IT Onboarding
& Notifications
The IT Onboarding module manages the process of provisioning system access for new employees. It tracks which employees need login accounts, creates their credentials, assigns roles, and sends notifications when IT setup is complete.
What is IT Onboarding?
IT Onboarding handles the technical provisioning workflow for new employees: identifying pending employees (active staff without login accounts), account creation (email, temporary password, role assignment), IT notification tracking (pending/completed status for email and account setup), and welcome notifications (automated alerts when setup is complete).
The module ensures that every employee has a system login before they start their duties, with the appropriate role-based permissions assigned from day one.
Why Does It Exist?
- → Security risk — New employees without proper accounts may resort to shared credentials, creating security holes
- → Productivity loss — Delayed account provisioning means new hires cannot access the tools they need
- → Audit compliance — Every user must have a unique, auditable login tied to their identity
- → Role misalignment — Without proper provisioning, employees may end up with wrong permissions
IT Onboarding Workflow
The complete lifecycle of provisioning system access for new employees.
Identify Pending Employees
Active employees without a linked login account are listed in the IT Onboarding queue. HR staff can view their details (department, designation, joining date, email).
Configure Account Details
HR selects a role for the new employee and optionally sets their login email. If the employee already has an email on file, it is pre-filled.
Provision Account
The system creates a user account with a secure randomly-generated temporary password. The employee record is linked to the new user ID. The password must be changed on first login.
Notify Employee
The temporary password is displayed to HR to share with the employee. The IT notification status is set to 'completed'. The employee receives a welcome notification when they log in.
IT Notifications
Track the status of IT account and email setup for every employee who needs it.
Setup Queue
Employees flagged for IT setup appear in a dedicated queue with their it_notification_status field. Initially set to 'pending' when an employee is identified as needing IT setup.
Account Provisioning
When an account is provisioned via IT Onboarding, the notification status automatically updates to 'completed'. The employee record is linked to the new user ID.
Mark Complete Manually
If accounts are created outside the system (e.g., external IT team), HR can manually mark the IT notification as 'completed' with confirmation.
Employee Notification
When status changes to completed, the employee receives a high-priority system notification: 'Your email and IT accounts have been created successfully'.
Every Feature Explained
Pending Employee Discovery
Automatically identify active employees without linked login accounts.
No employee should start without system access. Manual tracking is unreliable.
The system queries for employees with status=active and userId=null. Results include department, designation, joining date, and email. HR can filter by pending or completed status.
Temporary Password Generation
Generate secure temporary passwords for new accounts.
New users need a secure initial credential that they can change on first login.
Passwords are generated using cryptographic random bytes (16 characters, base64url). Hashed with bcrypt (12 rounds) before storage. The user must change password on first login (mustChangePassword=true).
Role Assignment
Assign appropriate roles during account creation.
Role determines module access, permissions, and record scope from day one.
HR selects from a list of active roles during provisioning. Only roles with isActive=true are available. The role assignment governs the employee's entire permission set.
IT Notification Status Tracking
Track IT setup completion status per employee.
Provides visibility into who has been set up and who still needs attention.
Each employee has an itNotificationStatus field (pending/completed/null). Stats show counts by status. Status can be updated automatically (via provisioning) or manually. Completed status triggers an employee notification.
Bulk Visibility & Filtering
View and filter the IT onboarding queue.
HR teams need to prioritize and track multiple onboarding requests simultaneously.
Paginated table view shows all pending/completed employees. Filter by status (pending/completed). Stats cards show aggregate counts. Employees without email are flagged with a 'Required' badge.
Secure Account Provisioning
Create user accounts with proper security controls.
Account creation must be secure, auditable, and integrated with the existing auth system.
Account creation happens in a database transaction: user record is created first, then the employee record is updated with the link. Audit logs capture the full change (deep audit). Dual endpoints: /complete (simple) and /provision (full account creation).
Technical Architecture
| Field | Type | Institutional Role |
|---|---|---|
| employee_id | UUID | Reference to the employee being onboarded. |
| user_id | UUID | Linked system login account (nullable). |
| it_notification_status | Enum | Pending, Completed, or null. |
| temp_password_hash | Varchar | bcrypt hash of temporary password. |
| must_change_password | Boolean | Forces password change on first login. |
Note: Sensitive fields use AES-256 field-level encryption where applicable.
Governance & Power
hr:it-onboarding:viewhr:it-onboarding:completehr:provision-accounthr:it-notifications:viewTransactional Safety
Account creation is atomic, if the user creation succeeds but employee update fails, the entire transaction rolls back. No orphaned accounts.
Audit Trail
Provisioning actions are recorded with deep audit (before/after snapshots). Every account creation is traceable to the HR operator who performed it.
Notification Bridge
The IT Onboarding and IT Notifications modules share the same employee status field. Completing onboarding automatically triggers notifications and updates both queues.