AI AGENTS FOR ENTERPRISE HR

The AI-readiness layeron top of your HR systems.

Oneward turns HR requests into finished work,
not open tickets.

Start your free 30-day analysisBook a demo call

Oneward sits on top of the systems you already run.

Agents read from them and write results back through a governed connection. Works with any HCM or HRIS, no new system of record.

HRIS
Payroll
Time Tracking
Benefits
LMS
PEO
Workday
SAP SuccessFactors
Oracle HCM
Governed connection
Your tenant
Requests & approvals
Slack
Microsoft Teams
WhatsApp
Your portal (widget)
EMPLOYEES · MANAGERS · HRYOUR HR SYSTEMS
Agents
Attract
Onboard
Grow
Move
Offboard
Screen applicants
Enroll payroll
Assign training
Update org chart
Close out payroll

Your HRIS records the work. It doesn't do it.

Every hire, move, and exit becomes tickets that people carry by hand. Agents change who carries them.

TodayPEOPLE CARRY THE WORK

Your HRIS holds the record, but the work happens around it: in inboxes, ticket queues, and spreadsheets. Every step waits on a person to notice, follow up, and re-enter what another system already knows.

MK
Re: Re: Re: How many vacation days do I have left?Employee → Manager → HR → Payroll → HR
Thu 6:42 PM
IT
Leave request still waiting on approvalManager is out this week, who else can sign off?
Fri 9:15 AM
PR
Payroll form missing bank detailsPlease re-send, the PDF was blank
Mon 8:03 AM
With OnewardAGENTS CARRY THE WORK

Agents live inside your tenant and carry each step themselves: they answer from your handbook, enroll payroll, send the day-one plan, and book the manager check-in. You keep the permissions and approvals. Every action is written to the record and can be reviewed later.

Preparing onboarding plan…
Offer letter · signed
Day-one plan · sent in Teams
Payroll enrolled · your tenant
Manager check-in · awaiting your approval
Requests fan out across HR, managers, and payroll
One agent runs the whole workflow inside your tenant
Data re-keyed between systems by hand
Written once, in the system of record, with a full audit trail
The same policy answers typed over and over in inboxes
Answered instantly, with citations from your own handbook
Day one arrives with payroll pending and no plan
Everything is ready before the hire logs in

Agents cover every stage, from the first job post to the exit survey.

An agent picks up each task, and the always-on foundation underneath keeps records clean, payroll correct, rules met, and questions answered.

ATTRACTONBOARDGROWMOVEOFFBOARD
Filling the role…Filling the role
Post the role…Post the role
Screen applicants…Screen applicants
Schedule interviews…Schedule interviews
Draft the offer…Draft the offer
Preparing day one…Preparing day one
Collect documents…Collect documents
Enroll payroll…Enroll payroll
Send day-one plan…Send day-one plan
Book manager check-in…Book manager check-in
Growing the team…Growing the team
Launch review…Launch review
Collect feedback…Collect feedback
Assign training…Assign training
Draft growth plan…Draft growth plan
Processing the move…Processing the move
Route transfer approval…Route transfer approval
Update org chart…Update org chart
Adjust compensation…Adjust compensation
Notify new team…Notify new team
Wrapping up…Wrapping up
Schedule exit…Schedule exit
Transfer knowledge…Transfer knowledge
Close out payroll…Close out payroll
Send exit survey…Send exit survey
ALWAYS-ON FOUNDATIONDATA · PAY · COMPLIANCE · SERVICE
Named agents sit behind the stages and the foundation above.Explore all agents

Every request ends in the system of record.

No new app to learn. Employees ask and request, managers and HR approve and decide, all inside the tools they already have open.

Employees
Ask a policy question, check a leave balance, submit a request, update their details.
Managers and HR
Approve requests, review changes, and make decisions with the context already attached.
hr-helpAsk HR anything. Answers come from your handbook.
42
Today
JK
Jonas K.9:41 AMHow many vacation days do I have left this year?
OnewardAPP9:41 AMYou have 12 days left. Your team has a blackout week Dec 15 to 19.Leave policy · section 3.2
JK
Jonas K.9:42 AMGreat, book Oct 6 to 10 please.
OnewardAPP
TO MARIA · MANAGERLeave request · Jonas K.Oct 6 to Oct 10 · 5 days
ApproveDecline
Approved
OnewardAPP11:05 AMMaria approved it. Your HRIS and the team calendar are updated.
Message #hr-help
OnewardChatShared
Oneward8:30
Morning Maria. One transfer on your team needs a decision.
Oneward
TRANSFER · YOUR DECISIONPriya S. → Product Ops, BerlinStart Nov 1 · same grade
ApproveAsk a question
Approved
8:34
Approved. Headcount for my team by location?
Oneward8:34
Routed to HR and IT. Berlin 14, Munich 9, remote 6.Workday · live
8:35
Perfect, thanks.
Type a message
Oneward HRonline
TODAYMessages are end-to-end encrypted.
Hi, I moved and need to change my bank account.18:02
Happy to help. I just sent a code to your work email to verify it is you.18:02
48291318:04
PERSONAL DATA · SECURE FORMUpdate bank accountEncrypted · payroll from next run
Open secure formLater
Submitted
Got it. IBAN updated, payroll uses the new account from November.Change log · #4821318:09
Message
HR AssistantReplies in seconds
Today, 14:12
I start Monday. What do I need to do before then?
Welcome, Tom. Two things left: sign your tax form and pick a laptop. Everything else is done.Onboarding plan · day 0
MacBook please. Where is the tax form?
ONBOARDING · 2 OF 9 OPENWaiting for youSigned
Sign tax formPre-filled from your HRIS record
Review and signLater
Signed and filed. MacBook ordered, IT will have it at your desk on Monday.
Ask HR anything…
Powered by
oneward
FREE 30-DAY ANALYSIS

See what agents can carry in your onboarding, leave, and payroll.

You pick up to three use cases. We analyze your systems and workflows for 30 days. You keep the written plan, whatever you decide next.

Start your free 30-day analysisBook a demo call
WORKFLOW · LEAVE REQUESTLIVE IN YOUR TENANT
TRIGGER9:41
Employee asks in Slack
Can I take Oct 6 to 17 off?
AGENT9:41
Spots a shortfall, proposes a split
Leave policy 3.210 asked · 8 left8 paid + 2 unpaid
APPROVAL11:05
Manager approves the split in Slack
ApproveDeclineApproved
ACTION11:05
Writes both records to your HRIS
Paid · Oct 6–15Unpaid · Oct 16–17Balance · 0 left
NOTIFY11:06
Confirms the split to the employee
EmployeePayrollTeam calendar
LOG11:06
Audit entry: who, what, when
#48213 · leave.split · agent · approved by M. Klein · reversible

The agents, plus the engineers
who run them.

Oneward is not a self-serve tool. We map, build, and tune each agent with you, then keep it running.

Deployed with your team
Our engineers set up each agent alongside your HR and IT teams, inside your tenant, until it runs reliably and you approve it.
Customized to your systems
Built for your workflows, policies, and approval chains, then updated as they change.
Models optimized for you
You choose the models. We evaluate and tune them per workflow so your team never manages model choices.
Runs in your environment
Runs in your infrastructure and tenant context, on the endpoints your security team approves.

Three agents from the library.

Each replacing a specific manual process in your HR stack. All run on one integrity foundation, one permission model, and one audit trail.

The rest of the library covers the rest of the lifecycle.Explore all agents

On the model you approve. Inside the boundary you set.

Your security team sets the policy. Agents cannot act outside it. Employee data never leaves your boundary of trust, and every agent action is logged, attributable, and reversible.

Your model, your endpoint
Agents call only the models your security team allowlists.
Humans approve what matters
Least-privilege access. Write actions wait for a named approval.
Every action on the record
Who, what, when, and why, logged for every step. Reversible.
MODEL POLICY · YOUR TENANT
ENFORCED
Approved modelyour-endpoint / v4
Data regionUS or EU · in-boundary
PII redactionON
Write actionsREQUIRE APPROVAL
Audit retention90d · exportable
AUDIT LOG · LIVE
11:04
leave.check · balance 12d
11:05MKapproval · M. Klein
11:05
hris.write · #48213
11:06
notify · slack thread
11:06JKaudit.viewed · J. Kaur

Questions enterprise HR asks first.

Something else on your mind? Write to partners@oneward.com.

SYSTEMS AND FIT
What systems does Oneward work with?

Any HCM or HRIS, including Workday, SAP SuccessFactors, and Oracle HCM, plus the systems around them: payroll, time tracking, benefits, learning, and PEO platforms. Most enterprises run a mix that accumulated over years, several payroll providers plus a time system from a different era, and that mix is the normal case for us. Mapping it is one of the first things the 30-day analysis does. Every connection is governed and scoped per workflow to the data you agree we may read and write, which means an agent that coordinates leave has no path to compensation data it does not need. We ask for narrow access first and widen it only when a workflow needs it.

Does it replace our HCM or HRIS?

No. Your existing platform stays the system of record, and that is deliberate. Workday or SuccessFactors is good at holding the record; what it leaves to your team is the work around the record, which today lives in inboxes and spreadsheets. Oneward sits on top of your platform as the layer that does that work. An agent reads the leave balance from your HRIS, walks the employee through the request, collects the manager's approval, and writes the approved dates back where they belong. Your platform keeps doing what you bought it for, and if you ever replace it, the agents connect to the new system of record instead of becoming one more thing to migrate.

Do we need to migrate any data?

No migration. Agents work against your live tenant through a governed connection, scoped to the fields you agree we may read and write. Nothing is copied into a second system of record, and that closes off a familiar failure: a copy has to be synced, a sync eventually drifts, and then someone on your team owns reconciling two versions of the truth. It also makes starting fast, since connecting is a scoping exercise with your IT team rather than a data project. During a 30-day analysis the connection is read-only from the first day to the last.

What about systems without an API?

Most HR landscapes include at least one, an older payroll engine or a portal your provider hosts, and the answer starts with mapping. During the 30-day analysis we map every system in scope and how each one can be reached, and reachability shows up in the plan as part of build effort. Where a clean interface does not exist, the plan says so and proposes a practical alternative rather than a workaround you have to maintain. Sometimes the honest alternative is that one step stays with a person while the agent carries everything around it; sometimes it changes which use case we recommend building first. What you will not get is a brittle integration that breaks on the next vendor update and quietly becomes your problem.

PEOPLE AND CHANNELS
Where do employees interact with Oneward?

In the tools they already have open: Slack, Microsoft Teams, WhatsApp, or an embedded widget inside your internal portal. There is no separate app to roll out and no new login to forget, which is usually where new internal tools lose their users. An employee asks a question in Slack and gets an answer drawn from your own handbook, with the policy section cited, or updates bank details over WhatsApp, with a verification code required before the change goes through. The channel is a preference; what happens behind it is identical. Every request ends in the system of record, with the same approvals and the same audit trail regardless of where the conversation happened.

Can managers approve things from Slack or Teams?

Yes. Approvals arrive as cards in Slack or Teams with the context already attached: what was requested, what the agent checked, and which policy it applied. A manager looking at a leave request sees the remaining balance and the proposed split of paid and unpaid days before deciding anything. One tap approves or declines, the decision writes straight back to the system of record, and the log entry carries the approver's name, reversible where the underlying system allows. Who approves what is defined by your own policy; we configure the approval chains you already have instead of inventing new ones. An action set to require approval waits until it gets one, because the write does not happen without it.

What kinds of requests can employees make?

The base set covers policy and benefits questions, leave and absence requests, personal data updates, document requests, and status checks on anything in flight. In practice it is more specific than that list sounds. An employee asking what parental leave allows gets the answer from your own handbook, with the section cited. Leave requests that overrun the remaining balance come back as a proposed split of paid and unpaid days, checked against policy before any dates are written. A bank-account change requires a verification code, and an employment-verification letter for a visa or a rental is generated from verified employment data. Each workflow you bring into scope adds its own request types, so the honest answer is that the list keeps growing as you deploy more agents.

What happens when an agent cannot handle something?

It hands over to a named person with the full context, and tells the employee it did so. Full context means the conversation so far, the data the agent checked, and the exact point where it stopped, which spares the employee from explaining everything twice. Handover is the designed behavior for anything the agent should not decide, like a sensitive employee-relations matter or a case the policies it was built on never covered. Which situations escalate, and to whom, is configured with your HR team during deployment and adjusted as experience shows what the agent handles well. The failure mode we build against is the silent dead end, where a request disappears and nobody owns it.

AGENTS AND CUSTOMIZATION
What HR workflows can agents handle?

Most of the HR process that runs off-platform, in the inboxes, spreadsheets, and follow-ups around your HRIS, can be automated with AI: onboarding, leave, role changes, reorganizations, performance cycles, offboarding, and keeping data aligned across systems in between. Chasing interviewers for overdue scorecards, mapping a parental leave split by hand against local law, rebuilding a reorg upload file that failed on broken reporting lines, checking a pay run before the money moves: none of that lives in the HRIS, and all of it can be carried by an agent. The practical test is simple: any HR task that follows rules and touches your systems can be a use case. What stays with people is judgment, the sensitive conversation and the exception no policy anticipated. See the use cases above for examples.

How are agents customized to us?

Each agent is built during deployment, with your team, around three things: your policies, which become the source of its answers, cited by section; your approval chains, which decide who says yes before anything is written; and your systems, the ones it actually reads and updates. Our engineers do that setup alongside your HR and IT teams until the agent runs reliably and you approve it, and nothing changes in production before you sign off. When a policy changes or a system is swapped out, the agent is updated to match. Nothing is shipped as a generic template you have to adapt yourself, because a template that is almost right about your leave policy is wrong about your leave policy.

Do we have to choose and manage AI models?

You choose which models are allowed, and that decision stays with your security team. Typical allowlists include OpenAI, Anthropic, Google Vertex AI, or self-hosted open models where you require them, and agents call only the endpoints on your list, private endpoints included. Everything past that line is our job. Model quality varies by task; the model that drafts a good reference letter is rarely the one you want checking a pay run, which is why we evaluate, tune, and monitor models per workflow against your real cases. When a model on your allowlist stops being the right choice for a workflow, we make the change, inside the same rules. Your team sets the boundary once and never has to become a model operations team.

Who maintains the agents after launch?

We do, together with your team, for an agreed period that is written into the contract. Agents run against policies and systems that keep changing, and an agent that was correct in March can be quietly wrong by June, which is exactly what maintenance exists to catch. During the engagement we ensure the agents keep working as expected: we monitor each workflow, update agents when your policies change, rebuild connections when you replace a system, and take on new use cases as they come up. Your team stays involved throughout, since the people who know a policy shifted before it reaches any document are yours.

SECURITY AND GOVERNANCE
How does tenant separation work?

Agents run in your cloud or in ours, with scoped, least-privilege service accounts either way. Where they run is a decision your security team makes during the review, and the controls do not loosen with the choice. In your cloud, agents operate under the network and identity controls you already enforce, and your team watches them the way it watches any other workload. In ours, each customer is separated at the tenant level, and a service account is scoped to the workflows you approved with no broader reach into your systems. Your data does not mix with anyone else's, and it never leaves your boundary of trust. Whichever way you decide, an agent holds the minimum permissions its workflows need, against only the data you agreed we may read and write.

How are permissions and audit trails handled?

Permissions follow the workflow: each agent operates with the minimum access that workflow needs, agreed when it is scoped. Any action that changes a record, a payment, or an entitlement can be set to require a named human approval, delivered in the tools your managers already use, and who approves what is defined by your policy. On the audit side, every action an agent takes is logged with what it read, what it did, and who approved it. Entries are attributable, reversible where the underlying system allows, and exportable to your own tooling, so your security team reviews agent activity in the same place it reviews everything else. Retention is agreed per customer, with a default of 90 days.

How do we run a security review of Oneward?

Under NDA, and before anything is connected. We work through your security questionnaires and hold architecture calls with your team, at whatever depth your security and IT people want: where agents run, how data flows, what is redacted before anything reaches a model, how service accounts are scoped, and how approvals and logging are enforced. Expect straight answers on limits as well; where something is a constraint, we describe it as a constraint instead of talking around it. The review runs at your pace, and nothing touches your systems until your team is satisfied. Write to partners@oneward.com to start.

THE 30-DAY ANALYSIS
What happens during the 30 days?

Week one we sign the NDA and, if you need one, a data processing agreement; you choose up to three use cases and we agree which data we may read. From day 8 to day 21 we read the agreed data and count how often each use case comes up, then check what is possible, what it costs to build, and what it returns. Week four we write the plan, and you have it on day 30. Throughout, access is read-only and we change nothing in your systems. Your side is light: one named contact, a 30-minute check-in each week, about one to two hours of your team's time each week. The counting matters, because the use case that feels urgent and the one your data shows is frequent are often not the same, and the plan follows the data.

What does it cost?

Nothing. The analysis is free, covering all 30 days of work and the written plan you keep; the only real cost is about one to two hours of your team's time per week. If you decide to build, we send a written offer for exactly the scope in the plan, which means the offer can be checked line by line against a document you already own. The plan is complete on day 30 whether or not you ever ask for the offer.

What do we get at the end?

A written plan for each use case you chose, built from your data and your process during the 30 days. Every plan covers the same eight items: what the agent does, as exact steps in plain language; which systems it reads and which it updates; cases per month, counted from your data; time saved per month, measured against your current process; build effort in weeks, including what we need from your team; risks and controls, down to what stays read-only and who approves each write; the return, and when the saving starts; and a recommendation on what to build first and why. It is written to be handed to a CFO or to another partner as it stands. If the numbers do not justify building a use case, the plan says that too.

What if we decide not to continue?

You keep the plan. Use it internally, or build it with another partner; it is yours to hand over, and specific enough to build from, with the steps and systems for each use case written out. Everything we read during the analysis is deleted after day 30 and our access ends with it, which makes walking away clean. There is no obligation. A plan that tells you not to build yet is still a useful plan, and some plans will say that.

Know where agents fit before you commit.

A free 30-day analysis of your HR systems and workflows, and a written plan you keep, whatever you decide next.

Start your free 30-day analysisBook a demo call
Book a demo callThirty minutes. See the agents live, in the Slack or Teams you already use.
Prefer email? partners@oneward.com