## TL;DR
Trigger on the HR system's hire record, then run the sequence: create AD user from the naming template, sync to Entra, assign licenses and groups by role template, provision SaaS via SCIM, and notify the manager. Build it idempotent (safe to re-run) and alert on any step failure; partial provisioning is the failure mode.

## The error
```text
(Automation project; no error.)
```

## Steps
1. Define the trigger: the HRIS hire record reaching "ready to hire" status. Expected: reliable trigger. Everything downstream depends on clean HR data; fix data quality first.
2. Create the AD account from the naming template (firstname.lastname, conflict handling). Expected: created in the right OU. The template must handle duplicates deterministically.
3. Let Entra Connect sync, then assign licenses and role-based groups from the job-title template. Expected: licensed and grouped. Role templates replace per-person decisions.
4. Provision SaaS: SCIM apps provision automatically from group membership; non-SCIM apps need API calls or manual steps documented. Expected: apps ready. List the manual ones explicitly; do not pretend they are automated.
5. Notify the manager with credentials handoff instructions and log everything. Expected: closed loop. Alert loudly on any step failure; a half-provisioned hire is worse than a slow one.

## When to use
- High hiring volume
- Reducing day-one access delays

## When not to use
- Low volume (manual checklists are fine)
- Orgs without clean HR data (fix that first)

## Compatibility
- HRIS (Workday, etc.), AD, Entra ID, SCIM apps; PowerShell/Azure Functions as glue

## Variants
### HR-driven provisioning (Workday to AD)
Native inbound provisioning can replace custom scripts for the AD/Entra portion.
### Day-one readiness
Run the flow 3 days before start date; the accounts wait, the hire does not.

## Why it happens
Manual provisioning is slow and error-prone at exactly the moment (day one) when errors are most visible. Automation trades upfront template work for reliable repetition.

## Edge cases
- Name changes and re-hires need explicit handling; do not let the automation guess.
- Test with a fake hire in a test OU before touching production.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_Fzb-PEj98pYi6vWBHFM0gQ
