Module 18, IT Onboarding & Notifications

IT Onboarding
& Notifications

The IT Onboarding module manages the process of provisioning system access for new employees. It tracks which employees need login accounts, creates their credentials, assigns roles, and sends notifications when IT setup is complete.

What is IT Onboarding?

IT Onboarding handles the technical provisioning workflow for new employees: identifying pending employees (active staff without login accounts), account creation (email, temporary password, role assignment), IT notification tracking (pending/completed status for email and account setup), and welcome notifications (automated alerts when setup is complete).

The module ensures that every employee has a system login before they start their duties, with the appropriate role-based permissions assigned from day one.

Why Does It Exist?

  • → Security risk — New employees without proper accounts may resort to shared credentials, creating security holes
  • → Productivity loss — Delayed account provisioning means new hires cannot access the tools they need
  • → Audit compliance — Every user must have a unique, auditable login tied to their identity
  • → Role misalignment — Without proper provisioning, employees may end up with wrong permissions

IT Onboarding Workflow

The complete lifecycle of provisioning system access for new employees.

1

Identify Pending Employees

Active employees without a linked login account are listed in the IT Onboarding queue. HR staff can view their details (department, designation, joining date, email).

2

Configure Account Details

HR selects a role for the new employee and optionally sets their login email. If the employee already has an email on file, it is pre-filled.

3

Provision Account

The system creates a user account with a secure randomly-generated temporary password. The employee record is linked to the new user ID. The password must be changed on first login.

4

Notify Employee

The temporary password is displayed to HR to share with the employee. The IT notification status is set to 'completed'. The employee receives a welcome notification when they log in.

IT Notifications

Track the status of IT account and email setup for every employee who needs it.

1

Setup Queue

Employees flagged for IT setup appear in a dedicated queue with their it_notification_status field. Initially set to 'pending' when an employee is identified as needing IT setup.

2

Account Provisioning

When an account is provisioned via IT Onboarding, the notification status automatically updates to 'completed'. The employee record is linked to the new user ID.

3

Mark Complete Manually

If accounts are created outside the system (e.g., external IT team), HR can manually mark the IT notification as 'completed' with confirmation.

4

Employee Notification

When status changes to completed, the employee receives a high-priority system notification: 'Your email and IT accounts have been created successfully'.

Deep Dive

Every Feature Explained

Pending Employee Discovery

What it is

Automatically identify active employees without linked login accounts.

Why it exists

No employee should start without system access. Manual tracking is unreliable.

How it works

The system queries for employees with status=active and userId=null. Results include department, designation, joining date, and email. HR can filter by pending or completed status.

Temporary Password Generation

What it is

Generate secure temporary passwords for new accounts.

Why it exists

New users need a secure initial credential that they can change on first login.

How it works

Passwords are generated using cryptographic random bytes (16 characters, base64url). Hashed with bcrypt (12 rounds) before storage. The user must change password on first login (mustChangePassword=true).

Role Assignment

What it is

Assign appropriate roles during account creation.

Why it exists

Role determines module access, permissions, and record scope from day one.

How it works

HR selects from a list of active roles during provisioning. Only roles with isActive=true are available. The role assignment governs the employee's entire permission set.

IT Notification Status Tracking

What it is

Track IT setup completion status per employee.

Why it exists

Provides visibility into who has been set up and who still needs attention.

How it works

Each employee has an itNotificationStatus field (pending/completed/null). Stats show counts by status. Status can be updated automatically (via provisioning) or manually. Completed status triggers an employee notification.

Bulk Visibility & Filtering

What it is

View and filter the IT onboarding queue.

Why it exists

HR teams need to prioritize and track multiple onboarding requests simultaneously.

How it works

Paginated table view shows all pending/completed employees. Filter by status (pending/completed). Stats cards show aggregate counts. Employees without email are flagged with a 'Required' badge.

Secure Account Provisioning

What it is

Create user accounts with proper security controls.

Why it exists

Account creation must be secure, auditable, and integrated with the existing auth system.

How it works

Account creation happens in a database transaction: user record is created first, then the employee record is updated with the link. Audit logs capture the full change (deep audit). Dual endpoints: /complete (simple) and /provision (full account creation).

Technical Architecture

FieldTypeInstitutional Role
employee_idUUIDReference to the employee being onboarded.
user_idUUIDLinked system login account (nullable).
it_notification_statusEnumPending, Completed, or null.
temp_password_hashVarcharbcrypt hash of temporary password.
must_change_passwordBooleanForces password change on first login.

Note: Sensitive fields use AES-256 field-level encryption where applicable.

Governance & Power

hr:it-onboarding:view
hr:it-onboarding:complete
hr:provision-account
hr:it-notifications:view
  • Transactional Safety

    Account creation is atomic, if the user creation succeeds but employee update fails, the entire transaction rolls back. No orphaned accounts.

  • Audit Trail

    Provisioning actions are recorded with deep audit (before/after snapshots). Every account creation is traceable to the HR operator who performed it.

  • Notification Bridge

    The IT Onboarding and IT Notifications modules share the same employee status field. Completing onboarding automatically triggers notifications and updates both queues.