New Hire Provisioning
100% of new hires productive on day 1
IT owns half of onboarding — accounts, devices, licences, SSO groups, MDM enrolment. When it's a ticket, IT is racing HR to be ready by the start date. When ten hires start the same Monday, the queue collapses. Automated end-to-end IT provisioning is table stakes for any IT team above ten hires a month.
An hour-by-hour walkthrough.
Step by step.
- 01
Reserve email + username
Read the HRIS event and reserve the standard email + username per your naming convention. Handles collisions (two Priya Nairs in the same domain) with your policy — usually adds an initial or department suffix.
HRIS · Google · Microsoft 365 - 02
Provision SSO + groups per role template
Create the Okta / Entra account, add to SSO groups derived from the role template (eng-mid gets #engineering + on-call + eng-tools; sales-AE gets #sales + Gong + Salesforce SSO). Templates versioned in Playbook Studio.
Okta · Microsoft Entra ID - 03
Assign licences
M365 / Slack / GitHub / Notion / Confluence / Datadog / Sentry / PagerDuty licences assigned per template. Costs flow to the requesting cost centre. Reclamation playbook fires on eventual offboarding.
M365 · Google · GitHub · Notion · Confluence · SaaS licence pool - 04
Ship laptop + enrol MDM
Trigger device order via CDW / Apple Business Manager / Lenovo direct. Jamf / Intune / Kandji auto-enrolment scheduled so laptop is provisioned the moment it powers on.
CDW · Apple Business Manager · Jamf · Intune · Kandji - 05
Add to team Slack channels
Slack channels per role template — team channel, on-call, engineering-random, etc. Bot invites the new hire; welcome message posts in each channel.
Slack · Teams - 06
Set day-1 KB reading list
Send the role-specific knowledge base reading list — engineering-onboarding, on-call runbook, deployment guide, incident-response playbook. Progress tracked in the LMS.
Confluence · Notion · LMS
What you connect to make this run.
Workday · BambooHR · HiBob · Rippling · ADP
triggerNew-hire webhook enabled. Signed payload verified. Ivy reads role + team + start date.
Okta · Microsoft Entra ID
writeService account with user-create + group-write scopes. Every write idempotent by external_id.
Jamf Pro · Intune · Kandji
writeMDM API credential with device-create + assignment scopes. Auto-enrolment happens on first power-on.
Slack · Google Workspace · Microsoft 365 · Confluence · GitHub · Notion
writePer-provider admin credentials in Models Studio. Group + licence assignment per role template.
Context Graph
read+writeEvery provisioning action writes edges (identity → group, identity → licence, identity → device). Offboarding reads these edges to know what to revoke.
Before and after, honestly.
Playbooks that pair with this one.
New Hire Onboarding
The HR-owned view of the same event; both playbooks fire from the same HRIS webhook.
Employee Offboarding
The mirror-image playbook — deprovisions everything this one provisioned.
Identity Group Management
Handles the ad-hoc group changes that come after Day-1 provisioning.
New Device Order
The subflow for device procurement; can run standalone for existing employees.
Answers about this playbook.
Can we have different provisioning templates per team?
Yes. Role templates live in Playbook Studio and are versioned. Engineering gets one template, sales another, finance another. Templates can inherit — sales-AE inherits from sales-base, adds Gong + Salesforce SSO.
What if a licence isn't available?
Ivy checks the licence pool before assignment. If a licence type is exhausted, she pings the licence owner (usually IT or finance) with a request-to-purchase card. New hire's other accounts still provision; the specific licence surfaces as a pending item.
How do we handle contractors vs. FTEs?
The employment-type field from HRIS drives the template. Contractors get a scoped template (fewer licences, contract-end-date on every group grant so offboarding fires on contract end). Interns get a third variant.
What if the laptop doesn't arrive in time?
Ivy detects the delivery slip from the procurement API and offers a loaner via the RMA / loaner playbook. Accounts work from any device; the primary laptop swaps in on arrival.
Does this replace our onboarding runbook?
It replaces the mechanical parts. Your onboarding runbook stays as the human-decision reference — which template applies, how VIP hires get handled, escalation paths. Ivy is the automation on top.
See it run on your data.
Free plan, no credit card. Connect the systems this playbook needs and run it against a past event first.