On/Offboarding

Ready for Frequent Joiners and Leavers

Automatically assign and revoke accounts as employees come and go—reducing the time spent on repetitive tasks.
Request a Demo
직원에게 요구할 게 없는 온보딩과 오프보딩
feature 2

Onboarding and Offboarding That Requires Nothing From Employees

When your organization’s SaaS is integrated with PoPs, administrative overhead is dramatically reduced.
New employees can simply open their device on day one and start working immediately.
All job-relevant apps have already been pre-configured by the administrator, and access is granted via Single Sign-On (SSO)—no setup required from the employee.
The same applies to offboarding.
When an employee leaves, deleting their PoPs account automatically revokes access to all connected SaaS.
There’s no need to manually track whether accounts are still active—it’s handled seamlessly.
It’s easier for managers, smoother for new hires, and cleaner for offboarding.
For environments where directory synchronization or user provisioning isn’t available, you can configure alerts to notify workspace owners or app managers when a user departs—so they can manually restrict access as needed.
faq

Frequently Asked Questions

Feature

Why Is Directory Synchronization Useful?
Directory synchronization eliminates the need for administrators to manually configure user directories one by one.
For example, if your organization uses Google Workspace or Microsoft 365, you can import your existing directory directly into PoPs and apply it without any additional setup.

You can also define the scope of synchronization—so only specific departments, business units, or organizational groups are synced.
This streamlines user management, reduces manual errors, and improves operational efficiency.
How Can We Automatically Provision Users to Identify SaaS Usage Across the Enterprise?
It depends on whether the SaaS application provides the appropriate user provisioning API.

Apps that support provisioning functionality typically allow operations such as viewing, inviting, adding, activating, deleting, and deactivating users.
If the app exposes these APIs, PoPs can retrieve the user list from the app’s admin console and compare it with your organization’s directory to detect usage gaps or inconsistencies.

Even without manual user assignment or removal, automatic provisioning can be triggered via directory synchronization—assigning or revoking access based on group, role, or organizational structure.

This makes it easier to identify who is using which SaaS tools and ensures consistent access control across your environment.
I Have a Former Employee. How Can I Immediately Reclaim All App Assignments?
You can automatically revoke all app permissions using PoPs.
When an employee leaves the company, PoPs supports automated deprovisioning workflows that eliminate the need for manual access removal.

Depending on your organization's policy, you can configure a step-by-step process like:
1. Notify deprovisioning stakeholders — such as the Org Admin, App Admin, License Admin, or the employee’s direct manager.
2Trigger an alert to the SCIM administrator for identity sync-related updates.
3Reassign or revoke accounts based on organizational unit, department, or job role.

This ensures secure, compliant, and efficient offboarding—without delays or overlooked access points.

Simplify Onboarding and Offboarding

Cut down the time spent on repetitive account provisioning and deprovisioning every time an employee joins or leaves.
Request a Demo
We’ll respond within 3 business days.
Includes a live demo of SaaS integration and automated user lifecycle management within your organization.