Help prepare an access-management plan for one person. At this stage, do not perform anything or send any requests. Event: [joining / role change / departure]. Person: [test identifier]. Change time: [date, time, time zone]. Input data: [approved role profile, tool catalogue, current accounts, permissions, and equipment, and the date they were checked]. Compare the current state with the target state. Indicate: keep, add, remove, hand over, or needs clarification. Do not invent missing permissions or account matches. For every item, state: - the person and the relevant system, organisation, project, or device; - the exact action and its justification; - who approves, who performs it, and by when; - whether an available integration or an administrator can perform it; - how we will check the outcome and where we will record confirmation. Separate access removal from account deletion and data preservation. Include documents, automations, and technical accounts to check. List every gap, ambiguity, and unchecked system. Clearly distinguish proposed results from completed and confirmed ones.