NEWFreshservice is now a Ploy integrationSee what shipped
1.0LIFECYCLE MANAGEMENT

Access that keeps up with your organisation.

Luna manages every employee's access from before day one through every role, team and tool change to departure. She runs on an evergreen policy engine, completes the work, and keeps access right without someone managing every step.

Lifecycle
Onboarding3Offboarding
From your HRISMia joined the board this week.1 syncedfirst starts Sat 4 JulMKMia — runbooks built from their profiles
Show me who's new
Day-one readiness1 of 3 will be ready for day one.1 ready1 catching up1 blocked1/3
See who's falling behind
Waiting on you2 things need your call.Priya — Assign Microsoft E5 licenceMia — approve AWS admin
Show them on the timeline
Search joinersStatusProfile Onboarding config
June142128July512Today
AOAmara OseiStarts tomorrow
Setup:9/10Access:7/7
MKMia KrügerNewStarts Sat 4 Jul
Setup:6/10Access:6/11
PRPriya RamanStarts Tue 7 Jul
Setup:4/8Access:2/9
1.1ACCESS PLAN

One live access plan for every employee.

Traditional lifecycle management runs a workflow when someone joins, moves or leaves. Between those moments, lists drift. Ploy keeps a live access plan for every employee, recalculated on any identity, role, team, tool or policy change.

Maya Oseimaya.osei@fintechcorp.com
✓ ActiveTitleCSM LeadDeptCustomer SuccessManagerStarted2023-05-13+ 20 more fields
Employment typeFulltimeRole levelIC4LocationLondonCost centreCS-114End date

Twenty-four fields under watch

Ploy watches twenty-four employee fields, so a change shows up as something to act on rather than a rumour in a Slack thread.

DepartmentOWNED BY BAMBOOHR
Job titleOWNED BY OKTA
ManagerLOCKED

One winner per field

Each field names its owning source and can be locked, so two systems disagreeing never turns into a silent overwrite.

Maya Oseimaya.osei@fintechcorp.com
✓ ActiveDeptSales OpsRECOMPUTING…Deal DeskProfileSales OpsRECOMPUTING…Deal DeskManaged apps12RECOMPUTING…14

Cohorts that follow the org

Profiles recompute as people move, so the cohort a person belongs to is never last quarter's answer.

History
15 Jun 2026, 15:53
DSales OpsDDeal Desk
JJess MertensManually overridden
29 May 2026, 09:39
DSalesDSales Ops
BBambooHRHRIS sync

Every change has a paper trail

Old value, new value, source, and who made it are recorded on the employee. The history answers questions a screenshot cannot.

1.2JOINERS

Every onboarding, managed by Luna.

A new hire appears in your HRIS, policy calculates the access their role needs, and Luna creates the accounts, licences and entitlements, routes the exceptions, and checks day-one readiness, with no dedicated operator and no ticket queue.

Nadia Khannadia.khan@fintechcorp.comSTARTS MON 1 SEPDAY ONE · ACTIVE
Dept DESIGNTitle PRODUCT DESIGNERBambooHR · HRIS sync
Profile DESIGNDAY-ONE READINESS · 0/4
No access yet, and nothing to clean up later either.
FigmaEditorEditor · Design profile · review at 90 daysSCHEDULED · ON START DATEPROVISIONED
Google WorkspaceAccountAccount · Design profile · standingSCHEDULED · ON START DATEPROVISIONED
SlackWorkspace memberWorkspace member · Design profile · standingSCHEDULED · ON START DATEPROVISIONED
MiroMemberMember · Design profile · 6 monthsSCHEDULED · ON START DATEPROVISIONED
Manager notified · no tickets filed

The lifecycle keeps running after day one.

Ploy keeps scanning between the milestones, and each finding carries the reason it was acted on.

1.3MOVERS

When the role changes, access changes with it.

A department, title, manager, location or status change triggers a full recalculation. What the new role needs is granted, what is no longer justified is removed, and every decision is recorded.

Maya Oseimaya.osei@fintechcorp.comACTIVE
DeptSALES OPSCUSTOMER SUCCESSProfileSALES OPSRECOMPUTING…CUSTOMER SUCCESS
Sales Ops › Customer Success · BambooHR · HRIS sync
SalesforceSales userGRANTED · PROFILEREMOVED
HubSpotDeals pipelineGRANTED · PROFILEREMOVED
MetabaseSales dashboardsCS dashboardsGRANTED · PROFILEENTITLEMENT CHANGED
SlackWorkspace memberGRANTED · PROFILEKEPT
ZendeskAgent seatGRANTED · PROFILEADDED
IntercomInbox accessGRANTED · PROFILEADDED
Review started · scoped to “changed recently”
HISTORY · DEPT · SALES OPS › CUSTOMER SUCCESS · BAMBOOHR · 2 REMOVED · 2 ADDED · 1 CHANGED
1.4HUMAN CONTROL

Luna handles the work. People handle the exceptions.

Routine access runs automatically under policy. Admin access, unclear ownership and unusual cases reach the right person with the context to decide. The answer arrives and Luna finishes the work.

Waiting on you2 things need your call.Priya — Assign Microsoft E5 licenceMia — approve AWS admin
Show them on the timeline
1.5LEAVERS

Every leaver, fully unwound.

An end date starts the offboarding across every account, grant, session, token, admin right and owned resource. Luna chases the owners, verifies the work, and will not close the exit while anything is still open.

Tom LigetiLast day Fri 1 Aug
IN PROGRESSOFFBOARDING COMPLETED
Checklist
Google Workspace account
Slack account
GitHub account
Okta account
Salesforce login
Sessions and tokens
Activity
Google Workspace · suspended by a flow
Slack · removed by the app owner
GitHub · deprovisioned over SCIM
Okta · revoked in Access Reviews
Salesforce · login blocked by a flow
Sessions and tokens · revoked by Luna
Mark complete is blocked while 6 items are openMark complete is blocked while 5 items are openMark complete is blocked while 4 items are openMark complete is blocked while 3 items are openMark complete is blocked while 2 items are openMark complete is blocked while 1 item is open
Mark completeMark complete

One exit, one live tracker

Revocations, login blocks, and token revokes done anywhere in Ploy check themselves off the leaver's list. Complete means verified: the tracker cannot be marked complete while any account or task is open.

Tom LigetiLast day Fri 1 Aug
IN PROGRESS
Confirmed Access8 revoked · 4 pending11 revoked · 1 pendingRevoked
Shadow Access1 revoked · 2 pending2 revoked · 1 pendingRevoked
Tasks2 done · 4 open5 done · 1 openDone
Admin Rights0 transferred · 2 pending1 transferred · 1 pendingTransferred
SCIM Accounts1 removed · 3 pending3 removed · 1 pendingRemoved

The checklist ticks itself

Confirmed Access, Shadow Access, Tasks, Admin Rights, and SCIM Accounts each carry their own count, and each ticks as the work lands anywhere in Ploy.

Tom Ligeti
3 SHADOW ACCOUNTS DETECTED

Shadow access is included

Accounts discovered outside the directory get their own offboarding tab, so an exit covers what IT never knew existed.

FigmaTRANSFERRED
ZoomPENDING
MiroNOT REQUIRED
AirtableNOT REQUIRED
CalendlyNOT REQUIRED

Ownership is transferred

Every app the leaver owned is Pending, Transferred, or Not required. There is no fourth state where the answer is nobody knows.

Ploynow
Reminder: 4 offboarding rows are waiting on you. Tom Ligeti leaves Friday.

Luna chases what is still open

The Offboarding Reminders playbook watches every open exit and nudges the owners, so nobody has to keep a private list of who has not replied.

Avantia Law
Ploy has transformed how we do access requests & we wouldn't be able to go back to the way it was.
Peter F.Head of IT & Infosec, Avantia Law
Read the story
Liberis
Ploy has enabled us to completely automate employee onboarding and offboarding, saving us 150 manual actions, clicks, and hours of time per employee.
Paul HartHead of IT, Liberis
Welcome to the Jungle
With Ploy, we've turned a tedious weekly task into easy automated flows. We're saving half a day a week and have completely streamlined onboarding across all our SaaS tools. Total game changer.
Devon BrownSenior IT Engineer, Welcome to the Jungle
Luno
Ploy saved me from drowning in spreadsheets, manual licence assignment and SaaS sprawl. It lets us easily make sense of what's being bought, used, and wasted which is more than I can say for most software tools. The best part? They listen, iterate fast, and don't take themselves too seriously. Perfect match.
Simon FishleyGlobal IT Director, Luno
Read the story

Stop managing employee access by hand.

An evergreen policy engine keeps every employee's access right, from before day one, through every role, team and tool change, to the day they leave.