Integrations / HR & people ops
How do you automate SOC 2, ISO 27001, and HIPAA personnel evidence from Rippling?
Quick answer
Rippling is where personnel controls are proved: joiner-mover-leaver, screening, and training records, plus the device posture that goes with each worker. The active roster is the population auditors sample when they test whether hiring and termination procedures actually ran. An onboarding or offboarding policy existing on paper is not the control. The control is the recorded event plus the record that it operated for every employee across the audit period. Screenata runs 8 native checks against those records on a schedule and turns each result into signed evidence mapped to the control it satisfies.
Screenata connects to Rippling read-only and runs 8 native checks against your workforce records: employee lifecycle and device management state. Because Rippling spans HR and devices, one connection evidences both the joiner-mover-leaver record and the device posture your policies claim. Each finding is a signed, timestamped artifact mapped to SOC 2, HIPAA, and ISO 27001 controls.
8 native checks · read-only · signed evidence
What it proves
Rippling evidence, mapped to controls.
Hires and terminations detected from the roster, triggering training assignment on start and access verification on departure.
The joiner-mover-leaver record auditors sample, with each event tied to the security action that followed.
Device posture for managed endpoints: whether the devices holding company data meet the requirements your policies set.
Per-device findings supporting the endpoint controls your system description names.
The active roster reconciled against accounts in identity and SaaS systems.
The ground truth quarterly access reviews start from: accounts without a current employee get flagged.
Control references are the requirements each evidence area supports, via the shared control catalog. Your auditor decides sufficiency; the artifacts are theirs to verify.
Compliance checks
What Screenata checks on Rippling, and why each matters.
Terminated Employees Deprovisioned
Verifies terminated employees have an end date and are marked inactive. Without it access removal cannot be timed and the offboarding trail is incomplete, and an auditor samples leavers to confirm departure was recorded.
All Employees Have Managers
Confirms active employees have a manager assigned. Reporting chains underpin access approvals and reviews, and an auditor verifies the org structure needed to attribute responsibility is populated.
All Employees Have Departments
Verifies active employees are assigned to a department. Access reviews scope by org unit, so missing departments leave populations unclassified, which an auditor relies on when sampling.
Onboarding Records Complete
Confirms active employees have start dates and work emails. These anchor the onboarding trail and link the roster to provisioning, and an auditor samples hires to confirm records are complete.
Timely Offboarding
Flags active employees carrying a past end date. The mismatch means a departure was not finalized and access may still be live, and an auditor checks that offboarding closed out on time.
Device Encryption Enabled
Verifies managed devices have disk encryption on. An unencrypted laptop exposes company data if lost or stolen, and an auditor checks that endpoints holding data enforce encryption at rest.
Device Password Set
Confirms managed devices require a password or passcode. A device with no lock screen gives anyone physical access to its data, and an auditor verifies endpoint access controls are enforced.
Rippling Managed-Device Inventory
Enumerates every managed device with its owner and platform to build the endpoint asset register. Unmanaged or unassigned devices escape hardening and audit scope, and an auditor checks the asset register is complete and system-generated.
Drawn from Screenata’s Rippling check library. Control refs are the requirements each check produces evidence for; your auditor decides sufficiency.
How it connects
Read-only, revocable, yours.
Read-only by construction
OAuth scopes and IAM roles are scoped to read. Vera never gets write access to your systems.
Signed findings
SHA-256 per artifact, RSA/ECDSA signatures, RFC 3161 timestamps. Verifiable without a Screenata account.
Mapped to controls
Each finding lands on the shared control catalog, so one scan satisfies SOC 2, HIPAA, and ISO 27001 at once.
What access does Screenata need to Rippling?
A read-only API connection that you authorize and control. Screenata reads lifecycle and device state for scheduled checks and never receives write access. You can revoke the connection at any time.
How does Rippling help with offboarding evidence?
The integration detects the termination, checks that access removal and device return followed, and records the timeline as signed evidence. A human performs the actual revocation and collection; Vera verifies and chases them.
Does the device data satisfy HIPAA device controls?
It evidences them. HIPAA §164.310(d) expects you to govern the devices holding ePHI, and Rippling's managed-device posture is direct evidence that governance operates. Your policies and the rest of the program supply the remaining pieces.
What are the steps to implement SOC 2 with Rippling?
Connect Rippling read-only and authorize the API connection. Let the first scan establish a baseline so you can see which records are complete and which are not. Fix what fails: record an end date and mark every terminated employee inactive, clear anyone still active past their end date, complete start dates and work emails on the onboarding records, assign a manager and department to every active employee, and on the device side turn on disk encryption, require a device password, and account for every managed device in the inventory. Collect the passing results as signed evidence on a schedule, so you hold coverage across the whole audit period rather than one snapshot. Then hand the evidence package to an independent auditor. The audit is a separate engagement with a CPA firm; Screenata prepares the evidence and does not issue the report.
What evidence do auditors ask for about onboarding and offboarding?
They sample hires and leavers. For each hire they expect a start date with the training and policy acknowledgments that followed it, and screening completed before access was granted. For each leaver they expect a termination date with the access removal, and with Rippling the device return, that followed it. Timing is what gets tested, not just existence. A laptop collected a month after the departure, or an account disabled two weeks late, is a finding even though the record exists.
Do auditors accept evidence Screenata collects from Rippling?
Yes. Every finding is exported as a signed, timestamped artifact, a SHA-256 hash with an RSA or ECDSA signature and an RFC 3161 timestamp, that an auditor verifies outside Screenata with a free CLI. A person reviews and approves the evidence before it reaches the auditor. Screenata collects and signs it; it does not decide the audit result.