Back to User Provisioning & Access Management

Launch Plan

What FullSpec will build for you, what happens at each stage, and what your automation looks like once live.

4 pagesPDF · Operations
FS-DOC-01Operations

Launch Plan

User Provisioning & Access Management

[YourCompany.com] · IT Department · Prepared by FullSpec · [Today's Date]

This Launch Plan covers everything you need to know about what is being built, how the build progresses, what FullSpec needs from you to get started, and what your ongoing role looks like once the automation is live. It is written for the business owner or operations lead, not a technical audience. FullSpec handles all build, integration, testing, and deployment work end to end. Your job is to provide access credentials, confirm one key configuration decision before the build begins, and then monitor results once the workflow is running.

01What you're launching

Right now, every new hire or departure triggers a chain of manual account actions across six systems, managed by an IT Administrator working from memory, Slack messages, or a shared spreadsheet. Steps get missed, new starters wait days for access, and ex-employee accounts can stay active for weeks after someone leaves. This automation replaces that process: the moment BambooHR marks an employee as a new hire, transfer, or terminated, two agents take over, creating or deactivating the correct accounts across Okta, Google Workspace, Microsoft 365, and Slack, then writing a timestamped audit record to Jira. A human review step is preserved only for requests involving elevated or non-standard permissions.

Process
User Provisioning & Access Management
Trigger
BambooHR employee record moves to New Hire, Transfer, or Terminated status
Final output
All accounts provisioned or deactivated across every connected system, with a timestamped audit ticket created automatically in Jira and the line manager notified via Slack
Agents being built
2 agents: Provisioning Policy Agent and Offboarding Audit Agent
Tools involved
BambooHR, Okta, Google Workspace, Microsoft 365, Slack, Jira
Volume
6 to 10 provisioning events per month
Launch PlanPage 1 of 4
FS-DOC-01Operations

02How the build works

The build runs across four sequential stages: Connect, Build, Test, and Launch. FullSpec leads every stage. Your involvement is lightweight and focused on access and approvals rather than technical work. The total delivery window is four weeks from the close of Connect, which is when all credentials and configuration decisions are confirmed and the build clock starts.

Complexity level: Moderate. Estimated delivery: 4 weeks (20 business days). The delivery clock starts at the close of Connect, not payment. Build cannot begin until all credentials are confirmed and the access policy is documented.
1
Connect
Business days 1 to 3
Who
Actions
FullSpec
Reviews your mapped process, confirms the role-to-access policy document, walks through the BambooHR webhook setup and Okta federation status, and schedules the credential handover session.
You
Attend a single onboarding call (30 to 60 minutes), provide API credentials for all six tools, and confirm whether an access policy document already exists or needs to be created before build starts.
2
Build
Business days 4 to 15
Who
Actions
FullSpec
Builds and configures the Provisioning Policy Agent (BambooHR trigger, role mapping logic, Okta, Google Workspace, Microsoft 365, and Slack account actions, plus the elevated-permissions review gate), then builds the Offboarding Audit Agent (deactivation sequence, file ownership transfer, and Jira audit ticket creation with error alerting).
You
Review and approve the role-to-access mapping rules prepared by FullSpec. No technical input is required. You simply confirm that the access levels described match your actual business policy.
3
Test
Business days 16 to 18
Who
Actions
FullSpec
Runs end-to-end tests using dummy employee records covering new hire, lateral transfer, and termination scenarios across all six systems. Verifies audit trail completeness in Jira, confirms Slack notifications reach the correct manager, and validates the elevated-permissions hold gate.
You
Review the test results summary provided by FullSpec, confirm that the output in Jira and Slack looks correct for your team, and sign off to proceed to Launch.
4
Launch
Business days 19 to 20
Who
Actions
FullSpec
Cuts over from the manual process to the live automation, confirms the BambooHR webhook is active in production, walks the IT Administrator through the monitoring dashboard and the elevated-permissions review queue, and delivers the full SOP and runbook documentation.
You
Attend the handoff walkthrough (approximately 60 minutes) with your IT Administrator present. Confirm that the first live provisioning event is processed correctly and that the IT team knows how to update access policy rules when roles change.
Launch PlanPage 2 of 4
FS-DOC-01Operations

03What FullSpec needs from you

FullSpec needs only access to your existing tools. No technical knowledge is required from your side. All connection setup, API configuration, and testing is handled by the FullSpec team. The table below lists exactly what is needed for each tool and when it must be provided.

Tool
What we need
When
BambooHR
API key with permission to read employee records and receive webhook events on status changes
Before Connect closes
Okta
API token with permissions to create, update, deactivate, and assign groups for user accounts
Before Connect closes
Google Workspace
A service account with domain-wide delegation enabled, covering user provisioning, group membership, Drive ownership transfer, and mailbox management
Before Connect closes
Microsoft 365
An Azure Active Directory app registration with admin consent granted for user and group management, licence assignment, and Teams membership
Before Connect closes
Slack
A Slack app installed to your workspace with permissions to invite users, manage channel membership, and post notifications
Before Connect closes
Jira
An API token for a service account with permission to create and update tickets in the designated IT audit project
Before Connect closes
One decision you must confirm before Connect closes: does a documented role-to-access policy already exist for your team? This policy defines which systems, groups, and permission levels each role receives. The Provisioning Policy Agent cannot be built without it. If no policy exists, your IT Administrator will need to complete this document before the build stage begins. FullSpec can provide a template to accelerate this step, but the business rules themselves must come from your team.

04Your role once live

Once the automation is live, day-to-day provisioning and offboarding runs without manual intervention. The table below summarises ongoing responsibilities for each party and what you no longer need to touch.

Role
Ongoing responsibilities
What you no longer touch
You (business owner / IT Administrator)
Review and approve any provisioning requests flagged for elevated or non-standard permissions (typically under five minutes per event). Update the role-to-access policy document when a new role is created or existing permissions change. Review the monthly Jira audit summary to confirm compliance.
Manual account creation across Okta, Google Workspace, Microsoft 365, and Slack. Chasing managers for role and access details. Writing audit notes in spreadsheets or Jira comments. Deactivating accounts manually on an employee's last day.
FullSpec
Monitor automation health and uptime. Investigate and resolve any workflow errors or failed deactivation alerts. Apply updates to integrations when a connected tool changes its API or authentication method. Provide ongoing support via support@gofullspec.com.
No manual process steps. FullSpec's role is to keep the automation running correctly and to update it as your business or tools evolve.
Launch PlanPage 3 of 4
FS-DOC-01Operations

05What success looks like

The table below sets out realistic expectations for each phase after go-live, so you know exactly what to look for and how to confirm the automation is delivering value.

Timeframe
What to expect
Sign of success
Week 1
The first live provisioning or offboarding events are processed by the automation. FullSpec monitors closely and resolves any edge cases that were not covered in testing. Your IT Administrator reviews the Jira audit tickets created for each event.
At least one provisioning event completes end to end in under 10 minutes with a Jira audit record created and manager notified via Slack, no manual steps required.
Month 1
The full volume of 6 to 10 provisioning events is handled automatically. IT Administrator time spent on account setup drops noticeably. Any elevated-permission requests are handled through the review queue rather than ad hoc Slack messages.
Zero missed accounts across new hires processed in the month. IT Administrator spends under 30 minutes total on provisioning tasks, down from roughly 5 hours per week. No ex-employee accounts left active past their end date.
Month 3
The automation is fully embedded in the IT workflow. Jira contains a complete, timestamped audit trail for every provisioning event since go-live. Annual IT staff cost on provisioning is tracking toward the $13,000 saving. Payback on the $4,500 build cost is on course for 4 months.
Provisioning audit completeness reaches 100% in Jira. New hire account access is confirmed on day one for 98% of starters. Offboarding lockout is completed in under 10 minutes on every termination event. IT team confidence in the process is measurably higher.

Next step: the FullSpec team will send a Connect session invitation to your nominated IT Administrator within one business day. Before that call, gather your BambooHR API key and confirm whether a role-to-access policy document exists. If you have any questions in the meantime, reach out to support@gofullspec.com and the team will respond promptly.

Launch PlanPage 4 of 4

More documents for this process

Every document generated for User Provisioning & Access Management.

ROI and Business Case
Finance · Owner
View
Process Runbook / SOP
Operations · Owner
View
Developer Handover Pack
Technical · Developer
View
Integration and API Spec
Technical · Developer
View
Test and QA Plan
Quality · Developer
View