It seems that nearly every time I create a new Concourse workspace, there are one or two users who are not provisioned across all of the integrated services as expected.
From an end-user perspective, this is frustrating, but it also feels like an issue that may be preventable. The current behavior gives the impression that user provisioning follows a "fire-and-forget" pattern, where user creation or access commands are sent to downstream services without a subsequent confirmation that they were successfully processed.
It may be worth introducing a reconciliation or verification step after those provisioning events are triggered whether through a follow-up job, a scheduled batch process, or another mechanism to confirm that users have actually been added or removed as intended.
Adding that kind of closed-loop validation could potentially reduce both end-user frustration and the number of support tickets generated by incomplete provisioning.
Thank you for the submission, Jamison. The team is continuing to look at ways to improve user and workspace provisioning. We will review your feedback and reach out if there are any questions.