IT playbook · AI Employee: Ivy

New Hire Provisioning

100% of new hires productive on day 1

The problem

IT owns half of onboarding — accounts, devices, licences, SSO groups, MDM enrolment. When it's a ticket, IT is racing HR to be ready by the start date. When ten hires start the same Monday, the queue collapses. Automated end-to-end IT provisioning is table stakes for any IT team above ten hires a month.

At a glance
Trigger
HRIS event (start T-3)
Approvals
IT lead spot-check on VIP roles
What it does
Writes to your systems
Systems
Workday · Okta · Google Workspace · M365 Admin · Slack · Jamf · GitHub
How it feels in production

An hour-by-hour walkthrough.

T-3 days. HRIS confirms Priya's start date. Ivy reads the event and pulls her role template: engineering, mid-level. That template calls for an Okta account with the eng-mid-level SSO group, a M1 Pro MacBook with the standard eng image, GitHub org membership, Notion + Confluence access, and licences for Datadog + Sentry + PagerDuty. Ivy provisions in order: Okta account created, added to groups, mail alias reserved. GitHub org invite sent to her recovery email. Notion + Confluence licences assigned. Jamf device order confirmed with M1 Pro SKU, MDM auto-enrolment scheduled for arrival. Ivy posts a status card in the IT team channel: green ticks where done, amber on device (waiting delivery). T-1 day. Laptop arrives at the office. Jamf enrolment fires as expected; device shows up in Ivy's inventory. She verifies the SSO login works from the enrolment session and marks the hire as IT-ready. Day 0, 9am. Priya logs in with SSO. Every account works. The IT team never touched a manual ticket. Weekly digest to the IT lead confirms all provisioning succeeded, or names the specific step that needs manual attention.
How it works

Step by step.

  1. 01

    Reserve email + username

    Read the HRIS event and reserve the standard email + username per your naming convention. Handles collisions (two Priya Nairs in the same domain) with your policy — usually adds an initial or department suffix.

    HRIS · Google · Microsoft 365
  2. 02

    Provision SSO + groups per role template

    Create the Okta / Entra account, add to SSO groups derived from the role template (eng-mid gets #engineering + on-call + eng-tools; sales-AE gets #sales + Gong + Salesforce SSO). Templates versioned in Playbook Studio.

    Okta · Microsoft Entra ID
  3. 03

    Assign licences

    M365 / Slack / GitHub / Notion / Confluence / Datadog / Sentry / PagerDuty licences assigned per template. Costs flow to the requesting cost centre. Reclamation playbook fires on eventual offboarding.

    M365 · Google · GitHub · Notion · Confluence · SaaS licence pool
  4. 04

    Ship laptop + enrol MDM

    Trigger device order via CDW / Apple Business Manager / Lenovo direct. Jamf / Intune / Kandji auto-enrolment scheduled so laptop is provisioned the moment it powers on.

    CDW · Apple Business Manager · Jamf · Intune · Kandji
  5. 05

    Add to team Slack channels

    Slack channels per role template — team channel, on-call, engineering-random, etc. Bot invites the new hire; welcome message posts in each channel.

    Slack · Teams
  6. 06

    Set day-1 KB reading list

    Send the role-specific knowledge base reading list — engineering-onboarding, on-call runbook, deployment guide, incident-response playbook. Progress tracked in the LMS.

    Confluence · Notion · LMS
Systems and wiring

What you connect to make this run.

Workday · BambooHR · HiBob · Rippling · ADP

trigger

New-hire webhook enabled. Signed payload verified. Ivy reads role + team + start date.

Okta · Microsoft Entra ID

write

Service account with user-create + group-write scopes. Every write idempotent by external_id.

Jamf Pro · Intune · Kandji

write

MDM API credential with device-create + assignment scopes. Auto-enrolment happens on first power-on.

Slack · Google Workspace · Microsoft 365 · Confluence · GitHub · Notion

write

Per-provider admin credentials in Models Studio. Group + licence assignment per role template.

Context Graph

read+write

Every provisioning action writes edges (identity → group, identity → licence, identity → device). Offboarding reads these edges to know what to revoke.

What changes

Before and after, honestly.

IT time per new hire
Before
2-4 hours across accounts + device + Slack + docs
After
~5 minutes reading Ivy's status card and handling exceptions
Day-1 IT tickets from new hires
Before
3-6 (missing group, missing licence, forgotten Slack channel)
After
0-1 (only genuine edge cases)
Time from HRIS event to IT-ready
Before
24-72 hours
After
Under 15 minutes
New-hire cohort scale
Before
IT capacity caps hiring pace
After
Hire rate is limited by business need, not IT bandwidth
Frequently asked

Answers about this playbook.

Can we have different provisioning templates per team?

Yes. Role templates live in Playbook Studio and are versioned. Engineering gets one template, sales another, finance another. Templates can inherit — sales-AE inherits from sales-base, adds Gong + Salesforce SSO.

What if a licence isn't available?

Ivy checks the licence pool before assignment. If a licence type is exhausted, she pings the licence owner (usually IT or finance) with a request-to-purchase card. New hire's other accounts still provision; the specific licence surfaces as a pending item.

How do we handle contractors vs. FTEs?

The employment-type field from HRIS drives the template. Contractors get a scoped template (fewer licences, contract-end-date on every group grant so offboarding fires on contract end). Interns get a third variant.

What if the laptop doesn't arrive in time?

Ivy detects the delivery slip from the procurement API and offers a loaner via the RMA / loaner playbook. Accounts work from any device; the primary laptop swaps in on arrival.

Does this replace our onboarding runbook?

It replaces the mechanical parts. Your onboarding runbook stays as the human-decision reference — which template applies, how VIP hires get handled, escalation paths. Ivy is the automation on top.

See it run on your data.

Free plan, no credit card. Connect the systems this playbook needs and run it against a past event first.