User Status Management APIs: empowering secure, automated access control for modern businesses
31 August 2026
Managing user access is a critical challenge for businesses that rely on digital platforms to drive operations. When employees join, leave, or take extended leave, keeping permissions up to date is essential for security and compliance. The User Status Management APIs, part of the User Management suite for J.P. Morgan Access®, empower security administrators to automate and simplify these tasks, helping ensure that user access aligns with organizational needs in real-time, subject to applicable laws, regulations, and internal policies.
Strategic value of user status management in business operations
User Status Management APIs are designed to help businesses maintain precise control over user permissions across portal applications. By integrating these APIs, organizations can automate the process of activating, deactivating, or deleting user access, reducing manual intervention and minimizing the risk of unauthorized access. The APIs play a strategic role in modern business operations, supporting compliance, operational efficiency, and a more seamless user experiences.
How the user status management APIs work
The User Status Management APIs operate by interfacing with the Payments API, enabling integration with client ERP systems. This allows for near real-time updates to user profiles, so changes in user status are reflected near instantly across connected systems. The suite offers several key capabilities:
- Get users by user ID: Retrieve profile details for a specific user on your client profile.
- Search users: Access a comprehensive list of all users, including their statuses and associated applications, for detailed reporting and management.
- Modify user status: Adjust user access status, such as activation or deactivation, to maintain precise control over permissions.
- Deactivate user: Set a user's status to inactive during temporary absences, such as maternity or extended leave.
- Activate user: Restore access when employees return to work.
- Delete user: Remove user profiles when employees leave the company.
- ERP integration: Automate access control processes by integrating user management functionalities into client ERP systems.
The APIs use protected endpoints and require mTLS or OAuth 2.0 authentication, helping ensure that only authorized personnel can make changes to user profiles.
Use Case: Automated user access management via ERP integration
Scenario
A retailer manages a large workforce across multiple locations, with employees regularly going on extended leave, returning to work, and occasionally leaving the company. Rather than relying on Security Administrators to manually update access, the retailer integrates their HR system with the User Status Management API to trigger access changes automatically based on HR events.
Flow
When an employee's extended leave is approved in the HR system, it generates a leave start event. The ERP integration listens for this event and automatically calls POST /users/actions to deactivate the employee's access on the leave start date, no admin intervention required.
When the employee's return date is reached, the HR system generates a return-to-work event. The integration responds by calling POST /users/actions again to reactivate the employee's access, ready for their first day back.
When an employee is marked as terminated in the HR system, an offboarding event is triggered. The integration calls POST /users/actions to permanently delete the user's profile, ensuring access is removed promptly and consistently.
Outcome
Because HR system events automatically trigger status updates, access changes occur at the right time without manual intervention. The retailer reduces the risk of delayed deactivations and reactivations, maintains a consistent offboarding process, and allows Security Administrators to focus on higher-value work. Clients remain responsible for reviewing and maintaining their own access control polices and procedures.
Explore further
Next Steps:
Explore the User Status Management API documentation for detailed integration guides, sample requests, and best practices. If you have questions or want to discuss your specific use case, contact us.
J.P. Morgan does not provide legal, tax, or accounting advice. Clients should consult their own advisors regarding the suitability and compliance of the User Status Management APIs for their specific circumstances.