FlowRunner
PricingContact
Theme
Start Free

Automate LastPass Enterprise user lifecycle. Agents bulk-provision employees from an HR source, disable departing users without deleting their vaults, pull login and admin activity reports for compliance, and reach any provisioning command through a raw escape hatch.

6 actions API key available
LastPass website ↗ Platform Documentation ↗ Capability data verified 2026-07-28
An offboarding event fires from the identity system the moment HR marks a departure
Get User Data pulls the LastPass account with its group memberships, admin flag, and status
Admin accounts and members of shared-credential groups are flagged for extended review
Change User Status disables the account, locking the login without touching the vault
Get Detailed Report pulls the departing user's recent login, admin, and vault events for the offboarding file
The security owner decides the vault's final disposition after credential handover, because deletion through Run Command destroys the vault permanently
The offboarding record posts to the security channel and appends to the compliance log

What This Integration Enables

A password manager is the one system where offboarding errors compound in both directions: leave the account enabled and a departed employee still holds the keys; delete it hastily and you destroy credentials the business may have stored nowhere else. LastPass Enterprise separates those outcomes cleanly, disable preserves the vault, deletion does not, and FlowRunner agents automate the lifecycle along exactly that line: provisioning and disabling run on identity events at machine speed, while destruction stays a named human decision. - Bulk-provision employees from an HR or identity source, with group membership assigned per user - Disable departing users the day they leave, preserving vaults for handover, and re-enable on return - Pull login, admin, and vault activity for any date range into compliance logs - Discover valid group names before any assignment references them - Reach any provisioning command through the Run Command escape hatch, gated

Without FlowRunner

Provisioning by invitation email New hires wait days for their vault, and password hygiene starts late or never
Offboarding is a checklist line The departing employee's account stays enabled for weeks because deactivation lives in a document, not a system
Audit data assembled under pressure Activity reports get pulled the day the auditor asks, from whoever remembers how

With FlowRunner

The roster provisions itself Batch Add or Update Users syncs the identity source nightly, with groups assigned by role
Departure locks the vault same-day The HR event disables the account within minutes, and the vault survives for credential handover
A standing audit trail Daily activity reports append to the compliance log, and anomalies escalate the day they occur

Use Case Scenarios

The roster that stays true to the identity source

Nightly, the agent pulls active employees from [Okta](/integrations/okta), calls Get Group List to validate the target group names, and runs Batch Add or Update Users with the full roster: new hires created with role-appropriate groups, changed names and departments updated in place. Day one of employment includes a working vault, and the quarterly access review starts from a roster that already matches HR.

The departure that closes access in minutes

An offboarding workflow fires when the identity system deactivates a user. The agent calls Change User Status to disable the LastPass account immediately, then Get User Data to confirm the state change took. The vault stays intact while the manager reviews what shared credentials the person held, and if the departure reverses, a rehire or a mistake, Change User Status re-enables the account without anything having been lost.

The audit log that is always current

Each morning, Get Detailed Report pulls the prior day's login, admin, and vault events and appends them to the compliance sheet in [Google Sheets](/integrations/google-sheets). Rules watch the stream: failed logins clustering on one account, admin actions outside change windows, exports where none are expected. Matches open an incident in [ServiceNow](/integrations/servicenow) with the events attached. When the auditor asks for six months of activity, the answer is a filter, not a project.

Human-in-Loop Highlight

Run Command reaches every provisioning command the dedicated actions do not wrap, including 'deluser', and deleting a LastPass user deletes their vault: every stored credential, gone, with no API to bring it back. That vault may hold the only record of a service account password or a legacy system login the business forgot it depends on. So FlowRunner flows treat every Run Command payload as a proposal, and destructive commands doubly so: "Offboarding for j.torres complete, account disabled 30 days, handover confirmed by manager. Command 'deluser' will permanently destroy the vault. Execute?" The security owner approves with the handover evidence in front of them. Disabling is automated; the [human-in-the-loop](/concepts/human-in-the-loop) gate stands wherever destruction is on the table.

Agent processes routinely
Detects exception requiring judgment
Clear match Continues automatically
Ambiguous Routes to human via preferred channel
Human decides
Agent resumes with decision

Agent Capabilities

6 actions

Users

3
  • Get User Data Retrieves account details for one user by email or all users at once, including name, admin flag, disabled status, group membership, and provisioning attributes. The roster read behind audits and offboarding checks.
  • Batch Add or Update Users Creates or updates users in bulk from a JSON array, matching existing users by email and setting names, groups, admin flags, disabled state, and provisioning attributes. The synchronization engine between your identity source and LastPass.
  • Change User Status Disables or re-enables a user account. Disabling blocks login without deleting the vault, which is exactly why it is the default offboarding move.

Groups

1
  • Get Group List Returns the groups defined in the account. The validation step before any batch operation assigns membership.

Auditing

1
  • Get Detailed Report Retrieves the activity and audit report for a date range: login, admin, and vault events with timestamps, usernames, and actions. The feed behind compliance logs and anomaly detection.

Escape Hatch

1
  • Run Command Posts any raw Provisioning API command with its data payload and returns the raw response, covering commands like 'batchchange', 'deluser', and 'getsfdata'. The operation this page's human gate exists for.

Frequently Asked Questions

What can FlowRunner do with LastPass?

FlowRunner agents can run Get User Data, Batch Add or Update Users, and Get Group List in LastPass, plus 3 more actions.

Does connecting LastPass to FlowRunner require OAuth?

No. LastPass connects to FlowRunner with an API key, no OAuth flow required.

Can LastPass trigger a FlowRunner workflow automatically?

LastPass doesn't currently expose triggers in FlowRunner. It connects as an action step inside workflows started by another trigger.

Start building with LastPass

$100 in credits. No card required. Connect in minutes.