Screenata

Integrations / HR & people ops

Screenata + Gusto

How do you automate SOC 2, ISO 27001, and HIPAA personnel evidence from Gusto?

Quick answer

Gusto is where personnel controls are proved: joiner-mover-leaver, screening, and training records. The payroll-derived roster is the population auditors sample when they test whether hiring and termination procedures actually ran. An onboarding or offboarding policy existing on paper is not the control. The control is the recorded event plus the record that it operated for every employee across the audit period. Screenata runs 10 native checks against those records on a schedule and turns each result into signed evidence mapped to the control it satisfies.

Screenata connects to Gusto read-only and runs 10 native checks against your employee records: lifecycle state and payroll-derived rosters. The active roster becomes the ground truth that access reviews and offboarding checks reconcile against. Each finding is a signed, timestamped evidence artifact mapped to SOC 2, HIPAA, and ISO 27001 controls.

10 native checks · read-only · signed evidence

What it proves

Gusto evidence, mapped to controls.

Each area below is scanned on a schedule. A finding is not a green checkmark: it is a signed artifact an auditor can verify, mapped to the exact requirement it satisfies.
Evidence area
What the checks verify
Maps to
Employee lifecycle

Hires and terminations detected from the roster, triggering training assignment on start and access verification on departure.

Per-event records connecting employment changes to the security actions that must follow them.

SOC 2CC6.2SOC 2CC6.3HIPAA§164.308(a)(3)
Active-roster reconciliation

The payroll-derived active-employee list reconciled against accounts in identity and SaaS systems.

The authoritative roster access reviews start from: accounts without a matching current employee get flagged.

SOC 2CC6.3ISO 27001A.5.16
Employment records

Employment records available as evidence when auditors sample personnel controls.

Start dates and roles supporting the personnel evidence requests that come with every audit.

SOC 2CC1.4

Control references are the requirements each evidence area supports, via the shared control catalog. Your auditor decides sufficiency; the artifacts are theirs to verify.

Compliance checks

What Screenata checks on Gusto, and why each matters.

Each row is a real native check, the framework control it produces evidence for, and the risk it closes. This is what continuous Gusto compliance actually looks like. Checks run on a schedule; a failing check opens a ticket and re-verifies after a human applies the fix.
Check & why it matters
Maps to

Terminated Employees Deprovisioned

Verifies terminated employees have a termination record with an effective date. Without it the offboarding trail is incomplete and access removal cannot be timed, and an auditor samples leavers to confirm departure was recorded.

SOC 2CC6.3

Timely Offboarding

Flags non-terminated employees carrying a past termination date. The mismatch means a departure was not finalized and access may still be live, and an auditor checks that offboarding closed out on time.

SOC 2CC6.3

All Active Employees Have Managers

Confirms active employees have a manager assigned. Reporting chains underpin access approvals and reviews, and an auditor verifies the org structure needed to attribute responsibility is populated.

SOC 2CC1.3SOC 2CC1.4

All Active Employees Have Departments

Verifies active employees are assigned to a department. Access reviews scope by org unit, so missing departments leave populations unclassified, which an auditor relies on when sampling.

SOC 2CC1.3

All Active Employees Have Current Jobs

Confirms each active employee has a current job with a title. Job titles map workers to expected access, and without them role-based reviews lose the reference point an auditor checks against.

SOC 2CC1.3

Work Email Recorded for Active Employees

Verifies each active employee has an email on file. Email is the primary identifier that joins the roster to identity provisioning, and an auditor verifies accounts can be reconciled against current employees.

SOC 2CC1.4SOC 2CC6.1

Onboarding Complete for Active Employees

Confirms started employees completed onboarding with a hire date. Incomplete onboarding leaves the provisioning trail open, and an auditor samples hires to confirm records are complete before access.

SOC 2CC1.4

Worker Classification Recorded

Verifies active workers have an employment type recorded. Access reviews segment employees from contractors, and without a recorded type the population cannot be partitioned cleanly, which an auditor depends on when sampling.

SOC 2CC1.3

Gusto Admin Count Reasonable

Checks that the number of Gusto admins stays consistent with least privilege. Excess admins over-expose payroll and personnel data, and an auditor verifies privileged access is limited to a narrow, documented group.

SOC 2CC6.1

Drawn from Screenata’s Gusto check library. Control refs are the requirements each check produces evidence for; your auditor decides sufficiency.

How it connects

Read-only, revocable, yours.

You authorize a read-only connection and Screenata uses it for scheduled scans. Vera never receives write access to your payroll or HR records, and credentials never touch the Screenata database.

Read-only by construction

OAuth scopes and IAM roles are scoped to read. Vera never gets write access to your systems.

Signed findings

SHA-256 per artifact, RSA/ECDSA signatures, RFC 3161 timestamps. Verifiable without a Screenata account.

Mapped to controls

Each finding lands on the shared control catalog, so one scan satisfies SOC 2, HIPAA, and ISO 27001 at once.

Gusto FAQ

What teams ask before connecting.

Full provider list on the integrations page.
What access does Screenata need to Gusto?

A read-only connection that you authorize and control. Screenata reads roster and lifecycle data for scheduled checks and never receives write access. You can revoke the connection at any time.

How does Gusto help with offboarding evidence?

The integration detects the termination in the roster, checks that access removal followed in your connected identity systems, and records the timeline as signed evidence. A human performs the actual revocation; Vera verifies and chases it.

Does Screenata read compensation data?

The checks use lifecycle and roster data: who is active, who started, who left. Compensation details are not part of any check.

What are the steps to implement SOC 2 with Gusto?

Connect Gusto read-only and authorize the connection. Let the first scan establish a baseline so you can see which records are complete and which are not. Fix what fails: record a termination with an effective date for every leaver and clear anyone still carrying a past termination date, complete onboarding with a hire date for each started employee, fill in the manager, department, current job title, work email, and worker classification fields the roster depends on, and keep the Gusto admin count consistent with least privilege. Collect the passing results as signed evidence on a schedule, so you hold coverage across the whole audit period rather than one snapshot. Then hand the evidence package to an independent auditor. The audit is a separate engagement with a CPA firm; Screenata prepares the evidence and does not issue the report.

What evidence do auditors ask for about onboarding and offboarding?

They sample hires and leavers. For each hire they expect a start date with the training and policy acknowledgments that followed it, and screening completed before access was granted. For each leaver they expect a termination date with the access removal that followed it. Timing is what gets tested, not just existence. A training record dated after the employee already had production access, or an account disabled two weeks after the departure, is a finding even though the record exists.

Do auditors accept evidence Screenata collects from Gusto?

Yes. Every finding is exported as a signed, timestamped artifact, a SHA-256 hash with an RSA or ECDSA signature and an RFC 3161 timestamp, that an auditor verifies outside Screenata with a free CLI. A person reviews and approves the evidence before it reaches the auditor. Screenata collects and signs it; it does not decide the audit result.

Connect and see

Fifteen minutes after connecting Gusto, you know your real posture.

Pricing

Related: BambooHR · Deel · Rippling · Okta