Monthly Docker Hub access review against your HR roster

By General Input

On the first working day of each month, compare who can reach your Docker Hub organization with your active staff list and post the gaps to Slack.

Integrations

  • Docker Hub
  • BambooHR
  • Slack Bot

Type

Agentic Task

Categories

  • Engineering
  • Operations

On a cron schedule, on the first weekday of each month at 9am, run an access review of my Docker Hub organization and post the findings to Slack. This is a report only review: never remove a member, never cancel an invite, and never change anyone's role. Revoking registry access is a decision a human should confirm.

Start by building the current Docker Hub roster. Use List Organization Members to get everyone in the organization along with their role and their email where one is available. Use List Organization Groups to get the organization's groups (teams), then use List Group Members for each group so you know which teams each person sits in. Use List Organization Invites to get invitations that have been sent but not yet accepted, including when each one was sent.

Then pull the active employee roster from BambooHR using Get Employee Directory. Treat the employees the directory reports as active as the source of truth for who currently works here.

Reconcile the two lists to find people who still hold registry access but are no longer active employees. Match on work email first, since that is the reliable signal. If a Docker Hub account has no email attached, or its email does not appear anywhere in the directory, fall back to matching on full name. Docker Hub IDs are frequently personal handles that will not resemble an HR record, so do not guess. If you cannot confidently match an account to a person in the directory, report it under "needs a human look" rather than concluding that the person has left. The same applies to accounts that match more than one employee, or that look like bots, CI runners, or shared build accounts.

Post one summary using Slack Bot Send a Message to the channel I specify, grouped by severity in this order: departed employees who still have access; accounts you could not confidently match; invites that have been sitting unaccepted for more than 30 days; and members holding owner or admin roles. For each person include their Docker Hub ID, their email if known, their role, and the teams they belong to, followed by a short plain English recommendation such as remove from the organization, confirm with their manager first, cancel the stale invite, or no action needed. If a section has nothing in it, say so in a single line rather than dropping the section, so the reader can see the check actually ran.

Optionally add a short closing section that lists the organization's access tokens using List Organization Access Tokens, flagging long lived or apparently unused ones as part of the same monthly hygiene pass. Do not describe this as covering every member's personal access tokens: personal tokens are only visible for the connected account, not across the organization.

Two scope notes to respect. There is no way to read which repositories each team is allowed to access, so do not claim to audit per repository permissions; team context should come only from the organization's group list and each group's members. Also note that member, group, and invite data requires a Docker Hub organization rather than a personal Docker account.

Related prompts

Explore more prompts
A brand asset library your marketing team actually searchesTurn Mailjet email clicks into ranked HubSpot follow-upsClean out the Looker dashboards and Looks nobody opensLiveKit live operations console for room moderationWake up dormant Keap leads with a researched reasonLiveChat coverage board for planning next week's shiftsPhone routing control panel for LiveKit voice agentsLinkedIn Ads budget pacing dashboard for every client accountGive your team Looker numbers without buying more seatsPause marketing emails to escalated customers, then restore them