Identity Lifecycle Management: HR Onboarding and HR Offboarding

With the HR Onboarding and HR Offboarding rules, you can automatically provision or revoke access in connected applications when a JSM request is submitted and approved. This guide walks you through creating and configuring both rules. The steps are identical except for the fields you map in the Access Definition and Mapping block.

Pre-requisites

  1. Jira and JSM admin access You need admin permissions in both Jira and Jira Service Management to create and save rules.
  2. A connected application At least one application must already be connected to the Identity Governance app via App Connections. Confirm this before creating a rule.
  3. A JSM project and request type set up for onboarding or offboarding requests You need an existing JSM project with a dedicated request type for each workflow. One request type can only be used by one automation rule, so make sure the request type you plan to use is not already assigned to another rule.
  4. Your Approved and Rejected workflow status names Make note of the exact JSM workflow status names for approval and rejection in your project. You will need them when configuring the Access Decision Mapping block.
  5. Custom fields created and added to the request type form The rule builder only shows fields that are already on the request type form. Before building the rule, make sure the following fields exist on your form. For HR Onboarding:
    • A text field for the new employee's first name
    • A text field for the new employee's last name
    • A text field for the new employee's work email
    • A single-select field for Access Package (optional, but at least one of Access Package or Downstream Provisioning must be mapped)
    • A multi-select field for Downstream Provisioning (optional, but at least one of Access Package or Downstream Provisioning must be mapped)
  6. For HR Offboarding:
    • A multi-select field for Target Applications

Video Setup Guide

Installation

  • Log in to your Jira instance and go to Apps in the top navigation bar.
  • Select Explore more apps and search for Identity Governance, Auditing and Access Control via JSM.
  • Click Try it free to start a trial, then follow the prompts to install the app.
  • Once installed, open the app from Apps in the top navigation bar. You will see the app sidebar with Dashboard, App Connections, Automation, Role Catalog, and Audit Logs.

1: Connect your application

Before creating a rule, confirm your target application is connected.

  • In the app sidebar, click App Connections.
  • Verify your application is listed and its status shows as connected.
  • If it is not connected yet, add it here before continuing.
Note: Offboarding is not supported by GitHub, AWS, and BambooHR. If your target application is one of these, offboarding access revocation will not execute even if the rule is configured.

2: Create the rule

  • Click Create Rule in the top right corner.
  • Create rule in Identity Governance
  • In the app sidebar, click Identity Lifecycle Management.
  • Identity lifecycle management
  • On the use case screen, click HR Onboarding or HR Offboarding depending on which rule you are setting up.
  • Create rule for HR Onboarding or HR Offboarding

3: Configure the Project block

The Project block is the trigger for your rule. It tells the app which JSM project and request type to watch.

  • In the rule builder, click the Project block to open its settings panel on the right.
  • Under Project, select your JSM project from the dropdown.
  • Under Request Type, select the request type designated for onboarding or offboarding requests.
  • HR Onboarding rule

Once both are selected, the field mapping options in the next block will become available. This block must be completed before any other block will load its fields correctly.

4: Configure Access Definition and Mapping

This block defines how the target user should be identified from the JSM request, how long access lasts, and which application the requester is asking to access.

  • Click the Access Definition and Mapping block to open its settings panel.

Target User

  • Select the JSM field from which the user (that is to be used for provisioning/deprovisioning actions) should be identified.

You can select among the following:

  1. Reporter: Choose this for self-service requests where the reporter is the target user.
  2. JSM user picker field: Choose this when the target user identity is already available in Jira/JSM.
  3. Email/Text field: Choose this when the target user is not available in Jira/JSM, such as brand-new users or external identities.
Configure access mapping workflow

Access Duration

  • Select Permanent if access should not expire.
  • Access definition permanent
  • Select Temporary if access should expire on a set date. A date field will appear, map it to the expiry date field on your JSM request form. The requester will need to fill in a date on every request; this field is never pre-filled automatically.
  • Access definition temporary

Target Application

  • Under Target Application (from access request), select the JSM field where the requester specifies which application they want access to.

Once approved, the app will automatically retrieve the entitlements for that application from your App Connection configuration and provision access accordingly.

5: Configure the Approval block

  • Click the Approval block to open its settings panel.
  • Under Assignee Users Field, select the field that defines who the approver is for requests of this type.
  • Under Add Users, search for and add any specific Jira users who should be able to approve requests.
  • If you want only the ticket assignee to be able to initiate the access request, toggle Only Assignee can Initiate on.
  • HR Onboarding approval assignee
Note: If you see a "Could not load approver fields" message, go back to Step 3 and confirm both the project and request type are selected.

6: Configure Access Decision Mapping

This block tells the app what to do when a request is approved or rejected.

  • Click the Access Decision Mapping block to open its settings panel.
  • Under Approval Status (JSM), select the JSM workflow status that means the request has been approved. When a ticket moves to this status, the app will execute provisioning or deprovisioning.
  • Under Rejection Status (JSM), select the JSM workflow status that means the request has been rejected. When a ticket moves to this status, no action is taken and the requester is notified via a comment on the ticket.
  • HR Onboarding access decision mapping

7: Save the rule

  • Click Save Rule in the top-right corner.

Test the rule

Before going live, run a quick test.

  • Submit a test request through the JSM portal.
  • Move the ticket to your approved status.
  • For Onboarding: confirm the new employee has been provisioned in the expected applications.
  • For Offboarding: confirm access has been revoked in the expected applications.
  • Check that a comment was posted on the ticket confirming the outcome.

Did this page help you?

miniOrange Atlassian Contact Us

Book a Free Consultation with
Our Experts Today!

Schedule a call now!


Contact Us
Hello there!

Need Help? We are right here!

support