Skip to main content

What Owlie does

Owlie connects the people in your organization with the access they need. It brings identity information and access from connected systems into one place, lets you decide who should have what, and coordinates changes and reviews.

For example, your HR system may tell you that Maya has joined Engineering. Owlie can use that information to create her identity and determine her lifecycle state. A policy can give her the access that Engineering employees need. Later, an access review can ask whether that access is still appropriate.

Each part needs configuration. Importing an employee does not, by itself, create accounts in every system or grant access.

See what exists and decide what should exist

Start with your people: where their information comes from, which attributes matter, and how you recognize a joiner, mover, or leaver. Then connect the systems whose accounts and access you want to manage.

Sync brings information into Owlie. An identity source populates your directory; a target system can show you existing accounts and entitlements, called Grants in Owlie. The Owlie model explains how identities, resources, assignments, and Grants fit together.

Policies define access rules, such as the access someone needs because of their department and lifecycle state. Requests let people ask for access outside that automatic baseline, with approvals when the resource requires them.

Apply changes and check the result

Provisioning carries out access changes. A connector can create an account or add a group membership if the target system supports it. Other resources may need a person to complete the work manually.

A decision to grant access is not proof that it exists. Check that fulfillment completed and, for connected systems, that the target reports the expected access. The same distinction matters when removing access.

Access reviews ask reviewers whether someone still needs their access. Choosing Revoke records the decision. Remediation handles removal, which you can track separately.

Diagram placeholder: From people to reviewed access. Show an identity source feeding Owlie through Sync; policies and requests deciding access; provisioning changing a target; and target Sync reporting what exists. Place access reviews against existing access, with a revoke leading to remediation. Clearly separate a decision from a completed change.

Set up your first application

Start by importing users and configuring sign-in. Then connect an application, assign access through a lifecycle policy, and review that access.

Use a test identity and a Grant you can add and remove without affecting production work.

Next, read Things you should know for the distinctions that matter throughout setup.