Skip to Main Content
IBM - Cloud, PowerVS and Ceph aaS - Structured Ideas

This portal is to open public enhancement requests. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.

Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

Status Under review
Workspace * IBM Cloud Ideas
Created by Guest
Created on Sep 8, 2025

Automation of User and Service Account Removal in Continuous Delivery

I would like to propose a significant operational improvement for IBM Cloud Continuous Delivery: automating the process of removing identities, including both users and service accounts associated with GitLab.

Currently, this process is manual and prone to errors, resulting in unintended reactivation of accounts that should have been permanently removed. Besides operational and governance costs, these errors directly impact billing, as the service is charged based on the number of authorized users per instance per month.

Automation would bring consistency, security, efficiency, and cost optimization—preventing unnecessary charges for users who should no longer have access.

Problem Statement

We face recurring cases where users removed from Continuous Delivery are automatically re-added. Joint analysis with IBM Cloud support and TAM revealed this issue is caused by incomplete removal, which must simultaneously address three areas:

  • Remove the user from IAM across all toolchains in the resource group.

  • Remove the user from the Authorized Users list in the Continuous Delivery service instance.

  • Revoke Developer access in all linked Git Repos (Git Repos and Issue Tracking) associated with the toolchains

The current manual process is error-prone and susceptible to inconsistencies, rework, and, importantly, billing inaccuracies—as each reactivated user remains counted in the monthly authorized users metric

Proposed Solution

Create an automated workflow (via Console, CLI, API, or toolchain) that:

01) Upon removal of the user from the Continuous Delivery IAM Group, automatically performs:

  • IAM revocation across all toolchains.

  • Removal from the Authorized Users list in the Continuous Delivery instance.

  • Access revocation in linked Git repositories.

02) Sends an alert if any step cannot be completed automatically.


This automation ensures complete, secure user removal and avoids unnecessary charges—while significantly enhancing governance and operational efficiency.


Idea priority Urgent
Needed By Yesterday (Let's go already!)