy crap, anonymous) user. Very nice of them, but still. It's also often the only way to get information that doesn't exist in an Intranet page, like, literally what teams are there in IT, where are their offices, who's somebody's manager, and of course, what distribution lists am I not on that some other user is on that's causing one of us to have issues accessing some internal company portal.
- mickeyp 3y agoIt has to be public (or at least not too locked down) or things like Address Book in outlook would stop working. Lots of weird things depend on the LDAP tree being broadly accessible. It's just that it leaks more information than most people think.
- xorcist 3y agoStill, it's a tool made for another era. It would be sufficient to let it return one search result at a time, or complete specified group aliases, in order to work for groupware clients. Applications mostly needs to authenticate a specific user. The ability to walk the tree is something else. Just like we don't allow zone transfers for dns anymore, there should have been similar best practice changes to ldap if people just gave it some love.
- jedberg 3y agoLayoffs in the WFH era are weird. Back in the day you had a pretty good idea of who got laid off because you saw them walking out the door with a box of their stuff. You could go up to them and say, "hey let's meet at $local_watering_hole and hang out". You could swap contact info if you didn't already have it. You could get closure. Now, one day a bunch of people just stop replying to email. You have a to wait a while to figure out if they are actually gone or just busy. And if you're waiting on them for some output to work on your project, they may just never deliver and you won't know why for a while. The company directory, if there is one, often still shows them for 60+ days because of the WARN act. And it seems most companies won't make a "layoff list". It's really hard to get closure if they won't even tell you who got let go, and if they don't give the people a chance to say goodbye by cutting off their access before telling them they are laid off.
- orangevelcro 3y agoAlso the language everyone uses to tip toe around saying people got laid off. Some employees 'were affected' or were 'part of the RIF' or whatever other acronym is currently popular.
- timeagain 3y agoIMO their slack avatar/posts go gray within minutes of them being sacked.
- Hamuko 3y agoYeah, whenever I want to find out if someone still works at the company, I just search them on Slack. If it has "(deactivated)" after their name, they're no longer employed here.
- supportengineer 3y agoThere must be a Slack API that could be used for this, and written to git periodically as the other post said.
- jedberg 3y ago
- simonw 3y agoLove this bit: "Incidentally, if someone gets mad about you running this sort of thing, you probably don't want to work there anyway. On the other hand, if you're able to build such tools without IT or similar getting "threatened" by it, then you might be somewhere that actually enjoys creating interesting and useful stuff. Treasure such places. They don't tend to last."
- Symbiote 3y agoI wonder if this counts as personal data. It's a copy of everyone's name, job title and employment dates. I can certainly see many European businesses would be wary of an employee keeping this list.
- brailsafe 3y agoIf I read it correctly, they just dumped and diffed their uid, not all of that information.
- notso411 3y ago[dead]
- Traubenfuchs 3y agoIn central Europe, we have the complete company organigram in namely, so it can't be that bad.
- athoscouto 3y agoAre you referring to GDPR? Does it apply to employees too, or only customers?
- M2Ys4U 3y agoGDPR applies to everyone in the EU/EEA/UK. They don't need to be a citizen, they don't need to have any sort of contractual arrangement with the data processor. If they're alive and identifiable, the GDPR applies.
- simonw 3y agoIf you're going to run something like this, I thoroughly recommend using Git for it. You can have your cron do something like this: curl https://internal.corp/employees.txt > employees.txt git add employees.txt git commit -m "Automated: $(date -u)" || exit 0 The || exit 0 should ensure no errors even if there is nothing to commit Now you have a commit history of every change made to that source of information - just run "git log" to view it. I run this kind of thing on scheduled GitHub Actions all the time, see https://simonwillison.net/2020/Oct/9/git-scraping/ https://simonwillison.net/2020/Oct/9/git-scraping/
- jacquesm 3y agoThat's clever, thank you! I will definitely use this.
- MarkSweep 3y agoMaybe add a ‘| sort’ in there for determinism. But yeah, git is an underrated database for this type of small scale data.
- svat 3y agoI do something similar but instead of `|| exit 0` I use `--allow-empty` on the `git commit`. I don't mind the empty commits this creates, as they let me know that there was a successful automated run that happened to be empty, rather than having failed to run for whatever reason.
- michaelcampbell 3y agoThanks for this, much more "intent revealing" than my (up to today) standard practice of `... || true` to keep my `set -e` from killing my script for this "error-but-not-really"
- GauntletWizard 3y agoI've been seriously considering using Git for all sorts of oft-changing-but-rarely-majorly data. Lists of books in my bookshelves. The other problem is that I sorta want transactional-database features on top of these things. Git does this well. I also want fast indexing on parts. Git does not do this well. I am considering writing a "standard" for the dumping of sqlite to git, so that I can just delegate this out; Any transaction can be expressed as a git commit, and I can run both at once for both the durability and the reasonable indexing; The sqlite database can be re-created and reindexed whenever, and it also sorta works for backups... Definitely just spinning my wheels, though. We'll see where databases take us next.
- loneranger_11x 3y ago"Treasure such places. They don't tend to last." True true true. Especially if people are building quirky cool stuff in smaller orgs, its simultaneously a great place to work and has a higher extinction probability.
- mmsc 3y agoI made a tool to track ldap like that [0]. LDAP is a treasure chest of info and great for stalking. for some reason i find it fascinating to see people leaving, and if possible, see how long they worked there for. seeing friends get fired via LDAP before they even knew about it was certainly interesting, too. I noted in the readme.. Know what's going on in your LDAP directory on-demand with Slack webhook integration. See new hires, leavers, and promotions as they appear in LDAP. Monitor when and what HR is doing. Detect unauthorized changes in LDAP. Monitor for accidentally leaked data. Detect when users are logging in and out of LDAP. There's also LDAPmonitor[1] which is designed for Microsoft and Active Directory which does effectively the same thing. [0]https://github.com/MegaManSec/LDAP-Monitoring-Watchdog https://github.com/MegaManSec/LDAP-Monitoring-Watchdog [1]https://github.com/p0dalirius/LDAPmonitor https://github.com/p0dalirius/LDAPmonitor
- mcqueenjordan 3y ago[flagged]
- randycupertino 3y agoI once worked at a large bureaucratic org that tried to keep it secret when people left (if quit or were fired) because they thought departures were bad for morale. So it was just a big secret. Are they here any more, are they on PTO, are they out sick, who knows! Can't talk about it. It caused way more gossip and bad morale than it would have just to be straightforward letting us know that so and so was gone.
- mkl95 3y agoThere's data and there's also the behavioral / psychological stuff which is the bigger tell in my experience. Things like delivering half assed work despite having a good track record, and not caring about problems that need to be solved in the mid term.
- brailsafe 3y agoHmm, how is this related to the article exactly? Bigger tell... of what?
- 72f988bf 3y agoScanning, dumping, and diffing of active directory also helps seeing when people got promoted. ("Software Engineer" -> "Software Engineer II" -> "Senior Software Engineer" etc). Useful for figuring out stats on "promotion velocity" in one org vs other. Wouldn't work at "a certain company" if such company now made all their levels secret by default of course.
- throwawaaarrgh 3y agoThere's a very common problem with systems that use SSO, where the 3rd parties that accept SSO logins cache the login information, sometimes indefinitely. A user can leave the company but their login placeholder account stays in the 3rd party, and active login sessions are maintained basically indefinitely. So you can leave the company and lose your AD account, but still access the 3rd party. As Rachel says it's kind of a hard problem to solve (but not that hard).
- grinich 3y agoThe answer to this is SCIM, which allows an app to sync the user state with the identity/directory system. IT admins call this "User Lifecycle Management" and it's typically a required feature for enterprise-scale customers. (I work at WorkOS and we help developers with this: https://workos.com/directory-sync https://workos.com/directory-sync)
- fbdab103 3y agoIn most cases wouldn't that session info be tied to physical hardware to which the employee no longer has access? Sure, tick all of your boxes, but I would think that losing the company laptop/phone/VPN would be a pretty significant barrier to maintaining access to other systems.
- n_plus_1_acc 3y agoNot with BYOD
- fbdab103 3y agoI refuse to BYOD, so I am not familiar with the nuances, but wouldn't the corporate controlling entity wipe/reset/deauthenticate the corporate partition of the device?
- n_plus_1_acc 3y agoThat entirely depends on how it's implemented. At least Windows, Android and iOS have the functionality to delete Work accounts / profiles. But I've also seen companies with no MDM at all, so YMMV.
- mfkp 3y agoHa, I did this about 10-15 years ago at a prior company. The turnover was so high (especially in the sales staff) that there would be at least a handful of people mysteriously disappearing each week. I automated a small newsletter called "The Weekly Diff" for a few close trusted coworkers and sent it out each Friday with a list of who's new and who was missing from the company directory. And I kept a scraped database including phone numbers in case anyone wanted to reach out to anyone after they'd been removed. Sometimes you make the best out of a failing company culture. Kept a lot of friends that way just by reaching out with some words of support :)
- lulznews 3y agoHacking is fun but how is this useful?
- brailsafe 3y agoA modicum of increased transparency/visibility.
- ElectricalUnion 3y agoBeing able to bind and query useful/interesting information on LDAP is always useful.
- Unfrozen0688 3y agoNot a WFH thing. This is a USA thing!! Edit: OP said "Layoffs in the WFH era are weird" Yes they are, but people here don't suddenly go offline quite as weird is what I was trying to get at. Here in Sweden if you are FTE there is usually a 1-3 month layoff period (upppsägningstid) where you work and get paid still. At the end of the period you leave. People usually email the team and even the entire company with "hey im leaving here is my info" Now people CAN get fired day of, but that has to be VERY grounded. Again, Not a WFH thing. This is a USA thing!! I notice this time and time again where people complain about IT or WFH, but it's just that you're in the USA, land of the exploited.
- lmz 3y agoBut if the company is worried about access can't it just pay the employee the 1-3 months without allowing them to work, even in Sweden?
- Unfrozen0688 3y agoI am unsure actually as I am not an employer. I am sure it is possible but probably for sensitive jobs like military or something. Some links if you want to google translate https://www.unionen.se/rad-och-stod/uppsagningstider-om-din-arbetsgivare-sager-upp-dig https://www.unionen.se/rad-och-stod/uppsagningstider-om-din-... There is "duty of loyalty" where you can get sued for leaks etc https://www.unionen.se/rad-och-stod/om-lojalitetsplikt-och-lagen-om-foretagshemligheter https://www.unionen.se/rad-och-stod/om-lojalitetsplikt-och-l...
- emj 3y agoOf course we fire people in Sweden pay them and revoke their access, this is very uncommon I have only seen it once myself. Would like to note that, simply speaking, the rules change the more responsibility you have.
- permalac 3y agoI work with identities. I've worked in Spain, France and uk. 99% of lay off are agreed and there is no need for account termination, my current company let's you have your account open 30 days after your last day, so you can move data out to your next company.
- doix 3y agoIt's amazing how many people came to the same idea independently. At my old gig I created "the sackinator" (getting sacked = getting fired). It was a cronjob that dumped the entire AD directory nightly and then a script to diff the output of any two days. Since the data was dumped, you could always go back and do more analysis. First I just cared about which accounts got deactivated. Then I started tracking title changes, last name changes (people getting married), department sizes, company head count over time etc. > Incidentally, if someone gets mad about you running this sort of thing, you probably don't want to work there anyway. On the other hand, if you're able to build such tools without IT or similar getting "threatened" by it, then you might be somewhere that actually enjoys creating interesting and useful stuff. Treasure such places. They don't tend to last. Couldn't agree more.
- eddiezane 3y agoBack when I was at DigitalOcean they were laying off/firing people from the company but not announcing any departures. You'd just go to message someone and their Slack account was deactivated. This was over the course of several weeks. I built a Slack bot to post when accounts got deactivated and learned of some new departures well before those impacted actually did. https://github.com/eddiezane/no-ghosties https://github.com/eddiezane/no-ghosties
- popcalc 3y agoIt seems DO uses the same methodology for their customer support.
- biosboiii 3y agoDid this for a supermarket delivery company, they had an API that exposed their exact stock level for products, scraped the data every 30ish seconds, diffed and repeated :D There were some interesting orders for sure (cigarettes + soap + 1 beer)
- evmar 3y agoI made epitaphs! AMA
- kajecounterhack 3y agoThanks for making epitaphs <3
- JoachimSchipper 3y agoWhy did you make epithaps? Any interesting organizational or technical challenges you encountered on the way?
- evmar 3y agoInitially it was a combination of just for the fun of it (it's a small script, as OP described). Secondarily there was the feeling of "everyone is going to go work at [major competitor]" and I was curious whether I could collect the data to show it. (I never ended up looking into this, but maybe HR did.) As a dumb script it was not designed to be especially flexible. One thing I remember needing to fix was that by its nature it was archiving old data and preserving it, which meant that it was accidentally deadnaming trans people. My recollection is this was a small code fix, but an interesting lesson in social consequences of oblivious software.
- hyperliner 3y ago[dead]
- bsimpson 3y agoI don't know what to ask you in a public forum, but it's nice to see your name pop up!
- umbauk 3y agoIs it still going? Were you ever made change it by HR? I left 5 years ago. Loved that thing!
- brunooliv 3y agoI find this super weird and almost borderline invasion of privacy? I mean, a job is your professional life and you’re there to work, not go directly make friends or stalk people… I mean sure I’ve made a few people whom I’d call friends in previous jobs and current one too and I’d like to believe that we’d have enough confidence in the friendship to tell each other about quitting. But seeing that potential info about anyone feels very weird…
- heads 3y agoSo negative! Where I work this tool is called “new-hires”. It uses a restricted read-only API key to our third-party people tool. It was given to me by our People Director. Sometimes there are lines beginning with - but the tool is named for the lines beginning with +. new-hires is built on top of the “people” python module / cli in our monorepo. That tool is so much more useful than just a way of diffing the org chart. Who is in what team, where are they, are they working today, is it time to celebrate their anniversary, etc. It also follows what I coin the “ZFS litmus test” for good CLI tools by providing -pH for parseable, headerless output. Treasure such places indeed.
- elromulous 3y agoWhere is this? Sounds like a great place!
- heads 3y agoSpeechmatics.com in London and Cambridge, UK. We build audio and language models that perform the most accurate speech recognition available. https://www.speechmatics.com/company/careers/roles https://www.speechmatics.com/company/careers/roles
- sevagh 3y agoYour site looks great. Clean description of the draw of your product!
- shermantanktop 3y agoI’ve done this multiple times, and have two instances running right now which have been active for years. One is simple and watches a smaller org: ldapsearch … > new; diff old new > updates; mail … < updates (On phone, pseudo code, definitely wrong) The other is perhaps more interesting. I built a tool for a tool for a population of specialists in a large company. The tool requires ldap data synced in, and I capture the diffs. That sampling approach provides surprising insights into what’s active/hot/declining, even when the total size of the company would making tracking every employee change quite difficult.
- rpigab 3y agoThis is a very fun thing to do, unfortunately where I work (France), the HR team send out weekly/monthly emails with somes HR updates, and at the end the list of everyone who is hired (this includes conctractors), and everyone who leaves (resigned or fired), so it would not add any information to run LDAP searches and dumps/diffs. It's always kinda stressful to open this email and find out if one colleague you liked has decided to leave, but most times, this colleague informed you before the email arrives.
- thrdbndndn 3y ago> uid (unix account name) Is this a joke or for real?
- enasterosophes 3y agoWhy wouldn't it be for real? Given the context of the post, the uid info is likely populated from a central source. I log into one box anywhere in their infrastructure and see who has what uids, it is evidence about who is permitted to that part of the infrastructure at that time.
- deleted 3y ago[deleted]
- thrdbndndn 3y agoSorry, for some reason, I thought the author meant UID stands for "unix account name". It's totally my fault for misunderstanding.
- saagarjha 3y agoRachel doesn't joke much in her posts.
- Denvercoder9 3y agoMost likely real. In LDAP, the "uid" attribute is commonly used to store the Unix account name. The numeric Unix uid/gid are stored in the "uidNumber"/"gidNumber" attributes.
- KingOfCoders 3y agoIn Germany it's also a very good idea to monitor the "Handelsregister" (register of all companies) and see who currently is really the CEO, who can sign things etc. This shows early ripples in the force (e.g. founders on their way out, willfully or forced).
- Havoc 3y agoDon’t think my employer would take too kindly to attempts to download bulk employee lists
- Banditoz 3y agoCan they monitor for such a thing? Does say, Azure AD show whenever someone downloads data? Does Outlook make a similar call to figure out the name dropdowns?
- Havoc 3y agoPerhaps for small orgs. We’ve got thousands upon thousands of people so little chance of grabbing the entire AD or leveraging some outlook dropdown. Is be surprised if any competently run large org allows that anyway. Just takes one rogue dude trying to make a quick buck by selling the info to spammers and you’re dealing with that for the next decade
- Foobar8568 3y agoWith Excel and Power Query, you have your own analysis tool...There is a direct connector to dump the full LDAP.
- MichaelMoser123 3y agoI wrote a script that is looking at the git log of a git repository, it tries to sum up how many commits per author/number of lines changed etc, when the author was active. This also gives some indication on the 'turnover rate' or whatever. (I know lines changed and number of commits is a very bad indication, but it is some indication) https://github.com/MoserMichael/gittools/blob/main/git-whoiswho.py https://github.com/MoserMichael/gittools/blob/main/git-whois...
- ben_w 3y ago> if you're able to build such tools without IT or similar getting "threatened" by it, then you might be somewhere that actually enjoys creating interesting and useful stuff. Treasure such places. They don't tend to last. Advice I wish I'd been given before graduating, second only to "get everything in writing".
- unobatbayar 3y agoDo you guys feel sad when your colleague leaves the company?
- romanovcode 3y agoI feel sad if this means I have more work and responsibilities for same amount of pay. Otherwise - no.
- suddenclarity 3y agoYou'd have to define "sad" but naturally there's a sense of emptiness immediately after a friend disappears from your life. Someone you've learned to know and share jokes and interests with. Not every colleague is a friend though.
- mlrtime 3y agoDepends, but not really. It's like saying sorry for someone getting divorced.... in all likely hood you should be happy for them and congratulating them on ending a toxic relationship.
- codeulike 3y agoNote that in Europe or UK downloading bulk employee lists would likely mean you are now handling 'personal data' and so various GDPR rules kick in
- hardware2win 3y agoIrc, cron, ldap, spying on other employees stuff Yea, admins.
- deleted 3y ago[deleted]
- Linda231 3y ago[flagged]
- fredley 3y agoI'm a WFH worker. My company is fully remote. They are really great at managing departures and make sure everyone's aware and has a chance to say goodbye. However I can't shake this feeling that the mindset that got us from treating servers like pets to treating them like cattle is creeping into workforce planning, and the WFH movement is making it that much easier. Why plan capacity when you can scale resources up and down on-demand on a whim? With the emotional and morale implications of letting people go hugely reduced it becomes easier to think like that.
- deleted 3y ago[deleted]
- wwilim 3y agoUnix hacker approach to corporate drama, I like it.
- cyclops1982 3y agoFor those wondering, by default, any user with an AAD account can query /all/ users via the MS graph API. The trick showed in the article can easily be done on AAD as well.
- gpvos 3y agoIs it common in the USA that employees just disappear without getting the chance to say goodbye to their colleagues? At most places I worked, people tended to send a goodbye email to everyone@company and got a chance to say personal goodbyes, even when there was a negative reason for them to leave.
- glimshe 3y agoIt isn't the usual way for an employee to depart a company. It is common in layoff situations, though. Note: don't ever depart with public criticism, you have little to gain and potentially a lot to lose with the burned bridges.
- dudul 3y agoYes it is common when the employee is being terminated. It may depend on the industry, but it's always been like that at the 10+ companies I worked at. Honestly, I much prefer it to the long notice (sometimes 3 months!) you get in say some European countries. Just rip the band aid and move on. Most likely you'll have a way to connect with former coworkers easily on LI and such.
- dghughes 3y agoAdam Savage's recent video said large companies don't like to lay off big blocks of employees so they just do it in small batches over the year. They fire the last person who made any mistake. https://youtu.be/CzjftlUQs4g?t=403 https://youtu.be/CzjftlUQs4g?t=403
- brlewis 3y agoThat doesn't fit my experience. Google's stock price increased after a large block of layoffs. And they were making every effort to put as many as possible in a single block. For example, my department was "impacted by the layoffs" but given 9 months to keep working and possibly transfer out. If they didn't want to announce a large number at once they easily could have waited.
- lapcat 3y agoFun fact: back when I was a contractor for Apple many years ago (while Steve Jobs was CEO), I learned through their directory service that Steve Wozniack was still an employee and reported to then-CFO Peter Oppenheimer.
- xmodem 3y agoAt one role our GitHub access was mediated by a CI job that would export users and groups from Google Workspaces and apply them to GitHub. The script would helpfully print a list of actions taken, and we had a general policy of CI logs being world-readable - and this job was no exception. It was a useful way to keep tabs on any skulduggery that was going on. Unrelated, but Confluence has very powerful support for email alerts on changes. These include notifications of deletions, and the email includes the diff of the deleted content. One thing I do at any org that uses confluence heavily is set up notification rules on some interesting spaces and check in from time to time.
- ezekiel68 3y agoThe last two sentences of the article were worth the whole read.
- pharmakom 3y agoI once discovered that a very large org had AD configured in such a way that you could see “last seen at” timestamp for everyone profile in the company. It would have been trivial to track everyone’s hours using this, which would likely have been unpopular.
- jjkaczor 3y agoHahahahaha... So, I um have a very similar script that I manage for 'KTMJ' - it's not to find deactivated users, but to synchronize certain ldap attributes to another system. This organization is large enough (300k+ users) that typically, between the time that the script queries ldap, prepares the synchronization file, then actually performs the synchronization import which validates if each user still exists, there are already several hundred accounts that have been deactivated during that window and reported in an 'error' log file. (The actual synchronization and 'error' log file are outside of my direct control) Why did I laugh maniacally? Due to 'budget constraints' my contract is being terminated (they have just been through several rounds of layoffs, I was expecting this), my account will be one of the ones deactivated on the next monthly cycle - prior to that, I will have to handover the processing and expected 'deactivated' users 'error' logging behaviour to my replacements...
- tonnydourado 3y agoI'm not sure I get this. If it's in my team/department, I'll know about it one way or another. If not ... Why would I care? People come and go, and if we're friends outside of work, we'll have other channels. Besides that, most companies I worked at don't even maintain the LDAP/whatever properly. I've seen contacts from people that left/were fired stay around for years.
- OJFord 3y agoOn an individual level: maybe you don't work closely but know the name, might be interested to know ahead of suddenly realising you haven't seen/heard from them for weeks/months; or maybe you used to but they moved to a different group, you're not in touch but vaguely interested if they've left. On a more macro level: you might be interested in an apparent layoff/significant restructuring. Someone used to (/maybe does) run this as an email service ('orgdiff') at Arm. I wouldn't have gone out of my way to do it myself, but it was something to skim with a Monday morning coffee.
- baud147258 3y ago> If not ... Why would I care? What if they're someone you're working with on and off. Or if you're waiting on some tasks from them?
- irrational 3y agoMy company has 80,000+ employees. I have a feeling I'd be inundated with the churn.
- khalilravanna 3y agoThere was an automated tool like this someone built at Twitter. At first it was cool just to see who the most tenured people were. Then the layoffs happened and it became essential due to the absolute 0 communication happening thanks to the Cool New Management. I remember we used the count of people in one of the default Slack channels to keep track of how many people got the axe. Woof.
- omgbear 3y agoA former company I was at was really weirdly tight-lipped about people leaving. I'm sure totally unrelatedly, we got dinged a bunch on our SOC2 reports improper "off-boarding" and not removing access from terminated folks since no one knew to remove them. Once we added quarterly SOC2 controls to make sure only employees had accounts it was always a shock to see who had to be removed. I know the intent was to improve morale, but it had the opposite effect.
- azemetre 3y agoThat definitely sounds bad. I wonder what sort of justification they had to not tell people who left? Not having closure is one of the most common grievances people have about relationships, friends, lovers, siblings, or colleagues that disappear. It seems purposely malicious.
- omgbear 3y agoAgreed the lack of closure was frustrating. Stemming the tide maybe? Don't want people to leave when they see a respected or well tenured person leave / get laid off? All happened after an acquisition, so I'm not sure if this was business as usual for the other company or in response to increased attrition. We ended up with an alumni slack like others here have mentioned.
- starkparker 3y agoI've had companies use privacy concerns as an excuse, which was hilarious. They couldn't tell us who left because they wanted to respect the laid-off people's privacy so the entire company spent the day compiling a list of all the deactivated Slack accounts. Great job!
- krsrhe 3y ago[dead]
- GIVEDADDYABYTE 3y agoI tried to make one of these systems at my first job, but my manager expressly forbade me after hearing about it. Later that company would go on to lay off 15% of software engineers in a day. The support team created tickets in the public issue tracker to decommission employee accounts, so a lot of people found out that way before anyone reached out for a meeting.
- marviel 3y ago> Incidentally, if someone gets mad about you running this sort of thing, you probably don't want to work there anyway. On the other hand, if you're able to build such tools without IT or similar getting "threatened" by it, then you might be somewhere that actually enjoys creating interesting and useful stuff. Treasure such places. They don't tend to last. too true
- drtz 3y agoI've been using POSIX systems regularly for 25 years. Why have I never seen the comm command used before?
- Lance_ET_Compte 3y agoI did this before. I ran a cron job once a day that counted the number of active entries in a particular file. It was neat to see the number bump up after an acquisition or drop after a layoff. It was neat to see the overall growth of the company I worked for. I eventually decided that someone _might_ decide that, although freely available, in aggregate, this material could be _sensitive_. I stopped doing it. I deleted years of interesting data...
- SoftTalker 3y ago> Incidentally, if someone gets mad about you running this sort of thing, you probably don't want to work there anyway. Well that depends I guess. A lot of companies/orgs have privacy policies that prohibit accessing services out of "curiosity." I.e. if you're working at a university it's OK to access student information if you're doing it for a specific work-authorized purpose but you can't go casually looking at people's information just to satisfy some personal interest.
- adrianmonk 3y agoI built this by accident once! We had this internal web application. It had its own separate username/password table. I was asked to make it so you could login with your regular password instead. It wasn't hard to solve the password part. I could make the web app consult the main system to verify your password at login. But... I couldn't eliminate the web app's user table entirely. It was too fundamental. So I built a thing that ran periodically, got a list of users from both places, diffed the lists, and then did the required create/update/delete operations on the web app's user table. Thus the web app's user table mirrored the main login system. I rolled this thing out and babysat it, keeping an eye on its log file. Naturally my code logged operations done on the user table. And I was like, "Hey, this is telling me who is joining and leaving the company!" It even gave me a little additional info. The web app had certain roles and permissions, and these needed to correspond to organizational structure, which I got from the main login system. So if a user's web app roles changed, it was a clue they may have switched teams or got promoted. I felt like I needed to be a bit careful with this info. Not that I wasn't allowed to have it, but I don't think IT expected anyone to have a tool that would make it that easy to notice changes as they happen. Potentially, I could have known someone was fired before their manager told them or something like that. TLDR: Tried to streamline operations, accidentally developed a signals intelligence capability.
- sciencesama 3y agoIs there a script to check the users from the windows graph !!??
- tandle 3y agoSpeaking from the other side (the side that does the termination), as long as your IT team is actually good a simple ldap diff isn't going to be enough. Why? Because a good termination process is sensitive to there needing to be a communication about a termination that can happen well after the actual process of eliminating their access and telling them it's their last day. So a better termination process is something like: 1. Employee goes to a physical space (preferred) where they don't have their work equipment or talk to their manager and/or HR using something that isn't work controlled (phone call, etc.). 2. A manual or scripted process executes that forces sign outs of all work things (computer, slack, google, whatever). Credentials get reset and not disabled. Perhaps someone can try to look for password reset metadata or other things that might indicate a departure, but it's a lot harder than looking for disabled uids. 3. After the person leaves or has finished their conversation remotely, the team that works with this person gets a broader communication from someone to tell them about the departure. If the company is small enough, maybe there's a broader communication to more people. 4. The rest of the termination process gets fired off that does disable accounts, etc. Why don't all IT departments do this? Well for a lot of reasons: 1. They don't care, don't have incentives, or haven't been told by HR, etc. to care about handling the termination process in a more sensitive way. 2. For any sufficiently complex company, the number of edges cases of systems where you can't force a logout or handle a password reset increase over time. It takes a lot of testing to make sure a process works because vendors have bugs all the time or unintended behavior. 3. The risk of poorly communicated terminations increase as the number of people that either perform or can troubleshoot the automated process to terminate increase. As others commented, you don't want some ticketing system that is readable by a wide amount of people to see termination requests, so now how do you communicate a termination without too many people knowing about it? Strangely enough, I think trying to achieve the most sensitive but automated process is good because it forces the company to communicate and acknowledge a departure before the full termination process fires off, but maybe I'm in the minority.
- kylestlb 3y agodoesn't every HRIS have this? workday, et al... all have some sort of "Leave Reason" field which can be reported on & aggregated
- 0x500x79 3y agoI worked at a company that had an internal website that showed all people, departments, teams, and had a filter you could use for new employees or employees that left. It was sort of a double edged sword: you had enough information to start asking questions about what it meant if a team member or coworker was on the list. What was more interesting is that it almost became ritual for some people to logon first thing in the morning and check the list, every morning.
- joshstrange 3y agoAt my last company they had no system for letting us know if someone had been let go. At one point they laid off the VP of sales and it came up almost by accident in an all-company meeting (not a massive company, <100 but >50) and people were surprised he had been let go. I was young, with nothing to lose (or rather just no self-preservation), and so I spoke up that the policy of saying nothing was silly and potentially very dangerous. If that VP, who I saw around regularly, had emailed me for a list of our clients I would have sent it to him, if he had been waiting at a door telling me he had forgot his keycard I would have let him in, etc. You could argue "You should have always asked up the chain before doing that or refused to let him in on your keycard", but then I'd just shake my head at you. When a VP tells you to do something it's not a great career move to throw up roadblocks, even if it's company policy, in my experience. Going forward the company agreed to send out bland, generic "X is no longer with the company" for "legal" reasons (as in they couldn't say "was fired", "left of their own accord", etc). Which was better for sure. I never thought to scrape our company directory, that's a clever way to do that for sure.
- nickm12 3y agoThis is funny... I thought I was the only one who did this. I work in an org of over 1000 people and have found doing a programmatic dump of the org chart gives me insights I would never get from reading our status update. Often it is the only way I learn about colleagues who have left (and returned!) because not everyone sends goodbye messages or even has the opportunity to.
- tonymet 3y agoJust be aware that your company will be logging this behavior and it will seem suspicious. They can make a good case for termination with this evidence.
- phendrenad2 3y agoI postulate that if your company uses LDAP, and you are here on HN, you're going to be laid off within the next 12 months. The existence of LDAP at a company implies that the company is likely highly um "mature" and isn't amenable to the kinds of hackers who have actual interest in the programming field.
- chrsw 3y agoThe power of turning information into data that can be processed by relatively simple Unix commands and pipelines is still mind blowing to me.
- jwalton 3y agoI was at a large company during the dot com bust. Someone added a world readable field (I assume by accident or because they didn’t realize we could all read it) to our LDAP called “Departure date”, which let you look up who was going to be laid off in the next few weeks. :/
- adityapurwa 3y agoWhen I was working on a small sized startup. We used to write “obituaries” for people who resigned in a newspaper format. We would add some insider jokes as a side article and some parody ads about their new company on the page if the person resigned already found a new company. IIRC, it started from my resignation. Then we kept doing it for future leavers
- tuananh 3y agoI made sth similar to monitor my github followers list. it's a simple script to use github api to get followers list & diff each day. https://github.com/tuananh/github-followers-watch/ https://github.com/tuananh/github-followers-watch/
- williamDafoe 3y agoEpitaths is a Google thing. I had a friend at Qualcomm who wrote a script to sample the employee phonebook every morning before work so he'd know if he were laid off. We used "ph" from UIUC and the company strangely laid people off not by deleting them but instead by putting them into department 700, "The laid-off department". The web UI allowed elaborate queries so the first time there was a big layoff the ph web page almost went down because everyone was querying to find out who was laid off. Management got mad at this but they really shouldn't have; its correct that you shouldn't work someplace that tries to hide attrition no matter what the source! My friend never got put into dept 700 because i recruited him into Google a few years later ...