BambooHR logo

BambooHR

Access
HR System

Mycroft syncs the BambooHR roster and uses hire and termination dates to evidence onboarding, offboarding, screening and training controls.

Most personnel controls come down to dates: screening before the start date, access removed within the window after departure, training completed in the first month. Mycroft reconciles that roster against every connected system.

How Mycroft connects to BambooHR

How it connects
An administrator authorizes Mycroft through BambooHR OAuth. The grant includes offline_access so the connection refreshes itself.
What Mycroft can access
Read-only. Granted scopes are employee_directory, employee:name, employee:job, employee:contact, access_level, user and report, alongside openid and email.

Which controls BambooHR evidence maps to

Each row is a control an auditor tests and the specific artifact Mycroft collects from BambooHR to satisfy it. Collection runs on a schedule and every result is timestamped.

BambooHR compliance control mappings and the evidence Mycroft collects for each
FrameworkControlWhat it requiresEvidence collected from BambooHR
SOC 2CC1.4The entity attracts, develops and retains competent personnel.Current roster with role, department and manager, used as the population for training completion and role-based access assignment.
SOC 2CC6.2Access is registered and authorized prior to credential issuance.Hire date per employee compared against the creation date of each of their system accounts, proving provisioning followed authorization.
SOC 2CC6.3Access is removed when it is no longer required.Termination date per departure, with the measured interval to removal of every downstream account across connected systems.
SOC 2CC1.1The entity demonstrates a commitment to integrity and ethical values.Completion records for acceptable use and code of conduct acknowledgements, tracked against the live employee roster.
ISO 27001A.6.1Background verification checks are carried out on candidates.Screening completion status per employee compared against their start date, with exceptions identified for review.
ISO 27001A.6.3Personnel receive security awareness education and training.Training assignment and completion measured against the current roster, so leavers do not inflate completion rates and new joiners are not missed.
ISO 27001A.6.5Responsibilities remain defined after termination or change of employment.Termination and role-change events, each linked to the corresponding access removal or modification record.
HIPAA§164.308(a)(5)A security awareness and training program is implemented for the workforce.Training completion for every current workforce member, with the roster sourced from the HRIS rather than a stale spreadsheet.

What Mycroft collects automatically

Gathered from BambooHR on a schedule, dated and stored against the controls above.

  • Employee roster with status, job title, department, manager and employment type
  • Hire dates, used to test that provisioning followed authorization
  • Termination dates, used to compute the offboarding interval per departure
  • Role and department change history, driving access recertification
  • Employee versus contractor classification for scoping personnel controls
  • Policy acknowledgement and training completion tracked against the live roster

Manual work this removes

The tasks that disappear from someone's quarter once BambooHR is connected.

  • Maintaining a parallel employee list outside the HR system
  • Requesting a leaver list from HR for each access review
  • Computing offboarding intervals by hand for sampled departures
  • Tracking training completion against an outdated roster
  • Confirming contractors are in scope for security training

BambooHR and Mycroft: frequently asked questions

Only the fields the controls require: name, work email, job title, department, manager, employment status and type, and hire and termination dates. Compensation, performance reviews, benefits enrollment, health information and bank details are not read and not stored.
It supplies the population. Without an HR source, an access review can only tell you which accounts exist; with one, it can tell you which accounts belong to people who no longer work here. That reconciliation is what turns a list of accounts into a defensible review under SOC 2 CC6.3.
Yes, because frameworks do. Employment type comes across from BambooHR so personnel controls (screening, training, confidentiality agreements) are applied to the right population, and contractors can additionally be scoped into vendor risk management where that is appropriate.
The termination date becomes the clock. Mycroft reconciles it against every connected system and starts measuring the interval to each account's removal, raising a finding if the interval exceeds your stated SLA. If Slack is connected, that finding lands in a channel the same day rather than surfacing at the next review.

We turn the compliance nightmare into a dream

Talk to us