Finance playbook · AI Employee: Fin

Zip Access Request

Card issued within 1 business day

The problem

Zip (procurement platform) access requests are the black-hole intake: new employees don't have access to submit requests, employees changing teams need scoped permissions, contractors need view-only, admins need approval-authority. Manual access management via Zip's admin panel takes ops hours per week + drifts silently. Employees can't get access to buy the things they need; access reviews find sprawl at audit time.

At a glance
Trigger
Form
Approvals
Finance manager approval
What it does
Writes to your systems
Systems
Zip · Corporate card platform · Okta
How it feels in production

An hour-by-hour walkthrough.

New hire Priya starts 2026-11-01. HRIS event triggers Fin to provision Zip access: - Role: Senior Engineer, cost center CC-ENG-PLATFORM - Zip role mapping: 'requester' (can submit + track requests, no approval authority) - Approval routing: Priya's requests route to manager Sarah (up to $5K), then VP - Category access: engineering-scoped catalog (Cloud, Dev Tools, SaaS) - SSO integration verified Priya has Zip access on day 1 alongside other tooling. When Priya submits her first request, approval routing works automatically because it was configured at provisioning. For role changes, Fin adjusts Zip role: Priya promoted to Team Lead gets approver authority for her team's requests. Cost center changes update the approval routing. Contractor exit deprovisions Zip access alongside other systems. Quarterly access review: Fin surfaces Zip access + role assignments across the org, comparing to policy. Drift (former engineer still has approver role from prior team) flagged for cleanup.
How it works

Step by step.

  1. 01

    Trigger from HRIS event or manager request

    New hire, role change, contractor, project team formation. Zip access needed determined from role + team.

    HRIS · Zip · Manager request
  2. 02

    Assign correct Zip role + scope

    Requester, approver, admin, viewer. Category access per role. Cost center for spend allocation.

    Zip role catalog · Cost center registry
  3. 03

    Configure approval routing

    Requester's requests route to correct approver chain. Approval authority per role + amount thresholds.

    Zip approval configuration · Approval matrix
  4. 04

    Verify SSO + notification setup

    SSO integration active. Notification preferences set (Slack integration, email digests).

    Okta · Slack integration · Notifications
  5. 05

    Deprovision on offboarding / role change

    Automatic deprovision on offboarding. Role adjustment on role change. Coordinated with employee-offboarding cascade.

    Employee-offboarding cascade · Zip deprovisioning
Systems and wiring

What you connect to make this run.

Zip · Procurement platform

read+write

User + role + approval + category configuration. Complete lifecycle management.

HRIS · Workday · BambooHR

read

Employee lifecycle events trigger Zip access changes.

Okta · Azure AD

read+write

SSO integration for authentication + group-based access.

Slack · Teams

read+write

Zip-Slack integration for in-flow request submission + approval.

What changes

Before and after, honestly.

Time from hire to Zip access
Before
3-10 days
After
Day 1
Fin ops hours per week on Zip access management
Before
5-15 hours
After
1-3 hours
Access drift (role-inappropriate access)
Before
15-35%
After
Under 3%
Approval routing errors (wrong approver)
Before
10-25%
After
Under 2%
Frequently asked

Answers about this playbook.

What about non-standard access needs (project-based, one-off)?

Project-based access with expiry supported. One-off access requests routed to Fin admin for one-time grant with reason.

How does it handle cross-cost-center requests?

Multi-cost-center approval routing supported. Each cost center's approver in chain per split.

What about Zip access for external stakeholders (auditors, consultants)?

External-user provisioning with view-only + scoped access. Time-limited by default; explicit approval for access extension.

Can we scope catalog access by team?

Yes — engineering sees Cloud + Dev Tools; sales sees CRM + Sales Tools. Prevents catalog overload + surfaces relevant options.

How does it handle Zip role changes for role-change vs. promotion?

Role change may increase authority (promotion) or shift scope (lateral). Fin adjusts per pattern; policy-based defaults.

See it run on your data.

Free plan, no credit card. Connect the systems this playbook needs and run it against a past event first.