I assume you can check Vault's audit logs and see if the user was created there or not.
But based on what you've just asked, I'd definitely never create anything like what you're working with because it sounds like ANY addition to your infrastructure is problematic.