E
HRIS / HCM / WFM

Envoy AI Integration

Connect Envoy to BeforeQuery for grounded AI answers and agent actions across HRIS / HCM / WFM.

What is it?

About Envoy

Envoy is one of the HRIS / HCM / WFM platforms BeforeQuery connects to. Once linked, the platform's data becomes a first-class source for grounded AI answers and a target for policy-gated agent actions — the same identity, approval, and audit-log guarantees every other integration ships with.

Setup

How to connect Envoy

  1. Step 01

    In the BeforeQuery dashboard, go to Integrations → HRIS / HCM / WFM and select Envoy.

  2. Step 02

    Sign in to Envoy with an account that has permissions to grant BeforeQuery the HRIS / HCM / WFM scopes required.

  3. Step 03

    Confirm the connection. Envoy is now available as a source and action target for every playbook in your workspace.

How BeforeQuery uses Envoy

What the agent does with your Envoy connection

  • 01

    Read employee, role, manager, and org data from Envoy to power identity-aware answers everywhere.

  • 02

    Trigger onboarding + offboarding playbooks on Envoy lifecycle events — start dates, role changes, terminations.

  • 03

    Answer HR policy questions ("how much PTO do I have?") grounded in Envoy records + policy documents.

  • 04

    Provision + deprovision access downstream from Envoy — same event fires 40 downstream write actions in the right order.

Use cases

What teams actually do with the Envoy integration

New-hire onboarding cascade

Envoy fires a hire event → BeforeQuery reads the role, team, and manager → provisions Okta account + Slack channels + GitHub team + laptop order + calendar meetings + welcome messages, all in the right order with the right approvals, in under 90 seconds.

Offboarding orchestration

Envoy termination event → BeforeQuery revokes SSO, transfers file ownership, closes tickets, cancels calendar invites, and archives the employee's Slack DMs — the entire deprovisioning cascade tracked to zero orphaned access in under 15 minutes.

HR policy Q&A grounded in Envoy + PTO records

Employees ask "how many days of PTO do I have left?" or "what's my parental leave policy?" — BeforeQuery pulls their record from Envoy, matches against your policy documents, and answers with the specific numbers for that employee.

Answer questions grounded in Envoy

Employees and customers ask Envoy-related questions in Slack, Teams, or the widget — BeforeQuery answers with the exact Envoy record shown alongside the response. No context switching, no "log into HRIS / HCM / WFM to check" round-trips.

Envoy — Frequently Asked Questions

Common questions about connecting BeforeQuery to Envoy.

The minimum set for the playbooks you enable. For onboarding: users, roles, manager relationships, start dates. For PTO Q&A: leave balances + policy. You approve the scope at install; nothing else is pulled. Sensitive fields (comp, PHI) can be excluded even from approved scopes.
Role-change events from Envoy propagate through the Context Graph on next sync (typically < 5 min). Group memberships, approval chains, and access policies re-evaluate automatically. Any playbook that depended on the old role uses the new one on its next run — no manual re-configuration.
Standard OAuth 2.0 where Envoy supports it, otherwise API-key or bearer-token auth. Credentials are stored encrypted at rest (AES-256-GCM) per workspace, never shared across customers, and rotated on request. The connection is scoped to the least-privilege set of scopes each playbook needs — you approve the scope list on install.
No. Your Envoy data feeds only your workspace's own agents and answers. Nothing is used to train a shared model, and nothing crosses workspace boundaries. Bring-your-own-model is available on Enterprise if you want to pin inference to your own OpenAI / Anthropic / self-hosted deployment.
Yes. Every Envoy integration is scoped at install time — you pick which resources, users, or record types are visible. You can further restrict per-playbook: a single playbook only touches the specific Envoy objects it needs. Scope changes take effect on the next sync.
Every write is logged with the acting user, the playbook that fired it, the exact operation, the target entity IDs, and the timestamp — all in the immutable audit log. Writes are rehearsable in simulation mode against a copy of live data before they touch Envoy for real.

Ready to connect Envoy?

Start free. No credit card required. Connect your first integration in under 5 minutes.