Automated user provisioning for quality control staff using Infor OS Workflows

I wanted to share our successful implementation of automated user provisioning for quality control staff in ICS 2021. Before automation, our manual setup process was painfully slow - HR would email IT when new QC inspectors were hired, IT would manually create accounts, assign roles, and the new employee would wait 2-3 days for access. This was particularly problematic during our seasonal production ramps when we onboard 15-20 QC staff within a few weeks.

We implemented an end-to-end automation using Infor OS Workflows that cut onboarding time from 2-3 days to under 30 minutes. The solution integrates our HR system (Workday) with Infor CloudSuite and handles everything from account creation through MFA enrollment. The results have been impressive: onboarding time reduced by 95%, zero manual errors in role assignments, and new QC staff can start productive work on day one.

The automation covers three key areas: HR workflow triggers that detect new hires in quality control roles, automated role assignment based on QC function and certification level, and mandatory MFA enrollment as part of the onboarding flow. Happy to share technical details if others are tackling similar challenges.

Great question Marcus. We handle MFA enrollment through a combination of automation and self-service. The workflow pre-registers the user for MFA in Infor OS and generates a registration token. We then send an automated email to the new employee’s personal email (collected during HR onboarding) with a personalized link to complete MFA setup. The email includes simple instructions with screenshots. Our QC supervisor also walks new hires through the process on their first day using a tablet. The key is triggering the MFA registration as part of the automated flow so it’s ready when the employee arrives.

This is exactly what we need! We’re still doing manual provisioning and it’s a bottleneck during high-volume hiring periods. Can you share more about how you trigger the workflow from Workday? We use Workday as well and have been struggling to find a reliable integration approach.

The Workday integration uses their REST API with event notifications. We configured Workday to send a webhook to our Infor OS API Gateway whenever a new employee record is created with job_code matching our QC roles (QC_INSPECTOR, QC_SUPERVISOR, QC_LAB_TECH). The webhook payload includes employee details, start date, department, and assigned manager. Infor OS Workflow picks up this event and orchestrates the entire provisioning sequence.

I’m curious about the role assignment logic. Quality control roles can be complex with different certification requirements and equipment access levels. How granular did you make the automated role assignment? Are you just assigning a base QC role and then manually adjusting, or does the automation handle the full role matrix?

Let me provide comprehensive details on our implementation covering all three focus areas:

HR Workflow Triggers - Workday Integration Architecture:

Our integration uses Workday’s Event Notification Framework. Here’s the technical flow:

  1. Workday Configuration:

    • Created custom Business Process: “New Hire - Quality Control”
    • Configured event subscription for job codes: QC_INSPECTOR, QC_SUPERVISOR, QC_LAB_TECH, QC_AUDITOR
    • Event triggers on “Hire” transaction completion in Workday
  2. Webhook Payload:

{
  "employee_id": "WD-12345",
  "first_name": "John",
  "last_name": "Smith",
  "email": "john.smith@company.com",
  "personal_email": "jsmith@gmail.com",
  "job_code": "QC_INSPECTOR",
  "department": "Quality Control - Assembly",
  "start_date": "2024-12-15",
  "manager_id": "WD-98765",
  "certifications": ["ISO9001", "SixSigma_GB"]
}
  1. Infor OS API Gateway:
    • Receives webhook at /api/hr/new-hire endpoint
    • Validates payload and authenticates Workday source
    • Triggers Infor OS Workflow: “QC_User_Provisioning_v2”

Role Assignment Automated - Intelligent Role Mapping:

Nina asked about role assignment granularity - we implemented a comprehensive role matrix that handles complex QC role structures:

Role Mapping Logic:

Base roles assigned by job_code:

  • QC_INSPECTOR → CloudSuite_QC_Inspector (read/write access to inspection records, equipment checkout)
  • QC_SUPERVISOR → CloudSuite_QC_Supervisor (includes inspector permissions + approval workflows, reporting)
  • QC_LAB_TECH → CloudSuite_QC_Lab (lab equipment access, test data entry, sample tracking)
  • QC_AUDITOR → CloudSuite_QC_Auditor (read-only across all QC modules, audit trail access)

Additional roles based on certifications:

  • ISO9001 certification → QC_ISO_Compliance role (access to compliance documentation, audit preparation)
  • SixSigma certification → QC_Process_Improvement role (statistical analysis tools, process mapping)
  • FDA_Validation → QC_Regulated_Products role (pharmaceutical/medical device quality workflows)

Department-based permissions:

  • Quality Control - Assembly → Assembly_Line_Access
  • Quality Control - Incoming → Vendor_Quality_Access
  • Quality Control - Final → Shipping_Release_Authority

The workflow queries a role mapping table we maintain in a configuration database. This allows HR and QC management to update role assignments without modifying workflow code.

Workflow Implementation:


Step 1: Receive HR trigger → Parse employee data
Step 2: Query role mapping table → Determine base + additional roles
Step 3: Call Infor OS User API → Create user account
Step 4: Call Infor OS Security API → Assign roles (iterate through role list)
Step 5: Call Infor OS MFA API → Pre-register for MFA, generate token
Step 6: Send welcome email → Include MFA setup link, first-day instructions
Step 7: Notify QC supervisor → Email with new hire details, MFA completion checklist
Step 8: Log provisioning event → Audit trail with timestamp, roles assigned

MFA Enrollment Included - Streamlined Security Onboarding:

Our MFA enrollment automation addresses Marcus’s concern about manual intervention:

Pre-Registration Process:

The workflow calls Infor OS MFA API to pre-register the user:


POST /api/security/mfa/pre-register
Payload: {"user_id": "jsmith", "method": "totp"}
Response: {"registration_token": "abc123xyz", "expires_in": 604800}

The registration token is valid for 7 days (604800 seconds), giving new hires time to complete setup.

Self-Service Enrollment:

We send an automated email to the employee’s personal email (to ensure they receive it before having corporate email access):

Email Template:


Subject: Complete Your Security Setup - Start Date [DATE]

Welcome to [Company]! Your Quality Control account is ready.

Next Step: Set up multi-factor authentication (MFA)
1. Click this link: https://company.inforcloud.com/mfa/enroll?token=abc123xyz
2. Download Microsoft Authenticator app (iPhone/Android)
3. Scan the QR code shown on screen
4. Enter the 6-digit code from your app

Video tutorial: [link to 2-minute walkthrough]

Questions? Contact your supervisor [SUPERVISOR_NAME] or IT Help Desk.

Your username: jsmith
Temporary password: [sent separately via SMS]

First-Day Process:

QC supervisors receive a notification with a checklist:

  • Verify employee completed MFA enrollment (can check via admin dashboard)
  • If not completed, walk through enrollment using tablet on production floor
  • Test login and application access
  • Review QC module training materials

We maintain a tablet at each QC supervisor station pre-loaded with the MFA enrollment page. If an employee hasn’t completed enrollment before arriving, the supervisor can complete it in 5 minutes during orientation.

Error Handling - Robust Fault Tolerance:

Robert asked about failure scenarios - we implemented comprehensive error handling:

Transaction Rollback:

The workflow uses compensating transactions. Each step has a corresponding rollback action:

  • Account creation fails → Stop workflow, alert IT
  • Account created, role assignment fails → Delete account, alert IT with details
  • Account + roles created, MFA pre-registration fails → Flag account for manual MFA setup, allow provisioning to complete

Alerting:

We send alerts to different teams based on failure type:

  • Integration failures (Workday webhook) → Alert integration team
  • API failures (Infor OS) → Alert Infor admin + IT ops
  • Partial provisioning → Alert IT ops + QC supervisor

Monitoring Dashboard:

Built a simple dashboard showing:

  • Provisioning requests in last 24 hours / 7 days / 30 days
  • Success rate percentage
  • Failed provisioning attempts with error details
  • Average provisioning time (target: <30 minutes)
  • MFA enrollment completion rate (target: >95% within 48 hours)

Results and Metrics:

After 6 months of operation:

  • 127 QC staff provisioned through automation
  • 98.4% success rate (2 failures due to duplicate employee IDs in Workday)
  • Average provisioning time: 18 minutes
  • MFA enrollment completion: 96% within first day, 100% within 3 days
  • Zero role assignment errors (previously 15-20% error rate with manual process)
  • IT time savings: 45 minutes per user × 127 users = 95 hours saved

Lessons Learned:

  1. Start simple: We initially tried to automate too much. Started with basic provisioning, then added role complexity and MFA integration in phases.

  2. Involve stakeholders early: QC management helped define role matrix. HR validated Workday integration. Security approved MFA enrollment approach. Cross-functional input was critical.

  3. Plan for exceptions: Not every scenario fits automation. We maintain a manual provisioning process for contractors, temporary staff, and special access requests.

  4. Invest in monitoring: The dashboard was an afterthought initially, but became essential for identifying issues quickly and proving ROI to leadership.

  5. Document everything: Created runbooks for IT ops covering common failure scenarios, manual intervention procedures, and escalation paths.

Happy to answer specific technical questions about any aspect of the implementation. The workflow definition and role mapping table schema are available in our internal documentation if others want to replicate this approach.

How are you handling MFA enrollment in an automated fashion? That’s been our sticking point - we can automate account creation and role assignment, but MFA enrollment still requires manual intervention where the user has to scan a QR code with their authenticator app. For quality control staff on the production floor, getting them through that process has been challenging.