HR & People automation · Agentic workflow
HR Onboarding Orchestrator
An LLM agent onboards a new hire across five systems through their APIs: HRIS, IT service desk, Payroll, Calendar and Messaging. Guardrails are enforced in code, transient failures are retried, and every exception waits for a human decision.
1 · Choose a new hire and a scenario
2 · Live agent timeline
- Press “Run onboarding” to stream each step: the agent’s reason, the API call, status, duration and retries.
3 · Run summary
Welcome message sent to the new hire
Illustrative estimate: 0 manual minutes avoided
Not a measurement. Assumed minutes a coordinator would spend on each step that ran:
How it works
- Agent loop with tool calling: an LLM behind an OpenAI-compatible API, with the model set by configuration, picks the next tool; a Cloudflare Pages Function executes it and streams every event to this page over Server-Sent Events.
- Real HTTP integrations: HRIS, IT, Payroll, Calendar and Messaging are stateless simulated APIs under
/api/onboarding/systems/, with deterministic IDs and scenario-driven failures. - Guardrails in code, not in the prompt: schema validation of every call, a dependency graph (no IT ticket or payroll before the HRIS record, welcome message last), least-privilege access groups and a 12-call budget. Rejected calls appear as “blocked by policy”.
- Resilience: HTTP 503s are retried with exponential backoff; if the LLM is missing, errors or makes two invalid calls, a deterministic planner finishes the same workflow through the same tools and guardrails.
- Human in control, no server state: exceptions end the stream with the run state; your decision resumes it, and the server replays and re-validates that state before acting. Visitors only choose from allow-lists, so no free text reaches the model.
Source code and tests: github.com/nepryoon/hr-onboarding-orchestrator (opens in a new tab)
Connecting to real systems keeps the same shape. An ATS webhook fires when an offer is signed and starts the run; each simulated endpoint is replaced by a thin adapter for the real HRIS, ITSM, payroll, calendar and messaging REST APIs, authenticated with OAuth service credentials held in the platform’s secret store. The tool schemas, dependency graph and call budget stay unchanged, idempotency keys replace the deterministic IDs so retries never create duplicates, every call is written to an audit log, and the approval step is routed to the HR coordinator’s queue instead of this page.