Getting Started with YeshID

Last updated: July 20, 2026

This guide takes a new admin from sign-up to a fully working YeshID setup. The end state: YeshID knows who your people arewhat they can access, and keeps that picture accurate automatically.

The work is organized into eight milestones. We recommend completing them in order — each builds on the last. This playbook is a hub: each milestone gives you the shape of the step, a checkpoint, and a link to the detailed guide for the mechanics. Read those linked guides when you're ready to actually do the step.

How to use this playbook

When you first sign in, the Home page shows a Getting started checklist that tracks the foundational steps for you. It hides itself once you're established (when every step is done, or after your org's first couple of weeks). This playbook follows that same path and then goes further — covering the automation, access control, and audit capabilities the in-app checklist doesn't.

Each milestone below has three parts:

  • Why it matters: what this step buys you, in plain terms.

  • What to do: the shape of the work, using the labels you'll see on screen — with a link to the full guide.

  • You've reached this milestone when: a checkpoint so you know you're done before moving on.

Milestone 1: Sign up and connect your directory

Why it matters: Your directory — Google Workspace, Microsoft, or Okta — tells YeshID who your people are. Connecting it is what lets everyone log in to YeshID and gives YeshID the roster it builds everything else on top of. This is the foundation.

What to do:

  1. Go to app.yeshid.com/login and select Create Account.

  2. Sign up with Google or Microsoft and follow the onboarding prompts. The account you sign up with becomes your first admin, and your directory starts syncing in the background.

  3. To confirm or add a directory later, go to Organization > Directories and select Add Directory. YeshID supports Google Workspace, Microsoft, and Okta (Okta is available on the Business plan).

  4. Open Organization > People and confirm your team appears.

You've reached this milestone when… your people show up under Organization > People and you (and they) can sign in. (In the in-app checklist, this completes Add your users.)

Milestone 2: Build your application inventory

Why it matters: YeshID governs the tools your organization uses — but before it can track access to an app, provision it, or include it in onboarding, that app has to be on your list. Building this inventory is quick and unlocks everything downstream. Add every tool you care about, even the ones you'll only ever track.

What to do: Go to Access > Applications and add the tools your team uses. You can:

  • add them one at a time from YeshID's catalog (or type a name to add a custom/internal app),

  • add them in bulk by pasting a list or uploading a CSV (Import application list), or

  • pull them in from Shadow applications YeshID already sees people logging into.

Assign a Technical Owner (1–5) to each — the people YeshID notifies about the app and who can manage it later.

Full methods and details: Adding Applications to YeshID.

You've reached this milestone when… the apps you care about appear on your Applications list, each with a Technical Owner.

Milestone 3: Import your current access (your source of truth)

Why it matters: Your directory (Milestone 1) tells YeshID who your people are; your source of truth tells it what each of them can access today. Importing this current-access snapshot turns YeshID from an empty inventory into an accurate map of your current reality — it's the single highest-value thing to do early.

What to do: YeshID gives you three ways to import current access, depending on how cooperative each app is. Start with the first that works:

  • Connect the app — best when the app is in the catalog. YeshID pulls in the existing accounts automatically, and the connection doubles as your live integration (Milestone 4).

  • Import a CSV — best when the app lets you export a user list. YeshID really only needs a column of email addresses.

  • Import a screenshot — best when the app has no export but does show a list of users with emails. YeshID reads the images (up to 5) and turns them into accounts.

Whichever method you use, review the mapped data and finish the import before it's applied. Full steps: Getting Your Source of Truth into YeshID.

You've reached this milestone when… at least one of your important applications shows its real accounts under its Accounts tab.

Milestone 4: Connect your core applications

Why it matters: Importing a snapshot (Milestone 3) tells YeshID what access exists; connecting an application lets YeshID act on it — create accounts, update them, and remove them as people join and leave. The more of your key apps are connected, the more YeshID can automate. (Apps you connected in Milestone 3 to import them are already done — this is about deliberately connecting your most important tools for lifecycle automation.) Aim for at least your most important three to start.

What to do: On Access > Applications, open the app's Manage (⋮) menu and choose Connect. Then Choose an integration type (PrebuiltSCIM, or Build your own), Authenticate, and enable only the Actions you want YeshID to perform. Full steps: Connecting Your Applications.

You've reached this milestone when… three or more applications are connected and authorized. (In the in-app checklist, this completes Connect 3 applications.)

Milestone 5: Automate onboarding and offboarding

Why it matters: This is where YeshID starts saving you real time. Instead of manually granting and revoking access for every new hire and departure, you define workflow templates once — a repeatable checklist of accounts to create, groups to add, and tasks to assign — and YeshID runs them on demand. Offboarding templates do the reverse, so access is removed reliably when someone leaves.

What to do:

  1. Go to Manage > Workflow Templates and create an onboarding template and an offboarding template. Add the apps, groups, and tasks that a typical new hire (or departure) needs.

  2. To run an onboarding, go to Organization > People, choose the person, and select Onboard person. Use Schedule this person to be onboarded to set a start date and time (and an optional end-date reminder). Offboarding works the same way with Offboard person.

  3. (Paid plans, with an HRIS connected) To run onboarding automatically, set up an HRIS onboarding trigger under Manage > Triggers so a new hire detected in your HR system kicks off — or stages — the right workflow. Staging keeps a human in the loop before anything runs. See Setting up an HRIS Onboarding Trigger.

You've reached this milestone when… you've created onboard and offboard templates and run at least one onboarding workflow. (In the in-app checklist, this completes Create onboard & offboard templates and Run an onboarding template.)

Workflows with YeshID

Milestone 6: Define access with RBAC

Available on the Business plan. If you don't see RBAC under Access, talk to your YeshID contact about upgrading.

Why it matters: Up to now, you've been managing access app by app and person by person. Role-Based Access Control (RBAC) lets you describe the rule once — "the Engineering team gets GitHub as a Developer" — and YeshID keeps reality lined up with it. It answers the questions auditors love to ask: Who has access to this app, and why? What should this person have, based on their role?

What to do: Go to Access > RBAC and create a policy: name the people or groups it covers (prefer groups — they maintain themselves as people join and leave), add the applications and roles, choose how each is provisioned, and set the policy active. If YeshID detects access drift against the policy, let it generate the remediation workflows to bring access in line. Full model and setup: Role-Based Access Control (RBAC).

You've reached this milestone when… you have at least one active policy and YeshID is reporting access drift against it (under Security > Access Drift).

Milestone 7: Let people request access, and turn on notifications

Why it matters: Not all access can be predicted ahead of time. Access Requests let your people ask for an app when they need it and route the request to the right approver — so access stays controlled without you becoming a bottleneck. Pairing this with Slack notifications means requests and approvals happen where your team already works.

What to do:

  1. Connect Slack and enable YeshID notifications so requests, approvals, and workflow updates reach your team. See Adding the YeshID Slack Bot.

  2. Your people can now request access from the My Apps page (select Request an application) or in Slack (type /request).

  3. As an admin or Technical Owner, review incoming requests under Access > Access Requests and approve or deny them. Fine-tune what YeshID sends and to whom under Manage > Settings > Notifications.

You've reached this milestone when… a test access request flows end to end — submitted, routed to an approver, and granted — and you see the notifications land in Slack. Full details are in Access Requests with YeshID and Notifications with YeshID.

Milestone 8: Prove it with an access audit

Available on paid plans (Growth and Business).

Why it matters: Everything you've set up converges here. An Audit Campaign captures a snapshot of who has access to what, asks the right people to certify it, removes what shouldn't be there, and produces signed, downloadable evidence. It's how you turn "we manage access carefully" into something you can show an auditor — SOC 2, ISO, or an internal review.

What to do: Go to Access > Audit Campaigns and create a campaign. Assign an Owner, the Certifiers who'll review access, and the Remediators who'll carry out removals, then work through the four phases — SnapshotCertificationRemediation and Verification, and Close — and export a PDF report when you're done. Full roles, phases, and actions: Audit Campaign User Guide.

You've reached this milestone when… you've closed your first campaign and can download its report.

Where to go next

Once the milestones are in place, YeshID becomes a living system rather than a one-time setup. A few good habits:

  • Keep groups current. RBAC, onboarding, and access reviews all lean on group membership. When groups are accurate, the rest stays accurate on its own.

  • Lean on automation. Move from manually onboarding people to HRIS-triggered workflows, and from one-off grants to RBAC policies, as you get comfortable.

  • Treat drift as a signal. Recurring access drift usually means a policy is missing or a group is stale — fix the cause, not just the symptom.

  • Audit on a cadence. Running campaigns regularly (not just before an audit deadline) keeps surprises small.

FAQ

Do I have to complete the milestones in order? The first four build on each other — you need people in (Milestone 1) before you can add their apps (Milestone 2), the apps on your list before you can import their access (Milestone 3), and access imported before connecting does much (Milestone 4). After that, Milestones 5–8 can be tackled in whatever order matches your priorities.

What's the difference between my directory and my source of truth? Your directory tells YeshID who your people are — the identities that log in (Milestone 1). Your source of truth tells YeshID what those people can access today — their accounts across your applications (Milestone 3). You connect the directory first, then import current access on top of it.

What's the difference between importing an app and connecting it? Importing (Milestone 3) captures a snapshot of existing access so YeshID can see it. Connecting (Milestone 4) establishes a live integration so YeshID can act — create, update, and remove accounts going forward. Connecting a catalog app also imports its accounts, so it can do both at once.

Why don't I see RBAC or Audit Campaigns in my navigation? These are paid features. Audit Campaigns are on paid plans (Growth and Business), and RBAC is on the Business plan (currently in beta). If they're missing, talk to your YeshID contact about upgrading.

The Getting Started checklist disappeared from my Home page. Did I lose it? The in-app checklist hides itself once you're established. This playbook covers the same ground and more, so you can keep using it as your reference.

Where can I manage notifications and integrations after setup? Notifications live under Manage > Settings > Notifications, directories under Organization > Directories, applications under Access > Applications, and workflow templates under Manage > Workflow Templates.