Skip to main content
With an HRIS integration, onboardings can be fully automated. When a new hire is created in your HRIS, AccessOwl automatically pulls their start date, name, email, manager, and other attributes, and assigns the correct Access Templates without manual input. This page covers the end-to-end workflow and the recommended way to structure your templates. For creating templates and the full reference on rule conditions, attribute priority, and the simulator, see Access Templates.
For setup instructions on connecting your HRIS, see HRIS Integrations.

How It Works

Zero Touch Onboarding in four steps: a new hire is added in your HRIS, only the Access Templates whose attribute rules match are applied, AccessOwl provisions each account automatically, and every account is ready on day one If no templates match, the onboarding is announced in your HR Slack notification channel. Someone can then manually select templates or applications.

Ensuring All Attributes Are Available

For auto-assignment rules to work effectively, AccessOwl needs access to your employees’ attributes from your HRIS. The more attributes available, the more flexibility you have when designing your templates. Most attributes like Department, Role, and Location are available by default. However, Employment Type is an attribute we recommend having for all employees, as it allows you to build a reliable baseline template that applies to everyone. If Employment Type (or other attributes) are missing for your employees, it is usually because the HRIS connection was set up with an older, more limited set of permissions. Re-connecting your HRIS resolves this in most cases.
Some HRIS providers may not support certain attributes. For example, if you are using Okta as your HRIS source, some fields may not be available regardless of the connection. Reach out to our team if you are unsure what is available for your setup.

How to Re-authenticate Your HRIS

  1. Go to SettingsGeneralDirectory Integrations.
  2. Click on your HRIS integration.
  3. Click Edit.
  4. Follow the steps to re-authenticate.
Once reconnected, AccessOwl will sync the updated attributes within the next sync cycle. Verify that Employment Type now appears in the attribute list when configuring auto-assignment rules on your templates.

Best Practices for Zero Touch Onboarding

Keep it simple: Baseline + Department + Role (Optional) + Location (Optional) A new hire can match multiple Access Templates at once. Each template contributes its own applications and permissions.

1. Baseline template (Everyone)

Use one default template for tools every employee needs on day one. Use the “Employment Type” attribute with the Is set operator to apply this template to every employee with an active employment status.

2. Department templates

Department templates cover shared tools most people in that department need.

3. Role templates (Optional)

Role templates are for extra tools or permissions only certain roles need. Add these only when a subset of a department needs additional access.

4. Location templates (Optional)

Location templates handle office-specific tools or access.
With this model, a new Sales Account Executive in the Montreal Office would automatically receive four templates: Baseline + Sales + Account Executive + Montreal Office. Each adds the right tools without any manual selection.

Example Auto-Assignment Setup

For a full reference on supported attributes, rule conditions, attribute priority, and the simulator, see Access Templates.

FAQ

Yes. Zero Touch Onboarding is optional. You can continue to onboard manually via Slack or the web interface. Auto-assignment only applies to HRIS-triggered onboardings.
If a required attribute is empty or not provided by your HRIS, the condition will not match. The template will not be assigned automatically, but can still be selected manually.
Last modified on August 5, 2026