HR · Colleague: Harry

Onboarding, offboarding, and every leave request — done

Harry, your HR Colleague, runs the loop from Workday to Slack — provisioning identities, answering benefits questions, coordinating leave, and offboarding cleanly across every system.

Phase 3 · Q2
Capability 01

22 pre-built HR playbooks

From new-hire handoff to 30/60/90 check-ins, from milestone moments to clean offboarding. Every playbook covers the loop end-to-end — trigger, identity resolution, action across systems, notification to the manager, audit entry. Install one in a click, connect your HRIS + IdP, and go live.
grounded answer · sources
answer

Priya’s Okta lockout can be cleared via self-serve MFA challenge — no IT intervention required. If MFA fails, escalate to IT on-call.

cited from
01
IT · Okta account lockout policy
runbook · updated 4d ago
02
HR · Emergency access procedure
policy · updated 2w ago
03
Ticket #48211 · priya · resolved
past ticket · similar match
Capability 02

Grounded in your handbook

Policy Q&A drawn from your Confluence, SharePoint, Google Drive, Notion, or uploaded PDFs. Every answer shows the paragraph it came from — no more "is our parental leave 12 or 16 weeks?" ambiguity. When policy conflicts across two documents, the Knowledge Health dashboard surfaces it before the wrong answer ships.
approvals · pending 4
unlock okta account
priya.sharma · self-serve · read-only
denyapprove
refund $128.40
stripe · ord_A4b2c · manager approval
denyapprove
revoke prod IAM role
aws · role/analyst · step-up MFA
denyapprove
reset zoom SSO
kiran.mehta · self-serve
denyapprove
Capability 03

Live from your HRIS

Workday, BambooHR, HiBob, Rippling, ADP, Paychex, UKG, Personio kept in sync via webhook where the source supports it, poll-fallback where it doesn't. New hires, terminations, manager changes, role transitions surface in Context Graph within seconds — every playbook runs against current-state.
context · priya.sharma
priyateamon-calloktagithubworkday
Capability 04

Provisioning across identity, mail, chat, devices, and docs

Day 0: SSO account, mail alias, Slack channels, device shipped with MDM enrolment, welcome docs assigned. Day 30: check-in scheduled, LMS onboarding completion tracked. Day out: SSO revoked, SaaS licences reclaimed, device wiped, files transferred. One playbook per lifecycle event, chained to your HRIS date.
reports · this week
Auto-resolved
78.4%
+4.1 pt
Avg. loop time
11.4s
-2.1s
Approvals pending
12
-3
Coverage
94%
+1.2 pt
monsun
Capability 05

Approvals where it matters

Manager approval on PTO, HRBP on comp changes, skip-level on role transitions, step-up MFA on regulated-field updates (SSN, DOB, banking). Approval chains configured once in Approval Policies, referenced from any HR playbook.
grounded answer · sources
answer

Priya’s Okta lockout can be cleared via self-serve MFA challenge — no IT intervention required. If MFA fails, escalate to IT on-call.

cited from
01
IT · Okta account lockout policy
runbook · updated 4d ago
02
HR · Emergency access procedure
policy · updated 2w ago
03
Ticket #48211 · priya · resolved
past ticket · similar match
Capability 06

The employee never leaves Slack

Harry answers in the DM or the channel where the employee asked — benefits, PTO balance, holiday schedule, expense-reimbursement status. Escalates to a human HRBP cleanly when policy demands it, keeping the thread continuity intact.
approvals · pending 4
unlock okta account
priya.sharma · self-serve · read-only
denyapprove
refund $128.40
stripe · ord_A4b2c · manager approval
denyapprove
revoke prod IAM role
aws · role/analyst · step-up MFA
denyapprove
reset zoom SSO
kiran.mehta · self-serve
denyapprove
The BeforeQuery method

Visibility. Reasoning. Action.

Every playbook, every action, every answer follows the same three-beat rhythm — one that keeps every write behind evidence and every decision behind policy.

01

Visibility

Read the full context — who is asking, what they own, what they can access, what breaks if we touch it. Nothing acts on incomplete signal.

02

Reasoning

Match the request to a grounded answer or a playbook. Cite the source paragraph, weigh the risk tier, and route to the correct approver where policy demands it.

03

Action

Execute the write on your systems with an audit-log id, an entity list, and a rollback path. Confirm the outcome with the requester in the same thread.

How every request flows

From ask to resolution in one loop

Six stages every request travels. What changes is how many stages policy lets the agent execute without waiting on a human.

01
Request

In Slack, email, widget, MCP, or the helpdesk. Same voice, same context.

Slack · Teams · Zendesk · Widget · MCP
02
Retrieve

Grounded lookup against your knowledge with source paragraphs held aside.

Knowledge Studio
03
Reason

Read the Context Graph — who, what they own, what breaks if we touch it.

Context Graph
04
Approve

Route to the correct approver per policy. Reversible writes gated, destructive step-up.

Approval matrix
05
Execute

Act on Okta, Stripe, Workday, GitHub, or your own systems. Logged and attributable.

Actions runtime
06
Verify

Confirm the outcome with the requester. Feed the result back into future decisions.

Feedback loop
Watch it work

New hire → provisioned in 90 seconds

One HRIS event triggers the whole cascade. Every downstream write logged and reversible.

slack · #it-help
live
$workday · new-hire event:Priya Sharma · Engineer · start 2026-11-01 · manager Sarah
·
remy resolve role template: Senior Engineer · Berlin · Platform Eng role.catalog#L4
·
remy order MacBook Pro 14" via Apple Business, ship to home coupa.po#82914
·
remy create Okta account + assign 18 role-mapped apps okta.user#c8a1 · scim
·
remy add to 6 Slack channels, GitHub team, Jira project cascade#a4b2c
·
remy schedule 5 onboarding meetings on Priya + manager calendars gcal.batch
remysarah:Priya's day-1 pack is ready. Anything to add to her buddy pairing?
resolved · 87s · full audit trail filed·reversible · policy-compliant

Every step above is a distinct playbook. Assemble them once per role and Remy runs them for every new hire that role sees.

Enterprise-grade by default

The controls your security team is going to ask about

SOC 2 Type II
audited annually
GDPR
EU data residency
HIPAA-ready
BAA available
SSO / SAML
Okta · Entra · Google
SCIM 2.0
auto-provision
Audit log
every write, traceable
Bring your key
AES-256-GCM at rest
Bring your model
Anthropic · OpenAI · self-host
Zero training
your data stays yours
Rollback
every write reversible
TLS 1.3
in transit
99.9% uptime
SLA on Enterprise

Frequently asked questions

Common questions about Agentic HR

Workday, BambooHR, HiBob, Rippling, ADP, and Paychex ship in Phase 3. Personio, UKG, Dayforce, Paylocity, Paycom, and Zoho People land in Phase 4 as their integrations complete. Every HRIS integration feeds Context Graph so playbooks reason on live state, not last night's dump.
Your HRIS emits a new-hire event on the start-date trigger. Harry reads it, resolves the role → group template, provisions identity + SSO group memberships + SaaS licences per template, orders and enrols the device via MDM, adds the hire to team Slack channels, sends the welcome pack, and schedules the 30/60/90 check-ins. Manager gets a summary; VIP hires trigger an escalation for skip-level review.
Two safeguards. First, changes to regulated fields require an approval with step-up MFA on the HRBP reviewer. Second, PII masking runs before any LLM call — the model never sees the raw SSN or banking details, only the masked form. Every change writes to the audit log with the reviewer's identity.
Yes — that's the default. Employees ask in the #ask-hr channel or DM Harry directly; grounded answers come back in seconds, with the handbook paragraph shown. Only questions Harry can't ground escalate to a human HRBP.
Harry Colleague + 22 pre-built HR playbooks + HRIS-read for Workday/BambooHR/HiBob/Rippling/ADP + policy Q&A grounding + approval chains for manager/HRBP/skip-level. Harry becomes a listed AI Employee in the marketplace on go-live.

Run hr on BeforeQuery

Book a demo and see what Agentic HR does on your own data — usually within 45 days.