Skip to main content
Blog
Annmarie BollerVice President
SHARE
    product

    User Status Management APIs: empowering secure, automated access control for modern businesses

    31 August 2026

    Managing user access is a critical challenge for businesses that rely on digital platforms to drive operations. When employees join, leave, or take extended leave, keeping permissions up to date is essential for security and compliance. The User Status Management APIs, part of the User Management suite for J.P. Morgan Access®, empower security administrators to automate and simplify these tasks, helping ensure that user access aligns with organizational needs in real-time, subject to applicable laws, regulations, and internal policies.

    Strategic value of user status management in business operations

    User Status Management APIs are designed to help businesses maintain precise control over user permissions across portal applications. By integrating these APIs, organizations can automate the process of activating, deactivating, or deleting user access, reducing manual intervention and minimizing the risk of unauthorized access. The APIs play a strategic role in modern business operations, supporting compliance, operational efficiency, and a more seamless user experiences.

    How the user status management APIs work  
    The User Status Management APIs operate by interfacing with the Payments API, enabling integration with client ERP systems. This allows for near real-time updates to user profiles, so changes in user status are reflected near instantly across connected systems. The suite offers several key capabilities:

    • Get users by user ID: Retrieve profile details for a specific user on your client profile.
    • Search users: Access a comprehensive list of all users, including their statuses and associated applications, for detailed reporting and management.
    • Modify user status: Adjust user access status, such as activation or deactivation, to maintain precise control over permissions.
    • Deactivate user: Set a user's status to inactive during temporary absences, such as maternity or extended leave.
    • Activate user: Restore access when employees return to work.
    • Delete user: Remove user profiles when employees leave the company.
    • ERP integration: Automate access control processes by integrating user management functionalities into client ERP systems.

    The APIs use protected endpoints and require mTLS or OAuth 2.0 authentication, helping ensure that only authorized personnel can make changes to user profiles.

    Use Case: Automated user access management via ERP integration

    Scenario

    A retailer manages a large workforce across multiple locations, with employees regularly going on extended leave, returning to work, and occasionally leaving the company. Rather than relying on Security Administrators to manually update access, the retailer integrates their HR system with the User Status Management API to trigger access changes automatically based on HR events.

    Flow

    When an employee's extended leave is approved in the HR system, it generates a leave start event. The ERP integration listens for this event and automatically calls POST /users/actions to deactivate the employee's access on the leave start date, no admin intervention required.

    When the employee's return date is reached, the HR system generates a return-to-work event. The integration responds by calling POST /users/actions again to reactivate the employee's access, ready for their first day back.

    When an employee is marked as terminated in the HR system, an offboarding event is triggered. The integration calls POST /users/actions to permanently delete the user's profile, ensuring access is removed promptly and consistently.

    Outcome

    Because HR system events automatically trigger status updates, access changes occur at the right time without manual intervention. The retailer reduces the risk of delayed deactivations and reactivations, maintains a consistent offboarding process, and allows Security Administrators to focus on higher-value work. Clients remain responsible for reviewing and maintaining their own access control polices and procedures. 

    Explore further

    Next Steps: 
    Explore the User Status Management API documentation for detailed integration guides, sample requests, and best practices. If you have questions or want to discuss your specific use case, contact us.

    J.P. Morgan does not provide legal, tax, or accounting advice. Clients should consult their own advisors regarding the suitability and compliance of the User Status Management APIs for their specific circumstances.

    Disclaimer

    © 2026 JPMorgan Chase & Co. All rights reserved. JPMorgan Chase Bank, N.A. Member FDIC. Deposits held in non-U.S. branches are not FDIC insured. Non-deposit products are not FDIC insured. The statements herein are confidential and proprietary and not intended to be legally binding. Not all products and services are available in all geographical areas. Visit jpmorgan.com/paymentsdisclosure for further disclosures and disclaimers related to this content.

    Updated: 2 September 2026