Corma
Corma
  • Docs
  • Changelog
  • Feature requests

Corma changelog

Custom Agents, Workflow Triggers & Actions, Tomorro Integration

Custom Agents

Corma can now build a custom integration for apps that don't have a native connector, just by watching you use them.

  • Train by demonstration: record yourself performing a task once (like onboarding a user), and Corma's agent turns it into a reusable automation

  • Chat to refine it: review, ask questions, and adjust the automation directly in a chat interface before it goes live

  • Works like any other integration: once built, the custom agent handles provisioning, deprovisioning, and license syncs for that app just like a native connector

This unlocks automation for the long tail of apps in your stack that would otherwise require manual work.


Workflow Builder: new actions

You now have more ways to act across your stack without manual intervention:

  • Change app status: mark an app as authorized, tolerated, or another status

  • Revoke all tokens: revoke every access token for a user on an app in one step

  • Launch access review: trigger a review with defined reviewers, apps and due date

  • Send email: send a custom email to specified recipients

  • Wait: pause a workflow for a set duration

  • Call webhook: send data to and receive responses from any external URL

  • Add role on Datadog: assign a Datadog role directly from Corma

More actions to automate across your stack, cutting down on manual work and one-off scripts.


Workflow Builder: new triggers

There are now more ways to kick off a workflow automatically:

  • Scheduled: run a workflow on a recurring schedule (e.g. every X days or months)

  • License status changed: trigger on billing or activity status changes: renewed, expired, cancelled, activated, deactivated

  • New app detected : fire a workflow whenever a new app is discovered in your SaaS directory, with the option to filter by app status

More ways to kick off a workflow automatically, so automations react to real events instead of manual runs.


Tomorro Integration

Corma now integrates with Tomorro!

Tomorro is a spend management platform that helps finance teams track expenses, automate approvals, and gain real-time visibility into company spending.
You can now:

  • Collect licenses: centralize Moss users and licenses in Corma

  • Get expenses: collect invoices and sync expense data from Moss to centralize your spend tracking and reconciliation directly in Corma


Improvements

  • URL and login fields are now optional when creating internal applications, and the URL field can be edited after creation.

  • Notes can now be added directly on a user's profile page, the same way as on an app's page.

Fixes

  • Onboarding/offboarding page failing to load for a client has been fixed

  • Claude integration showing as connected after a failed login has been fixed

  • Automation builder misreading CSV columns and dropping data has been fixed

  • License-triggered action bugs (missing link, missing log entry) have been fixed

  • License action bugs (failed triggers, missing option) have been fixed

  • Multiple workflow bugs (stuck steps, audit logs, display issues) have been fixed

  • Bulk deletion of 100+ users timing out has been fixed

  • Unmatched CSV license rows now save as unmatched accounts

  • "Delete User" crashing has been fixed

  • HR sync crashing after the first customer has been fixed

  • Internal app descriptions silently failing to save has been fixed

  • SSO, MFA, and SAML checkboxes showing wrong state has been fixed

  • Broken internal API documentation has been repaired

  • Multiple Workflows bugs (activation, drafts, loaders, config) have been fixed

  • "Send Slack message" crashing without a user target has been fixed

  • A dropdown not closing after selection has been fixed

  • Google Workspace issues now trigger a reconnect alert instead of failing silently

  • Revoked accounts not being correctly identified has been fixed

  • Connected integrations disappearing from filters has been fixed

  • Decimal prices in contract line items not accepting commas/dots has been fixed


New workflow actions, custom variables and 2 new Integrations

New workflow actions: launch On/Offboarding, wait actions & more

Workflows can now trigger a user's onboarding or offboarding directly as a single action.

  • One-click lifecycle triggers: "Trigger onboarding" and "Trigger offboarding" launch the full bundle-based provisioning or deprovisioning sequence for a user

  • Wait steps: combine with a Wait step to delay the trigger, using variables to set the exact timing if needed

Removes the need to manually kick off on/offboarding as a separate step outside your workflow, enabling true end-to-end lifecycle automation.


Dynamic variables in provisioning actions:

Admins can now use dynamic variable (like the target user's name, email, or manager) when configuring provisioning, deprovisioning, bundles, and on/offboarding actions.

  • Personalized by default: reference the target user's info, their manager, or the license involved directly in your action config, no manual edits needed per user

  • Available wherever actions are configured: works in default (de)provisioning actions, bundle setup, and on/offboarding workflows alike

Replaces static, one-size-fits-all configs with actions that adapt automatically to whoever they're applied to.


Moss Integration

Corma now integrates with Moss!

Moss is a spend management platform that combines corporate cards, expense management, and accounts payable automation into a single tool for finance teams.
You can now:

  • Collect licenses: centralize Moss users and licenses in Corma

  • Get expenses: collect invoices and sync expense data from Moss to centralize your spend tracking and reconciliation directly in Corma


Deel Integration

Corma now integrates with Deel!

Deel is a global payroll and HR platform that helps companies hire, pay, and manage employees and contractors compliantly across 150+ countries. You can now:

  • Identity: collect identities from Deel and list them in Corma to keep your user directory accurate and up to date

  • Collect licenses: centralize Deel users and licenses in Corma

  • Collect HR data: enrich user profiles in Corma with key HR attributes from Siit, including job title, team, manager, country, start date and termination date


Improvements

  • New action: automatically create a Jira ticket 7 days before an employee's last day, listing accounts that need manual removal.

  • Bulk-assign licenses to multiple users at once instead of creating each of them

  • IdP status and HR status are now editable directly from the main users table, including in bulk.

  • Lucca HR integration now syncs employee country data.

  • New action: create Siit support tickets directly from a workflow.

  • Provisioning setup simplified: just enter an email, and role and group default automatically.

  • License status, type, and role can now be edited directly from the user detail page.

  • User type is now visible and editable on individual user pages.

  • Improved license roster extraction accuracy, catching more users and seats during scans.


Fixes

  • HR and integration features failing after a recent update have been fixed

  • Auto-generated workflows not matching customer previews has been fixed

  • Provisioning incorrectly reporting success early has been fixed

  • Multiple onboarding and workflow QA issues have been fixed

  • Unreadable warning text and wrong dialog context have been fixed

  • Three security vulnerabilities in the automation system have been fixed

  • Failed or empty demo recordings now automatically fall back to a backup method

  • Automated processes freezing or crashing have been fixed

  • Multiple bugs across Bundles, onboarding/offboarding, and workflows (broken configs, misleading errors, display glitches, incorrect data) have been fixed

  • Activity tracking silently failing in the background has been fixed

  • Filtering users by an exact start date returning no results has been fixed

  • HR and common integration reliability issues have been fixed

  • Linear free plan users being unable to connect their account has been fixed

  • SSO-detected apps with no active users showing no source has been fixed

  • Data sync silently skipping most companies after the first few has been fixed


MCP, actions for Slack, Google and JumpCloud, & 2 new Integrations

Corma MCP

Corma now has an official MCP server, making your workspace data directly accessible to AI tools like Claude, Cursor, and VS Code through a standardized interface.

  • Plug into your AI tools: connect the Corma MCP server to any compatible AI assistant in a few clicks, no complex setup, just a URL and your Corma API key

  • Query your workspace with natural language: ask your AI tool questions about your users, licenses, and applications directly, without leaving your development or AI environment. For example 'Which users have an inactive Salesforce license?' or 'What applications are running in my stack?'

To get access to your Corma MCP, click on this link

You can also check our public documentation about our MCP right now.


New Actions for Slack, Google and JumpCloud

  • Slack:

    • Send a message to a channel directly from Corma as part of an access management workflow.

    • Automatically add users to Slack channels when granting access or onboarding new employees.

  • JumpCloud: suspend users directly from Corma when offboarding or changing roles.

  • Google: remove a user from all or specific Google Groups directly from Corma, making access cleanup faster.


Connector health alerts

Corma now surfaces integration issues proactively so admins never miss a broken connection.

  • Warning banner: appears at the top of the Connectors page whenever a connector has invalid credentials or needs configuration

  • Sidebar indicator: an orange warning icon on the Connectors nav item signals issues at a glance, while hovering over it shows a quick summary

The banner and icon disappear automatically once all connectors are healthy.


Siit Integration

Corma now integrates with Siit!

Siit is an AI-powered IT service desk that handles employee requests and workflows directly within Slack and Microsoft Teams. You can now:

  • Collect HR data: enrich user profiles in Corma with key HR attributes from Siit, including job title, team, manager, country, start date and termination date

  • App catalog sync: push your Corma app catalog to Siit so employees can request access to the right apps directly from their Slack or Teams service desk

  • Automated ticket creation: let Corma automatically create tickets in Siit when access requests or provisioning tasks need human action, keeping your IT team in the loop without manual intervention


Voiso Integration (Agent)

You can now integrate with Voiso using Corma’s Clicker Agent!

Voiso is an AI-powered cloud contact center platform that helps businesses manage customer interactions across voice, SMS, and messaging channels. You can now:

  • Collect licenses: Centralise Voiso users and licences in Corma

  • Provisioning & deprovisioning: Automatically assign and revoke Voiso access directly from Corma to effortlessly manage your licenses use


Improvements

  • OCR now processes scanned and image-based PDFs, not just native ones, making invoice import more reliable across all document types.

  • "Validate" and "Clear" buttons added to the user selection dropdown, making it clear how to confirm or reset your selection for Bundles & Teams configuration.


Fixes

  • Failed data extractions incorrectly reported as successful have been fixed

  • ChatGPT integration failures for specific customers have been resolved

  • Bulk user and workspace deletion database timeouts have been fixed

  • A recurring visual bug on the Access Reviews page has been fixed again

  • Microsoft alias users incorrectly shown as deprovisioned have been fixed

  • Pennylane false disconnection alerts caused by expired tokens have been fixed

  • A crash when pasting text into the search bar has been fixed

  • Microsoft license types returning empty API results have been fixed

  • Multiple bulk user deletion bugs have been fixed

  • Broken manual HR sync and incorrect data skipping have been fixed

  • Invalid credential errors now show a clear message instead of a technical error

  • Multiple workflow usability issues (missing errors, confusing UI) have been fixed

  • Three provisioning and bundle bugs (onboarding crash, Slack loop, config data loss) have been fixed

  • Voiso license revocation silently failing has been fixed

  • HR sync bugs causing duplicate employees and missing data have been fixed

  • Google login sync leaving licenses appearing unassigned has been fixed

  • Microsoft license data failing to sync for some customers has been fixed

  • Austrian city 'Perg' being misidentified as Peru has been fixed

  • Security page getting stuck loading for some customers has been fixed

  • Access requests disappearing after approval has been fixed

  • Broken team filter on the apps page has been fixed

  • Modjo integration broken by outdated credentials and API version has been fixed

  • Voiso usage data syncing to the wrong app has been fixed


New API capacities, User multiple emails & Coda Integration

New API endpoints:

Corma's public API now supports full write access, letting teams create, update, and delete core workspace data programmatically.

  • Full CRUD on core entities: create, update, and delete users, licenses, license types, license roles, teams, and HR jobs via the API

  • Built for reliable automation: mutations require an idempotency key to prevent duplicate writes, and deletions return a snapshot of the removed resource

  • Richer user data model: users now support multiple emails with clear sourcing (manual, API, SSO, integration), with new filters to query by email or source

Manage your entire user and license lifecycle from external tools, as reliably as in Corma itself. Full details in our public API documentation.


User multiple emails:

Corma now tracks multiple emails per user, synced from your IdP and HR tools, and uses all of them for more accurate license matching.

  • Full email visibility: see every email associated with a user, with its source (manual, Google, Microsoft, etc.) and which one is primary

  • Smarter license matching: licenses are now matched against any of a user's emails, not just their primary one, reducing unmatched accounts

This directly improves match rates for users with multiple work or personal addresses tied to different tools.


Coda Integration

Corma now integrates with Coda!

Coda is an all-in-one collaborative document platform that combines docs, spreadsheets, and apps into a single customizable workspace for teams.
You can now:

  • Collect licenses: centralize Coda users and licenses in Corma


Improvements

  • Standardized app dropdown: infinite scrolling and already-selected apps shown first, everywhere in the platform.

  • Simplified account statuses: merged "Active" and "Provisioned" into a single "Active" status.

  • Cleaner access reviews: clearer labels and a simple progress bar replace the old complex chart.

  • Bulk app owner assignment: assign an owner to multiple apps at once from the main apps page.


Fixes

  • Google license types being incorrectly removed from accounts has been fixed

  • Claude AI license list CSV export timing out has been fixed

  • Repeated sign-in prompts caused by a server issue have been fixed

  • OpenAI invite tasks incorrectly showing as failed has been fixed

  • Misaligned and cut-off labels on the Security page have been fixed

  • Multiple onboarding/offboarding workflow bugs (dropdowns, app icons, stuck runs, missing notifications, bundle settings) have been fixed

  • Outdated license activity statuses after sync have been fixed

  • Bulk user deletion limiting selection to the current page has been fixed

  • Access review layout issues on 13-inch screens have been fixed

  • A Google sync getting stuck in an endless loop has been fixed

  • Workflow run history now shows actual values instead of placeholders

  • Unmatched accounts showing no username has been fixed

  • Data source alerts not being clickable or filterable has been fixed

  • Escape key not clearing table selections has been fixed

  • License reassignment blocked by missing data has been fixed

  • Deleted OpenAI users importing as phantom accounts has been fixed

  • Workflow tasks missing from app filters has been fixed

  • Mismatched user counts between apps page and app detail has been fixed

  • A crash blocking SSO app matching in production has been fixed

  • A memory crash during large-scale account matching has been fixed

  • Microsoft SSO login failures after email changes have been fixed

  • A valid email wrongly blocked by an "invalid domain" error has been fixed

  • A broken agent-document integration connection has been repaired

  • Atlassian access changes failing for large workspaces has been fixed


Workflow Builder, REST API & Yousign Integration

Workflow Builder (beta)

Corma now includes a built-in Workflow Builder, letting admins automate multi-step access management sequences that trigger automatically based on real employee events, no code required.

  • Event-based triggers: automatically kick off workflows when an employee starts, leaves, or a license becomes inactive

  • Sequential action chains: build workflows from a searchable action library across all your connected apps

  • Full execution history: every run is logged in the Previous Runs tab for a complete audit trail

Teams can now replace manual provisioning tasks with reliable automated workflows that run exactly when they should.


Corma API (rest)

Corma's first public REST APIs are now available, giving teams programmatic access to their workspace data directly from external tools and systems, no manual exports required.

  • Core entities exposed: query users, licenses, applications, and usage signals via clean, rate-limited endpoints

  • Built for real use cases: covers the most common needs: billing, reporting, internal dashboards, and workflow automation

  • Developer-ready: full API documentation available, with straightforward authentication via your Corma API key

Get started with our public API documentation: https://corma.apidocumentation.com/api-v1/guides/authentication


Yousign Integration

Corma now integrates with Yousign!

Yousign is a European e-signature platform designed to help businesses create, send, and manage legally binding digital signatures. You can now:

  • Collect licenses: centralize Yousign users and licenses in Corma

  • Provisioning & deprovisioning: automatically create, suspend, and delete Yousign user accounts directly from Corma to effortlessly manage access and licenses


Improvements

  • Clearer Agent connection cards: setup now guides users to configure a workspace upfront, with a button to review the connected workspace, reducing misconfiguration risks.

  • Improved license list consistency: unmatched accounts now show the same mapping action in the "More actions" menu as matched licenses, making the UI consistent throughout.


Fixes

  • Monday.com connection failures during setup have been fixed

  • Cursor AI connection failures despite correct credentials have been resolved

  • Overdue access review notifications not being sent have been fixed

  • Employee app store displaying incorrect apps by team filter has been fixed

  • Duplicate license type entries caused by name mismatches have been resolved

  • Google email alias creation failing for Skello users has been fixed

  • Bitwarden user roles and licenses not displaying correctly have been fixed

  • Manual contract creation errors have been resolved

  • HubSpot authentication token refresh failures have been fixed

  • License count mismatch between overview and licenses pages has been fixed

  • Bulk actions applying to only 20 users instead of all selected has been fixed

  • Qonto sync crashes caused by an unrecognized invoice status have been fixed

  • Browser extension connection and authentication issues have been resolved

  • ChatGPT license assignment failures have been fixed


Google Role Management & new on-the-fly User and Team creation

Google Role Management

Corma now supports full Google Workspace role management, allowing admins to assign and remove roles directly from Corma during onboarding and offboarding flows.

  • Accurate role display: roles are now retrieved and displayed with their correct names, giving admins a reliable view of assignments across the organization

  • Assign roles on onboarding: select and assign Google Workspace roles to a user directly from Corma, no need to switch to the Google admin console

  • Remove roles on offboarding: remove specific roles from a user selectively or all at once, ensuring access is fully revoked without leaving Corma

Teams managing Google Workspace will save significant time during both onboarding and offboarding, with role management now fully centralized in Corma.


On-the-fly user and team creation

Corma now supports on-the-fly creation of both users and teams directly from where you need them, eliminating unnecessary context switches during key workflows.

  • Create users on the spot: when assigning an app owner, matching a license, or any other assignment dropdown, admins can now create a new user directly inline without leaving the current workflow

  • Create teams on the spot: when adding, onboarding, or offboarding a user, admins can create a new team directly from the Team dropdown without navigating to Settings first

Teams managing frequent onboarding and access assignment will spend less time jumping between pages, keeping their focus on the task at hand.


Silent login for browser extension

Corma's browser extension now supports silent authentication across all major browsers, so users are automatically logged in without any manual sign-in step.

  • Edge: silent login now supported for Microsoft Edge users

  • Firefox: silent login now supported for Firefox users

  • Chromium-based browsers: silent login now supported across all Chromium-based browsers including Chrome, Brave, and Arc

Users across your organization will experience a smoother, frictionless extension setup. No more manual login prompts every time the extension is installed or the session expires.


Improvements:

  • Admins can now configure Clicker Agent integrations using Okta or JumpCloud SSO credentials, expanding compatibility for organizations using these identity providers

  • All integration cards in the app are now fully scrollable, fixing a display issue where content was previously cropped.


Fixes:

  • Spendesk integration skipping newly added companies has been fixed

  • Onboarding and offboarding status badges now display all statuses correctly

  • Critical bug removing all Slack group members when modifying a single user has been fixed

  • Qonto sync error has been resolved

  • Microsoft & Google licenses appearing unmatched after first sync have been fixed

  • Conflict with React DevTools Chrome extension has been resolved

  • Claude AI integration add/remove user scripts now work correctly

  • Missing Slack license not appearing in Corma has been fixed

  • Revoking unassigned licenses now correctly reflects the real outcome

  • FXBO automated offboarding failure due to interface change is being investigated

  • Re-adding an offboarded Slack user now correctly reactivates their existing account


Editable license grant details & Snowflake Integration

License grant details: auto-fill & inline editing

When manually logging a license in Corma, the 'Granted at' and 'Granted by' fields now auto-fill with smart defaults and remain editable at any time.

  • Auto-filled on creation: both fields default to today's date and the current user when adding a license, eliminating manual entry in the most common scenario

  • Editable after the fact: clicking either field in the license table opens a dedicated modal to update the date or reassign the 'granted by' user at any time

Available wherever licenses can be manually logged, on the app-specific page, user-specific page, and main licenses page.


Integration:

Corma now integrates with Snowflake!

Snowflake is a cloud data platform designed to centralize, store, and analyze large volumes of data across an organization's entire data infrastructure. You can now:

  • Collect user information: track Snowflake users and their details directly in Corma


Improvements:

  • When setting up a Clicker Agent card with Google SSO, passwords can now be copied and pasted instead of typed manually.

  • A new Slack action allows admins to automatically add a user to a specific channel as part of their provisioning workflow.


Fixes:

  • Slack interactivity crashes on certain actions have been fixed

  • ClickUp credentials incorrectly flagged as invalid due to missing profile picture have been fixed

  • Broken Notion license sync has been restored

  • Desktop app activity on Windows not being recorded after sync has been fixed

  • Microsoft account connection failing for first-time Microsoft sign-ins has been resolved

  • Several user creation flow issues including mislabeled button and broken pre-fill have been fixed

  • Ghost accounts incorrectly appearing during access reviews have been removed

  • Microsoft user group sync now correctly includes nested sub-group members

  • Diabolocom integration has been repaired

  • Jamf license sync failure caused by unexpected email formats has been fixed

  • Active licenses incorrectly shown as inactive on the Contracts page have been fixed

  • New employee onboarding issues with group memberships and bundle assignments have been resolved

  • Bundle drawer dropdowns randomly becoming unclickable have been fixed


Setup default (de)provisioning actions & sign out Google users

Default (de)provisioning actions

Admins can now define default provisioning and deprovisioning actions per app, so every time access is granted or revoked, the right method is already pre-configured.

  • Three methods available: manual task, automated via API (with a mini workflow builder to chain actions), or automated via Agent

  • Applied everywhere: default actions are respected across app settings, manual license revocation, and offboarding flows, for both onboarding and offboarding

To configure, open any app page → settings icon (top left) → Provisioning tab.

Teams managing access at scale will spend less time on repetitive configuration, with the confidence that the right actions always trigger automatically.


Sign out Google users from all sessions

Admins can now instantly sign out a user from all their devices and active web sessions directly from Corma, as part of a Google offboarding flow.

  • One-click session revocation: triggering this action immediately disconnects the user from all Google web sessions and devices, ensuring access is cut off the moment offboarding begins

A simple but critical addition for teams who need to act fast when an employee leaves.


Light improvement

  • Corma now supports Okta SSO, allowing users to sign in with their existing Okta credentials for a faster and more secure login experience.

  • User search dropdowns now support infinite scroll and smarter sorting, active users first, archived at the bottom, with a 'No Assignee' option where relevant.


Fixes

  • Claude AI license retrieval bug has been investigated and resolved

  • Google SSO login issues have been fixed

  • Multiple bugs in provisioning/deprovisioning workflows including silent failures, missing task logs, incorrect email notifications and UI issues have been resolved

  • Several Bundles and User Groups bugs causing unexpected modal closures, random deselections, unclickable areas and screen flickering have been fixed

  • Incorrect title and button on the access review page have been fixed

  • User selection dropdown now correctly shows active users first, followed by archived ones, and no longer gets stuck on partial lists

  • Two-click bug and missing loading indicator in the onboarding user creation step have been fixed

  • Multiple User Groups and Bundles bugs including broken search, unresponsive clicks, hidden save buttons and password manager interference have been resolved

  • Excessive scrolling beyond content on the access review page has been fixed

  • Large user and activity exports failing due to outdated export system have been resolved

  • Missing option to create a new license type or role on the spot when manually adding a license has been added

  • Confusing technical error when adding an already existing internal app now shows a clear helpful message

  • OpenAI license data sync error has been fixed