AccessOwl’s HRIS integrations are read-only and take just a few easy steps to set up.
Setup
- Go to Settings → Directory Integrations.
- Find the HRIS section and select Connect.
- Search for your HRIS provider and follow the setup flow.
Permissions We Request and Why
AccessOwl reads employee data from your HRIS in order to assign new joiners the right access automatically and to offboard them on time. In order to do so AccessOwl requests the read permissions below. The HRIS integration is read-only, and AccessOwl only requests the fields it needs for this automation. All write permissions are disabled. AccessOwl reads your employee data, your work locations and your team structure so that it can assign the correct Access Template and run Zero Touch Onboarding for you:Read employees
Read employees
AccessOwl reads employee number, first name, last name, display name, job title, work email, avatar, employment status, employment type, start date, end date, manager, work location and custom fields, plus record IDs and created, changed and deleted timestamps. Personal email is read as well.
- Job title, employment status, employment type, work location and custom fields let AccessOwl assign a new joiner to the right Access Template automatically. Custom fields are read so you can drive that assignment off your own HR fields.
- Start date and end date of the contract let AccessOwl trigger the onboarding automatically, and the offboarding when the end date is reached.
- Personal email lets AccessOwl send a newly onboarded employee the access details for their new business email account, because they cannot receive them in that mailbox yet.
- Manager is used for approvals and notifications.
- Employee number, names, display name, work email and avatar identify the person inside AccessOwl.
- Record IDs and timestamps let AccessOwl detect what changed since the last sync.
Read work locations
Read work locations
AccessOwl reads the name, address and type of your work locations. These are your company’s office and site locations, not the home addresses of your employees.Work location is one of the attributes you can use to decide which Access Template a new joiner receives.
Read groups
Read groups
AccessOwl reads the name and type of your groups, which represent your team and department structure.Team and department are among the most common attributes for deciding which Access Template a new joiner receives.
HRIS Settings
If you’re unsure how to set up your HRIS integration, review the documentation below for an explanation of each setting and our recommended configuration.Update Manager Information
Update Manager Information
AccessOwl imports each employee’s manager information for these key reasons:
- It streamlines access requests and approval workflows.
- It is essential for Access Reviews.
If an employee doesn’t have a manager listed, AccessOwl will treat them as an executive, meaning they won’t need approval for their requests.
Import Users from HRIS
Import Users from HRIS
AccessOwl creates user profiles for employees who don’t already have one. Most users are typically added via integrations like Slack, Google Workspace, or Microsoft 365.
Exclude Users Without Company Emails
Exclude Users Without Company Emails
If your HR team uses personal emails for new employees:
- Enable this filter to ensure AccessOwl only adds users with emails in your company’s domain.
- Helps maintain an accurate and organized user list.
Onboard Users Discovered in HRIS
Onboard Users Discovered in HRIS
When activated:
- AccessOwl sends a notification when a new employee is added to HRIS with a future start date.
- Your onboarding team can schedule onboarding and assign access or use templates.
When this setting is off, AccessOwl does not start an onboarding for new hires discovered in your HRIS. This goes beyond muting notifications, no onboarding is created at all, so you will need to onboard those employees manually.
Offboard Terminated Users
Offboard Terminated Users
When activated:
- Employees are automatically offboarded on their last workday by default at 8 PM (local time). Time can be adjusted indivdually.
- AccessOwl sends notifications about upcoming offboarding, allowing cancellations or rescheduling.
If connected to Google Workspace or Microsoft 365: - The user’s account is automatically suspended.
- All access tracked by AccessOwl is revoked.
FAQ
Can I connect two HRIS to one AccessOwl tenant?
Can I connect two HRIS to one AccessOwl tenant?
No. AccessOwl supports a single HRIS per tenant.
Slack or Google Workspace has the highest source priority. Do HRIS attributes still sync?
Slack or Google Workspace has the highest source priority. Do HRIS attributes still sync?
Yes. Departments, teams, job title, employment type, and location come from your HRIS alone, so they are filled in from the HRIS regardless of its position in the ranking. The system at the top decides the name and email. See Source Priority.
What if my HRIS is not supported, or we run two HR platforms?
What if my HRIS is not supported, or we run two HR platforms?
Push the employee fields (start date, end date, role, location, department, team) from your HR system into Google Workspace, then use Google Workspace as your HRIS source.
- Most HRIS vendors support a Google Workspace sync even when they have no public API.
- Tell AccessOwl the schema name you used and the sync gets activated.

