How to Automate SaaS App Provisioning (for Humaans HR)

How to Automate SaaS App Provisioning (for Humaans HR)

Humaans runs the HR side of onboarding and offboarding well. On the IT side it can sync a new hire to your Google Workspace or MS 365 directory. What it will not do is provision the individual SaaS apps your team runs, like Slack or your productivity tool. That still falls to someone that manually opens each admin console and creates accounts.

There are three ways you can automate SaaS account creation/deletion: Through your IdP with SCIM/SAML, with a specialized tool like AccessOwl that does not need SCIM/SAML, or wire it up yourself via APIs if you have technical people with spare time and only a few apps.

SCIM provisioning works, but SMBs under 300 employees often hit the SSO tax: adding SSO to Calendly moves it from $12 to $25 per user per month, more than double. Those expensive upgrades often mean IT only puts a list of core apps under SCIM automation and leave the rest manual. A provisioning tool that doesn't rely on SCIM can extend your coverage.

In this blog:

  • SaaS provisioning with Humaans's native features

  • Automating onboarding and offboarding with Humaans and AccessOwl

  • Provisioning SaaS apps with Humaans and DIY automation (scripts, API connectors, spreadsheets)

What each method automates:


Humaans + SCIM

Humaans + AccessOwl

Humaans + DIY automation

App provisioning coverage

Apps with SCIM/SAML connectors, often behind an enterprise tier

400+ apps, no SCIM required

Whatever you build and maintain

Permission depth

Account provisioning; in-app roles only where the SCIM schema allows

Account and in-app permissions, per person

Depends on the script

Offboarding completeness

Deactivates SCIM-connected apps; anything outside SCIM is manual

Full stack of third-party apps, incl. Shadow IT

Only what is scripted

Shadow IT discovery

No

Yes

No

Audit evidence

Partial, depends on the IdP

Logged end to end

Manual

Access permission templates

Group and role based, via the IdP

Yes

No

Cost

Your IdP plus per-app SSO/SCIM upgrades (the SSO tax)

Per user pricing. No SSO tax.

Tooling plus engineering time

Method 1 - SaaS access management with Humaans's native features

What Humaans handles on its own

Humaans is your system of record for who works at the company: their role, team, department, and their start and end dates. On the onboarding side it does real work. It collects and stores documents, handles contract e-signatures, keeps ID documents with expiry reminders, and lets a new hire fill in their own details in one central record.

It also runs onboarding and offboarding as workflows: triggers that fire tasks and emails with due dates and reminders, including the task that tells IT to set up a new person's accounts. Humaans is hosted in the EU, and for a growing company this is a genuinely good way to run the HR half of onboarding.

Does Humaans have an IT module to automate SaaS provisioning?

There is no dedicated Humaans IT product or access add-on. Humaans markets an HR Access Management page, but that is provisioning through a short, fixed set of identity platforms, not a full IT module.

It does reach your directory. Humaans can create and suspend the Google Workspace account itself, and it can push a joiner or leaver one way into Microsoft Entra ID, Okta, or JumpCloud. The individual SaaS apps in your stack are still reached through your IdP's SCIM or SAML, one app at a time, or added and removed by hand.

Partial automation of onboarding and offboarding is a common wall teams hit with their HR tools. One IT lead at an analytics software company we talked to told us that even with an HR tool in place, their process still came down to "manually adding and deactivating" accounts before they brought in a lifecycle automation tool.

Why teams add a dedicated access management tool on top of Humaans

A clean, modern flat-illustration diagram showing an employee onboarding automation flow for SaaS access. On the left, an HR system icon labeled "Humaans" with a start date. An arrow flows to a central automation hub, which fans out to multiple SaaS app tiles (chat app, design tool, cloud storage, notes app) each getting a green checkmark for provisioned access. Muted blue and teal palette, soft rounded shapes, subtle drop shadows, professional B2B SaaS aesthetic, no text clutter, wide 16:9 aspect ratio.

The trigger and the workflow are the easy half. The hard half, creating and removing accounts across the whole app stack, is the part Humaans leaves to you, and it is usually most of the work.

From our research and conversations with our own customers, this is the point where a growing team reaches for a tool that turns the HR event into the actual access. Drieam, a 54-person education technology company, reached it as it scaled (hear how Drieam handles it):

"And because of the AccessOwl onboarding template, new employees already have access to multiple applications on day one, by default, so they can have a great start to their new job."

Tom Lamers, Strategy and Operations Lead, Drieam

A dedicated tool takes Humaans's joiner and leaver events and turns them into access across 400+ apps, and AccessOwl publishes its full integrations list so you can check your stack against it before you commit.

Method 2 - Automating SaaS access with Humaans + AccessOwl

AccessOwl layers on top of Humaans to handle access management for SaaS onboarding, offboarding, and access controls.

The stack most teams actually want is straightforward: your HRIS (here Humaans), your IdP (Google Workspace or Microsoft 365), and your third-party apps all stay in sync. Access should follow templates rather than someone setting up each new hire by hand. Requests, approvals, and remediations should be logged instead of scattered across tickets and spreadsheets.

AccessOwl is the layer that does that:

  • A start or end date in Humaans triggers the whole workflow.

  • Access templates are matched to HR attributes (role, team, department, entity) and can be tweaked per person.

  • Requests and approvals happen in Slack or the dashboard, and employees can self-serve.

  • Onboarding drops to minutes, and offboarding can be one click or fully hands-off.

  • Every action is logged as it happens, so access reviews become evidence you already have.

  • You get one place to see who has access to what, including apps outside SSO or SCIM.

  • Shadow IT that your HRIS and IdP never see gets surfaced.

Humaans does not provision the app stack itself, and it points customers to a dedicated tool to do it. AccessOwl is the access-automation integration listed in Humaans's own integrations directory, where it is described as automating how new employees receive access to any SaaS app.

What onboarding and offboarding looks like with Humaans + AccessOwl

Onboarding, start to finish:

  1. Humaans says a designer starts Monday.

  2. AccessOwl loads the access template: Figma, Adobe Creative Cloud, Slack, and the design team's Notion space.

  3. The relevant managers approve with one click in Slack (or another channel).

  4. AccessOwl provisions each app through its own connected integration, so no one on your team opens an admin console. Every action is logged for audit evidence later.

Offboarding runs the same way in reverse. On the termination date in Humaans, AccessOwl removes the person's licenses across their apps and reassigns their owned assets to their manager.

It also runs a free Shadow IT scan that catches apps your IT team may not have known those employees signed up for, including free accounts or username and password logins that sit outside SSO. Leftover access is where risk concentrates.

Viafintech, a 90-person fintech, reduced the cases of former employees keeping access after they left to zero once it automated with AccessOwl (Viafintech customer story). In the words of Martin Seener, their Senior Director of IT Administration: "Nowadays the same process takes less than a minute and works with the click of a button."

What access review compliance looks like with Humaans + AccessOwl

Because every grant, approval, and removal is logged, an access review for SOC 2 or ISO 27001 becomes a report you pull, not a spreadsheet you build. Instead of exporting a user list from each app and stitching it together by hand, you have one record of who has access to what and how they got it.

One survey found fully manual access reviews took 149 days to finish, across 23 people, versus 55 days and 15 people for teams that had an automation tool (data from Secureframe). In practice AccessOwl takes a review from around 2 hours per app down to about 10 minutes per app (detailed guide to SOC 2 access reviews).

How AccessOwl integrates with Humaans (and Google Workspace or Microsoft 365)

AccessOwl has native integrations with Google Workspace, Microsoft 365, and Okta, and it is the access-automation integration listed in Humaans's integration directory. Humaans stays your source of truth for joiners and leavers. AccessOwl reads those events and works alongside your existing Google Workspace or Microsoft 365, and Okta too if you run it, rather than replacing any of them.

Method 3 - Managing SaaS accounts with Humaans + DIY automation

This method comes up when a team has someone technical, a short list of apps, and the spare time to own it. Under roughly 30 people or 5 third-party apps it is genuinely viable. Teams might set up these automatic workflows for core apps like productivity tools and leave the rest on manual tickets.

A Zapier or Make rule watches Humaans for a new joiner and calls each SaaS app's API to create the account, or a script does it: PowerShell in a Microsoft shop, GAM in a Google one. A leaver fires the reverse.

It holds until the app list grows and the edge cases pile up. The failure that matters most is offboarding: when a script does not cover an app, that access just lingers, and no one notices until an audit or an incident.

At larger company sizes this compounds. No clean log to hand an auditor, no self-serve, and Shadow IT stays invisible because scripts only touch the apps that were wired up.

FAQs

Does Humaans offer features to automate provisioning of SaaS apps to automate onboarding and offboarding?

Partly. Humaans automates the HR side, the employee record, e-signatures, document collection, and onboarding and offboarding workflows with reminders. It can also create a Google Workspace account and sync a joiner or leaver one way into Microsoft Entra ID, Okta, or JumpCloud.

What it does not do is provision the individual SaaS apps in your stack. To automate that, you connect a dedicated tool. AccessOwl reads Humaans's start and end dates and provisions and deprovisions across 400+ apps, without requiring SCIM or SAML.

If I'm using Humaans, why use AccessOwl over Okta?

Okta Workforce Identity Cloud is the right call for some teams: large or regulated companies with a dedicated identity team and a multi-IdP setup get real value from its depth.

For a growing company on Humaans, it is usually more platform than you need, and it carries the SSO tax, where each app is upgraded to an enterprise tier just to connect.

If you already run Okta, AccessOwl layers on top of it and adds app coverage and lifecycle automation without ripping anything out. If you have not rolled out Okta yet, AccessOwl gives you the onboarding, offboarding, and access control you were after for a fraction of the cost, live in days rather than a months-long rollout.

Can Humaans automatically create and delete SaaS accounts in Google Workspace, Microsoft 365, or Slack?

For Google Workspace, yes in part: Humaans can create the account and suspend it when someone leaves, one way, though suspending does not release the license. For Microsoft, it provisions Entra ID, the directory, not Microsoft 365 mailboxes and licenses, and it does not reach Slack or the apps behind your IdP.

Google's own admin documentation notes that automated provisioning reaches a set number of apps depending on your plan, 3 on the Starter edition and up to 100 on higher tiers (about automated user provisioning). AccessOwl provisions across 400+ apps without requiring SCIM.

What does Humaans do natively for onboarding and offboarding?

On the HR side, a lot: e-signatures, document collection, ID documents with expiry reminders, a central employee record, and onboarding and offboarding workflows with tasks and reminders. It can also create a Google Workspace account and push a joiner or leaver into your Entra ID or Okta directory.

What it does not do is create or remove the accounts in the rest of your apps. It provisions the directory; a person still handles everything beyond it.

What are the best access management tools that integrate with Humaans?

It depends on your stack, but the category to look at is IGA and lifecycle automation that plugs into Humaans as the HR source of truth. AccessOwl is built for this and is listed in Humaans's own integrations directory: it reads Humaans's joiner and leaver events and provisions across 400+ apps.

What are the best tools that integrate with Humaans to provision accounts automatically for onboarding and offboarding?

For automatic provisioning and deprovisioning specifically, you want a tool that turns Humaans's start and end dates into action across your whole app list. AccessOwl does this on top of Humaans, including apps outside SSO and SCIM.

How do I automate onboarding with Humaans without manually creating software accounts and adjusting permissions?

Connect Humaans to a lifecycle tool that turns the start date into access. With AccessOwl, Humaans signals the new hire, a template based on their role loads the right apps and permission levels, the manager approves in Slack, and AccessOwl provisions each app for you.

Because templates carry permissions and not just accounts, you are not going back in to set roles by hand.

Our team uses Humaans, how do I make sure all app access is revoked when an employee leaves?

Humaans can deactivate the directory account, the Google Workspace or Entra ID side, but it does not remove access in your third-party apps. AccessOwl uses the termination date in Humaans to remove licenses across every connected app and reassign owned assets to the manager, and it surfaces Shadow IT accounts your HRIS never saw, so offboarding is complete and logged.

Can I use role, team, or department from Humaans to decide app access automatically during onboarding?

Yes. Humaans holds each person's role, team, and department. AccessOwl maps access to those HR attributes, along with entity, and lets you customize per person, so a Product Designer in Berlin gets exactly the right apps and permissions on day one.t

Get an AI summary of this article

Table of contents

    Get an AI summary of this article

    Table of contents