Skip to content

APIs and automation

Automatable by default.

A GraphQL API for every first-class platform object. Tenant-scoped API keys, each bound to its own service-account identity. Functions let your code run inside Owlie.

GraphQL

Every platform object. One schema.

Owlie exposes a GraphQL schema covering every first-class platform object — identities, resources, Grants, assignments, operations, tickets, requests. Read and mutate from automation, from your ticketing system, from your own tools. Authentication is tenant-scoped API keys or session-based for browser calls, and the connector gateway's enroll, connect, and bundle endpoints are rate limited. A typed TypeScript SDK and an MCP endpoint cover the governed subset of that schema for scripts and agents — covered on the AI & agent access page.

Functions

Participate from inside.

An API reads and mutates state from outside. A Function runs your code inside as an approval step, a fulfillment path, a custom admin action, or an HTTP endpoint. When an integration has to take part in a decision by gating an approval, owning a fulfillment step, or exposing a custom action, that logic runs within Owlie.

There’s no managed webhook delivery today. For identity lifecycle events, the outbound direction composes from two existing blocks. A reaction fires when a watched attribute transitions (hired to terminated, a department change) and runs a Function, whose allowlisted egress calls whatever external system you point it at. Endpoint Functions cover the inbound direction. A general subscribe-to-any-event feed doesn’t exist yet.

Run custom governance logic within Owlie.