- Mover: HR-Triggered - Oleria periodically polls your connected HR system and processes employees whose department, job title, or manager changed. Best suited for planned moves detected from HR data.
- Mover: Manual Entry - An admin enters employees individually or uploads a CSV file to start a move on demand. Best suited for moves you need to run without waiting for an HR system sync.
Prerequisites
- Admin, Governance Operator, or Identity Lifecycle Operator role on the Oleria platform
- A connected HR platform (required for HR-Triggered lifecycles) - see Integrations
- Access Bundles defined for the roles, departments, or job functions movers should receive
- Connected applications for provisioning and deprovisioning
Before you publish a mover lifecycle, confirm that Access Bundles exist for the attribute combinations you expect after a move.
Creating a mover lifecycle
Navigate to Employee Lifecycle -> Lifecycles and select Create lifecycle to open the template picker. Choose Mover: HR-Triggered or Mover: Manual Entry to begin the setup wizard.
- HR-Triggered
- Manual Entry
The HR-Triggered lifecycle monitors your connected HR system and processes role changes automatically. After you publish the lifecycle, Oleria periodically checks your HR data and enrolls employees whose department, job title, or manager has changed.
1
Review the schedule trigger
The schedule is pre-configured. Oleria periodically checks your connected HR system to detect employees with attribute changes. Changes to department, job title, and manager are monitored - these three attributes are fixed and cannot be modified.Set a Correlation window (1-72 hours, default 24 hours) so that multiple attribute changes for the same employee within that window are combined into a single mover event. This prevents duplicate events when HR updates department, job title, and manager in close succession.
Configure your HR system connection under Settings before creating an HR-Triggered lifecycle.
2
Configure modify access
Configure how Oleria grants new-role access and revokes previous-role access. Access changes are driven by Access Bundles assigned and removed based on each employee’s attribute changes.
Get approval to modify accessFallback when the approval window expires without a response:

Even when approval is not required for bundle-matched changes, you still configure an approver. Approvers are needed as a fallback - for example, when no Access Bundle matches the employee’s new role (cold start).
- Remove previous-role access - existing access is kept (revocation is not performed)
- Grant new-role access - new access is granted automatically
- Revoke immediately - removal starts as soon as approval completes (or immediately if approval is not required)
- After a grace period - removal waits the number of days you set, so the employee can finish work tied to their previous role
Per-group exceptions
Grant new-role accessChoose when new-role access is assigned:
- Assign immediately - grants start as soon as approval completes (or immediately if approval is not required)
- After a grace period - grants wait the number of days you set
3
Configure notifications
Optionally send email and Slack or Teams messages during the mover process. Choose recipients and which events trigger a notification.
For email, choose whether to notify the employee’s manager or a specific user. You can also configure Slack or Teams messages if you have a messaging system connected - choose a direct message recipient or a channel.
When a mover event enters the Awaiting Approval phase, Oleria automatically notifies the assigned approver via email and Slack or Teams (if connected) with a summary of review details and a link to the Governance app.
4
Review and publish
On the summary page, review your full configuration. Enter a lifecycle name (required, 3-60 characters) and an optional description.Enable Dry-run mode to preview what access changes Oleria would make without applying them. Disable dry-run when you are ready for the lifecycle to take effect on future runs. Previous simulated runs are not retroactively applied.Select Publish to activate the lifecycle. Once published, Oleria runs on schedule and enrolls employees automatically.
Lifecycles cannot be deleted - if you need to stop a lifecycle, disable it from the lifecycle details page.
Running a Manual Entry lifecycle
After publishing a Manual Entry lifecycle, process movers by navigating to the lifecycle details page and selecting Add employees.
1
Choose how to add employees
Select one of two methods:
- Add employees manually - enter up to 10 employees and provide their new role attributes
-
Upload a file - upload a CSV file with up to 500 employees

2
Add employees
If adding manually: Search for each employee by name or email address. Employees are sourced from your connected HR system, so only employees Oleria already knows will appear. For each employee, provide the new job title, manager, and department that reflect the move. Leave an attribute blank if it is unchanged. At least one attribute must be set per employee. You can add up to 10 employees per run.
If uploading a CSV file: Prepare a spreadsheet with these columns (header names are case-insensitive):

All four columns are required. Export the file as
.csv (maximum 1 MB, 500 rows). Drag and drop it onto the upload area or select it using the file picker.Then choose when access modification starts:- Immediately - the mover event begins as soon as you submit
- Schedule for later - pick a date, time, and timezone up to 90 days in the future
3
Review and submit
The review step shows how many employees matched records in Oleria and when access modification is set to begin. Any email addresses, manager emails, or departments with no match are listed so you can verify them before proceeding.If a department name matches multiple entries, the review step lists the candidate department IDs. Correct the file to use a department ID before re-uploading.Select Submit to start the lifecycle run. Employees may take up to a minute to appear in the lifecycle details page.
Mover event details
Each employee processed by a mover lifecycle appears as an individual event. Select an employee’s name from the lifecycle details page to open their event details page.
- User details - name, email, User ID, Employee No., employee start date, department, manager, job title, and company code
- Attribute changes - the previous and new values for department, job title, and manager, shown side by side as previous role and new role
- Current phase - the employee’s position in the lifecycle: Resolving Bundles, Awaiting Approval, Provisioning, and others
- Access removed / Access granted - the count of access entries removed or granted out of the total identified, shown as a percentage

- Applications - application access being granted or removed, with identity provider, change type, status, action, completion time, and any errors
- Groups - group memberships being granted or removed, with the same columns
- Access Bundles - bundles matched to the employee’s new attributes, with counts of identity providers, assigned applications, and groups
Lifecycle phase
Each mover event moves through phases that reflect where it is in the access-change process. The current phase appears on the event details page and in the lifecycle details table.Event status
Each mover event also has a status that reflects the state of its actions. The status appears alongside the phase in the lifecycle details table and on the event details page.If a lifecycle is running in Dry-run mode, the event details page shows a Dry Run label alongside access progress. Actions appear to complete normally, but no access changes are applied.
Approver flow
When approval is required - or when cold start forces a manual path - Oleria creates review items for the configured approver. Approvers need access to the Oleria Governance app to act on requests. Ensure the users you select can sign in before you publish.- The primary approver is notified according to your notification settings.
- If the primary approver cannot be resolved, the alternate approver is assigned.
- The approver reviews the planned grants and removals and approves or rejects them.
- If no decision is made within the approval window, fallback applies: revocations are skipped (access retained) and grants are auto-approved.
- Approved changes move into Provisioning on the timing you set (immediate or after a grace period).
Reviewing access changes in the Governance app
Approvers review and act on mover access requests in the Oleria Governance app. Navigate to Employee Access in the left sidebar to see requests assigned to you.
- Assigned - pending reviews waiting for your decision, sorted by approval window deadline by default
- Done - reviews where all items have been decided or the approval window has lapsed
Review detail page
The detail page shows the employee’s user details and a side-by-side Attribute Changes panel with the previous and new values for each changed attribute.
The Pending tabs disappear once all items are decided or the approval window closes.
Each row in the Pending tabs includes context to help you decide:

