Alert customer success when enterprise SSO goes live

By General Input

The moment an enterprise customer switches on single sign-on, your account team hears about it in Slack and the milestone lands on their CRM record.

Integrations

  • WorkOS
  • HubSpot
  • Slack Bot

Type

Agentic Task

Categories

  • Customer Support
  • Sales

Run this workflow whenever WorkOS sends a connection.activated webhook event. That event is the signal that an enterprise customer has finished turning on single sign-on and the connection is ready to roll out, so treat every delivery as a go-live moment that my account team needs to hear about immediately.

Start from the webhook payload. Read the organization ID and the connection details off the event. WorkOS IDs are type-prefixed, so pass the full prefixed value (org_..., conn_...) everywhere it is used, never a trimmed version. Note the connection type, which tells us which identity provider the customer connected, for example Okta SAML, Microsoft Entra ID, or Google SAML. If the payload does not carry a readable provider name, call WorkOS Get a Connection with the connection ID to resolve it.

Call WorkOS Get an Organization with that organization ID to resolve the customer's display name and their associated domains. These domains are what I will match on in the CRM, so keep the full list rather than just the first one.

Then call WorkOS List Directories, filtered to the same organization, to check whether that customer has also set up directory sync (SCIM). If one or more active directories come back, directory sync is already in place. If none come back, single sign-on is live but directory sync is still outstanding, which means the customer is still adding and removing users by hand. Treat that as the useful follow-up signal, not a footnote.

Look the customer up in the CRM using HubSpot Search Companies, matching on the organization's domain. If the organization has several domains, try them in turn until a company matches. If more than one company comes back for a domain, pick the best match against the organization name and say in the Slack message that the match was ambiguous.

When a company matches, log the milestone with HubSpot Create Note associated to that company record. The note should state that single sign-on went live, the date it activated, which identity provider was connected, and whether directory sync is also configured or still outstanding. Write it so an account manager reading the record in six months understands what happened without any other context.

Finally, post to my customer success channel with Slack Bot Send a Message. Name the organization, state which identity provider they connected, and say clearly whether directory sync is done or still outstanding, so the CSM knows the exact next step to chase. When directory sync is missing, spell out that the customer is still managing users manually and that SCIM is the natural next conversation. Keep it to a short, scannable message rather than a wall of text.

If no HubSpot company matches any of the organization's domains, still post the Slack message. Say explicitly that the CRM match failed, list the domains that were tried, and include everything that was resolved from WorkOS so the go-live is still actionable. Never let a failed CRM lookup silently swallow the notification, and do not skip the Slack post just because the note could not be written.

Related prompts

Explore more prompts
A brand asset library your marketing team actually searchesTurn Mailjet email clicks into ranked HubSpot follow-upsClean out the Looker dashboards and Looks nobody opensLiveKit live operations console for room moderationWake up dormant Keap leads with a researched reasoniMessage campaign console with pre-flight checks and delivery boardLiveChat coverage board for planning next week's shiftsPhone routing control panel for LiveKit voice agentsA searchable RFP answer library your bid team drafts fromLinkedIn Ads budget pacing dashboard for every client account