Claude AI Access Request
Handles a tier upgrade request for an AI coding assistant. Reads the requester's current tier from their IdP group membership, bumps them to the next one, routes the approval to their group manager, then moves them between groups and logs the change to a dataset. Requests already at the top tier escalate to the department VP against a tracked token pool.
Drag to pan, or use the controls to zoom. This is the flow exactly as it is built in Harmony.
Step by step
- EventCatalog Item Submitted
- TicketsGet Ticket
- PeopleGet Reporter Details
- CodeFormat Employment End Date
- CodeCheck If Leaving Within 2 Weeks
- Jumpcloud IDPList Reporter's Current JumpCloud Groups
- CodeDetect Current Tier and Calculate Next Tier
- PeopleGet Requester's Manager
- PeopleGet Manager's Manager (Group Manager Candidate)
- CodeResolve Approver (Group Manager or Almog)
- IfAlready at Max Tier ($500)?
- TicketsClose Ticket - Already at Max Tier
- ApprovalsApprover Approval
- SlackNotify Requester - Already at Max Tier
- IfApproved?
- TicketsClose Ticket - Denied
- CodeDetermine Old Group to Remove
- SlackNotify Requester - Denied
- Jumpcloud IDPAdd to New Tier Group
- Jumpcloud IDPRemove Old Tier Group
- SlackNotify Approver - Provisioned
- SlackNotify Requester - Approved
- TicketsResolve Ticket
- CodeCalculate Wait Until 1st of Next Month (3am Israel)
- WaitWait Until 1st of Next Month
- Jumpcloud IDPAuto-Remove from New Tier Group
Integrations you'll need
- JumpCloud IdP
- Slack
Connect these in Harmony before importing, and the steps that use them will run as they are.
More from the community
Resolution Time SLA Breach Escalation
When a resolution-time SLA is breached, notify the assignee in Slack. A day later, check whether the ticket is still open and escalate to the assignee's manager; a day after that, escalate again to a final owner.
Access Employee Data
Former employee data access request. Requires former employee's manager approval, then assigned to IT for fulfillment.
Grant Device Temp Admin Permissions
Grants a requester temporary local admin rights on their own managed device, checks the device is theirs first, and takes the rights back on a timer once the window is up.