Workflow diagram: a Role record passes a key step and fans out to Granted, Privileged, and Approved, ending at an Access Verified badge.
IT / Identity

Automate User Provisioning

Provision the right access to the right people — automatically, on day one.

Access on day one

Productive immediately

Accounts and entitlements exist when the person starts rather than accumulating over their first fortnight.

Entitlement by role

Least privilege by default

Access comes from a defined role rather than being copied from whoever sits nearby.

Reviews read from evidence

Audit readiness

Every grant records the role, the rule, and the approver, so access reviews are a read rather than an investigation.

One governed workflow across systems that never talked.

Who it's for
IT and identity teams granting, changing, and removing access across systems that each have their own model.
What it does
A governed workflow that resolves entitlements from role, routes privileged access for approval, and verifies every grant.
Systems involved
Your identity provider, directory, and every system holding accounts — connected through the REST Client, with dedicated activities built on request.
How it stays governed
Entitlement rules in decision tables, approval routing for privileged access, and a verified record per grant.

What this looks like today

The friction that makes this workflow expensive to run by hand.

01

Precedent

Access is copied from a colleague

Provisioning by cloning an existing user propagates whatever that person accumulated, so privilege grows quietly with every hire.

Over-provisioningPrivilege creep
02

Delay

Each system is its own request

Access to five systems means five tickets to five teams, so new joiners spend their first week waiting rather than working.

Sequential requestsLost productivity
03

Evidence

Nobody can explain a grant

When a reviewer asks why someone has an entitlement, the answer is usually that they have always had it.

Unexplained accessAudit findings

The workflow

How Koodisi runs it

Koodisi automates user provisioning across identity, SaaS, and enterprise systems — triggered by HR events, ensuring employees have the correct access on their first day without manual IT tickets.

01

Start from an authoritative event

A hire, a role change, or an access request from the HRMS or service desk starts the process, so provisioning follows a decision someone actually made.

Webhook and scheduled triggers over the REST Client.

02

Resolve entitlements from role

A decision table maps role, department, and location to the exact account and group set that role is entitled to — not what a colleague happens to hold.

Entitlement rules live where security can review them.

03

Route privileged access for approval

Anything elevated goes to a named approver with the requested entitlement shown, and the workflow waits rather than granting on assumption.

The approval and approver are recorded.

04

Provision across every system

Accounts and group memberships are created in each target system in one pass rather than as a chain of separate requests.

Retry policies cover transient failures.

05

Verify the access exists

Each system is read back to confirm the account and entitlements actually landed — the difference between requesting access and having it.

Unconfirmed grants raise a failed run rather than completing.

06

Record the grant

Each entitlement records the role it came from, the rule that produced it, and any approver, which is what an access review needs.

Execution logging with before and after state.

Connectivity

The systems in this workflow

Koodisi orchestrates the platforms this workflow touches — through the REST Client today, and through a dedicated activity whenever you need one.

The capability underneath

Every workflow above is assembled from the same governed building blocks — which is why connecting one more system is a day of work, not a project.

Connect to anything

  • REST and webhook connectivity with managed authentication (4 activities)
  • Secure file transfer over SFTP (5 activities)
  • Direct database reads and writes (4 activities)

Move and reshape data

  • Translate between CSV, JSON, XML, and fixed-width formats (6 activities)
  • Field-level mapping between systems that model data differently
  • High-volume batch processing with per-record tracking (7 activities)

Decide and protect

  • Decision tables for approval and routing rules your team can read
  • Encryption, hashing, and signature verification on sensitive fields
  • Retry policies, error handling, and full execution logging

Business systems connect through Koodisi’s REST Client, and our team builds dedicated activities for the ones you depend on — typically within a day of you asking.

Request a system →

Governance

Automated, but still under control

Every run is authorised, recorded, and observable — the part that decides whether automation survives an audit.

Entitlements defined by role

Role-to-access mapping lives in a decision table security can review, so least privilege is a design rather than an aspiration.

Approval authority scoped

Permission scopes control who can approve privileged access and who can change the entitlement rules themselves.

Every grant explainable

Each entitlement carries the role, rule, approver, and timestamp that produced it.

Credentials in Key Vault

Directory and system credentials are stored in Key Vault and referenced at run time, never held in a step.

Personal data masked

Identifiers and contact details are masked in logs so provisioning records stay operational.

Verified, not assumed

Traces show each grant confirming, so an incomplete provisioning run is visible immediately.

FAQ

Frequently asked questions

Still have a question? Talk to our team.

Ship integrations faster. Operate them without chaos.

Less time on auth, retries, and deployment scripts. More time on the integrations your customers are asking for.

Contact Sales