Home › Use cases › Human Resources
CPO · on/offboarding, benefits, promotions, reviews

Human Resources agents: 5 use cases

People workflows touch identity, groups and confidential content. Sequencing and separation of duties matter more than any single scope.

ServiceNowSalesforceHubSpotAtlassian Each step lists the resource and the exact permission or role the agent uses.

HR1

New-hire onboarding provisioning

  1. TriggerApproved “New Hire IT Provisioning” request in ServiceNow
  2. ServiceNow1Approved catalog requestsc_request, sc_req_item · role:public; sc_cat_item · role:catalog_manager
  3. Atlassian2Create identityJiraUser: write:user:jira
  4. Atlassian3Add to team groupJiraGroup: write:group:jira
  5. Atlassian4Grant space accessConfluenceUser: write:group:confluence
  6. Atlassian5Create onboarding checklistJiraIssue: write:issue:jira · JiraProject: read:project:jira
  7. ServiceNow6Point to policykb_knowledge · role:public; ConfluencePage: read:page:confluence
  8. ParapetGroup allowlist; admin groups denied.Deny excess
Why Parapet

write:group:jira covers every Jira group, not just new-hire-standard. Parapet enforces group-level allowlisting so the bot can never place a new hire — or itself — in an admin group.

− granted: write:group:jira on all groups
+ needed: write:group:jira on new-hire-standard only
HR2

Employee offboarding & access revocation

  1. Trigger“Termination” request and sc_task assigned to IT
  2. ServiceNow1Termination tasksc_request · role:public; sc_task · role:sn_request_read
  3. Atlassian2Remove user accesswrite:user:jira
  4. Atlassian3Strip group membershipswrite:group:jira, write:group:confluence
  5. Atlassian4Reassign open issueswrite:issue:jira
  6. Atlassian5Confirm zero membershipsread:user:jira
  7. ParapetClose gated on verification; agent’s own credential revocation checked.Gate / review
Why Parapet

Offboarding is HR’s highest-blast-radius workflow. Parapet enforces sequencing — the task cannot close until Atlassian reads confirm zero memberships — and flags if the agent’s own credentials were not revoked in the same run.

− granted: sc_task closable at any time
+ needed: sc_task closes only after Atlassian confirms zero memberships
HR3

Promotion & role-change workflow

  1. TriggerPromotion request approved by manager and CPO
  2. ServiceNow1Approved requestsc_request · role:public
  3. Atlassian2Update user team / rolewrite:user:jira
  4. Atlassian3Adjust group membershipwrite:group:jira
  5. Atlassian4Track pay-band changeJiraIssue: write:issue:jira (Compensation project)
  6. Atlassian5Update people directorywrite:content.property:confluence
  7. ParapetToxic scope combination blocked.Deny excess
Why Parapet

Separation of duties: an agent that can write:group:jira must not also hold write:permission:jira on JiraProject — that combination lets a promotion workflow silently elevate its own project permissions.

− granted: write:group:jira + write:permission:jira
+ needed: write:group:jira without project-permission write
HR4

Performance review cycle orchestration

  1. TriggerScheduled review-cycle kickoff
  2. Atlassian1One issue per employeewrite:issue:jira · read:project:jira
  3. Atlassian2Attach feedback, track statuswrite:comment:jira, read:issue-status:jira
  4. Atlassian3Publish calibrated resultswrite:page:confluence
  5. Atlassian4Restrict page to HR leadershipwrite:content.restriction:confluence
  6. ParapetRun cannot complete until restriction is confirmed.Gate / review
Why Parapet

Parapet verifies the restriction actually took effect before the run is marked complete — every review page confirmed locked to HR leadership, not inheriting the broader default of the parent ConfluenceSpace.

− granted: Pages left inheriting space defaults
+ needed: Every page verified restricted
HR5

Benefits enrollment & policy support

  1. Trigger“Benefits Enrollment Change” request via catalog item
  2. ServiceNow1Read benefits articleskb_knowledge · role:public
  3. ServiceNow2Transition request itemsc_req_item · role:public
  4. Atlassian3Escalate out-of-threshold cases to HRBPwrite:request:jira-service-management
  5. ParapetOpen boundary flagged; scope recommended.Gate / review
Why Parapet

kb_knowledge resolves to role:public — any authenticated identity, human or agent, can read it. Benefits content can imply comp-band eligibility, so Parapet flags it and recommends scoping before more agents get catalog access.

− granted: kb_knowledge readable by any authenticated identity
+ needed: Benefits articles scoped to the enrollment agent

See what your agents actually hold.

Discover, inventory and enforce across every connected SaaS system.