Skip to main content

GroWrk Embedded for IT & Identity

Complete joiner-mover-leaver in the physical world.

Identity platforms control digital access. GroWrk lets the same workflow provision, track, recover, and retire the physical device — without replacing your IdP, MDM, or ITAM.

  • Joiner · Mover · Leaver
  • Zero-touch ready
  • MCP actions
  • Audit evidence
Your identity platformDirectory · User

Sofia Martins

Security Engineer · Lisbon, PT

Identity active
Groups
eng, security
Licenses
Provisioned
Device
Required

webhookuser.created

  1. Identity
  2. Policy
  3. Deploy
  4. Configure
  5. Enroll
  6. Asset

Illustrative partner interface · GroWrk executes behind it

The gap today

Provisioning an account is only half the job.

A joiner gets an identity, groups, licenses, and app access in minutes. The laptop that access runs on is ordered by a different team, from a different vendor, on a different timeline, and tracked in a different spreadsheet.

  • Two lifecycles, one employee.

    The identity record and the asset record drift apart from the first day.

  • Leavers are the risk.

    Access is revoked in seconds; the device holding cached data can take months to come back.

  • Movers get ignored.

    Role and country changes rarely trigger the hardware change they imply.

  • Evidence is manual.

    Chain of custody and wipe certificates get assembled by hand at audit time.

The opportunity

Own the physical half of the lifecycle you already orchestrate.

Your platform is already the place where joiner, mover, and leaver events are defined. Attaching real device operations to those events is a natural extension, not a new product category.

  • Complete the workflow

    One trigger drives both the account action and the device action.

  • Close the offboarding gap

    Revocation and retrieval start from the same event.

  • Asset truth

    Ownership, location, and condition maintained alongside identity.

  • Automation depth

    Real-world actions become part of your workflow engine.

  • Audit-ready records

    Custody and disposition evidence retrievable through the API.

  • Complementary, not competitive

    Works alongside the IdP, MDM, ITSM, HRIS, and ITAM already deployed.

Joiner · Mover · Leaver

One lifecycle, digital and physical.

Each identity state change has a physical counterpart. GroWrk executes it and returns the result to your platform.

  1. 01

    Identity created

    A user is created and assigned to groups. Your workflow engine already knows role, location, and access profile.

    Your identity platformDirectory · User

    Sofia Martins

    Security Engineer · Lisbon, PT

    Identity active
    Groups
    eng, security
    Licenses
    Provisioned
    Device
    Required

    webhookuser.created

    1. Identity
    2. Policy
    3. Deploy
    4. Configure
    5. Enroll
    6. Asset
  2. 02

    Device policy resolved

    Group membership maps to a hardware standard, so the device follows the same rules as the access profile.

    Your identity platformWorkflows · Device policy

    SEC-STD-14

    MacBook Pro 14 · encrypted

    Approved
    Trigger
    group: security
    Enrollment
    Zero-touch
    Approval
    Manager

    webhookdevice_policy.matched

    1. Identity
    2. Policy
    3. Deploy
    4. Configure
    5. Enroll
    6. Asset
  3. 03

    Deployment created

    GroWrk sources the unit and prepares it for your customer's management posture before it ships.

    GroWrk infrastructureDeployment · PT

    GRW-52140

    Lisbon, PT · local stock

    Configuring
    Serial
    Reserved
    Image
    Corp baseline
    Encryption
    Enabled

    webhookdeployment.configured

    1. Identity
    2. Policy
    3. Deploy
    4. Configure
    5. Enroll
    6. Asset
  4. 04

    Enrollment ready

    The device is registered for zero-touch so it lands in the existing MDM on first boot. GroWrk does not replace that MDM.

    Your identity platformDevices · Enrollment

    Ready for MDM

    Serial handed to enrollment program

    Enrollment ready
    MDM
    Existing tenant
    Profile
    Security baseline
    First boot
    Supervised

    webhookdevice.enrollment_ready

    1. Identity
    2. Policy
    3. Deploy
    4. Configure
    5. Enroll
    6. Asset
  5. 05

    Asset assigned

    The device record is bound to the identity, giving you one view of who holds what, where, and in what condition.

    Your identity platformDirectory · User · Assets

    Sofia Martins

    1 assigned device

    Assigned
    Asset
    GRW-PT-52140
    Assigned
    Sep 9
    Custody
    Employee

    webhookasset.assigned

    1. Identity
    2. Policy
    3. Deploy
    4. Configure
    5. Enroll
    6. Asset

Software in. Hardware out.

Software is only half the infrastructure.

Revoking a token is instant. Getting a specific laptop out of a specific apartment in a specific country, verified and wiped, is an operating network.

POST /v4/orders
  • 01

    Employee

  • 02

    Courier

  • 03

    Facility

  • 04

    Inspection

  • 05

    Certified wipe

  • 06

    Disposition

{ "id": "RTV-40218", "status": "scheduled", "custody": "employee" }

Where the line sits

Your platform decides. GroWrk executes.

GroWrk complements the IdP, MDM, ITSM, HRIS, and ITAM already in place. It does not replace any of them.

Your product owns

The experience

  • Identity and access lifecycle
  • Workflow triggers and approvals
  • Device policy definitions
  • Agent and automation surface
  • Compliance reporting UI
  • Customer relationship

GroWrk operates

The infrastructure

  • Sourcing and configuration
  • Enrollment readiness for your MDM
  • Delivery and swaps
  • Retrieval and chain of custody
  • Certified wiping and evidence
  • Storage, redeployment, retirement

Why it matters

What changes when the physical side is connected.

01

One joiner-mover-leaver lifecycle.

The same trigger that grants or revokes access also provisions or recovers the hardware that access runs on.

  • No parallel manual process
  • Consistent SLAs across both halves
  • Fewer orphaned assets
02

Connect digital identity to physical asset ownership.

Every device carries an assignment history tied to real identities, locations, and custody transfers.

  • Who holds what, right now
  • Condition and warranty tracked
  • Custody and wipe evidence on demand
03

Automate real-world actions without replacing your stack.

GroWrk sits underneath your workflow engine as an execution layer, alongside the tools your customers already run.

  • Complements IdP, MDM, ITSM, ITAM
  • Scoped API and MCP access
  • Approval gates on high-impact actions

Product & developers

Software primitives for physical operations.

Identity platforms typically use webhooks plus the REST API, and add MCP when they expose an agent surface.

Example request
POST /v4/orders

{
  "asset_id": "GRW-DE-60441",
  "reason": "offboarding",
  "requires_approval": true,
  "wipe": "certified"
}
  • REST API

    Deployments, swaps, retrievals, custody, wipe evidence, and disposition.

  • Webhooks

    Custody transfers, delivery, receipt, wipe, and disposition events.

  • CLI & automation

    Bulk retrievals and inventory reconciliation for large tenants.

  • MCP & AI agents

    Permission-aware tools so agents can act, not just advise.

  • White-label

    Employee-facing retrieval communications under your brand where scoped.

  • Permissions & approvals

    Scoped tokens, approval gates, and a complete audit log.

MCP & AI agents

Give your IT agent the ability to act in the physical world.

GroWrk exposes lifecycle capabilities over the Model Context Protocol, so an agent inside your platform can start real device operations inside real permission and approval boundaries.

Agents inherit the scopes of the user or service they act for. High-impact actions — purchases, retrievals, disposition — can require explicit human approval, and every action is written to the audit log.

MCP · agent sessionAwaiting approval

Prompt

Offboard Sofia. Revoke access and retrieve her MacBook.

  • Identity accessRevoked
  • Assigned deviceMacBook Pro 14 · GRW-DE-60441
  • Device retrievalPending approval

Embedded infrastructure

One integration. An entire physical operations layer.

Your developers work with a handful of software primitives. GroWrk absorbs the operational complexity underneath them.

Partner product
REST APIWebhooksCLIMCP
  • Procurement
  • Configuration
  • Deployment
  • Warehousing
  • Maintenance
  • Retrieval
  • Redeployment
  • Disposition

Commercial models

How IT platforms package it.

Physical actions are usually sold as an operational tier on top of automation.

  • Automation tier

    Physical actions unlocked in a higher workflow-automation plan.

  • Per-action pricing

    Charged per deployment, retrieval, or certified disposition.

  • Compliance package

    Bundled with custody and disposition evidence for regulated customers.

  • Enterprise add-on

    Attached to multi-country enterprise agreements.

GroWrk does not set end-customer pricing. Commercial terms are agreed during partnership design.

Why GroWrk

Why GroWrk.

  • Execution layer, not another console

    Designed to be driven by your workflows rather than to own the user.

  • Evidence by default

    Custody transfers, inspections, and wipe certificates recorded as they happen.

  • Global reach

    Retrieval and deployment supported across more than 150 countries.

  • Agent-ready

    MCP tools with scopes and approval gates rather than open-ended automation.

FAQ

IT & Identity questions.

How does identity lifecycle data trigger device actions?

Your workflow engine calls GroWrk when a joiner, mover, or leaver event fires. Group membership or role attributes resolve to a device policy, and the resulting deployment, swap, or retrieval reports back through webhooks so the identity record stays accurate.

Does GroWrk replace an MDM?

No. GroWrk prepares devices so they arrive ready for the customer's existing MDM — including zero-touch enrollment registration where supported. Management, configuration profiles, and policy enforcement stay in the MDM.

How does GroWrk work with IT asset management platforms?

GroWrk maintains the operational record — sourcing, custody, condition, location, and disposition — and exposes it through the API and webhooks. Partners typically sync that data into their own asset views or into the customer's ITAM rather than replacing it.

Can devices arrive MDM-ready?

Yes. Imaging, encryption baselines, accessories, and enrollment registration can be completed before the device ships, so first boot lands the machine in the correct management posture.

Can offboarding trigger retrieval automatically?

Yes. A leaver event can create a retrieval immediately, optionally behind an approval gate. GroWrk then coordinates pickup with the employee, records custody transfers, and performs certified wiping on receipt.

How do approval controls work for AI agents?

MCP tools are scoped to the permissions of the acting user or service. Actions with cost or compliance impact can be configured to require explicit human approval before execution, and every call is written to the audit log with the requesting identity.

How is device lifecycle history maintained?

Each device has one record for its entire life: procurement, configuration, assignments, location changes, maintenance, custody transfers, wipes, and final disposition. History is preserved across employees and across redeployments.

Can lifecycle actions be exposed directly inside our product?

Yes — that is the intent. Partners render device actions inside their own UI and workflows; GroWrk stays behind the API. White-label scope for any employee-facing communication is defined during partnership scoping.

Built for your platform

Explore the other categories.

Connect digital access to the physical device.

Bring your joiner-mover-leaver model and we will map it to GroWrk lifecycle operations.