Humi logo

Humi

Access
HR System

Mycroft syncs the Humi roster and uses hire and termination dates to evidence onboarding, offboarding, screening and training controls.

Humi is the employment record for many Canadian technology companies. Mycroft reconciles it against every connected system and measures the interval between each departure and the removal of that person's access.

How Mycroft connects to Humi

How it connects
You issue a Humi API credential for Mycroft, which you can revoke at any time.
What Mycroft can access
Read-only employee directory data.

Which controls Humi evidence maps to

Each row is a control an auditor tests and the specific artifact Mycroft collects from Humi to satisfy it. Collection runs on a schedule and every result is timestamped.

Humi compliance control mappings and the evidence Mycroft collects for each
FrameworkControlWhat it requiresEvidence collected from Humi
SOC 2CC1.4Competent personnel are retained and responsibilities are defined.Current roster with role, department and reporting line, used as the population for personnel and training controls.
SOC 2CC6.2Access is authorized before credentials are issued.Hire dates compared against account creation timestamps in each connected system.
SOC 2CC6.3Access is removed promptly when no longer needed.Termination dates with the measured interval to removal of each downstream account, tested against your documented SLA.
ISO 27001A.6.1Background verification checks are performed prior to employment.Screening completion status per employee relative to their start date, with exceptions raised for review.
ISO 27001A.6.3Security awareness training is delivered and tracked.Training completion measured against the live roster so new joiners are captured and leavers do not distort the rate.
ISO 27001A.6.5Responsibilities after termination or role change are enforced.Role change and termination events linked to the corresponding access modification or removal record.
ISO 27001A.5.11Assets are returned on termination of employment.Termination events reconciled against device management records to confirm issued equipment was returned or wiped.

What Mycroft collects automatically

Gathered from Humi on a schedule, dated and stored against the controls above.

  • Employee roster with status, job title, department, manager and employment type
  • Hire dates for provisioning evidence
  • Termination dates for offboarding interval measurement
  • Role and department change history driving access recertification
  • Employee versus contractor classification
  • Policy acknowledgement and training completion against the live roster

Manual work this removes

The tasks that disappear from someone's quarter once Humi is connected.

  • Requesting a leaver export from HR before each quarterly access review
  • Maintaining a duplicate roster outside the HR system
  • Calculating offboarding intervals manually for sampled departures
  • Tracking training completion against an outdated roster

Humi and Mycroft: frequently asked questions

Directory fields only: name, work email, job title, department, manager, employment status and type, and hire and termination dates. Compensation, benefits, time-off and personal identifiers beyond work contact details are not accessed.
The roster supports the personnel side of any framework, PIPEDA included. Accountability and safeguards obligations rest on knowing who has access to personal information and removing it when they leave, which is what an accurate HR roster reconciled against system accounts provides.
Yes, and it should be. Humi answers who works here and when they started or left; the identity provider answers what they can reach. Mycroft joins the two so every account traces to a current employee, and any account that doesn't is surfaced as an orphan.

We turn the compliance nightmare into a dream

Talk to us