Deel logo

Deel

AccessPeople
HR System

Mycroft syncs the Deel worker roster so internationally engaged staff and contractors fall inside the same personnel controls as everyone else.

An auditor sampling departures does not distinguish between employing entities. Mycroft merges Deel with any other connected HR source into a single workforce population and measures offboarding from each contract end date.

How Mycroft connects to Deel

How it connects
You authorize Mycroft through Deel OAuth.
What Mycroft can access
Read-only. Granted scopes are Users:read, people:read and organizations:read.

Which controls Deel evidence maps to

Each row is a control an auditor tests and the specific artifact Mycroft collects from Deel to satisfy it. Collection runs on a schedule and every result is timestamped.

Deel compliance control mappings and the evidence Mycroft collects for each
FrameworkControlWhat it requiresEvidence collected from Deel
SOC 2CC1.4The entity retains competent personnel and defines their responsibilities.Global worker roster with role, team and engagement type, forming the population for personnel and training controls.
SOC 2CC6.2Access is authorized before credentials are issued.Contract start date per worker compared with the creation timestamp of each system account they hold.
SOC 2CC6.3Access is removed when no longer needed.Contract end dates for terminated engagements, with the measured interval to removal of each downstream account.
SOC 2CC9.2Risks associated with vendors and business partners are managed.Contractor population identified separately, so engagements that should sit inside vendor risk management are visible rather than assumed to be employees.
ISO 27001A.6.1Background verification is proportionate and completed before engagement.Screening status per worker against their contract start date, across every jurisdiction in the roster.
ISO 27001A.6.2Employment terms state information security responsibilities.Confidentiality and acceptable-use acknowledgement status per worker, tracked against the live contract roster.
ISO 27001A.6.5Post-termination responsibilities are defined and enforced.Contract end events linked to access removal records and to asset return where equipment was issued.
HIPAA§164.308(a)(3)Workforce security procedures cover authorization, supervision and termination.Complete workforce roster including internationally engaged staff, with termination dates driving access revocation evidence.

What Mycroft collects automatically

Gathered from Deel on a schedule, dated and stored against the controls above.

  • Global worker roster spanning employees of record, contractors and direct employees
  • Contract type and status per worker, with country of engagement
  • Start dates for provisioning evidence and end dates for offboarding intervals
  • Role and team assignment, driving role-based access expectations
  • Contractor versus employee classification for correct control scoping
  • Policy acknowledgement and training completion measured against the live roster

Manual work this removes

The tasks that disappear from someone's quarter once Deel is connected.

  • Merging the domestic HRIS and EOR rosters before each access review
  • Accounting for internationally engaged staff omitted from the training population
  • Confirming offboarding for contractors whose engagement has ended
  • Rebuilding the workforce list each quarter

Deel and Mycroft: frequently asked questions

No. The integration reads directory-level fields only: name, work email, contract type and status, role, team, country and engagement dates. Rates, invoices, payments, tax forms and identity documents are outside its scope.
Yes, and that is the common configuration. With a domestic HRIS and Deel both connected, Mycroft merges them into a single workforce population, deduplicating anyone who appears in both. Personnel controls then cover everyone, which is what an auditor's sample assumes.
Contract end dates give international departures the same termination clock as domestic ones. Mycroft measures the interval from each end date to the removal of every downstream account, so an EOR-employed engineer's GitHub access is evidenced to the same standard as anyone else's.
It depends on the control, and Mycroft keeps the distinction available. Contractors with system access belong in access reviews and security training; contracting entities may also warrant vendor risk assessment under SOC 2 CC9.2. Because engagement type comes across from Deel, you can scope each control correctly rather than guessing.

We turn the compliance nightmare into a dream

Talk to us