
Humi
Access
HR System
Mycroft syncs the Humi roster and uses hire and termination dates to evidence onboarding, offboarding, screening and training controls.
Humi is the employment record for many Canadian technology companies. Mycroft reconciles it against every connected system and measures the interval between each departure and the removal of that person's access.
How Mycroft connects to Humi
- How it connects
- You issue a Humi API credential for Mycroft, which you can revoke at any time.
- What Mycroft can access
- Read-only employee directory data.
Which controls Humi evidence maps to
Each row is a control an auditor tests and the specific artifact Mycroft collects from Humi to satisfy it. Collection runs on a schedule and every result is timestamped.
| Framework | Control | What it requires | Evidence collected from Humi |
|---|---|---|---|
| SOC 2 | CC1.4 | Competent personnel are retained and responsibilities are defined. | Current roster with role, department and reporting line, used as the population for personnel and training controls. |
| SOC 2 | CC6.2 | Access is authorized before credentials are issued. | Hire dates compared against account creation timestamps in each connected system. |
| SOC 2 | CC6.3 | Access is removed promptly when no longer needed. | Termination dates with the measured interval to removal of each downstream account, tested against your documented SLA. |
| ISO 27001 | A.6.1 | Background verification checks are performed prior to employment. | Screening completion status per employee relative to their start date, with exceptions raised for review. |
| ISO 27001 | A.6.3 | Security awareness training is delivered and tracked. | Training completion measured against the live roster so new joiners are captured and leavers do not distort the rate. |
| ISO 27001 | A.6.5 | Responsibilities after termination or role change are enforced. | Role change and termination events linked to the corresponding access modification or removal record. |
| ISO 27001 | A.5.11 | Assets are returned on termination of employment. | Termination events reconciled against device management records to confirm issued equipment was returned or wiped. |
What Mycroft collects automatically
Gathered from Humi on a schedule, dated and stored against the controls above.
- Employee roster with status, job title, department, manager and employment type
- Hire dates for provisioning evidence
- Termination dates for offboarding interval measurement
- Role and department change history driving access recertification
- Employee versus contractor classification
- Policy acknowledgement and training completion against the live roster
Manual work this removes
The tasks that disappear from someone's quarter once Humi is connected.
- Requesting a leaver export from HR before each quarterly access review
- Maintaining a duplicate roster outside the HR system
- Calculating offboarding intervals manually for sampled departures
- Tracking training completion against an outdated roster
Humi and Mycroft: frequently asked questions
What data does Mycroft read from Humi?
Does Humi support PIPEDA-aligned compliance work?
Can Humi be combined with an identity provider?
We turn the compliance nightmare into a dream
Talk to us


