Automated Joiner-Mover-Leaver Playbook with BambooHR and EntraID
Overview
This document provides a step-by-step, walkthrough for configuring and using Joiner–Mover–Leaver (JML) Playbooks in BalkanID. It covers the complete setup flow from integrating your HRIS and Microsoft Entra ID, to configuring webhooks with HRIS and n8n, and finally executing playbook actions that automatically create, route, and approve access requests based on defined policies.
While this guide is specific to BambooHR and EntraID, the same concepts apply to other HR systems and applications for which provisioning & de-provisioning are supported by BalkanID.
What Are JML Playbooks?
JML Playbooks in BalkanID allow you to automate identity and access workflows triggered by employee lifecycle events such as:
Joiner: A new employee starts
Mover: An employee changes role, department, or title
Leaver: An employee exits the organization
Playbooks can automatically:
Create access requests
Route requests for approval or auto-approval based on policy
Trigger provisioning and deprovisioning workflows
Maintain a complete audit trail within your BalkanID tenant
Playbooks can be triggered in real time via webhooks or run automatically based on defined conditions, providing consistency, speed, and governance across identity workflows.
Pre-requisites
Before you begin, ensure the following are in place:
An active BalkanID tenant accessible at
https://<yourdomain>.app.balkan.idAdministrator access in BambooHR (or your HRIS) to configure API keys and webhooks
Global Administrator access in Microsoft Entra ID for integration setup
An active n8n instance (cloud-hosted or self-hosted)
This guide uses n8n-based workflows as an example, BalkanID playbooks supports multiple workflows. If you use a different workflow orchestration platform or custom scripts, please contact BalkanID Support: support@balkan.id
Integration Setup
1. Configure HRIS - BambooHR Integration
Log in to
<yourdomain>.app.balkan.idNavigate to Configure → Integrations
Click Add Integration

Search for and select 'Merge'
Provide a description and assign an owner

Click on 'Get Access Token'
Complete the setup using either:
API Key authentication, or
Credential-based authentication (as supported by your HRIS)
Click on next to move onto Optional Configuration.
Fill Optional configuration, if required.

Once you filled in the information, click Save. Your integration is now configured and you will see the status of the integration displayed alongside other integrations on the Integrations page. When data is available, the integration Status will read Connected and the integration Message will read Data available.
2. Configure Microsoft Entra ID Integration
BalkanID recommends using a dedicated service account for Entra ID integrations instead of a personal user account.
Follow the official setup guide here:
This integration enables BalkanID to evaluate identity attributes, roles, and group memberships required for access decisions.
Webhook Configuration: BambooHR ↔ n8n
n8n Playbook Setup
Download the playbook JSON file provided by the BalkanID team. If you have not yet received the file, please contact support@balkan.id to request it.
Import the workflow into your n8n instance
Configure credentials:
Create a new BalkanID API Key from
<yourdomain>.app.balkan.id → Account → API Keysand use it in playbook configuration

BambooHR credential using the API key created in BambooHR API and Webhook setup - Step 1
Initialize configuration variables in the workflow nodes
Activate the workflow
Once active, the n8n workflow listens for HRIS events and triggers the appropriate BalkanID playbook.
BambooHR API and Webhook setup
To enable real-time JML automation, BambooHR events must be forwarded to n8n using webhooks.
Step 1: Create a BambooHR API Key
Log in to BambooHR as an administrator
Navigate to My Account → API Keys

Click Add New Key
Name the key (for example:
BalkanID-Playbooks-API)
Save the API key securely
Step 2: Create BambooHR Webhooks
Each JML playbook requires a separate webhook, as the triggering data differs by event type. Navigate to Account —> Settings —> Webhook(Create Webhook)
Joiner Webhook
Enter a meaningful name for the webhook (for example, Joiner Webhook)
In 'What fields do you want to monitor?' and 'What fields do you want to post?', select Employee #
For 'What format should the data be in?', select JSON
In 'Where should the data be posted?', enter the production webhook URL generated from n8n
Example:
https://balkanid.app.n8n.cloud/webhook/<webhook-id>
Save the webhook configuration

Mover Webhook
Enter a meaningful name for the webhook (for example, Mover Webhook)
In 'What fields do you want to monitor?' and 'What fields do you want to post?,' select Department, Job TitleFor
'What format should the data be in?', select JSON
In Where should the data be posted?, enter the production webhook URL generated from n8n
Example:
https://balkanid.app.n8n.cloud/webhook/<webhook-id>
Save the webhook configuration

Leaver Webhook
Enter a meaningful name for the webhook (for example, Leaver Webhook)
In 'What fields do you want to monitor?' and 'What fields do you want to post?,' select Employment Status
In 'What format should the data be in?', select JSON
In Where should the data be posted?, enter the production webhook URL generated from n8n
Example:
https://balkanid.app.n8n.cloud/webhook/<webhook-id>
Save the webhook configuration

Playbooks in Action
Joiner Playbook Flow
The Joiner playbook automates identity creation and access provisioning when a new employee joins the organization.

A new employee record is created in BambooHR
A Webhook or scheduled sync sends the event to BalkanID
The Joiner playbook is triggered
A user account is created in Entra ID on the employee’s start date
The playbook:
Applies preferred email formats
Detects and resolves name or email conflicts
Birthright access is determined using peer analysis based on attributes such as:
Job title
Department
Manager
Employment type
BalkanID generates access grant requests
Requests are:
Auto-approved via policies(see how to create policies here, or
Manually approved by designated approvers
Approved access is provisioned in Entra ID
The newly created corporate email address is written back to BambooHR
Login credentials are securely shared with the employee’s manager
Leaver Playbook
The Leaver playbook ensures timely deprovisioning when an employee is terminated.

An employee is marked as terminated in BambooHR
The termination event is sent to BalkanID Leaver playbook and is triggered
BalkanID generates access revoke requests
Requests are:
Auto-approved through policy, or
Routed for manual approval
Upon approval, the user is suspended in Entra ID, preventing further access
Mover Playbook
The Mover playbook manages access changes when an employee’s attributes change.

An employee’s attributes (job title, department, manager, employment type, etc.) are updated in BambooHR
The change is detected and the Mover playbook is triggered
BalkanID recalculates the employee’s required access
Access grant and revoke requests are generated
Requests are:
Auto-approved using policies, or
Sent for manual approval
Approved changes are provisioned in Entra ID

