Skip to main content

HRIS Lifecycle Management [Beta]

Learn how to automate block list additions, watch list additions, sign-outs, and access control credentials for terminated employees.


Overview

If your HR system is connected to Envoy, you can ensure that offboarding happens automatically. When an employee is marked as terminated in a connected system, Envoy runs a configurable routine that carries out each offboarding task across your security ecosystem. Offboarding by hand is easy to miss; a terminated employee can keep an active badge for days, leaving your workplace exposed and your team without proof that access was ever revoked. Automating it secures your workplace the moment HR records a termination, and keeps a verifiable audit trail for compliance standards like SOC 2 and NIST SP 800-53.

How offboarding works

Once you’ve connected an HRIS and enabled the offboarding routine, the process runs on its own:

  1. An employee is marked terminated in your connected HR system.

  2. Envoy receives the termination event and schedules an offboarding routine. The routine waits through a configurable grace period. During this window, you can cancel it or run it immediately.

  3. When the grace period ends, the routine runs each configured step: revoking badge access via an integrated ACS, adding the person to your Watch and/or Block List, and signing them out of the workplace.

  4. Assigned admins can receive an email summary, and every action is written to the audit log for future reference.

Available offboarding steps

  • Deprovision access control credentials

    • Suspends the employee’s badge/credentials in your connected access-control systems. This is reversible, so a credential can be reactivated if needed. Available for Brivo, CCure, Genea, Genetec, Kantech, and Lenel S2/Netbox.

  • Add to Watch list

    • Adds the employee's email address and phone number to your watch list.

  • Add to Block list

    • Adds the employee to the Block list with the reason “HRIS termination,” so they’re flagged if they try to sign in as a visitor. By default, this addition never expires and is added to every location.

  • Force sign-out

    • Automatically signs the employee out of the workplace, freeing a desk if used.

PREREQUISITES

  • You must have your HRIS installed in Envoy prior to setting this up. You will not see the HRIS Lifecycle tab in the Integrations section of your dashboard if your HRIS is not connected. Learn more about installing an HRIS integration.

  • To add to the block list or watch list, you need a Visitors Enterprise plan.

Configure HRIS Lifecycle events

The HRIS Lifecycle page contains four tabs:

  • Routine configuration

  • Admin approvals

  • Notifications

  • Audit log

Routine configuration

Global admins can make changes to any step, but location admins can only change the mode of ACS integrations installed at their assigned location(s).

This tab is where you'll set the desired offboarding events.

Modes

  • Live: the step runs and takes action

  • Simulate: the step records what it would do without making any permanent changes. Use this to validate identity matching before going live.

  • Disabled: the step is skipped entirely.

  1. Select the Lifecycle routine type. At this time, the only option is Terminate.

  2. Set the Grace period. This controls how long after the termination event occurs in HRIS until the termination routine begins. You can set a grace period in minutes, hours, or days. The maximum limit is 5 days.

    1. For example, if an employee is terminated at 2 PM, a 4-hour grace period would result in their badge being deactivated at 6 PM.

  3. Deprovision ACS credentials: This step lists all applicable access control integrations across all Envoy locations. Change the drop-down to Live to enable deprovisioning.

  4. Add to watch list: This step adds the terminated employee's email and phone number to the watch list. Learn more about the watch list.

    1. To reduce any false positives, the former employee's name is not added. Email and phone number are unique identifiers, so if a match occurs, it is likely a true positive.

    2. If that employee has ever been associated with a different email, such as a personal email, Envoy will add that additional address.

  5. Add to visitor blocklist: This step adds the terminated employee's name, phone number, and email address to the global block list. The reason for blocking will be "HRIS termination," and the record does not expire. Learn more about the block list.

    1. This automation creates the block list record, which can be edited. You can add additional details, like a photo, aliases, and keywords, if desired.

  6. Force sign-out: This step will automatically sign the terminated employee out of the workplace. This will release a booked desk (if applicable) and remove the employee from any on-site logs.

    1. This will not unassign any permanent desks or remove employees from your directory. If you use a SCIM-based directory integration, these actions are completed when your directory syncs.

  7. Click Save changes to complete configuration.

Location admin options

Admin approvals

Only global admins are able to bypass the grace period or cancel a deactivation

This tab shows any pending actions triggered by a termination. You can click Run now to skip the grace period and run the configuration steps immediately.

You can click Cancel to stop all deactivation events for that employee.

Notifications

Only global admins are able to configure notifications

You can configure email notifications to be sent to specific admins or admin roles. At minimum, we suggest turning on alerts for failures. Users must have the correct permissions in order to be added.

Click Save changes to finish configuring notifications.

Audit log

The Audit log tab will show all actions related to automations. You can customize the columns shown by clicking on the Columns control. You can also filter by integrations, activities, statuses, and locations shown. You can find an employee by using the search bar at the top.

Row headers are:

  • Timestamp

  • Status: Skipped, Success, or Failure

  • Employee: The terminated employee

  • Activity: Routine enqueued, Routine expedited, Routine started, Routine completed, Deprovisioned ACS credentials, Added to watch list, Added to visitor block list, Added to watch list, Forced sign-out, Notification skipped (no recipients)

  • Integration: Which ACS is affected by the removal

  • Location: Global or a specific location

  • Mode: Live, Simulated, or Skipped

  • Attempt: The # of attempts this step has completed. If the integration is having connection issues, you may see multiple attempts before a success status.

  • Initiated by: System or a specific user

  • Execution ID: The unique ID used for this specific action

To produce a copy of all automated actions taken by Envoy, click Export. The export streams all step timestamps and outcomes with a chain-of-custody header, formatted for SOC 2 and NIST audit submissions. Audit records are retained for two years.

You can click on an individual Event to view more details.

Employee identity matching

For each step, Envoy must match the terminated employee to the correct record in each system.

It matches in this order:

  1. Work email (primary)

  2. Employee number (an HRIS vendor-specific ID field)

  3. Full name (a lower-confidence match, flagged in the audit log)

If no match is found in a given system, that step is recorded as skipped for that system, and the other steps still proceed. For Watch List and Block List, Envoy checks all of the employee’s emails and phone numbers. A skipped step usually means the employee’s record in that system uses a different email or ID than the one in your HRIS; the audit log shows why.

FAQ

Can I undo a deprovision if someone is rehired?

  • Access-control deprovisioning is reversible; however, you cannot complete a reversal in Envoy. Suspended credentials can be reactivated in your ACS. Refer to your Access Control Provider's documentation for guidance.

What happens if one access control system is down?

  • Only that step retries, on its own schedule, with increasing wait times between attempts over roughly five hours. The other steps and systems complete normally, and the retries are recorded in the audit log.

Does directory or profile removal happen here?

  • No. Removing the employee from your directory is handled separately by Envoy’s directory service, not by the offboarding routine.

Why don’t I see all four steps?

  • You only see the steps your plans support. If a step is missing, your plan doesn’t currently include it.

    • Visitors Watch list and Block list require a Visitors Enterprise plan.

    • ACS Deprovisioning requires Workplace Platform Enterprise or Legacy Premium/Premium plus.

Did this answer your question?