Employee onboarding and offboarding, automated
New starters shouldn't wait days for system access, and people who've left shouldn't keep it. We build joiner-mover-leaver automation across Entra ID, Microsoft 365 and your connected SaaS apps, then hand it over fully documented.
The problem, named plainly
In most growing companies, onboarding a new employee means someone in IT working through a checklist by hand: create the account, assign licences, add the right groups, provision the laptop, grant access to the CRM, the ticketing tool, the finance system, and the ten other apps that team uses. It takes hours per starter, and when IT is busy the new hire spends their first days locked out of the systems they were hired to use.
Offboarding is worse, because nobody chases it. When someone leaves, their Microsoft account usually gets disabled. Their accounts in Salesforce, Slack, Notion, HubSpot and every other SaaS app often don't. Those orphaned accounts are a real, named security and compliance risk: an ex-employee with a live login to customer data, and a licence your company is still paying for. Auditors ask about exactly this. ISO 27001 and SOC 2 both expect leavers' access to be revoked promptly and provably.
What a joiner-mover-leaver automation is
Joiner-mover-leaver (JML) is the standard name for automating the three moments an employee's access changes: they join, they change role, or they leave. Instead of a manual checklist, one trigger drives everything:
- Joiner: a new record in your HR system or a ticket kicks off account creation in Entra ID, licence assignment, group membership based on role and department, and provisioning into the SaaS apps that role needs. The new starter has working access on day one.
- Mover: a role or department change updates group memberships and app access automatically, so people don't accumulate permissions from every job they've ever held.
- Leaver: a termination date triggers account disablement, session revocation, licence reclaim, mailbox and file handover, and deprovisioning from connected apps, on the day it should happen, every time, with a log to prove it.
How Somvio builds it
We start from the systems you already run. The core is Entra ID and Microsoft 365: dynamic groups, group-based licensing, and provisioning into SaaS apps using SCIM where the app supports it and REST APIs where it doesn't. Orchestration sits in the tool that fits your stack, typically Power Automate, Logic Apps or n8n, connected to your HR source of truth so the automation reacts to real events instead of someone remembering to raise a ticket.
Every build is scoped in writing first: which apps are in scope, what triggers each step, what the exception process is when something needs a human decision. We test against real joiner and leaver scenarios before it goes live, including the awkward ones like rehires and contractors.
What you end up owning
At handover you get the working automation, the configuration, and documentation covering how it works, how to add a new app to the flow, and how to handle exceptions. It runs in your tenant, under your accounts, with our access revoked. There's no retainer and no dependency on us: your team, or any engineer you hire later, can maintain and extend it.
Find out what this looks like in your tenant
Bring the process as it works today, however messy. In 20 minutes we'll tell you what can be automated, what it involves, and roughly how long it takes.
Book a free 20-minute call