APIs and automation
Automatable by default.
A GraphQL API for every first-class platform object. Tenant-scoped API keys, each bound to its own service-account identity. Functions let your code run inside Owlie.
GraphQL
Every platform object. One schema.
Owlie exposes a GraphQL schema covering every first-class platform object — identities, resources, Grants, assignments, operations, tickets, requests. Read and mutate from automation, from your ticketing system, from your own tools. Authentication is tenant-scoped API keys or session-based for browser calls, and the connector gateway's enroll, connect, and bundle endpoints are rate limited. A typed TypeScript SDK and an MCP endpoint cover the governed subset of that schema for scripts and agents — covered on the AI & agent access page.
GraphQL query + response
Static peek: a query against the GraphQL schema and its structured response.
Functions
Participate from inside.
An API reads and mutates state from outside. A Function runs your code inside as an approval step, a fulfillment path, a custom admin action, or an HTTP endpoint. When an integration has to take part in a decision by gating an approval, owning a fulfillment step, or exposing a custom action, that logic runs within Owlie.
There’s no managed webhook delivery today. For identity lifecycle events, the outbound direction composes from two existing blocks. A reaction fires when a watched attribute transitions (hired to terminated, a department change) and runs a Function, whose allowlisted egress calls whatever external system you point it at. Endpoint Functions cover the inbound direction. A general subscribe-to-any-event feed doesn’t exist yet.
Run custom governance logic within Owlie.