Skip to main content

Why Active Employees May Appear as Former Employees in Drata

Updated yesterday

Personnel records in Drata reflect the information provided through connected systems and configuration settings. When users appear as Former Employee or do not appear in the Personnel list, the status is a direct result of the data received from integrated sources or group inclusion settings.

The following sections outline the conditions that lead to these outcomes and the actions administrators can take to address them.

Conditions That Affect Personnel Status

1. Group Sync Configuration

When Group Sync is enabled, Drata imports only the users who belong to the selected group(s). Group Sync rules are applied during:

  • Daily automated syncs: Drata retrieves updated user information from connected IdP/HRIS systems each day.

  • Manual personnel resyncs: Administrators can trigger a resync from Connections → Identity Provider or HRIS → Resync Personnel.

  • Initial setup: Group Sync is applied immediately when it is first enabled during the connection process and the selected groups are saved.

After any of these sync processes run, users who are not included in the synced groups, or who have been removed from those groups, are reflected in Drata according to the current group configuration and may appear as Former Employee.

2. Identity Provider (IdP) or HRIS Connectivity

Drata presents personnel data based on the information retrieved from connected systems. If an IdP or HRIS connection becomes inactive, loses authentication, or is unable to sync:

  • Current user information may not be available

  • Users may appear as Former Employee

  • Users may transition into an Unknown status if no data can be retrieved

Reconnecting the system or performing a personnel resync typically restores the most recent user details.

3. Profile or Field Mismatches Between Systems

Differences in key profile attributes, such as email addresses, employment status fields, or user identifiers, between your IdP and HRIS can affect how users are matched and displayed in Drata. Incomplete or inconsistent data may result in users appearing under an unexpected status or not appearing in the Personnel list.

Steps to Update Personnel Status

Step 1: Review Group Sync Settings

  • Confirm that the correct groups are selected for syncing.

  • Ensure that all intended users remain members of the synced groups.

Step 2: Reconnect the IdP and/or HRIS

  • Verify that each integration is connected and authenticated. Re-authenticate credentials if they have expired or changed.

  • After reconnecting, trigger a Personnel Resync to refresh user data.

Step 3: Align Profile Fields Across Systems

  • Compare user profiles in both the IdP and HRIS.

  • Ensure that key fields (email, employee ID, employment status) are complete and aligned.

  • Update any mismatched fields and perform a resync.


Preventative Measures

To maintain accurate personnel records:

  • Review Group Sync settings regularly and remove outdated groups.

  • Monitor integration health to avoid unexpected disconnections or expired credentials.

  • Periodically audit user data across identity and HR systems for consistency.

Step 1: Verify Group Sync Settings

  • Check the inclusion or exclusion criteria of the synced group in Drata.

  • Ensure that all intended users are still part of the synced group to avoid unintended status changes.

Step 2: Reconnect the IdP and/or HRIS

  • Confirm that the connection to your IdP or HRIS is active and valid.

  • Reauthenticate credentials if they have expired.

  • Once reconnected, trigger a personnel resync from Drata to retrieve up-to-date user data.

Step 3: Resolve Field Discrepancies

  • Cross-check user profiles in the HRIS and IdP for consistent and complete data.

  • Ensure fields like email addresses, employee IDs, and employment statuses align between systems.

Preventative Measures

To avoid future issues, consider these best practices:

  1. Regularly audit group sync settings and clean up inactive or outdated groups.

  2. Periodically verify active connections with your IdP and HRIS to prevent unexpected disconnections or expired credentials.

  3. Implement a monitoring system to flag inconsistent or missing profile information across integrated systems.

By addressing the outlined factors and adopting these preventative measures, you can minimize the occurrence of incorrect user statuses in Drata.

Did this answer your question?