JML approval workflows that end in a confirmed outcome.
Inside the workflow
Approval workflows and access bundles built for how you run.
Approvals, requirements, access bundles, execution, and responsibility work together, so the right people act on the right work, and nobody acts on work that isn’t needed.
Approvals
Know what changes, why it matters, and what your approval authorizes.
The approval arrives in Microsoft Teams with the employee, effective date, business unit, requester, approval step, and due date in view. Approve, give the reason for a rejection, or open the full request to see the requested access and cost. Whether the decision starts in the chat or a workspace, the outcome still stays with the lifecycle record.

Requirements
IT work only for a verified difference.
With TeamConnect AI, requirements come from each employee’s primary and additional license roles, including project assignments, together with subscription mappings, security-group rules, and linked access bundles. On its own, however, TeamJML AI uses the selected access bundle. Removing one role keeps any subscription another role or group rule still requires, and adding a role that brings nothing new creates no duplicate work.

Operating model
Turn a role into the access, licenses, and equipment it needs.
Bring platforms, subscriptions, and devices into reusable access bundles. Then apply approval responsibilities and service deadlines to each change, with regional working calendars that reflect how your organization operates, so HR and IT share one consistent process across business units.

Service desk
Clean work in the tools IT already uses.
Approved work then reaches ServiceNow, Jira Service Management, Freshservice, or BMC Helix, or the IT Servicedesk Workspace for manual fulfillment. Completed work, connector updates, and manual confirmations all return to the same lifecycle record afterward. When an additional role or project assignment ends, TeamJML AI also reassesses the requirements before it creates any revocation.

Roles
Assign responsibility at enterprise scale.
On its own, TeamJML AI assigns operational roles through Role Members: add people individually, import assignments from CSV, or connect several Microsoft 365 security groups to a role, and the agent then follows the same assignments. TeamJML AI also adds people automatically once it routes them an approval step or assigns them an IT task, so Role Members is for granting access before any work arrives. With TeamConnect AI, you manage the agent catalog, Agent Roles, and governance centrally, while TeamJML AI’s lifecycle capabilities follow the same controls.

How it runs
The JML workflow in four steps: request, approve, execute, confirm.
Every step keeps the person, the effective date, and the decision attached, so IT work starts only where requirements actually change.
Who takes part
- Managers & HR
- Approvers
- IT Servicedesk
- Your service desk
- 01
Request with context
A joiner, mover, or leaver request carries the employee, role, location, and effective date, and asks only for what is missing.
- 02
Approve with accountability
Each decision then goes to its accountable owner, with the reason, the requested access, and its cost in view.
- 03
Execute with control
Only verified differences become work, so IT never works on unchanged access. Your service desk then runs Microsoft 365 changes straight from the ticket, and hands everything else to your ITSM or completes it by hand.
- 04
Confirm the outcome
Each line closes with its confirmation method, while TeamJML AI escalates unresolved work and verifies it after the effective date.
Works with
- ServiceNow
- Jira Service Management
- Freshservice
- BMC Helix
The lifecycle record
One lifecycle record for every JML workflow, from decision to confirmed outcome.
What your auditors, your service desk, and your leadership each need to see stays together for every change, so nobody has to reconstruct it later.
The change
Employee, role, department, location, manager, and effective date.
The decisions
Recorded approval history with accountable decision-makers and timestamps.
The work
Required subscriptions, access, and equipment work, with the relevant admin links.
The outcome
Completion status, confirmation method, responsible party, and recorded exceptions, especially every license assigned or revoked outside Microsoft 365.
Related: license management for Microsoft 365 · JML automation for IT leaders · the employee directory and JML automation together
Buyer questions
What IT and HR operations ask about JML workflows.
The questions that come up when service management, identity, and HR teams evaluate how TeamJML AI runs.
Approval workflow and requirements
How are the right approvers selected?
Approval follows the requested resources and your policies, and with TeamConnect AI also the employee’s organizational context. Managers, application owners, regional device owners, and other accountable roles then receive the decisions that belong to them, with a recorded history of the outcome.
What happens when an additional role or project assignment ends?
TeamJML AI then reassesses the requirements. It creates revocation work only when no remaining valid role, group rule, or approved entitlement still requires the license.
Licenses and systems outside Microsoft 365
Can available licenses cover upcoming joiners before we buy more?
Yes. With TeamConnect AI, requirements come from each joiner’s role and entitlement context; on its own, however, TeamJML AI uses the selected access bundle. TeamJML AI accounts for compatible subscriptions, existing assignments, reservations, and available capacity, including licenses freed by confirmed revocations, before it recommends a purchase.
What about applications and subscriptions outside Microsoft 365?
Include them in the same lifecycle, too. Their owners fulfill the work through your connected service desk or a controlled manual action, and the confirmation then returns to the lifecycle record as evidence.
HR data and the agent
Does TeamJML AI replace HR imports?
No, because a request carries no contract details, vacation, CVs, bios, or skills. HR still maintains those through file imports and connectors in TeamConnect AI, and a person must exist in Microsoft Entra ID before HR can import them.
What governs the agent?
On its own, TeamJML AI’s agent follows the operational roles assigned through Role Members — individually, by CSV, or through Microsoft 365 security groups — with request scope and approval policies deciding which records and actions belong to each person. With TeamConnect AI, you manage the full agent catalog, Agent Roles, and governance centrally, while TeamJML AI’s lifecycle capabilities follow the same controls. Answers also link to the relevant lifecycle records, and sensitive actions require the appropriate authority and confirmation.
Bring your process
See your own JML workflow, from approval to service desk, end to end.
Think of someone starting soon, someone changing roles, and someone leaving. In a thirty-minute demo, we then walk each one through the approval decision, the work each system receives, and the evidence that closes the request. Weighing the cost? See the business case first.