Onboarding

Day one access, without a ticket

What replaces the onboarding checklist somebody copies from the last hire and edits.

The plan is built from the HR record the moment it exists and held until the start date. Department, title, manager and employment type decide most of it, and the manager sees the whole thing before the person arrives.

What you are replacing is a document. Onboarding is the process every company has written down and almost nobody has automated past the first 10 apps.

The written version is a checklist. Somebody copies the doc from the last hire in that department, edits the bits that differ, and works through it. It is correct on the day it is written and drifts from there, because nothing tells it the team adopted a new tool in March.

What the checklist cannot do

It cannot start early. A hire appears in the HRIS weeks before their start date, and that is the most useful time in the whole process, because a decision can be checked then without any consequence. A checklist has nowhere to hold a decision that has not happened yet.

It cannot record why. Every line is an action, not a reason, so nothing downstream can work out which grants were departmental and which were exceptions. That is what makes role changes so lossy later.

And it cannot tell you it was wrong. A missed line looks exactly like a line that did not apply.

What replaces it

A plan, built from the HR record the moment it exists, and held until the start date.

Department, title, manager and employment type decide most of it. The manager sees the whole thing and can change it before it runs. On the start date it executes in order, and anything policy could not decide was routed to a person days earlier.

An Iden onboarding workflow shown as a branching graph, with a task list underneath showing three accounts provisioning for one new hire, one running and two queued.

The same workflow as a definition and as a run. Underneath, three accounts going out for one hire, each with its own ticket ID.

Every provisioning task carries its own ID, including the apps with no SCIM. That is the difference between an app being covered and an app being listed.

The part most teams get wrong

Contractors. A contractor is a joiner whose end date is the entire point, and the end date is the field most often left empty.

If it is in the HRIS, it gets enforced. If it is not, that is the highest-value thing on this page to go and fix, because contractor access outliving the engagement is the most common way accounts survive the person.

What still needs a person

Capped licences, apps where seats cost enough to be a budget decision, and anything requested outside policy. These reach the app owner with the context attached, days before the start rather than on it.

Frequently asked questions

The hour the record appears in your HRIS, usually one to three weeks before the start date. Nothing is provisioned until the start date, so a date that moves costs nothing to undo.

Most teams do not, and that is fine to start. Iden can derive a starting profile from what people in the same department already have, which you then correct. Editing a draft is faster than designing a role model from nothing.

Only when the plan runs. Credentials go to the personal address on the HR record, which is the only address that exists before day one.