About This Automation User provisioning involves creating identities, assigning application access, and notifying stakeholders whenever someone joins, changes roles, or leaves. Doing this by hand across multiple systems creates delays, inconsistent access, and audit gaps.
The automated version reads approved requests, provisions accounts and access across every core system based on role, and logs the grant for compliance. The result is faster, more consistent access with a reliable audit trail.
Key features:
Reads new hire, role change, and termination requests directly from the HR system Maps each request to the correct standard access template automatically Provisions identity and application access across every core system in one pass Sends welcome notifications with login details to new hires and managers Logs every access grant with timestamp and requester for audit review Flags exceptions that fall outside the standard role template for human review Top friction points when done manually The issues teams report most often with this process
# Friction point Companies Report This 1 Inconsistent access grants
Manual setup across many systems leads to gaps or extra access being granted by mistake.
80% 2 Slow new hire turnaround
New hires often wait one to three days before receiving full system access.
67% 3 Repetitive console switching
Technicians move between several admin consoles to complete a single request.
53% 4 Incomplete audit records
Access grants are sometimes logged late or with missing detail for compliance review.
40% 5 Missed termination steps
Offboarding steps can be delayed or skipped when requests are handled manually.
26%
Disclaimer All data is based on anonymized FullSpec mapping sessions and proprietary industry research. Learn more Automation readiness How well-suited this process is for automation
Process Pain Score™ Manual provisioning across many systems creates delays and inconsistent access. 8.8 / 10
AI Fit Rating™ Requests follow predictable role templates that automation can map reliably. 8.9 / 10
Automation Lift Index™ Automation cuts turnaround from days to minutes with consistent results. 8.6 / 10
Hidden Overhead™ Switching between multiple admin consoles adds unseen time and error risk. 6.9 / 10
How The Automation Works The full workflow, from trigger to completion.
Press enter or space to select a node.You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.
1. New Hire Request Submitted trigger
A new hire, role change, or termination request is submitted and starts the workflow automatically.
2. Validate Role & Access Template
The automation checks the request against the approved role template and flags any mismatch before provisioning begins.
3. Create Identity & Assign Groups
's API creates the identity record and assigns the correct baseline and application security groups.
4. Provision Mailbox
Creates the mailbox, calendar, and shared drive permissions for the new user.
5. Add Workspace
Automatically adds the user to the correct team and department channels.
6. Grant License & Profile
Creates the user record and applies the matching profile and permission set.
7. IT Reviews Custom Access Request
An IT technician manually reviews and approves any request that falls outside the standard access template.
8. Send Welcome Email With Credentials
Sends the new hire and their manager a welcome email confirming access and first day details.
Most popular tool stack used — the complete tool combinations companies use Disclaimer All data is based on anonymized FullSpec mapping sessions and proprietary industry research. Learn more What you get when you map this process Everything you need to understand, plan, and build your automation.
ROI and business case What this process costs today and what changes once it's automated.
Launch schedule What gets built, in what order, and what success looks like once it's live.
Process runbook How the automation runs day to day, including exceptions and human decision points.
Developer handover pack Full build spec, logic, and configuration — ready to hand off without a briefing call.
Integration and connections guide Every tool connection, credential, and data mapping the build needs.
Test and QA plan Every scenario checked and signed off before the automation goes live.
Recommended for you Other high-impact processes teams commonly map alongside this one.
Frequently asked questions Everything you need to know before mapping this process.
What kinds of access requests can this automation handle? It handles new hire, role change, and termination requests, mapping each to the standard access template for that role.
Does someone still need to review unusual requests? Will this work with the identity and HR tools we already use? What happens to our existing user and access records? Is this a good fit for a small IT support team? View more FAQs