Provision and Deprovision Users Automatically via Your Identity Provider
Keep access tight — sync user access with your identity provider so joiners get accounts and leavers lose them without manual steps.
- 1
Trigger on Directory Changes
Add a
Webhooknode fed by your identity provider on user create, update and deactivate events. - 2
Provision on Join
Add nodes creating the user's accounts and adding them to the right groups when they're added.
- 3
Sync Role Changes
Add a step adjusting group and app access when a user's role or department changes.
- 4
Deprovision on Exit
Add nodes revoking access and disabling accounts when a user is deactivated.
- 5
Activate and Test
Activate the workflow and add then deactivate a test user. Confirm access is granted and removed.
Frequently asked questions
Why automate deprovisioning?
Orphaned accounts are a top security risk — automatic removal on exit closes that gap immediately.
Can I keep an audit trail?
Log every provisioning action so access changes are fully traceable for audits.
Keep every recipe free
FlowRecipesHub is free and always will be. If a workflow saved you time, chip in what you like — it helps us keep the lights on and build the next batch of automations for everyone.
Secure checkout via Paddle · one-time, no account needed
