01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Automated Employee Onboarding |
| 9.7% | 43 43 active |
| Employee Offboarding & Termination |
| 2.4% | 27 27 active |
| Access Request & Group Provisioning |
| 74.0% | 29 29 active |
| Temporary Access Control | 68 executions | 0.1% | 18 18 active |
| Identity Directory Sync & Maintenance | 504 executions | 0.8% | 26 26 active |
| Google Workspace Administration | 451 executions | 0.7% | 21 21 active |
| Access Operations SLA & Reporting | 298 executions | 0.5% | 14 14 active |
| Audit Log Pipeline & Platform Health | 6,806 executions | 11.3% | 2 2 active |
| Total | 60,201 executions | 100% | 180 180 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
Deeply integrated end-to-end lifecycle automation. PM Group has built one of the most complete IAM lifecycle automation stacks observed — new hire events in HiBob propagate through account creation in six systems, group assignments, SecHub identity linking, welcome email, and SLA tracking with no manual handoffs. The HiBob webhook parser alone processed 2,063 lifecycle events in 12 months.
High-volume access request throughput at scale. The access request flow (Process Access Request Ticket + AD/AMS Group flows) handled 1,175 requests and executed 1,577 group membership changes autonomously. The SLA tracking layer (20,806 events) provides real-time operational visibility that would be impossible to maintain manually.
Custom identity platform integration (SecHub & AMS). Unlike most customers who work with off-the-shelf directories, PM Group has built deep automation around two proprietary internal systems — SecHub (their HR/identity registry) and AMS (GR8Tech access management). The depth of integration (create, link, status sync, manual review, delete) is a significant implementation investment.
Proactive scheduling and operational resilience. Multiple scheduled safety nets exist — pre-activation checks 1 day and same-day before start dates, morning/evening termination checks, daily webhook monitoring, and weekly SLA data quality runs — demonstrating mature operational thinking beyond simple reactive automation.
Audit log compliance pipeline. Running 4,885 times in 12 months (every 30 minutes), the S3 audit backup is one of the most execution-heavy playbooks and reflects a clear compliance or regulatory driver for long-term log retention.
Google Drive data custody now automated during offboarding. New Drive-transfer workflows (Google Drive Transfer, transfer status check, bridge-account finish, person-transfer finish) handled 93 combined executions, ensuring departing employees' files are preserved and reassigned rather than orphaned — closing a common offboarding
gap.
Expanding investment in identity data quality. PM Group added a substantial suite of scheduled and on-demand data-integrity tooling — duplicate employee/account detection and merge, SecHub ambiguous-ownership scanning, account-mismatch scanning and auto-patch, and removed-account cleanup — reflecting growing maturity in keeping SecHub and directory data clean without manual audits.
Gaps & Opportunities
Temporary access control is beginning to see production use, but adoption is uneven. The Block/Reinstate use case has grown to 19 playbooks, and the Daily Reinstate check (37 executions) plus a new InfoSec-driven block path (InfoSec Block webhook, 6 executions) show real activity. However, most of the underlying per-system Block/Reinstate subflows (AD, AMS, Google Workspace, Slack, Asana, 1Password) still show 0 executions, meaning many block/reinstate actions may still be handled outside the orchestrator.
No automated Atlassian offboarding. Atlassian user operations (Suspend, Remove, group management) appear in the access request flow but are absent from the Master Dismissal orchestration. Atlassian suspension must currently be handled manually during terminations.
Re-hire volume is low but the flow exists. Only 13 re-hire setups were completed via the automated flow, and the re-hire subflows (AD Re-hire Update, AMS re-hire) show single-digit usage. If re-hires are being processed partially manually, this is an opportunity to drive all volume through the automated path.
Agent-generated compliance playbooks are unused. Three AI agent–generated playbooks (Asana/HiBob reconciliation, user count) have 0 executions. The compliance reconciliation use case (cross-referencing Asana users against HiBob active employees) is high value and worth operationalizing.
Azure group changes are minimal (12 executions) vs. AD (948) and AMS (629). Either Azure AD group management is handled elsewhere, or there is underutilization of the existing Azure Groups Add\Remove automation.
A growing volume of 0-execution SecHub/directory maintenance tooling. Roughly half of the new Identity Directory Sync & Maintenance playbooks (SecHub - Entity Migration, AD Employee Patch, SecHub Ambiguous Ownership Scan, Open CSV file, AD email update (asana), sechub delete by integration ID, duplicated employee merge, Duplicated accounts per employee, Patch employee status, Account_mismatches) have not yet run. These appear to be recently built maintenance/data-quality tools awaiting rollout or first use.
Integration Ecosystem
| Integration | Use Cases |
|---|---|
| HiBob | Onboarding trigger, offboarding trigger, user status check, email group sync |
| Active Directory (LDAP) | Account create/delete/modify, group management, re-hire, email/data patch and reconciliation |
| Google Workspace | Account create/delete/block/unblock, group management, OU sync, device management, Drive transfer |
| AMS (GR8Tech) | Account create/delete/block, group management, user export, re-hire |
| SecHub | Identity record create/delete/link, status sync, manual review, entity migration, dedup/cleanup |
| Asana | Access request intake, ticket management, user provisioning/deprovisioning, onboarding Slack channel setup |
| Atlassian | User suspend/remove/activate, group management, email update, Confluence inactivity suspension |
| Slack | User invite, account disable/reinstate, channel create/archive |
| Azure AD / Entra ID | Account disable/reinstate/block, session revocation, group management, VDI data |
| 1Password | User suspend, group management |
| Azure Blob Storage | AMS user export, JSON data store for onboarding blobs |
| AWS S3 | Audit log long-term retention |
| Google Sheets | AVD reporting, SecHub manual review, employee lookup |
| N8N | Webhook source for E3 license automation |
A Case Management
Case Management
No case management data found for this customer.
B AI Agents 1 active | 3 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Asana Access Auditor | Access_team | 3 | 0 | 415,239 |
| 2 | Agent Blink | Access_team | 0 | 0 | 0 |
| 3 | Agent Blink | oleksii.b@pm.group | 0 | 0 | 0 |
| 4 | Software review agent | InfoSec | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| Access_team | 3 |
| oleksii.b@pm.group | 0 |
| InfoSec | 0 |
C Self-Service & Webforms
Self-Service Applications
No self-service usage data found for this customer.
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 8 use cases | 60,457 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Employee HR lifecycle events automatically routed | 2,063 | HiBob webhook parser |
| Access requests processed end-to-end | 1,175 | Process Access Request Ticket |
| AD group membership changes executed | 948 | AD Groups Add\Remove |
| AMS group membership changes executed | 629 | AMS Groups Add\Remove |
| M365 E3 license assignments automated | 127 | E3 License automation |
| Google Workspace accounts provisioned | 103 | Create GW Account |
| Active Directory accounts created | 99 | Create AD Account |
| New-hire onboarding flows initiated | 97 | Onboarding |
| SecHub identity records created | 94 | Create SecHub account |
| Asana users deprovisioned | 92 | Asana User Remove |
| Full onboarding provisioning sequences completed | 86 | Onboarding - Master Provisioning |
| Access profiles reviewed & approved | 73 | Onboarding - Manage Access |
| AMS accounts provisioned | 71 | Create AMS account |
| Atlassian users suspended | 52 | Atlassian Suspend User |
| Employee offboarding events processed | 44 | Offboarding webhook |
| Google Drive transfers completed during offboarding | 40 | Google Drive Transfer |
| Access request webhook events auto-routed | 36 | Access Request Router |
| AMIS role checks executed on dismissal | 34 | AMIS approvers |
| Finance license checks executed on dismissal | 34 | Asana Finance licenses check |
| Post-onboarding access verifications completed | 31 | post-onboarding verification |
| Slack channels created for new hires | 26 | Create Slack Channel |
| Employee terminations fully executed | 16 | Master Dismissal |
| Re-hire identity setups completed | 13 | Re-hire Identity Accounts |
Use Case Summary
| # | Use Case | Category | Total Playbooks | Active Playbooks |
|---|---|---|---|---|
| 1 | Automated Employee Onboarding | IAM | 41 | 33 |
| 2 | Employee Offboarding & Termination | IAM | 29 | 24 |
| 3 | Access Request & Group Provisioning | IAM | 29 | 24 |
| 4 | Temporary Access Control | IAM | 19 | 4 |
| 5 | Identity Directory Sync & Maintenance | IAM | 28 | 16 |
| 6 | Google Workspace Administration | Other | 21 | 16 |
| 7 | Access Operations SLA & Reporting | GRC | 16 | 10 |
| 8 | Audit Log Pipeline & Platform Health | Cloud Security | 2 | 2 |
| Total | 185 | 129 |
Use Cases
1. Automated Employee Onboarding
Description: End-to-end onboarding automation triggered by HiBob HR events. Creates accounts across AD, Google Workspace, AMS (GR8Tech), SecHub, Slack, and Asana; resolves role-based access profiles; and manages start-date activation through scheduled pre-activation checks and a structured human-approval web form flow.
Business Problem: Manual onboarding across six-plus identity systems creates multi-day delays, inconsistency, and security gaps. A single new hire requires coordinated account creation, group assignments, and a welcome experience across every platform simultaneously.
Category: IAM
Subcategories: Employee onboarding · Identity lifecycle automation · Full employee lifecycle
Key Integrations: HiBob · Active Directory (LDAP) · Google Workspace · AMS (GR8Tech) · SecHub · Slack · Asana · Atlassian · Azure Blob Storage · Blink Web Forms
| Playbook | Executions | Role |
|---|---|---|
| HiBob webhook parser | 2,063 | Primary event trigger — routes all HiBob lifecycle events to onboarding and offboarding flows |
| Onboarding | 97 | Orchestrator — initiates onboarding sequence from HiBob hire event |
| Onboarding - Master Provisioning | 86 | Orchestrator — provisions accounts, assigns groups, sends welcome email |
| Onboarding - Manage Access | 73 | Web form — interactive access profile review and approval |
| Create Identity Accounts | 69 | Web form — human-guided identity account creation with conflict detection |
| Create Identity Accounts (Auto) | 53 | On-demand — automated version of identity account creation |
| Start Date Trigger | 76 | Scheduled — triggers provisioning for all employees starting today |
| Onboarding - Pre-Activation Check (1 Day Ahead) | 76 | Scheduled — readiness check for employees starting the next day |
| Onboarding - Pre-Activation Check (Same Day) | 76 | Scheduled — same-day activation check for employees starting today |
| Provide onboarding instructions | 76 | Subflow — adds employee to Google instruction groups |
| Remove onboarding instructions | 54 | Subflow — removes temporary instruction group access |
| Create GW Account | 103 | Subflow — creates Google Workspace account with dynamic connection |
| Create AD Account | 99 | Subflow — creates Active Directory account via LDAP |
| Create SecHub account | 94 | Subflow — creates SecHub identity record and sets hiring status |
| Create AMS account | 71 | Subflow — creates AMS (GR8Tech) account |
| Onboarding - Cancellation | 30 | Web form — cancels a pending onboarding with confirmation |
| Re-hire Identity Accounts | 13 | Web form — manages identity account setup for returning employees |
| Create Custom Account | 10 | Web form — manual account creation bypass for contractors or edge cases |
| AD Re-hire Update | 10 | Subflow — updates existing AD account for re-hire (enable, OU, password) |
| Onboarding - Start date update | 6 | Web form — updates start date for a pending onboarding |
| Re-hire password update | 6 | Subflow — resets SecHub passwords for re-hired employees |
| AMS re-hire | 3 | Subflow — unblocks AMS account and restores groups for re-hires |
| secHub create and link accounts from google sheet | 24 | On-demand — bulk imports and links accounts from a Google Sheet |
| Assign AD groups | 169 | Subflow — assigns AD group memberships during provisioning |
| SecHub - Link Accounts | 192 | Subflow — links all created accounts to the SecHub identity record |
| Slack Invite | 79 | Subflow — invites user to Slack workspace and handles re-activation |
| Resolve Access Profile | 89 | Subflow — resolves role-based group/app access from profile name |
| SecHub - Check | 86 | Subflow — verifies SecHub employee record exists |
| Build Access Plan and Asana comment | 69 | Subflow — builds provisioning plan and posts to Asana ticket |
| Notify HR Webhook | 68 | Subflow — notifies HR system of completion |
| Trigger SecHub webhook | 62 | Subflow — sets EMPLOYED status and triggers SecHub webhook |
| Daily webhook check | 48 | Scheduled — monitors for missed HiBob hire events |
| Assign GW Groups | 15 | Subflow — assigns Google Workspace group memberships |
| Asana invite | 4 | Subflow — invites user to Asana workspace |
| Create SecHub Employee and Link Accouts | 1 | Subflow — creates SecHub employee and links all accounts in one call |
| HiBob_Fetch_Status | 0 | Utility — fetches HiBob employee statuses (data-fetch helper) |
| SecHub_Fetch_Registry | 0 | Utility — fetches full SecHub registry (data-fetch helper) |
| Create Slack Channel | 26 | Subflow — creates an onboarding Slack channel and invites employee, HR, manager, and accountant |
| Archive Slack channel | 23 | Subflow — archives the onboarding Slack channel once no longer needed |
| post-onboarding verification | 31 | On-demand — verifies all provisioned account access after onboarding completes |
| Create custom AD account | 0 | Web form — manual AD account creation across all PM Group business entities |
| (NON PROD VERSION)Asana invite | 0 | On-demand — non-production test variant of the Asana invite subflow |
| Activate AD account | 0 | On-demand — activates an existing AD account by SAM/email lookup (re-hire/reactivation) |
2. Employee Offboarding & Termination
Description: Automated employee termination workflow triggered by HiBob lifecycle events or manual web forms. Disables accounts and revokes group memberships across AD, AMS, Google Workspace, Azure, Slack, and Asana; decommissions the SecHub identity record; and runs scheduled morning/evening checks to ensure timely execution on the last working day.
Business Problem: Incomplete or delayed offboarding leaves terminated employees with active access across multiple systems, creating critical security and compliance exposure. Manual cross-system deprovisioning is error-prone and often takes days.
Category: IAM
Subcategories: Employee offboarding · Full employee lifecycle · Identity lifecycle automation
Key Integrations: HiBob · Active Directory (LDAP) · Google Workspace · AMS (GR8Tech) · Azure AD / Entra ID · Slack · Asana · SecHub · Blink Web Forms
| Playbook | Executions | Role |
|---|---|---|
| Offboarding webhook | 44 | Orchestrator — initiates offboarding sequence from webhook event |
| Master Dismissal | 16 | Orchestrator — executes full cross-system termination sequence |
| Termination - Morning Check | 29 | Scheduled — morning review of pending terminations, Slack alerts |
| Termination - Evening Check | 29 | Scheduled — evening review and last-working-day processing |
| Change position SecHub | 50 | On-demand — updates employee entity/position in SecHub |
| Termination - Manage | 10 | Web form — HR-initiated termination management interface |
| Daily Dismissal Ticket Check | 8 | Scheduled — ensures Asana termination tickets are created on time |
| Dismissal manual run (without HiBob) | 5 | Web form — manual termination bypass when HiBob event is unavailable |
| Update Dismissal date | 3 | On-demand — updates last working day in blob and Asana |
| Cancel Dismissal | 0 | On-demand — cancels a pending dismissal record |
| Reinstate Dismissal | 0 | On-demand — reinstates a previously cancelled dismissal |
| Disable AD Account and Remove Groups | 17 | Subflow — disables AD account and removes all group memberships |
| Disable Slack Account | 24 | Subflow — deactivates Slack account via SCIM |
| Delete SecHub Account | 24 | Subflow — removes employee record from SecHub |
| Disable Google Workspace | 19 | Subflow — suspends and signs out Google Workspace user |
| Delete AD Account | 19 | Subflow — deletes Active Directory account via LDAP |
| Disable AMS Account and Remove Groups | 15 | Subflow — blocks AMS account and removes group memberships |
| Sync SecHub Account Status | 15 | Subflow — syncs termination status back to SecHub |
| Disable Azure account | 16 | Subflow — disables Entra ID account and revokes sessions |
| Delete GW Account | 17 | Subflow — deletes Google Workspace account |
| Disable Asana Account | 13 | Subflow — deactivates Asana workspace membership |
| Delete AMS account | 12 | Subflow — deletes AMS account |
| Create Asana Tickets from AMIS | 12 | Subflow — creates Asana child tickets for AMIS-specific actions |
| Google Drive Transfer | 40 | On-demand — initiates Google Drive file transfer for a departing employee |
| check google drive transfer status | 31 | On-demand — monitors an in-progress Drive transfer and routes to person or bridge-account completion |
| Google Drive Bridge account finish | 3 | On-demand — completes bridge-account Drive transfer (folder recreation, file move, cleanup) |
| Google Drive Person transfer finish | 19 | On-demand — completes person-to-person Drive transfer with optional account deletion |
| Asana Finance licenses check | 34 | On-demand — pulls licenses held by a departing employee and opens a Finance ticket |
| AMIS approvers | 34 | On-demand — checks AMIS approver roles held by a departing employee on dismissal |
3. Access Request & Group Provisioning
Description: Automated handling of access requests submitted through Asana tickets. Processes group membership additions and removals across AD, AMS, Azure, Atlassian, 1Password, and Asana; automates M365 E3 license assignments from N8N webhook events; and tracks SLA compliance for every request in real time.
Business Problem: High-volume access request management (1,175+ per year) across seven identity platforms cannot scale with manual processing. Every delay increases both security risk and employee productivity loss.
Category: IAM
Subcategories: Access review & group mgmt · JIT & temporary access
Key Integrations: Asana · Active Directory · AMS (GR8Tech) · Azure AD · Atlassian · 1Password · Slack · SecHub · N8N (webhook source)
| Playbook | Executions | Role |
|---|---|---|
| Process Access Request Ticket | 1,175 | Orchestrator — processes Asana access tickets end-to-end |
| Access Operation - SLA update | 20,806 | Event — records SLA data on every access ticket status change |
| AD Groups Add\Remove | 948 | Orchestrator — processes AD group add/remove operations |
| AMS Groups Add\Remove | 629 | Orchestrator — processes AMS group add/remove operations |
| E3 License automation | 127 | Event — automates M365 E3 license assignment from N8N webhook |
| Asana User Remove | 92 | On-demand — removes user from Asana workspaces |
| Atlassian Suspend User | 52 | On-demand — suspends Atlassian user across org |
| Update users in Google email groups | 46 | Scheduled — syncs HiBob employment status to Google email groups |
| Access Look up | 45 | On-demand — looks up current user accesses across all systems |
| 1Password Groups Add\Remove | 26 | On-demand — processes 1Password group membership changes |
| 1Password Suspend User. Dynamic spaces | 25 | On-demand — suspends 1Password user with dynamic instance lookup |
| Azure Groups Add\Remove | 12 | On-demand — processes Azure AD group membership changes |
| Atlassian Add user to group | 9 | On-demand — adds user to Atlassian group |
| Atlassian Update User Email | 7 | On-demand — updates Atlassian user email address |
| 1Password Suspend User | 6 | On-demand — suspends 1Password user (static space config) |
| AMS - Remove Specific groups | 6 | On-demand — removes specific AMS group memberships by email |
| Atlassian Remove User | 5 | On-demand — removes user from Atlassian organization |
| Atlassian Activate User | 3 | On-demand — re-activates a suspended Atlassian user |
| Slack remove users from channel | 3 | Subflow — removes users from Slack channels |
| Confluence 60-days suspend | 1 | Scheduled — suspends Confluence users inactive for 60+ days |
| Atlassian Remove user from group | 1 | On-demand — removes user from Atlassian group |
| Get Users ID by email | 77 | Subflow — resolves Atlassian user IDs from email addresses |
| Atlassian Define OrgID and DirectoryID | 77 | Subflow — resolves Atlassian org and directory IDs by name |
| Get Group ID by name | 10 | Subflow — resolves Atlassian group IDs from group names |
| List converter | 7 | Utility — converts email list formats for downstream steps |
| Clear table by ticket ID | 1 | Utility — clears table records by ticket ID |
| Add users to project/portfolio | 0 | On-demand — adds users to Asana projects/portfolios (unused) |
| Confluence NUC 60-days suspend | 3 | Scheduled (weekly) — suspends NUC-organization Confluence users inactive 60+ days |
| Access Request Router | 36 | Event — parses inbound access-request webhook and computes final ticket status/comment |
4. Temporary Access Control
Description: A complete workflow suite for temporarily blocking and reinstating employee access across all identity systems — AD, AMS, Google Workspace, Azure, Slack, Asana, and 1Password — without triggering a full offboarding. Includes a unified management web form, per-system block/reinstate subflows, a daily reinstatement check, and an InfoSec-triggered block path for security-driven access suspensions.
Business Problem: Employees on leave, under HR review, or in dispute resolution need a reversible access suspension mechanism that doesn't permanently delete accounts or trigger the full termination process. Security incidents also require a fast, auditable way to suspend access outside the standard offboarding flow.
Category: IAM
Subcategories: JIT & temporary access
Key Integrations: Active Directory · AMS · Google Workspace · Azure AD · Slack · Asana · 1Password · SecHub
| Playbook | Executions | Role |
|---|---|---|
| Temporary block - Manage | 0 | Web form — unified interface: Block / Reinstate / Start Dismissal / Update date |
| Master Block | 0 | Orchestrator — blocks access across all identity systems |
| Master Reinstate | 0 | Orchestrator — reinstates access across all identity systems |
| Block AD | 0 | Subflow — blocks Active Directory account |
| Block AMS | 0 | Subflow — blocks AMS account |
| Block Google Workspace | 0 | Subflow — suspends Google Workspace account |
| Disable 1Password | 0 | Subflow — suspends 1Password account |
| Reinstate AD | 0 | Subflow — re-enables Active Directory account |
| Reinstate AMS | 0 | Subflow — re-enables AMS account |
| Reinstate Azure | 0 | Subflow — re-enables Azure account |
| Reinstate 1Password | 0 | Subflow — re-enables 1Password account |
| Remove Manual Override | 0 | On-demand — removes manual block flag from table record |
| Daily Reinstate check | 37 | Scheduled (daily) — checks for pending reinstatements and triggers per-system reinstate flows |
| Reinstate Google Workspace | 0 | Subflow — re-activates a suspended Google Workspace account |
| Reinstate Slack | 0 | Subflow — re-activates a deactivated Slack account via SCIM |
| Reinstate Asana | 0 | Subflow — re-invites a removed user to the Asana workspace |
| Block Azure account | 2 | On-demand — disables Azure/Entra ID account and revokes active sessions |
| InfoSec Block webhook | 6 | Event — receives InfoSec block requests, opens an AMIS ticket, and triggers access block |
| Infosec - Resolve access and update Asana ticket | 4 | Subflow — resolves flagged access and updates the related Asana ticket |
5. Identity Directory Sync & Maintenance
Description: Scheduled and on-demand workflows that keep identity data consistent across systems. Covers OU management in Google Admin, Azure VDI reporting, daily AMS-to-Azure data exports, SecHub manual review reporting, employee lookup tooling, and a growing suite of data-quality automation — duplicate employee/account detection and merge, account-mismatch scanning and patching, entity migration, and removed-account cleanup.
Business Problem: Identity directories drift apart without continuous synchronization. Stale OU assignments, outdated VDI data, duplicate or ambiguously-owned accounts, and inconsistent employment records across HR and identity systems create audit failures and access anomalies.
Category: IAM
Subcategories: Identity sync & directory mgmt · Identity lifecycle automation
Key Integrations: AMS (GR8Tech) · Azure Blob Storage · Azure AD / Entra ID · Google Workspace · Active Directory (LDAP) · HiBob · SecHub · Google Sheets
| Playbook | Executions | Role |
|---|---|---|
| AMS Users Export to Azure | 147 | Scheduled (daily) — exports AMS user data to Azure Blob Storage |
| AVD Info | 80 | Scheduled (daily) — syncs Azure Virtual Desktop data to Google Sheets |
| SecHub - Get Manual Review | 34 | On-demand — fetches SecHub manual review items and writes to Google Sheet |
| OU Updater | 44 | Scheduled (daily) — updates Google Workspace user OU assignments |
| hiBob user status check | 23 | On-demand — checks HiBob employment status for a list of emails |
| Search Employee | 21 | On-demand — searches employee data from Google Sheets with a web form |
| secHub employee\accounts search | 3 | On-demand — looks up SecHub employee records and linked accounts |
| Asana_Export_Users | 0 | Utility — exports full Asana user list (data-fetch helper) |
| Azure JSON view | 0 | Utility — reads JSON files from Azure Blob Storage |
| Sechub - Delete from account matches | 5 | On-demand — bulk-removes SecHub accounts matching a supplied email list |
| SecHub - Entity (Company) Migration | 0 | On-demand — migrates employee records between company entities in SecHub |
| AD Employee Patch | 0 | On-demand — reconciles HiBob and SecHub employee data into AD |
| Daily PATCH check | 15 | Scheduled (daily) — scans identity data for patch-worthy discrepancies |
| SecHub Ambiguous Ownership Scan | 0 | On-demand — scans for accounts with ambiguous SecHub ownership |
| SecHub Re-link Account | 10 | On-demand — re-links an account to a different SecHub identity |
| Open CSV file | 0 | Utility — reads and parses an uploaded CSV file (data-fetch helper) |
| Email change | 2 | Event — routes an email-change webhook to the correct per-system update flow |
| AD email update | 1 | On-demand — updates AD email/SAM mappings in bulk |
| AD email update (asana) | 0 | On-demand — updates a single AD account's email and posts result to Asana |
| sechub delete accounts by integration ID | 0 | On-demand — deletes all SecHub accounts tied to a given integration ID |
| duplicated employee merge | 0 | On-demand — merges duplicate employee records and their linked accounts |
| Duplicated accounts per employee | 0 | On-demand — detects and cleans up duplicate/mis-assigned accounts per employee |
| Patch employee status | 0 | On-demand — patches an employee's status field in SecHub |
| SecHub-Removed-Account-Cleanup | 2 | Scheduled (daily) — cleans up accounts already removed from source systems |
| daily duplicated employee\accounts scan | 2 | Scheduled (daily) — scans for duplicated employees/accounts and alerts if found |
| Account_mismatches | 0 | Scheduled — scans for account/employee data mismatches and alerts if needed |
| PATCH accounts for Account_mismatches | 7 | Event — patches accounts flagged by the Account_mismatches scan |
| OU Updater | 16 | Scheduled (daily) — second OU assignment sync job across available Google Workspace suites |
6. Google Workspace Administration
Description: On-demand IT administration toolkit for Google Workspace covering user lifecycle management (create, block, unblock, delete, OU change, password reset), group management, 2FA code generation, device management, and audit log retrieval. Serves as a self-service operations layer for the access team.
Business Problem: Access team members need a reliable, auditable interface for routine Google Workspace operations without direct admin console access. Each action needs to be logged, repeatable, and executable by non-admin staff.
Category: Other
Subcategories: SaaS / IT administration
Key Integrations: Google Workspace (Admin Console) · Google Drive · Google Groups · Blink Web Forms
| Playbook | Executions | Role |
|---|---|---|
| User Devices Manager - Main | 46 | On-demand — interactive device management with web form actions |
| Get User Info | 34 | On-demand — retrieves full GWS user profile information |
| Create User | 28 | On-demand — creates a new Google Workspace user |
| View G-Drive link information | 23 | On-demand — inspects Google Drive file sharing and access details |
| Reset User Password | 16 | On-demand — generates and sets a random GWS user password |
| Get Group Info | 16 | On-demand — retrieves Google group details and membership list |
| User 2FA Codes Generation | 13 | On-demand — generates 2FA backup codes for a GWS user |
| Block User | 11 | On-demand — suspends a Google Workspace user account |
| Change User OU | 9 | On-demand — moves a GWS user to a different organizational unit |
| Add Users to Group | 8 | On-demand — adds one or more users to a Google group |
| Create Group & Add Users | 7 | On-demand — creates a new Google group and adds initial members |
| Check Transfer and Delete User | 5 | On-demand — handles Drive transfer and conditional user deletion |
| Remove Users From Group | 5 | On-demand — removes users from a Google group |
| Delete Group | 3 | On-demand — deletes a Google Workspace group |
| Get Admin Logs | 3 | On-demand — retrieves Google Workspace admin audit logs |
| User Devices Manager - Subflow | 46 | Subflow — device action loop for User Devices Manager - Main |
| View User Drive Log | 0 | On-demand — retrieves user Google Drive activity log (unused) |
| Log Manager | 0 | On-demand — retrieves various GWS activity logs (unused) |
| Create: user\fille\delete | 0 | Test — prototype test playbook (unused) |
| Unblock User | 1 | On-demand — re-activates (unblocks) a suspended Google Workspace user account |
| Create User copy | 1 | On-demand — creates a Google Workspace user with try/catch error handling |
7. Access Operations SLA & Reporting
Description: Real-time SLA monitoring and reporting for the access request operation, tracking ticket open/close rates, processing time, and per-analyst performance via Blink dashboard widgets. Includes Asana ticket search/export tooling, data quality checks, quarterly P90 completion-time reporting, and AI agent–generated compliance reports.
Business Problem: Access operations teams need visibility into request volumes, SLA adherence, and individual workload distribution. Without automated reporting, management relies on manual spreadsheet aggregation that is always stale.
Category: GRC
Subcategories: Security metrics & reporting · RBAC review & access mgmt
Key Integrations: Asana · Blink Tables · Blink Dashboards (widget update) · Google Sheets · Email
| Playbook | Executions | Role |
|---|---|---|
| SLA - General | 86 | Event — updates general SLA dashboard widgets (open/closed/AMIS) |
| Asana tickets search | 86 | On-demand — searches all Asana tickets associated with user emails |
| SLA - Sofiia Shepelieva | 13 | Event — per-analyst SLA dashboard update |
| SLA - Data Quality | 9 | Scheduled (weekly) — monitors SLA table data quality and flags anomalies |
| SLA - Sergey Troyan | 8 | Event — per-analyst SLA dashboard update |
| SLA - Daria Puhakova | 7 | Event — per-analyst SLA dashboard update |
| Asana tickets export | 7 | On-demand — exports Asana ticket data for a date range to email |
| SLA - Iryna Kril | 5 | Event — per-analyst SLA dashboard update |
| Total update | 0 | On-demand — bulk recalculation of SLA totals (maintenance tool) |
| Update type field | 0 | On-demand — backfills empty ticket type fields (maintenance tool) |
| Run review | 0 | On-demand — runs AI agent–based Asana access audit (unused) |
| Agent Generated: count_asana_users | 0 | Agent-generated — counts active Asana users (unused) |
| Agent Generated: count_asana_users_v2 | 0 | Agent-generated — counts active Asana users v2 (unused) |
| Agent Generated: asana_hibob_compliance_report | 0 | Agent-generated — reconciles Asana users against HiBob status (unused) |
| SLA - P90 quater | 0 | On-demand — calculates quarterly P90 SLA completion time for tickets |
| SLA - Check open tickets in Asana | 1 | Scheduled (daily) — checks open Asana tickets against SLA thresholds |
8. Audit Log Pipeline & Platform Health
Description: Continuous Blink audit log backup running every 30 minutes, shipping logs to AWS S3 for long-term retention and compliance. Paired with automated failure notification that emails the team on any workflow execution error.
Business Problem: Blink-native audit logs have limited retention. A compliance-driven need to retain audit trails for regulatory and forensic purposes requires continuous export to a durable external store. Workflow failures need immediate team visibility without manual log monitoring.
Category: Cloud Security
Subcategories: SIEM & log pipeline monitoring
Key Integrations: AWS S3 · Email (Blink native)
| Playbook | Executions | Role |
|---|---|---|
| Blink Audit Log S3 Backup | 4,885 | Scheduled (every 30 min) — exports Blink audit logs to AWS S3 |
| Blink Error Messaging | 42 | Event — sends email notification on any workflow execution failure |
Key Observations
Strengths
Deeply integrated end-to-end lifecycle automation. PM Group has built one of the most complete IAM lifecycle automation stacks observed — new hire events in HiBob propagate through account creation in six systems, group assignments, SecHub identity linking, welcome email, and SLA tracking with no manual handoffs. The HiBob webhook parser alone processed 2,063 lifecycle events in 12 months.
High-volume access request throughput at scale. The access request flow (Process Access Request Ticket + AD/AMS Group flows) handled 1,175 requests and executed 1,577 group membership changes autonomously. The SLA tracking layer (20,806 events) provides real-time operational visibility that would be impossible to maintain manually.
Custom identity platform integration (SecHub & AMS). Unlike most customers who work with off-the-shelf directories, PM Group has built deep automation around two proprietary internal systems — SecHub (their HR/identity registry) and AMS (GR8Tech access management). The depth of integration (create, link, status sync, manual review, delete) is a significant implementation investment.
Proactive scheduling and operational resilience. Multiple scheduled safety nets exist — pre-activation checks 1 day and same-day before start dates, morning/evening termination checks, daily webhook monitoring, and weekly SLA data quality runs — demonstrating mature operational thinking beyond simple reactive automation.
Audit log compliance pipeline. Running 4,885 times in 12 months (every 30 minutes), the S3 audit backup is one of the most execution-heavy playbooks and reflects a clear compliance or regulatory driver for long-term log retention.
Google Drive data custody now automated during offboarding. New Drive-transfer workflows (Google Drive Transfer, transfer status check, bridge-account finish, person-transfer finish) handled 93 combined executions, ensuring departing employees' files are preserved and reassigned rather than orphaned — closing a common offboarding gap.
Expanding investment in identity data quality. PM Group added a substantial suite of scheduled and on-demand data-integrity tooling — duplicate employee/account detection and merge, SecHub ambiguous-ownership scanning, account-mismatch scanning and auto-patch, and removed-account cleanup — reflecting growing maturity in keeping SecHub and directory data clean without manual audits.
Gaps & Opportunities
Temporary access control is beginning to see production use, but adoption is uneven. The Block/Reinstate use case has grown to 19 playbooks, and the Daily Reinstate check (37 executions) plus a new InfoSec-driven block path (InfoSec Block webhook, 6 executions) show real activity. However, most of the underlying per-system Block/Reinstate subflows (AD, AMS, Google Workspace, Slack, Asana, 1Password) still show 0 executions, meaning many block/reinstate actions may still be handled outside the orchestrator.
No automated Atlassian offboarding. Atlassian user operations (Suspend, Remove, group management) appear in the access request flow but are absent from the Master Dismissal orchestration. Atlassian suspension must currently be handled manually during terminations.
Re-hire volume is low but the flow exists. Only 13 re-hire setups were completed via the automated flow, and the re-hire subflows (AD Re-hire Update, AMS re-hire) show single-digit usage. If re-hires are being processed partially manually, this is an opportunity to drive all volume through the automated path.
Agent-generated compliance playbooks are unused. Three AI agent–generated playbooks (Asana/HiBob reconciliation, user count) have 0 executions. The compliance reconciliation use case (cross-referencing Asana users against HiBob active employees) is high value and worth operationalizing.
Azure group changes are minimal (12 executions) vs. AD (948) and AMS (629). Either Azure AD group management is handled elsewhere, or there is underutilization of the existing Azure Groups Add\Remove automation.
A growing volume of 0-execution SecHub/directory maintenance tooling. Roughly half of the new Identity Directory Sync & Maintenance playbooks (SecHub - Entity Migration, AD Employee Patch, SecHub Ambiguous Ownership Scan, Open CSV file, AD email update (asana), sechub delete by integration ID, duplicated employee merge, Duplicated accounts per employee, Patch employee status, Account_mismatches) have not yet run. These appear to be recently built maintenance/data-quality tools awaiting rollout or first use.
Integration Ecosystem
| Integration | Use Cases |
|---|---|
| HiBob | Onboarding trigger, offboarding trigger, user status check, email group sync |
| Active Directory (LDAP) | Account create/delete/modify, group management, re-hire, email/data patch and reconciliation |
| Google Workspace | Account create/delete/block/unblock, group management, OU sync, device management, Drive transfer |
| AMS (GR8Tech) | Account create/delete/block, group management, user export, re-hire |
| SecHub | Identity record create/delete/link, status sync, manual review, entity migration, dedup/cleanup |
| Asana | Access request intake, ticket management, user provisioning/deprovisioning, onboarding Slack channel setup |
| Atlassian | User suspend/remove/activate, group management, email update, Confluence inactivity suspension |
| Slack | User invite, account disable/reinstate, channel create/archive |
| Azure AD / Entra ID | Account disable/reinstate/block, session revocation, group management, VDI data |
| 1Password | User suspend, group management |
| Azure Blob Storage | AMS user export, JSON data store for onboarding blobs |
| AWS S3 | Audit log long-term retention |
| Google Sheets | AVD reporting, SecHub manual review, employee lookup |
| N8N | Webhook source for E3 license automation |
E New Integrations (detail) 2 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| pm-group | asana | asana_steppro_connection | 2026-08-12 |
| pm-group | google-drive | google_drive_parimatch | 2026-08-05 |