Screenata

Integrations / HR & people ops

Screenata + BambooHR

How do you automate SOC 2, ISO 27001, and HIPAA personnel evidence from BambooHR?

Quick answer

BambooHR is where personnel controls are proved: joiner-mover-leaver, screening, and training records. It is the roster auditors sample when they test whether hiring and termination procedures actually ran. An onboarding or offboarding policy existing on paper is not the control. The control is the recorded event plus the record that it operated for every worker across the audit period. Screenata runs 12 native checks against those records on a schedule and turns each result into signed evidence mapped to the control it satisfies.

Screenata connects to BambooHR read-only and runs 12 native checks against your employee records: lifecycle state, onboarding, and offboarding evidence. Joiners trigger training assignment and access checks; leavers trigger verification that access removal actually followed. Each finding becomes a signed, timestamped evidence artifact mapped to SOC 2, HIPAA, and ISO 27001 controls.

12 native checks · read-only · signed evidence

What it proves

BambooHR evidence, mapped to controls.

Each area below is scanned on a schedule. A finding is not a green checkmark: it is a signed artifact an auditor can verify, mapped to the exact requirement it satisfies.
Evidence area
What the checks verify
Maps to
Onboarding

New hires detected from the roster, with security training assigned and policy acknowledgment requested at start.

Per-hire records showing training was assigned and policies acknowledged when employment began.

SOC 2CC6.2HIPAA§164.308(a)(5)ISO 27001A.6.3
Offboarding

Terminations detected from the roster, then verified against identity providers so departed employees no longer hold access.

The termination timeline auditors sample: departure date next to the access removal that followed it.

SOC 2CC6.3HIPAA§164.308(a)(3)(ii)(C)ISO 27001A.6.5
Roster reconciliation

The active-employee roster reconciled against accounts in your identity and SaaS systems.

The ground truth quarterly access reviews start from: every account either belongs to a current employee or gets flagged.

SOC 2CC6.2SOC 2CC6.3

Control references are the requirements each evidence area supports, via the shared control catalog. Your auditor decides sufficiency; the artifacts are theirs to verify.

Compliance checks

What Screenata checks on BambooHR, and why each matters.

Each row is a real native check, the framework control it produces evidence for, and the risk it closes. This is what continuous BambooHR compliance actually looks like. Checks run on a schedule; a failing check opens a ticket and re-verifies after a human applies the fix.
Check & why it matters
Maps to

Terminated Employees Deprovisioned

Verifies every terminated employee has a termination date recorded. Without it the offboarding trail is incomplete and access removal cannot be timed, and an auditor samples leavers to confirm departure was recorded and access followed.

SOC 2CC6.3

Timely Offboarding

Flags employees still marked active past their termination date. A lingering active record means access may not have been revoked on time, and an auditor checks that departures triggered prompt deprovisioning.

SOC 2CC6.3

All Active Employees Have Managers

Confirms active employees have a supervisor assigned. Reporting chains are what access reviews and approvals rely on, and an auditor verifies the org structure needed to attribute responsibility is populated.

SOC 2CC1.3SOC 2CC1.4

All Active Employees Have Departments

Verifies active employees are assigned to a department. Access reviews scope by org unit, so missing departments leave populations unclassified, which an auditor relies on when sampling.

SOC 2CC1.3

Work Email Recorded for Active Employees

Confirms each active employee has a work email. Work email is the primary key that joins HR records to identity provisioning, and an auditor verifies the roster can be reconciled against account access.

SOC 2CC1.4SOC 2CC6.1

Hire Date Recorded for Active Employees

Verifies each active employee has a hire date. The hire date anchors the onboarding trail and the start of access, and an auditor samples it to confirm employment records are complete.

SOC 2CC1.4

Worker Classification Recorded

Confirms active employees have an employment type recorded. Access reviews segment employees from contractors, and without a type the population cannot be partitioned cleanly, which an auditor depends on when sampling.

SOC 2CC1.3

NDA Signed for Active Employees

Verifies each active employee has a recorded NDA signature date. A signed confidentiality agreement is a personnel control auditors sample, and a missing NDA leaves a worker with access but no binding obligation.

SOC 2CC1.2SOC 2CC1.4

Background Check Completed for Active Employees

Confirms active employees completed pre-employment screening. Screening is the competence control auditors sample per hire, and a missing background check means someone gained access without vetting.

SOC 2CC1.4

Security Training Completed for Active Employees

Verifies each active employee completed security or HIPAA training within the past twelve months. Lapsed training raises phishing and social-engineering risk, and an auditor checks that workforce awareness training is current.

HIPAA§164.308(a)(5)HIPAA§164.308(a)(5)(i)ISO 27001A.6.3

Drawn from Screenata’s BambooHR check library. Control refs are the requirements each check produces evidence for; your auditor decides sufficiency.

How it connects

Read-only, revocable, yours.

You create a read-scoped API key and Screenata uses it for scheduled scans. Vera never receives write access to your HR records, and credentials never touch the Screenata database. Findings are hashed and stored as evidence the moment they land.

Read-only by construction

OAuth scopes and IAM roles are scoped to read. Vera never gets write access to your systems.

Signed findings

SHA-256 per artifact, RSA/ECDSA signatures, RFC 3161 timestamps. Verifiable without a Screenata account.

Mapped to controls

Each finding lands on the shared control catalog, so one scan satisfies SOC 2, HIPAA, and ISO 27001 at once.

BAA & attestation status

BambooHR handles employee data rather than PHI in most deployments, so a BAA is usually not the relevant instrument. A data processing agreement is. If your HR system does hold PHI, confirm BAA availability with BambooHR directly.

BambooHR FAQ

What teams ask before connecting.

Full provider list on the integrations page.
What access does Screenata need to BambooHR?

A read-scoped API key that you create and control. Screenata reads roster and lifecycle data for scheduled checks and never receives write access to your HR records. You can revoke the key at any time.

How does BambooHR help with offboarding evidence?

The integration detects the termination event, checks that access removal followed in your connected identity systems, and records the timeline as signed evidence. A human performs the actual revocation; Vera verifies it happened and chases it if it did not.

Does connecting BambooHR expose salary data?

The checks use lifecycle and roster data: who is active, who started, who left. Scope the API key to what the checks need; compensation details are not part of any check.

What are the steps to implement SOC 2 with BambooHR?

Connect BambooHR read-only with a scoped API key. Let the first scan establish a baseline so you can see which records are complete and which are not. Fix what fails: record termination dates for every leaver and clear anyone still marked active past that date, complete background checks for active employees, keep security training current within the past twelve months, capture signed NDAs, and fill in the manager, department, work email, hire date, and worker classification fields the roster depends on. Collect the passing results as signed evidence on a schedule, so you hold coverage across the whole audit period rather than one snapshot. Then hand the evidence package to an independent auditor. The audit is a separate engagement with a CPA firm; Screenata prepares the evidence and does not issue the report.

What evidence do auditors ask for about onboarding and offboarding?

They sample hires and leavers. For each hire they expect a start date with the training and policy acknowledgments that followed it, and screening completed before access was granted. For each leaver they expect a termination date with the access removal that followed it. Timing is what gets tested, not just existence. A completed background check dated after the start date, or an account disabled two weeks after the departure, is a finding even though the record exists.

Do auditors accept evidence Screenata collects from BambooHR?

Yes. Every finding is exported as a signed, timestamped artifact, a SHA-256 hash with an RSA or ECDSA signature and an RFC 3161 timestamp, that an auditor verifies outside Screenata with a free CLI. A person reviews and approves the evidence before it reaches the auditor. Screenata collects and signs it; it does not decide the audit result.

Connect and see

Fifteen minutes after connecting BambooHR, you know your real posture.

Pricing

Related: Gusto · Rippling · Checkr · Okta