
Factorial tells you the day a new hire starts and the day someone's last day lands. What it doesn't do is hand that new hire their Slack, Notion, and GitHub logins on the first morning, or claw all of them back on the last one. That part still falls to whoever owns IT, working through each admin console one account at a time.
Past about 30 employees, teams want the reverse: a start date in Factorial kicks off access to every app a person needs, managers approve the sensitive ones in a click, and a departure revokes all of it automatically.
The usual fix is a full identity platform like Okta. It works, but it is a heavy rollout for a growing team, and it comes with the SSO tax: adding single sign-on to a tool like Airtable means moving from its $20 per user Team plan to the $45 per user Business plan, more than double, just to connect one app to your identity provider (IdP). That pattern repeats across the stack, documented vendor by vendor on ssotax.org.
In this blog:
SaaS provisioning with Factorial's native product, and where it stops
Automating onboarding and offboarding with Factorial plus an IGA tool like AccessOwl
SaaS provisioning with Factorial plus DIY automation (scripts, API connectors, spreadsheets)
Method 1 - SaaS provisioning with Factorial's native product
Factorial is not only an HR database. Between Factorial HR and the paid Factorial IT add-on, it does a real slice of provisioning on its own. Here is what each part covers, and the line where it hands the rest back to you.
Factorial HR
Factorial HR is your system of record for who works at the company: their role, team, department, and their start and end dates. For onboarding and offboarding it can fire checklists, tasks, and reminders, and it holds the data (role, manager) that should decide who gets what. A free Google Workspace integration can also handle the Google account itself.
What it does not do is create or delete the accounts in your other apps. Factorial HR records that Marta started. It does not put Marta into Notion.
One founder at a small software company we talked to told us that what they were really after was "programmatic onboarding, offboarding, and Shadow IT," and that today they were stitching it together with rough integrations between services.
Automating SaaS onboarding and offboarding with Factorial IT

Factorial IT is Factorial's IT product line, covering device management and access management. On the access side it goes further than a checklist. Its SaaS Management module can provision and deprovision apps directly, and it gives you three ways to handle each tool: "automate with an AI Agent, connect via SAML (Security Assertion Markup Language), or track it manually when provisioning isn't available," on top of a ready-to-use catalog of apps (Factorial SaaS Management). That is a real access-management layer, and more than most HR tools ship.
Factorial IT is a separate product from Factorial HR, and its access management is sold by quote rather than a public per-seat price.
What Factorial IT provisioning can do
Build access rules by role and team.
Provision a catalog app automatically when someone joins, through a direct connector or an AI Agent.
Connect an app for login with SAML, and track anything outside the catalog manually so it shows up in one place.
Trigger scheduled removal of the apps Factorial IT manages when someone leaves.
Factorial IT SaaS provisioning limitations
The limitation you will run into with Factorial IT provisioning is the size of the catalog.
The catalog is small. Factorial markets "60+ native integrations," but that count folds in HRIS and identity providers; its help centre puts the actual app catalog at "more than 30." There is no public list, so you cannot check whether your stack is covered before you buy.
Past the catalog you are back to manual. "Custom SAML" is login only, not provisioning, and "manual tracking" is a record, not an action.
It is role and team based. You can template access by role or team, but no source shows finer logic on manager, legal entity, or cost center, or per-person tweaks on top of a template. It decides whether an account exists more than what that account can do. We see this constantly with customers who tried to automate provisioning through an HR tool: they have an "IT tool," and they still end up in tickets and spreadsheets.
It cannot see Shadow IT yet. Factorial's help centre lists identity mapping for Shadow IT as coming soon, so apps bought outside IT never surface, and those are the accounts that stay open when someone leaves.
What that means for you
Factorial IT handles the popular core of your stack, and it handles it well. But there will be a long list of apps it does not cover, and those stay manual. Because there is no published catalog, you usually don't find out which apps fall outside it until after you have bought, often at the worst moment: when someone has left and still has access to a tool Factorial IT was never connected to.
Why teams layer a dedicated SaaS access management tool on top of their HRIS
What most teams don't account for before buying is two things: the size of that catalog, and whether the "connectors" an HR IT tool offers actually rely on SCIM (System for Cross-domain Identity Management). You might have the technical ability to provision an app through SCIM, but your finance and leadership team will push back on upgrading every SaaS tool to its enterprise tier just to switch SCIM on.
Maxio, a B2B finance platform, evaluated bringing access management in through an HR platform's IT module and turned it down. Their Senior IT Admin, Shane Fritts, put it this way when comparing AccessOwl to Rippling's IT product (hear how Maxio thinks about it):
"I'd say probably ninety percent of our tools are automated for on and off boarding in AccessOwl. I would lose most of that through Rippling IT."
Shane Fritts, Senior IT Admin, Maxio
The math is the catalog. A tool that automates a few dozen apps leaves the rest to be created and killed by hand, and the rest is usually most of the stack. AccessOwl provisions 400+ apps and publishes its full integrations list, so you can check your stack against it before you commit.
Method 2 - Automating SaaS Onboarding & Offboarding with Factorial + AccessOwl
AccessOwl layers on top of Factorial to handle access management for SaaS onboarding, offboarding, and access controls.
The stack most teams actually want is straightforward: your HRIS (Human Resources Information System, here Factorial), your IdP (Google Workspace or Microsoft 365), and your third-party apps all stay in sync. Access should follow templates rather than someone creating accounts and setting permissions for each new hire. Who has access to what, along with access requests, approvals, and remediations, should be logged for access controls instead of scattered across tickets and spreadsheets.
AccessOwl is the layer that does that:
A start or end date in Factorial triggers the whole workflow.
Access templates are matched to HR attributes (role, team, department, entity) and can be tweaked per person.
Requests and approvals happen in Slack or the dashboard, and employees can self-serve.
Onboarding drops to minutes, and offboarding can be one click or fully hands-off.
Every action is logged as it happens, so access reviews become evidence you already have.
You get one place to see who has access to what, including apps outside SSO or SCIM, like internal tools.
Shadow IT that your HRIS and IdP never see gets surfaced.
What onboarding and offboarding looks like with Factorial + AccessOwl
Onboarding, start to finish:
Factorial says a backend engineer starts Monday.
AccessOwl loads the access template: GitHub, AWS, Linear, and the engineering Slack channels.
The relevant managers approve with one click in Slack (or another channel).
AccessOwl provisions each app through its own connected integration, so no one on your team opens an admin console. Every action is logged for audit evidence later.
Offboarding runs the same way in reverse. On the termination date in Factorial, AccessOwl removes the person's licenses across their apps and reassigns their owned assets to their manager. It also runs a free Shadow IT scan that catches apps your IT team may not have known those employees signed up for, including free accounts or accounts with a username and password that sit outside SSO. That completeness matters, because leftover access is exactly where breaches start. IBM put the global average cost of a data breach at $4.44 million in 2025 (IBM Cost of a Data Breach 2025).
Motion, one of our customers, cut onboarding from about 2 hours to under 30 minutes per hire (Motion customer story). Across our wider customer base, automating access this way removes roughly 75% of the manual access-management work a team does, on the order of 30 hours a month at a 100-person company.
What access review compliance looks like with Factorial + AccessOwl

Because every grant, approval, and removal is logged, an access review for ISO 27001 or SOC 2 becomes a report you pull, not a spreadsheet you build. Instead of exporting a user list from each app, screenshotting the ones with no export, and pasting it all together, you have one record of who has access to what and how they got it. In practice that takes a review from around 2 hours per app down to about 10 minutes per app (detailed guide to SOC 2 access reviews).
How AccessOwl is different from Factorial IT's catalog
The core difference is coverage. Factorial IT provisions a catalog of a few dozen apps; AccessOwl provisions across 400+ apps, including the long tail of tools that don't offer SCIM or an API connector, or hide them behind an enterprise plan. There is no catalog you have to be inside of.
It also surfaces Shadow IT today rather than as a roadmap item, works at the permission level rather than only creating or deleting an account, and lets you customize a template per person. And it works whether or not you have bought the separate Factorial IT module.
AccessOwl does not replace your IdP or handle logins, passwords, or multi-factor authentication, and it does not manage devices. It sits on top and automates the access lifecycle.
How AccessOwl integrates with Factorial (and Google Workspace or Microsoft 365)
Factorial stays your source of truth for joiners and leavers. AccessOwl reads those events and works alongside your existing Google Workspace or Microsoft 365, and Okta too if you run it, rather than replacing any of them. AccessOwl has native integrations with Google Workspace, Microsoft 365, and Okta.
Who this is best for
AccessOwl plus Factorial fits a growing team (30+ people) running Factorial, with a mix of third-party SaaS apps beyond what the catalog provisions. You may have a small IT team owning device and software provisioning, or this might sit with a non-technical operations person.
Method 3 - SaaS provisioning with Factorial + DIY automation
Another route teams on Factorial can take is to layer DIY automation on top of Factorial. If you have technical people on your team, they might own this: tickets in Jira or Linear, spreadsheets, Zapier or Make on Factorial events, or scripts against Factorial's API. Microsoft shops often lean on PowerShell, Google shops on GAM (Google Apps Manager), wiring the APIs themselves.
To be fair, under roughly 30 people or 5 third-party apps, with someone technical who owns it, this is genuinely workable.
Where it breaks as you grow:
No audit trail when a review comes around.
Missed offboarding, the scary one, when a script does not cover an app.
Shadow IT stays invisible.
Brittle maintenance every time an app changes its API.
No approvals and no self-serve.
Key-person risk when the one person who understood the scripts leaves.
Which method is right for you?
Factorial native (HR + Factorial IT) | Factorial + AccessOwl | Factorial + DIY | |
|---|---|---|---|
App coverage (incl. non-catalog long tail) | The Factorial IT catalog (a few dozen apps) | 400+ apps, no catalog to be inside of | Whatever you build and maintain |
Permission depth | Role and team templates | Account and in-app permissions, per person | Depends on the script |
Offboarding completeness | Apps in the catalog; the rest is manual | Full stack of third-party apps, incl. Shadow IT | Only what is scripted |
Shadow IT discovery | Coming soon | Yes | No |
Audit evidence | Partial | Logged end to end | Manual |
Access permission templates | Yes | Yes | No |
Cost | Factorial IT, priced by quote | See our plans | Tooling plus engineering time |
Device management is a separate job: if Factorial IT covers your laptops, MDM (Mobile Device Management), and procurement, keep it for that. AccessOwl does not manage devices. This comparison is about SaaS access.
FAQs
If I'm using Factorial, why use AccessOwl over Okta?
Okta Workforce Identity Cloud is the right call for some teams: large or regulated companies with a dedicated identity team and a multi-IdP setup get real value from its depth. For a growing company on Factorial, it is usually more platform than you need, and it carries the SSO tax, where each app is upgraded to an enterprise tier just to connect. If you already run Okta, AccessOwl layers on top of it and adds app coverage and lifecycle automation without ripping anything out. If you have not rolled out Okta yet, AccessOwl gives you the onboarding, offboarding, and access control you were after for a fraction of the cost, live in days rather than a months-long rollout.
Can I automatically create and delete SaaS accounts with Factorial's Google Workspace or Microsoft 365 integration?
Partly. Factorial's Google Workspace integration can handle the Google account, and its SaaS Management catalog provisions the apps it natively supports. Microsoft 365 and Entra cover their own SCIM-enabled gallery. Google's own admin documentation notes that automated provisioning reaches a set number of apps depending on your plana Past that, provisioning is manual, and connecting more apps usually means SAML for login rather than full provisioning. AccessOwl reaches the apps beyond that line, across 400+ integrations.
What access management features does Factorial IT offer?
Factorial IT is Factorial's IT suite, covering device management and access management. On the access side, its SaaS Management module provisions a catalog of apps, with a choice per tool of an AI Agent connector, SAML for login, or manual tracking, and it can template access by role and team and schedule removal on exit. The access-management module is sold by quote rather than a public per-seat price.
What are the best access management tools that integrate with Factorial?
It depends on your stack, but the category to look at is IGA and lifecycle automation that plugs into Factorial as the HR source of truth. AccessOwl is built for this: it reads Factorial's joiner and leaver events and provisions across 400+ apps.
What are the best tools that integrate with Factorial to provision accounts automatically for onboarding and offboarding?
For automatic provisioning and deprovisioning specifically, you want a tool that turns Factorial's start and end dates into action across your whole app list. AccessOwl does this on top of Factorial, including apps outside SSO and SCIM.
How do I automate onboarding with Factorial without manually creating software accounts and adjusting permissions?
Connect Factorial to a lifecycle tool that turns the start date into access. With AccessOwl, Factorial signals the new hire, a template based on their role loads the right apps and permission levels, the manager approves in Slack, and AccessOwl provisions each app for you. Because templates carry permissions and not just accounts, you are not going back in to set roles by hand.
Our team uses Factorial, how do I make sure all app access is revoked when an employee leaves?
The gap is that Factorial, like any HRIS with a bounded app catalog, only removes what it is connected to. To be sure nothing is left open you need the long tail and Shadow IT covered too. AccessOwl uses the termination date in Factorial to remove licenses across every connected app and reassign owned assets to the manager, and it surfaces Shadow IT accounts your HRIS never saw, so offboarding is complete and logged.
Can I use role, team, or department from Factorial to decide app access automatically during onboarding?
Yes. Factorial IT can template access by role and team. For finer control, AccessOwl maps access to HR attributes like role, department, and entity, and lets you customize per person, so a "Backend Engineer in the EU" gets exactly the right apps and permissions on day one.
Does Factorial integrate with Google Workspace or Microsoft 365 for provisioning?
Yes, within its catalog. Factorial's Google Workspace integration can handle the Google account, and its SaaS Management module provisions the apps in its catalog, with Google or Microsoft as the identity provider behind it. That means your automatic provisioning reach equals that catalog. AccessOwl extends provisioning to the apps the catalog cannot reach, across 400+ integrations.
