WORKFLOW TEMPLATES
IT Ops workflows
Provisioning, monitoring, and incident response.
380 workflows
Weekly Shadow-IT Posture Report for Leadership
Aggregates the week's shadow-IT findings and review outcomes from Snowflake and Linear into a single rollup with trends.
Revoke departed-employee app access on HRIS termination
When a termination record lands via webhook, this workflow revokes the employee's access across Slack, GitHub, and Google Drive, then writes an immutable audit record to Notion.
Reconcile offboarding actions into a queryable audit ledger
After access is revoked, this workflow gathers proof from Slack, GitHub, and Google Drive, writes a structured row per system to a Postgres audit ledger.
Incident Resolution All-Clear Publisher
When Sentry marks an issue as resolved, drafts a friendly all-clear update, confirms the error rate has actually dropped via Cloudflare.
New-Hire Cloudflare Access Grant-Gap Checker
On a new-hire event from HR, checks which baseline Cloudflare Access apps the role should have, compares against what is actually granted.
Cloudflare 5xx surge to auto-published degraded-service banner
Watches Cloudflare for a surge in 5xx responses and, when origin errors confirm a real outage, writes and auto-publishes a degraded-service banner to your status page…
Audit departed employees for lingering shadow-SaaS access
On an offboarding webhook, checks Datadog SSO logs and Snowflake expense records for any tools the departing employee used or paid for outside the managed app catalog.
Incident commander agent: draft, decide channels, and broadcast everywhere
An agent takes a Sentry-detected outage, judges blast radius, writes channel-tailored updates, and broadcasts to the status page, customer email, and a Discord community at once.
Urgent voice-complaint detection and escalation
Transcribes inbound voice notes, scores sentiment and urgency with an LLM, files the request in Linear.
Onboarding Form to Multi-SaaS Account Fan-Out
Takes a submitted IT onboarding intake form and fans out account creation across CRM, project tracking, and ticketing tools in parallel, then collects the results.
Triage field voice reports: urgent ones page on-call, rest go to Trello
Transcribes an inbound field voice report, classifies its urgency with OpenAI, and either pages the on-call responder via PagerDuty for emergencies or files a standard Trello…
Offboarding Data Archive to Cold Storage with Retention Tag
Triggered by an offboarding webhook, this workflow exports the departed user's Drive and Dropbox files into a dated archive in object storage and logs the retention record…
AI agent rightsizing review for underused premium seats
An agent reviews per-user usage telemetry to distinguish never-used seats from premium-tier overprovisioning, drafts a personalized recommendation per user.
Catch SaaS Signup Confirmation Emails in the Shared Inbox
Monitors a forwarding inbox for SaaS welcome and verify-your-email messages, extracts the app and the employee.
PagerDuty resolve to status resolution + recap
When a PagerDuty incident resolves, this drafts the closing status-page update plus a short customer-facing recap, gets it approved in Slack, and publishes the resolution.
Emergency Maintenance Escalation to On-Call
Classifies severity from a maintenance photo and, only for emergencies like floods or electrical hazards.
Refresh status-page ETA when PagerDuty escalates an incident
When a PagerDuty incident escalates or its priority changes, regenerates an honest.
Idle-User Grace Period Nudge Before Auto-Revoke
Detects users approaching the idle-seat cutoff, emails them a keep-or-lose-it nudge with a grace window, and auto-revokes only those who stay inactive through the deadline.
Idle-User Grace Period Nudge Before Auto-Revoke
Detects users approaching the idle-seat cutoff, emails them a keep-or-lose-it nudge with a grace window, and auto-revokes only those who stay inactive through the deadline.
Manager-Approved Offboarding with Slack Gate
Starts on a manager's offboarding request, asks them to approve the revocation list in Slack, then sweeps the approved systems and reports back which seats were confirmed revoked.
Offboarding SaaS Seat Sweep with Confirmation Ledger
When HR marks an employee as departed, this sweeps every connected SaaS tool, deactivates their seat.
Scheduled maintenance announcement to status page + hotline voice
On a schedule ahead of a maintenance window, OpenAI drafts a maintenance notice, posts it to the status page, announces in Slack.
Scheduled maintenance pre-notice from calendar
From a maintenance event on a shared calendar, this drafts an advance status-page notice with the window and expected impact, approves it in Slack, and schedules publication.
Auto-Enrich a Shadow-IT Finding with Vendor Risk Research
When a new shadow-IT Linear issue is created, an agent researches the vendor's security posture and data practices on the web, writes a risk brief into the issue.
Renewal-Triggered Seat Rightsizing Brief
When a SaaS renewal date approaches via webhook, the CEO agent cross-references SSO usage against contracted seats and drafts a rightsizing brief recommending exactly how many…
Offboarding Orphaned Access Sweep Agent
An agent that investigates a named departed employee across your systems, finds every lingering access grant and shared resource.
Offboarding SaaS Seat Reclaim Sweep with Cost Report
When HR marks an employee as departed, sweep every connected SaaS tool, revoke the person's seats.
Severity-Tiered Incident Router
Classifies a Sentry-confirmed incident into a severity tier and routes the right plain-language update to the right place: critical posts to the status page immediately.
Sentry Outage to Plain-Language Status Update
When a Sentry issue crosses an alert threshold, drafts a customer-readable incident update with a severity tier, routes it to Slack for one-tap approval.
Scheduled Open-Incident Status Digest
On a fixed schedule, pulls all currently open Sentry issues above a severity floor, writes a single consolidated plain-language status digest.
On-Call Manual Incident Intake to Status Page
An on-call engineer submits a short incident form via webhook; the flow enriches it with the linked Sentry issue, drafts a customer-ready update at the chosen severity.
Datadog monitor alert to drafted status update
When a Datadog monitor trips, this drafts a public status-page update with tone matched to the alert's priority and posts it to a Slack approval channel before anything goes live.
Sentry outage to plain-English status draft with Slack approval
When Sentry flags a spiking error, drafts a customer-readable status update with a sensible ETA and posts it to Slack for one-click approve or edit before anything goes public.
Draft an all-clear update when the underlying alert recovers
When the Datadog monitor that opened an incident recovers, this drafts a plain-language "resolved" update and routes it to Slack for a final human sign-off before closing…
Catch shadow SaaS signups from welcome emails and triage them
Monitors a shared IT inbox for SaaS welcome and verification emails sent to company addresses, uses an LLM to identify the vendor and the employee.
Agent-driven full onboarding kit for a new department mailbox
An agent takes a new-department brief, provisions the Outlook shared mailbox, configures signature and auto-reply, creates a Teams channel, and files an onboarding doc.
Auto all-clear update when Sentry error rate returns to baseline
Monitors a resolving incident and, once Sentry error volume drops back to baseline and stays there, drafts and posts a friendly resolved update closing out the status-page…
Route HVAC sensor anomalies to the right vendor on-call
Receives HVAC sensor alerts via webhook, classifies severity by deviation from setpoint, and pages the assigned mechanical vendor's on-call while logging the incident to Airtable.
AI Access-Policy Reviewer for Onboarding Requests
An agent reviews each onboarding access request against your written access policy, flags over-provisioned or unusual requests for IT, and auto-approves the rest.
Role-Based Access Request with Manager Approval
Routes a new hire's requested app access through their manager for approval, then provisions only the approved apps and logs the decision for audit.
Recover Google Workspace licenses from dormant accounts
Detects Google Workspace users with no Drive activity for a configurable window, confirms each with their department lead in Slack.
Daily sweep for dormant accounts of departed staff
Runs every morning, cross-checks an offboarding roster against live access in GitHub and Google Drive, and flags any account that should have been revoked but is still active.
On-demand access revoke from a Slack command
An IT admin types an offboarding command in Slack with an employee email, and the workflow revokes GitHub and Google Drive access.
Agent-driven full access discovery and revocation
An agent investigates everywhere a departed employee still has access across connected systems, decides what to revoke versus reassign, executes the changes.
HR Termination Webhook to Cloudflare Access Auto-Revoke
When your HRIS sends a termination event, this looks up every Cloudflare Access app the departing employee can reach, revokes those grants.
Offboarding License Reclaim and Cost Recovery Audit
On a scheduled run, this workflow finds recently departed users still holding paid SaaS seats, reclaims the licenses, and reports the monthly savings to finance and IT.
Offboarding-Triggered SaaS Seat Revocation Queue
When an HR webhook marks an employee as departed, instantly enumerates all their SaaS seats and opens a single consolidated deprovision approval with a Slack approve/deny prompt…
Offboarded-User Orphan Seat Sweep
When an HR offboarding event fires, it sweeps every SaaS app for seats still assigned to the departed user, cross-checks SSO to confirm no recent activity.
Cloudflare WAF Daily Drift Audit Report
Each morning compares the live Cloudflare WAF rulesets against the version-controlled config in Git and reports any out-of-band drift to Slack and a Notion audit log.
Ticket-Driven Offboarding Revocation Runbook
Watches for offboarding tickets and works the access-revocation checklist item by item.
Day-One Welcome Kit and Document Access Setup
Triggered by an onboarding webhook, builds the new hire's welcome kit by creating their personal folder, granting access to role-relevant docs and handbooks.
Auto-revoke at the end of an employee's last working day
Triggered by a last-day calendar event, this workflow waits until end of day, then revokes Slack and GitHub access and emails the manager a completed offboarding checklist.
PagerDuty incident to status-page note + ElevenLabs hotline update
When a PagerDuty incident is triggered, drafts a customer-safe status-page note with OpenAI, posts it to your status webhook.
Onboarding Access Completion Verifier and Nudge
On a new hire's start date, verifies every required account was actually created across systems and nudges IT about any gaps before the employee logs in.
Agentic Offboarding: Discover, Revoke, and Verify All Access
An agent takes a departing employee's name, discovers every SaaS tool they touch across your org, revokes access in each.
Publish an approved status update and broadcast it everywhere
When an on-call lead clicks Approve on a drafted update in Slack, this publishes it to the status page and simultaneously broadcasts the same wording to customers via email…
Scheduled Pre-Start Access Prep Sweep
Each morning, scans for hires starting in three days and pre-stages their accounts and welcome materials so everything is ready before day one.
Day-One SaaS Access Bundle from HR Webhook
When HR marks a new hire as starting, this provisions their core SaaS accounts (email, chat, file storage) based on their department and posts a checklist to the IT channel.
Certificate Renewal Owner Investigator and Dispatcher
For each near-expiry certificate, an agent figures out the responsible service owner from your records, drafts a renewal action plan, files a tracking ticket.
Correlate Expense and DNS Signals into a Shadow-IT Risk Score
Joins SaaS charges from Snowflake with first-seen domains from Cloudflare DNS to confirm real shadow-IT adoption, scores each tool by spend and reach.

Start with a template, not a blank canvas.
14-day trial. No DevOps. No Sales call. Provisioned in under a minute.
